1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Cpu 100%

Discussion in 'Malware and Virus Removal Archive' started by wahlroot, 2007/04/20.

  1. 2007/04/20
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    The CPU on one of my computers is at CPU 100% even when doing nothing. Process Explorer shows Hardware Interupts at 33% to 39% CPU. It shows Deferred Procedure Calls at 27% t0 31%. This happens, whether doing something or nothing. Nothing else comes close to this. Here is the Hijack This.

    Logfile of HijackThis v1.99.1
    Scan saved at 7:59:05 PM, on 4/20/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\xp_quickres.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Clean Cache.bat
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: xp_quickres.lnk = C:\xp_quickres.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
     
  2. 2007/04/22
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Use HjT to FIX the following:
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)

    If no longer use, remove these:
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    Is this your own custom bat file?
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Clean Cache.bat

    Personally, I'd dump the DLink wifi utility and use the XP built in Wireless Zero Config to manage wifi.

    Also, use regedt to drill to HKLM/Software/Microsoft/Windows NT/Current version/Winlogon/Notify
    The default # of entries is 9. This is a spot where rootkits execute from.
     

  3. to hide this advert.

  4. 2007/04/22
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    Fixed the 3 items with Hjt. So far no help. I do have a bat file that works at startup. When I click the plus sign by notify I get the following:
    cryptnet
    cscdll
    ScCertprop
    schedule
    sclgntfy
    senslogon
    termsrv
    wlbaloon
    wgalogon with settings at the plus sign.
     
  5. 2007/04/22
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    Things in Notify are the same as on my other computer that does not have these problems. Also the D-Link is a wireless card to use the modem to log on to the Internet.
     
  6. 2007/04/22
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    Your mention of the D-Link gave me an idea. Since Hardware Interrupts mentions Hardware and the D-Link wireless card is hardware, maybe the problem is there. All I can think of is D-Link, Keyboard, and mouse. D-Link has a driver. I disabled D-Link, and CPU Usage dropped way down. Of course I cannot use the internet. I will get with D-Link tech, and try to learn what to do next.
     
  7. 2007/04/23
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Do this:
    1. reload the dlink. (if possible, only install the drivers)
    2. search the utility preferences to disable loading at boot. (may not have one).
    3. rt click My Network Places icon on desktop.
    4. select Properties
    5. rt click Wireless network icon.
    6. select Properties.
    7. find the place to check "let windows manage my wireless... "
    8. check both boxes at bottom re icons in tray.

    This action should shut off the dlink utility & start windows wireless zero config.
     
  8. 2007/04/23
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    I removed the D-Link card, uninstalled apps, reinstalled the apps,and reinstalled the card. I do get 0% to 30% usage by Hardware Interupts and Deferred Procedure Calls. CPU Usage is not 100% most of the time. In fact sometimes the above usage by HI and DPC drops when other things use more. Also usage some times drops to 15% when not doing anything. Sometimes usage goes to 100% when starting an app and everything slows, but it does not seem to last long. So I may be back where I was. Will see how long it will last.
     
  9. 2007/04/24
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Are you now using Windows to manage the wifi instead of the dlink utility?
     
  10. 2007/04/24
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    This is a D-Link wireless card that is inside of the computer tower. This connects wirelessly to the DSL modem, to allow the computer to logon to the internet. The D-Link does not manage the network. The network was set up with Wireless Zero Config.
     
  11. 2007/04/26
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    is the dlink utility that loads at boot. Apparantly it is an app that ties into the dlink access point & used to set it up. But, this program may not ne needed to do that. Do a little research re your AP and see if it requires a driver. Some cheaper low end router-APs require a driver to be installed on the computer, offloading the router resources to the computer. This is because these low end routers have a small amount of ram. Other mid range & higher router-APs do not require a driver and handle everything all by themselves. It could very well be that this program is what is using your resources full time. And there may even be updated versions at the dlink site.
     
  12. 2007/04/26
    wahlroot

    wahlroot Inactive Thread Starter

    Joined:
    2002/08/15
    Messages:
    546
    Likes Received:
    1
    The D-Link card requires a driver and I downloaded and installed the latest update from D-Link when I first installed the card. I checked and I have the latest driver installed. D-Link tech says I am doing the proper things.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.