SunQuest
           Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #1  
Old December 17th, 2004, 04:29 AM
Fslemko Fslemko is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 5 Fslemko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
100% CPU usage help!

Please forgive me, I am not exactly computer literate to a fashion in the way many of you are.

Recently, my CPU usage has been jumping to 75%+ without me doing a single thing, even if I am to restart the PC, it will continue doing so.

It usually stops in several hours, but I can't wait that long every day!

I use my PC for online gaming, it's an AMD Athlon 2500+ with a Radeon 9700. I have Windows XP '04 and have downloaded every update of late.

If I could get any suggestions or any help, please post!

If you need any more information from my PC, please instruct me!

PLEASE HELP

Reply With Quote
  #2  
Old December 17th, 2004, 07:07 AM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(^^;?(Usually it is because of Trojan backdoor.)

Download Hijackthis and post that log to ANTIVIRUS FORUM.

And post here its url only.

Take a look at Task manager again. What process or programs are using CPU?

Reply With Quote
  #3  
Old December 17th, 2004, 01:52 PM
Fslemko Fslemko is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 5 Fslemko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Quote:
Originally Posted by megumi amatuka
Take a look at Task manager again. What process or programs are using CPU?


The programs using the CPU fluctuate, it varies at time to time.. (Explorer.exe jumps up, svchost.exe jumps up, and of course System Idle Process is usually at 99.)

I will post the Hijack this log and put the URL up.

Thank you!

And here's the Hijackthis log~

http://forums.devshed.com/showthread.php?p=913619#post913619

Reply With Quote
  #4  
Old December 17th, 2004, 01:55 PM
Fslemko Fslemko is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 5 Fslemko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
100% CPU usage Hijackthis log.

Hey~ I was told to send a Hijackthis log to this forum, if you find anything wrong, please tell me!

Logfile of HijackThis v1.99.0
Scan saved at 11:52:33 AM, on 12/17/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\DOCUME~1\h\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [Spyware Stormer] C:\Program Files\Spyware Stormer\SpywareStormer.Exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe

Thank you!

Reply With Quote
  #5  
Old December 17th, 2004, 02:29 PM
balamm's Avatar
balamm balamm is offline
Permanently Banned
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Mar 2004
Posts: 1,742 balamm User rank is Corporal (100 - 500 Reputation Level)balamm User rank is Corporal (100 - 500 Reputation Level)balamm User rank is Corporal (100 - 500 Reputation Level)balamm User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 6 Days 12 h 8 m 2 sec
Warnings Level: 10
Number of bans: 1
Reputation Power: 0
System Idle Process is supposed to be at 99%.

that means the system (CPU) is 99% idle

if other things are high, note those here.

your logs look good actually.

Do you have indexing enabled? Something like that might account for a daily period of high activity or high activity after a reboot. If you don't use the search dialogue often, turn indexing off.

Last edited by balamm : December 17th, 2004 at 02:32 PM.

Reply With Quote
  #6  
Old December 17th, 2004, 02:38 PM
Fslemko Fslemko is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 5 Fslemko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Quote:
Originally Posted by balamm
Do you have indexing enabled? Something like that might account for a daily period of high activity or high activity after a reboot. If you don't use the search dialogue often, turn indexing off.


As said before, I'm not very literate when it comes to computers.. Indexing, could you help me out on figuring how to turn it off?

Reply With Quote
  #7  
Old December 17th, 2004, 03:23 PM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(Oo;?(Such a short log is also out of common or may be too common?)

For my opinion, it's too much out of problems.

Tere may be some suggestions from AntiVirus Section though, I think the likely culprit is nothing but SP2.

C:\WINDOWS\system32\wscntfy.exe is Security Center Notification from SP2. Adjustment seems possible by Control Panel. <--(^^;(I prepared SP2, but not yet installed, since I'm afraid.)

Possible solutions I consider for you for the moment are as follows:

Try to disable wscntfy.exe by "msconfig">Process or Start up, otherwise admin tools> services

Uninstall SP2

Upgrade bios and any drivers in order to support SP2 as far as you can.

Though there even seems to be the report that some AMD is not compatible with SP2, no ways or unreliable even if it is the most direct suggestion..

Reply With Quote
  #8  
Old December 19th, 2004, 05:35 AM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 36 m 40 sec
Reputation Power: 92
Quote:
Originally Posted by Fslemko
http://forums.devshed.com/showthread.php?p=913619#post913619


Threads merged
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
  #9  
Old December 21st, 2004, 04:15 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Hi Fslemko,

Please rescan with HijackThis and post a fresh log for final review.

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #10  
Old December 23rd, 2004, 01:23 AM
Fslemko Fslemko is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 5 Fslemko User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Logfile of HijackThis v1.99.0
Scan saved at 12:19:00 AM, on 12/23/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\s\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103578272671
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe



You'll notice some differences, I downloaded a driver for ATI catalyst, installed a radeon 9250, added another 512 of ram. Still, no improvement.

When looking over taskmanager it seems the perpetrators are a few things; spoolsv.exe (not as much), explorer.exe, and svchost.exe (under user name SYSTEM).

I've scrubbed this thing clean, and the problem still doesn't go away (hardware? ) so any suggestions or advice would be greatly appreciated.

Reply With Quote
  #11  
Old December 23rd, 2004, 03:46 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 13
Hi Fslemko,

Your log is clean.

As balamm has already pointed out, some CPU usage is normal. Service Pack 2 has added more overhead to our systems also.

I don't see an antivirus program running in your log...

AVG has a new, free version available - AVG7 Free edition:

http://free.grisoft.com/freeweb.php.

Be sure to update it right away and perform a full system scan.

Also...

I don't see a firewall running in your log. Are you using the firewall in Service Pack 2's Security Center? If so, are you aware that it only blocks incoming traffic?

ZoneAlarm has a free firewall:

http://www.zonelabs.com/store/conte...reeDownload.jsp

Both are necessary to keep your computer safe.

Tom

Reply With Quote
  #12  
Old January 2nd, 2005, 02:51 PM
jakk-tam-comp jakk-tam-comp is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2005
Posts: 1 jakk-tam-comp User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Give this a try ??????

My problem was also the same thats been doing my head in all day ! but ive found a solution ? it may work for you ? let me know ?
Do all of you have ati graphics card & driver Version: 6.14.10.6497 if you do try rolling back you driver in device manager ? i recently updated mine and it seems that this caused the problem ???

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > 100% CPU usage Hijackthis log.


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |