View Full Version : win xp cpu 100% while ram 21%
mixxer
12-17-2003, 02:32 PM
hi im running windows xp on a p4 1.5ghz 512 133sdram pc
the problem im having is my cpu is being used 100% while looking at flash sites or playing games and it freezes for a second before smoothing out and does this in a vicious cycle making the computer unusable for the most part :(
ive checked the ram usuage and its staying a constant 21%(windows load)
i have switched out the ram..........switched out video card.......reformated .............updated sp1 service pack........
tested hard drive processer ram and can not come up with a fix or solution
imho whats happening is windows is loading into ram then everything else is loading threw the cpu to give me such high usuage making me hang up alot
i.e have task manager up now on the comp in question
and a flash site up
imagename cpu memusage peakmemusage memdelta pagefault vmsize gdio
IEXPLOER.exe 89 20,700k 20,789k ok 8,342 13,020k 270
the cpu part jump from 40-100% while memory stays same
i really need help
also i have spybot s&d so no adware
scanned for trojans and viruses all 100% clean
if anyone has any ideas or suggestions please get back to me
bassvax
12-17-2003, 02:47 PM
I ran into this similar problem while I was trying to clean up the hard drives on my kids' pc. Running XP Pro...I copied a large file from C drive to another.....I waited until it was done and then I attempted to deleted the file from C drive...it kept telling me that some other process was using the file (230MB wmv)...long story short:
Explorer was showing 100% cpu usage...things were crawling! I found this (http://club.cdfreaks.com/archive/topic/74137.html) and it worked great for me. There doesnt seem to be any negative side effects either.........
Please be careful within the registry!!!!!
mixxer
12-17-2003, 02:55 PM
thanks for reply
but sadly ive tried that fix also and it didnt fix the problem in having :(
saphalline
12-17-2003, 04:26 PM
Sounds like spyware to me. Have you scanned your system using Spybot (http://www.safer-networking.org/index.php?page=spybotsd) or something similar?
mixxer
12-17-2003, 04:27 PM
<< also i have spybot s&d so no adware
scanned for trojans and viruses all 100% clean
>>
:(
saphalline
12-17-2003, 04:38 PM
Oops, hehe. I missed that, sorry.
Ok, so your memory usage looks normal, but for some reason IE is taking up 89% of your CPU's time? Flash isn't normally that intensive. :p
How about a BIOS update?
david eaton
12-17-2003, 05:08 PM
Spy bot doesn't catch everything. Now items of gackware seem to arrive every day!
It would be a good idea to download and run Hijack this, and post a log just in case there is something else lurking in the dark corners of your drive!
(Hmmm.. how can a drive have corners? need to think about that!;) )
Hijack this (http://www.merijn.org/files/hijackthis.zip)
mixxer
12-17-2003, 05:44 PM
StartupList report, 12/17/2003, 4:36:47 PM
StartupList version: 1.52
Started from : C:\hijackthis\HijackThis.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\hijackthis\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Zone Labs Client = C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
AVGCtrl = C:\Program Files\AVPersonal\AVGNT.EXE /min
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 2,923 bytes
Report generated in 0.031 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
the av was just installed today previously i had mcafee but trail ran out so no update
i actually updated the bios last night but it did not help sadly :(
Budfred
12-17-2003, 10:29 PM
Is this a fresh download of HijackThis??? Normally HJT produces a scan that is more than a Startup List and allows you to save the log that we can look at here. If this isn't a fresh download, please download and run the standard scan, then copy/paste the log here....
mixxer
12-17-2003, 11:36 PM
StartupList report, 12/17/2003, 10:34:21 PM
StartupList version: 1.52
Started from : C:\hijackthis\HijackThis.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
* Showing rarely important sections
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\hijackthis\HijackThis.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Zone Labs Client = C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
AVGCtrl = C:\Program Files\AVPersonal\AVGNT.EXE /min
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating Windows NT/2000/XP services
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (autostart)
AntiVir Service: C:\Program Files\AVPersonal\AVGUARD.EXE (autostart)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
AntiVir Update: C:\Program Files\AVPersonal\AVWUPSRV.EXE (autostart)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Upload Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
vsdatant: \??\C:\WINDOWS\System32\vsdatant.sys (autostart)
TrueVector Internet Monitor: C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (autostart)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 7,385 bytes
Report generated in 0.078 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
forgot to click on full report sorry :(
mixxer
01-12-2004, 12:46 PM
bump still having this problem :(
david eaton
01-12-2004, 02:29 PM
Please post your Hijack this log. What you have posted is your startup list.
In Hijack this, click "scan". The button changes to "save log" click again, and the log opens in Notepad. save it somewhere, and copt/paste into a reply here.
mixxer
01-12-2004, 02:42 PM
Logfile of HijackThis v1.97.7
Scan saved at 1:38:58 PM, on 12/21/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\hijackthis\HijackThis.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
hope this is the one you need :)
Budfred
01-12-2004, 08:13 PM
I don't see anything in this log that would indicate a problem, but it looks like most of the log is missing.... The only thing it is showing is two extra buttons running in your browser and nothing about the ISP, other processes or much of anything else.... Did you edit it???
mixxer
01-12-2004, 11:13 PM
nope cut emailed to other comp and pasted it on here
have adaware spybot s&d
the comp was freshly formatted at the time of the post
ive tried a few fixes nothing has changed
it freezes specifically on certain flash sites some it does some it does not..... aswell as hangs for about 5 seconds every few minutes while playing online games.............such as eq
it ran great for about a year then one day it just started happening
ive switched out ram
put a household fan inside to see if temp problems
reformatted 3 or 4 times :(
tried new video card
removed modem card
switched ram slots from 1 & 2 to 1 & 3
updated bios
tried windows 98
aswell as regediting out some media(was a suggestion listed in this thread)
Budfred
01-12-2004, 11:17 PM
If you just reformatted it could explain why it is so bare, but it suggests that you probably have a hardware problem. The only software problem that would persist through a reformat is a virus that hides in RAM and reinstalls if you don't power down after the reformat or malware that you reinstall yourself with some program you install....
gwallen4
01-13-2004, 03:57 PM
Try disabling/uninstalling your virus check, firewall, and any other security programs and see if that makes a difference.
mixxer
01-13-2004, 07:07 PM
have tried it with no firewall no anti virus
same problem :(
the comp is still fully operational besides for certain flash sites and online games
so im very lost in fixing this :(
Budfred
01-13-2004, 11:13 PM
I am afraid I am baffled. Even with a new install, if you are getting online there should be more to the HJT log. It might be worthwhile to download it again and try a fresh one. Maybe this one is corrupted???:confused:
Paleo Pete
01-14-2004, 11:22 PM
Budfred:
I've seen similar HJT logs on customers' machines a couple of times. Fresh HJT install, I did it myself so I know it was done right, and I get a log that looks just like the last one posted...running processes and buttons, that's it. Don't know why...just wanted to let you know, it's not just this person, I've seen it happen on more than one machine, the next one may or may not show a full log.
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.