#1
  1. No Profile Picture
    Registered User
    Devshed Newbie (0 - 499 posts)

    Join Date
    Apr 2004
    Posts
    1
    Rep Power
    0

    CPU Usage 100%....pls help :(


    Hi ppl,
    I'm using AMD Athlon XP 1700+ cpu. I'm using Windows 2000 OS. Every time i boot up my cpu usage shoots up to 100%..and never semms to come down. The process I see in the task mananger that is running high is 'svchost.exe' and at times 'System'. i've downloaded HijackThis.exe...and this is the result. C if u guys can help...will be obliged

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\DRIVERS\CDANTSRV.EXE
    C:\WINNT\system32\crypserv.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\Program Files\avSoft Technologies\SmartCOP\SCComm.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\tcpsvcs.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\avSoft Technologies\SmartCOP\STrap.exe
    C:\WINNT\Explorer.exe
    C:\WINNT\System32\winlog.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\System32\inetsrv\inetinfo.exe
    C:\WINNT\System32\hallowelt.exe
    D:\Software\RAMFREE\FreeRAM XP Pro 1.11.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\WINNT\system32\faxsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\WinZip\winzip32.exe
    C:\Documents and Settings\sushant\Desktop\AntiViruses\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://best-search.cc/search.php?v=6&aff=3074272
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://best-search.cc/index.php?v=6&aff=3074272
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://best-search.cc/index.php?v=6&aff=3074272
    F1 - win.ini: run=hpfsched
    O1 - Hosts file is located at: C:\WINNT\nsdb\hosts
    O1 - Hosts: 81.211.105.69 lender-search.com
    O1 - Hosts: 81.211.105.68 hot-searches.com
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [^`d}qZxu] ~`d}qzxu3zYF
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [yeahdude.exe] hallowelt.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [FreeRAM XP] "D:\Software\RAMFREE\FreeRAM XP Pro 1.11.exe" -win
    O4 - HKLM\..\Run: [Windows Login] winlog.exe
    O4 - HKLM\..\RunServices: [^`d}qZxu] ~`d}qzxu3zYF
    O4 - HKLM\..\RunServices: [yeahdude.exe] hallowelt.exe
    O4 - HKLM\..\RunServices: [Windows Login] winlog.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\scopinet.dll
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...095.8683333333
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...wflash5r42.cab
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents...r/imloader.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{05FE2B0F-86F0-4DB9-BBAE-1EB84C56CD65}: NameServer = 203.195.128.66 203.195.128.67
    O17 - HKLM\System\CS1\Services\Tcpip\..\{05FE2B0F-86F0-4DB9-BBAE-1EB84C56CD65}: NameServer = 203.195.128.66 203.195.128.67
  2. #2
  3. Just another guy
    Devshed Frequenter (2500 - 2999 posts)

    Join Date
    Jun 2003
    Location
    Wisconsin
    Posts
    2,953
    Rep Power
    261
    Download and run spybot search&destroy.
    --Dave--

    U2kgSG9jIExlZ2VyZSBTY2lzLCBOaW1pdW0gRXJ1ZGl0aW9uaXMgSGFiZXM=

    My hobby: collecting US coins
  4. #3
  5. Contributing User
    Devshed Newbie (0 - 499 posts)

    Join Date
    Sep 2003
    Posts
    100
    Rep Power
    11
    Have you updated your patches since MSBlast came out?

    Download stinger from here:

    http://vil.nai.com/vil/stinger/
  6. #4
  7. Contributing User
    Devshed Newbie (0 - 499 posts)

    Join Date
    Mar 2003
    Posts
    193
    Rep Power
    12
    Use the windows update to keep the patches up to date. It's a must.

    Saving money is easy with discount codes from Rollback coupons. Coupon codes for online purchases.

IMN logo majestic logo threadwatch logo seochat tools logo