| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 48811 | 2004-09-01 23:03:00 | Laptop Fan and Processor Running All The time | Winston001 (3612) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 268107 | 2004-09-01 23:03:00 | I'm not sure what to do. Using XP Pro. Since the weekend my laptop has the fan running almost all the time and Task Manager shows 100% CPU usage. I've run Spybot, Adaware, and AVG virus scan. Nothing found. Use Zonealarm but maybe I have allowed a connection I shouldn't. Got svchost running for at least 4 different processes under Processes. Only application open is Opera. Went to Blackviper.com but got a headache. Can I print the process list somehow from Task Manager? Any suggestions for where to look to see what is making the processor work? Cheers Winston001 |
Winston001 (3612) | ||
| 268108 | 2004-09-01 23:22:00 | Can you post us a list of items in startup? Easist way is to crank open spybot,dropkick her into advanced mode,Drop a flying elbow onto the system start-up tab,Then body slam the Export button..... |
metla (154) | ||
| 268109 | 2004-09-01 23:32:00 | In the task manager, you can sort processes by %CPU Usage. Do this and it'll tell you what process is churning through your CPU. Chill. |
Chilling_Silence (9) | ||
| 268110 | 2004-09-01 23:54:00 | Thanks Metla. I always said you were a fine fellow ;) And Chill, I looked at the processes running but they didn't seem to be using a lot of memory. Mind you, I'm not sure how to read the info........ Located: HK_LM:Run, AVG_CC command: C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP file: C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe size: 345661 MD5: a21829ad1ff2db8b77f3d6e42d76b9e1 Located: HK_LM:Run, BrowserBrand command: C:\Program Files\ONLINE~1\XTRA\brand.exe file: C:\Program Files\ONLINE~1\XTRA\brand.exe size: 113408 MD5: 94112e4ec5fac432f4e072bc1ee87560 Located: HK_LM:Run, CARPService command: carpserv.exe file: C:\WINDOWS\system32\carpserv.exe size: 4608 MD5: ea3be7f5cdef0fe4df1bf6dbfe7abde0 Located: HK_LM:Run, FastUser command: C:\WINDOWS\System32\fast.exe file: C:\WINDOWS\System32\fast.exe size: 49216 MD5: 1be84e434200cbcc51da6b3aae5f2330 Located: HK_LM:Run, InvalidDelete command: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe /Delete C:\Program Files\Genius NetScroll+ Mini Traveler Mouse file: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe size: 200704 MD5: 1cc3874617c40d447ee5f47e8b2e6443 Located: HK_LM:Run, PreloadApp command: c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d file: c:\hp\drivers\printers\photosmart\hphprld.exe size: 36864 MD5: 18575be35bb3312614c035352496f841 Located: HK_LM:Run, QT4HPOT command: C:\Program Files\HPQ\One-Touch\OneTouch.EXE file: C:\Program Files\HPQ\One-Touch\OneTouch.EXE size: 106496 MD5: ccd883f2ca796c3e050457d74dbf4962 Located: HK_LM:Run, srmclean command: C:\Cpqs\Scom\srmclean.exe file: C:\Cpqs\Scom\srmclean.exe size: 36864 MD5: 787b8ad5fef1a68d3ed00e4e393b9d18 Located: HK_LM:Run, SynTPEnh command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe size: 634880 MD5: 7bc86f172bb5d9cdbdf76495df944242 Located: HK_LM:Run, SynTPLpr command: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe file: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe size: 110592 MD5: 36dc858d4f83059ddaf0d885bdbc2734 Located: HK_LM:Run, Zone Labs Client command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 705808 MD5: a0ce57a58dcc1572374b583837a0fc79 Located: Startup (common), Device Detector 2.lnk command: C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe file: C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe size: 106496 MD5: eaa708b50b32c9ded8dea839e57d39cf Located: Startup (common), WordWeb.lnk command: C:\Program Files\WordWeb\wweb32.exe file: C:\Program Files\WordWeb\wweb32.exe size: 18432 MD5: b8fb9aa4191a8bcb3a7cb387bd34cc60 Located: Startup (disabled), Adobe Gamma Loader (DISABLED) command: C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE file: C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE size: 113664 MD5: c2ff17734176cd15221c10044ef0ba1a Located: Startup (disabled), Microsoft Office (DISABLED) command: C:\PROGRA~1\MICROS~4\Office\OSA9.EXE -b -l file: C:\PROGRA~1\MICROS~4\Office\OSA9.EXE size: 65588 MD5: f2020569df0e5cdf0ccedb3406d15cb3 Located: Startup (disabled), Microsoft Works Calendar Reminders (DISABLED) command: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.ex e file: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.ex e size: 24633 MD5: 7084b58a098d2f83b304832251a8c6a8 Located: Startup (disabled), WinZip Quick Pick (DISABLED) command: C:\PROGRA~1\WinZip\WZQKPICK.EXE |
Winston001 (3612) | ||
| 268111 | 2004-09-02 00:15:00 | CPU Usage... Not memory.... ;-) Have another look. You may have to click it again if it shows the highest-use processes down the bottom, this will make them display up the top :-) | Chilling_Silence (9) | ||
