Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - [Fixed] Hope you can help 100% cpu usage posted in the Security & Safety forums; After down loading and running the programs you use in your pre-work, hjt , avg, super spyware and ccleaner and following your protocal I managed to find and kill two ...


Reply
Recommended Driver Scanner
Old 11-27-2007   #1
Bronze Member
 
Join Date: Nov 2007
Location: New Jersey
Posts: 15
PC Experience: Some Experience
Default [Fixed] Hope you can help 100% cpu usage

After down loading and running the programs you use in your pre-work, hjt, avg, super spyware and ccleaner and following your protocal I managed to find and kill two loggers (pophot.if) I believe they were and an adware.qpc trojan, along with a bunch of adware cookies, also cleaned up a bunch of loose ends in the reg. I still had the cpu usage issue, I switched the power theme from energy star to full throttle and it seems to work, although i don't like the idea of having to turn up the cpu power without knowing why. I'm attaching the last hjt log, btw the other programs give the computer a clean bill of heath.....okay spoke too soon worked well for a while but eventually crept up to 100%.....mcsysmon.exe seems to be the usage hog 70 percent or so most times.......thats the sys monitor for mcafee? I removed norton (using their utility) and installed mcafee it was free for a year from my ISP.......I already had the cpu usage issue at that point
Thank you for your attention
Attached Files
File Type: log hijackthis.log (10.2 KB, 2 views)

Last edited by chopperdoc; 11-27-2007 at 01:01 PM.
chopperdoc is offline   Reply With Quote
Register for a Free PCHF account
Advertisement - Register to Remove
Old 11-27-2007   #2
Senior Security Analyst
 
valis's Avatar
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,677
PC Experience: PC Illiterate
Default Re: Hope you can help 100% cpu usage

hello chopper, and welcome to the forums.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

thanks,

v
__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

valis is offline   Reply With Quote
Old 11-27-2007   #3
Bronze Member
 
Join Date: Nov 2007
Location: New Jersey
Posts: 15
PC Experience: Some Experience
Default Re: Hope you can help 100% cpu usage

Okay, here are the two logs, btw nice toys you guys have, cpu is about the same or is that expected?
Attached Files
File Type: txt ComboFix.txt (9.6 KB, 1 views)
File Type: log hijackthis.log (7.5 KB, 1 views)
chopperdoc is offline   Reply With Quote
Old 11-27-2007   #4
Senior Security Analyst
 
valis's Avatar
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,677
PC Experience: PC Illiterate
Default Re: Hope you can help 100% cpu usage

Yes, they are kind of fun to work with....makes things a LOT easier.

You may want to print these out. please close all other applications, start hjt again, click 'perform system scan only', place a tick next to the following and click 'fix checked'

O2 - BHO: (no name) - {0FB37502-7C57-41D8-82E8-DBF1D0C94F24} - (no file)
O4 - HKCU\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\DOCUME~1\HP_Owner\LOCALS~1\TEMPOR~1\Content.IE5 \GDM7OXU7\YAHOO_~1.SH! C:\DOCUME~1\HP_Owner\LOCALS~1\TEMPOR~1\Content.IE5 \OPENS1QF\DETAIL~1.SH! C:\DOCUME~1\HP_Owner\LOCALS~1\TEMPOR~1\Content.IE5 \FMTA1K8X\FF2_1_~1.SH! C:\DOCUME~1\HP_Owner\LOCALS~1\TEMPOR~1\Content.IE5 \GDM7OXU7\SPYWAR~1.SH!


reboot, and post a new log please.

thanks,

v
__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

valis is offline   Reply With Quote
Old 11-28-2007   #5
Bronze Member
 
Join Date: Nov 2007
Location: New Jersey
Posts: 15
PC Experience: Some Experience
Default Re: Hope you can help 100% cpu usage

Here is the latest log from hjt, couldn't get rid of the banner helper, boot remove? Valis, I just noticed if i log in as a guest I don't have the cpu problem. Also logged in as an admin (my usual log in), the computer seems almost normal, but the task manager still shows 100% usage with a lot of kernal action about 50% on average, hope that helps shed some light on the problem
Attached Files
File Type: log hijackthis.log (7.1 KB, 3 views)

Last edited by chopperdoc; 11-28-2007 at 02:48 AM. Reason: more info
chopperdoc is offline   Reply With Quote
Old 11-28-2007   #6
Senior Security Analyst
 
valis's Avatar
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,677
PC Experience: PC Illiterate
Default Re: Hope you can help 100% cpu usage

got rid of that vundo, at least.

start hjt, click 'perform a system scan only', close all other apps, place a tick next to the following, and click 'fix checked':

O2 - BHO: (no name) - {0FB37502-7C57-41D8-82E8-DBF1D0C94F24} - (no file)

Next, please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


reboot, and load up task manager. Go to the processes tab, and double click the cpu tab to see what process is using up your kernel and post that back please.

thanks,

v
__________________
M.C.S.A.
M.C.P - MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

valis is offline   Reply With Quote
Old 11-28-2007   #7
Bronze Member
 
Join Date: Nov 2007
Location: New Jersey
Posts: 15
PC Experience: Some Experience
Default Re: Hope you can help 100% cpu usage

Okay explorer.exe is the largest cpu user, high 90's
explorer.exe and System svchost.exe both use about 25000k memory
I noticed I have 2 svchosts for System is this normal?
After working for awhile I've noticed the usage stays low until I open any of the work folders on my desktop, then about of a quarter of the items on the processes list take turns at high usage, then it settles down to the above mentioned items, If I shut down and reboot all goes back to normal, high 90's for system idle. If I open iexplorer and do mail, surf, whatever before explorer all seems fine until I open desk top items.

Last edited by chopperdoc; 11-28-2007 at 03:21 PM.
chopperdoc is offline   Reply With Quote

Reply

Bookmarks

Tags
100%, cpu, fixed, hope, usage
Similar discussions...
Thread Thread Starter Forum Replies Last Post
high cpu usage cngz [Fixed] Hijackthis! Logs 10 11-21-2007 10:35 AM
[Fixed] Help!! My PC has the sniffles. CPU usage reptilebro1 [Fixed] Hijackthis! Logs 9 04-28-2007 03:04 AM
CPU usage BluesMatt Unfinished Threads 4 01-09-2007 10:08 PM
[Resolved] CPU usage Sean.Mathew [Fixed] Hijackthis! Logs 21 04-26-2006 09:20 PM

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 06:05 AM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2