Home   News  Product reviews  Website reviews  Forums   Competitions  Subscribe 

Security >> HijackThis logs help and analysis

 |  Print Thread
rhorvath1
regular


Reg'd: Tue
Posts: 48
Re: SLOWDOWN
      Sun Feb 17 2008 04:57 AM

Bricat,
I've been experimenting, but this is too WEIRD for me to figure out.

I used the Elite Toolbar remover and rebooted. For ten minutes, everything was GREAT!: webpages were loading fast, and the Task Manager showed svchost.exe at zero. So I tried opening MY COMPUTER as a test--it took 2-3 minutes to search and finally list the drives and two document folders. Checking Task Manager again, svchost.exe went to 99%. I shut down MY COMPUTER window, but svchost.exe stayed at 99%! Webpages were again slow.

I have repeatedly shut down and restarted, and checked Task Manager. There are four to six svchost.exe's when I start (e.g. one LOCAL SERVICE, two NETWORK SERVICE, two SYSTEM). Sometimes when I start up, they are zero usage, and system idle is about 99%; other times, one of the svchost.exe's is at 99% (either SYSTEM or no username). If it's at zero, I can trigger it to 99% by hitting MY COMPUTER or perhaps opening Google.

I tried disabling programs. I first shut down and rebooted, and svchost.exe was still 99% (username SYSTEM). I sequentially disabled and re-enabled Kerio Personal Firewall, AVG Anti-Spyware and AVG Anti-virus while checking the CPU USAGE; nothing made any difference, i.e., the svchost.exe stayed at 99% after I disabled each program. Are there others I should try this with? (I also tried to uninstall Indeo, which triggered an Uninstall Shield, but got a message about Unable to locate the installation logfile-uninstallation will not continue).

When I startup after a longer shutdown, I still get the message: To help protect your computer, Windows has closed this program--Name:Generic Host Process for Win 32 Services, and after closing the message, Generic Host Process for Win 32 Services encountered a problem and had to close--I get more info about the Error Signature and Technical Info if I click further. Does this mean anything with regard to the other issues?

In summary, something seems to trigger 99% CPU usage by svchost.exe, and I can do it by opening MY COMPUTER, but other things also seem to trigger it. It slows down my other operations. Sometimes shutting down works to relieve it, other times not.

I see there are free downloads such as RegCure Svchost Repair; Should I try this? (they also offer a Registry Cleaner)

What would happen if I used Task Manager to simply end the process which is using 99% of the CPU?

Am I giving you the right information? I'm not sure if there's any logic here.

I'll end with another HJT log. Thanks for your help.

Bob

Logfile of HijackThis v1.99.1
Scan saved at 8:59:00 PM, on 2/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Hijackthis2\HijackThis.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe

Post Extras Print Post   Remind Me!     Notify Moderator
Rate this thread

Jump to


Entire topic
Subject Posted by Posted on
* SLOWDOWN rhorvath1 Sun Feb 10 2008 10:07 PM
. * * Re: SLOWDOWN bricatModerator   Mon Feb 11 2008 04:42 PM
. * * Re: SLOWDOWN rhorvath1   Tue Feb 12 2008 06:22 AM
. * * Re: SLOWDOWN bricatModerator   Tue Feb 12 2008 09:23 AM
. * * Re: SLOWDOWN rhorvath1   Wed Feb 13 2008 05:26 AM
. * * Re: SLOWDOWN bricatModerator   Wed Feb 13 2008 09:31 AM
. * * Re: SLOWDOWN rhorvath1   Sun Feb 17 2008 04:57 AM
. * * Re: SLOWDOWN bricatModerator   Sun Feb 17 2008 09:46 AM
. * * Re: SLOWDOWN rhorvath1   Mon Feb 18 2008 01:34 AM
. * * Re: SLOWDOWN bricatModerator   Mon Feb 18 2008 08:47 AM
. * * Re: SLOWDOWN rhorvath1   Mon Feb 18 2008 08:57 PM
. * * Re: SLOWDOWN bricatModerator   Mon Feb 18 2008 11:10 PM
. * * Re: SLOWDOWN rhorvath1   Thu Feb 21 2008 08:54 PM
. * * Re: SLOWDOWN bricatModerator   Thu Feb 21 2008 10:21 PM

Extra information
0 registered and 20 anonymous users are browsing this forum.

Moderator:  putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate 


Print Thread
Forum Permissions
      You cannot start new topics
      You cannot reply to topics
      HTML is disabled
      Mark-up is enabled

Rating:
Thread views: 0

Contact Us | Privacy statement Main website
Hitwise Top 10 Award Winner - Jan-Mar 2005

About us | Contact us | Link to us | Terms & Conditions | Privacy Policy
© Copyright IPC Media Limited, All rights reserved