| 268112 | 2004-09-02 00:38:00 | Ok, thanks. System is the Image SYSTEM is the User Name CPU usage is about 94% Ended the process but it arrived back instantly. ?:| |
Winston001 (3612) | ||
| 268113 | 2004-09-02 02:07:00 | I can't see it in that list you posted but I am wondering if the Indexing service might be the problem? Seems unlikely but you could disable it anyway (Black Viper's site will tell you how to) . If you want to post a list of what is running you can download HijackThis, do a scan with it then click on the Config button down the bottom right then Miscellaneous Tools . On the next page click on "Open process manager" and see what is listed in there . |
Susan B (19) | ||
| 268114 | 2004-09-02 03:08:00 | Thanks Susan. Indexer is off so must be something else. Here is what Hijackthis found Logfile of HijackThis v1.98.2 Scan saved at 2:05:51 p.m., on 2/09/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Citrix\ICA Client\ssonsvr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG6\avgserv.exe C:\Program Files\Olympus\DeviceDetector\DM1Service.exe C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\Fast.exe C:\Program Files\HPQ\One-Touch\OneTouch.EXE C:\WINDOWS\System32\fast.exe C:\WINDOWS\System32\carpserv.exe C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe C:\Program Files\WordWeb\wweb32.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Opera75\opera.exe C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us4nb.hpwis.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SolidConverter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\ExploreExtP DF.dll O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\Speech\Dragon\web_ie.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: SolidConverter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\ExploreExtP DF.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [BrowserBrand] C:\Program Files\ONLINE~1\XTRA\brand.exe O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [InvalidDelete] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe /Delete C:\Program Files\Genius NetScroll+ Mini Traveler Mouse O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\System32\wweb32.dll/lookup.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU) O16 - DPF: {9329D8E0-FDB5-4708-A306-5D8C20FB5984} (AutoDetect.AutoDetectCtrl) - secure2.landonline.govt.nz I'm totally bewildered! |
Winston001 (3612) | ||
| 268115 | 2004-09-02 03:59:00 | Out of desperation, also here is the list provided by Open Process Manager in Hijackthis. The only significant change to my system was at the weekend when I edited the Registry (based on MS advice) to enable my password to be retained in OE. It worked. Process list saved on 2:59:15 p.m., on 2/09/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) [full path to filename] [file version] [company name] C:\WINDOWS\System32\smss.exe 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\winlogon.exe 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\services.exe 5.1.2600.0 Microsoft Corporation C:\WINDOWS\system32\lsass.exe 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\svchost.exe 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\svchost.exe 5.1.2600.0 Microsoft Corporation C:\Program Files\Citrix\ICA Client\ssonsvr.exe C:\WINDOWS\system32\spoolsv.exe 5.1.2600.0 Microsoft Corporation C:\PROGRA~1\Grisoft\AVG6\avgserv.exe 6.0.1.696 GRISOFT s.r.o C:\Program Files\Olympus\DeviceDetector\DM1Service.exe 1.2.0.0 OLYMPUS Corporation C:\WINDOWS\system32\HPConfig.exe 3.0.1.8 Hewlett-Packard C:\WINDOWS\System32\svchost.exe 5.1.2600.0 Microsoft Corporation C:\WINDOWS\Explorer.EXE 6.0.2800.1221 Microsoft Corporation C:\WINDOWS\system32\ZoneLabs\vsmon.exe 5.1.11.0 Zone Labs Inc. C:\WINDOWS\System32\Fast.exe 5.1.3564.0 Microsoft Corporation C:\Program Files\HPQ\One-Touch\OneTouch.EXE 1.6.8.0 Dritek System Inc. C:\WINDOWS\System32\fast.exe 5.1.3564.0 Microsoft Corporation C:\WINDOWS\System32\carpserv.exe 1.0.0.1 Conexant Systems, Inc. C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe 6.0.0.515 GRISOFT s.r.o. C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe 5.1.11.0 Zone Labs Inc. C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe 2.4.2.2 OLYMPUS Corporation. C:\Program Files\WordWeb\wweb32.exe 2.2.0.0 Antony Lewis C:\WINDOWS\System32\wuauclt.exe 5.4.3790.2182 Microsoft Corporation C:\Program Files\Opera75\opera.exe 7.0.3778.0 Opera Software C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe 1.98.0.2 Soeperman Enterprises Ltd. C:\Program Files\Outlook Express\msimn.exe 6.0.2800.1123 Microsoft Corporation |
Winston001 (3612) | ||
| 268116 | 2004-09-02 04:06:00 | Havent got a lot of time to do a complete rundown on the data provided,so just as an experiment can u disable everything under start up(via spybot start-up panel) reboot and see if the problem has disapeared? If it has then re-enable them one by one untill the culpret is identified. And that xtra browser branding has no need to be run. |
metla (154) | ||
| 1 2 3 | |||||