Hidden process taking up 90% of processor

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by porschedrifter, Jul 30, 2007.

  1. porschedrifter

    porschedrifter Private E-2

    There's definitely something going on with my system. I do use shareaza, I am very careful with what I open and download.

    However, I've tried all the normal scans and I use NOD32 as well as Spybot and A2. I also tried a hijackthis and fsecure blacklight scan which found nothing. The others keep finding just the norm cookies and zedo and some other things but nothing that stands out to me.

    I'll just be doing stuff then at random my computer will come to a very choppy speed and I cant go anywhere online and even do anything on my system. Something is using almost all the power of my 4600+ and when I go to task man to see what it is, there will be nothing in the list by cpu usage and sometimes it'll be svchost.exe

    here are the logs attached.

    I'm using xp pro 64 as well.

    Havent had a problem like this since I built the system about a year ago.
    It has been very quick and very responsive that I can definitely tell there's a problem.

    I have plenty of HD space, 4gb ram, dual core 4600+
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow our instructions for downloading and renaming HJT>
    D:\Downloads\hijackthis_199\HijackThis.exe


    * Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    * On the page that opens, scroll down to Event Log
    * then right click the entry, select Properties and press Stop Service.
    * When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    Do the same for Plug and Play.
    * Click OK until you get back to Windows.

    * Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    * At the lower right, click on the Config button
    * Then click the Misc tools button
    * Select Delete an NT Service
    * Copy/paste Eventlog into the box that opens, and press OK
    Do the same for PlugPlay
    * If you receive any error messages just ignore them and continue.
    When done exit HJT.

    Now
    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. porschedrifter

    porschedrifter Private E-2

    Yeah I did those scans. Well, the ones that would work for xp 64 pro at least.

    Nothing is coming up.

    here are my logs.

    Spybot was the only thing that found stuff

    By the way when i went to disable the eventlog and delete it, windows wouldnt boot up again i had to go into last good setting

    as well I couldnt disable the plug and play service the start stop was all greyed out.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What programs would not run on your system?

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    This does not look like a malware issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds