Forum Home
Press F1
 
Thread ID: 48811 2004-09-01 23:03:00 Laptop Fan and Processor Running All The time Winston001 (3612) Press F1
Post ID Timestamp Content User
268107 2004-09-01 23:03:00 I'm not sure what to do. Using XP Pro. Since the weekend my laptop has the fan running almost all the time and Task Manager shows 100% CPU usage.

I've run Spybot, Adaware, and AVG virus scan. Nothing found. Use Zonealarm but maybe I have allowed a connection I shouldn't. Got svchost running for at least 4 different processes under Processes. Only application open is Opera.

Went to Blackviper.com but got a headache. Can I print the process list somehow from Task Manager? Any suggestions for where to look to see what is making the processor work?

Cheers
Winston001
Winston001 (3612)
268108 2004-09-01 23:22:00 Can you post us a list of items in startup?

Easist way is to crank open spybot,dropkick her into advanced mode,Drop a flying elbow onto the system start-up tab,Then body slam the Export button.....
metla (154)
268109 2004-09-01 23:32:00 In the task manager, you can sort processes by %CPU Usage. Do this and it'll tell you what process is churning through your CPU.


Chill.
Chilling_Silence (9)
268110 2004-09-01 23:54:00 Thanks Metla. I always said you were a fine fellow ;)

And Chill, I looked at the processes running but they didn't seem to be using a lot of memory. Mind you, I'm not sure how to read the info........

Located: HK_LM:Run, AVG_CC
command: C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
file: C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
size: 345661
MD5: a21829ad1ff2db8b77f3d6e42d76b9e1

Located: HK_LM:Run, BrowserBrand
command: C:\Program Files\ONLINE~1\XTRA\brand.exe
file: C:\Program Files\ONLINE~1\XTRA\brand.exe
size: 113408
MD5: 94112e4ec5fac432f4e072bc1ee87560

Located: HK_LM:Run, CARPService
command: carpserv.exe
file: C:\WINDOWS\system32\carpserv.exe
size: 4608
MD5: ea3be7f5cdef0fe4df1bf6dbfe7abde0

Located: HK_LM:Run, FastUser
command: C:\WINDOWS\System32\fast.exe
file: C:\WINDOWS\System32\fast.exe
size: 49216
MD5: 1be84e434200cbcc51da6b3aae5f2330

Located: HK_LM:Run, InvalidDelete
command: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe /Delete C:\Program Files\Genius NetScroll+ Mini Traveler Mouse
file: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe
size: 200704
MD5: 1cc3874617c40d447ee5f47e8b2e6443

Located: HK_LM:Run, PreloadApp
command: c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
file: c:\hp\drivers\printers\photosmart\hphprld.exe
size: 36864
MD5: 18575be35bb3312614c035352496f841

Located: HK_LM:Run, QT4HPOT
command: C:\Program Files\HPQ\One-Touch\OneTouch.EXE
file: C:\Program Files\HPQ\One-Touch\OneTouch.EXE
size: 106496
MD5: ccd883f2ca796c3e050457d74dbf4962

Located: HK_LM:Run, srmclean
command: C:\Cpqs\Scom\srmclean.exe
file: C:\Cpqs\Scom\srmclean.exe
size: 36864
MD5: 787b8ad5fef1a68d3ed00e4e393b9d18

Located: HK_LM:Run, SynTPEnh
command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 634880
MD5: 7bc86f172bb5d9cdbdf76495df944242

Located: HK_LM:Run, SynTPLpr
command: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
file: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
size: 110592
MD5: 36dc858d4f83059ddaf0d885bdbc2734

Located: HK_LM:Run, Zone Labs Client
command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
size: 705808
MD5: a0ce57a58dcc1572374b583837a0fc79

Located: Startup (common), Device Detector 2.lnk
command: C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
file: C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
size: 106496
MD5: eaa708b50b32c9ded8dea839e57d39cf

Located: Startup (common), WordWeb.lnk
command: C:\Program Files\WordWeb\wweb32.exe
file: C:\Program Files\WordWeb\wweb32.exe
size: 18432
MD5: b8fb9aa4191a8bcb3a7cb387bd34cc60

Located: Startup (disabled), Adobe Gamma Loader (DISABLED)
command: C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
file: C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
size: 113664
MD5: c2ff17734176cd15221c10044ef0ba1a

Located: Startup (disabled), Microsoft Office (DISABLED)
command: C:\PROGRA~1\MICROS~4\Office\OSA9.EXE -b -l
file: C:\PROGRA~1\MICROS~4\Office\OSA9.EXE
size: 65588
MD5: f2020569df0e5cdf0ccedb3406d15cb3

Located: Startup (disabled), Microsoft Works Calendar Reminders (DISABLED)
command: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.ex e
file: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.ex e
size: 24633
MD5: 7084b58a098d2f83b304832251a8c6a8

Located: Startup (disabled), WinZip Quick Pick (DISABLED)
command: C:\PROGRA~1\WinZip\WZQKPICK.EXE
Winston001 (3612)
268111 2004-09-02 00:15:00 CPU Usage... Not memory.... ;-) Have another look. You may have to click it again if it shows the highest-use processes down the bottom, this will make them display up the top :-) Chilling_Silence (9)
268112 2004-09-02 00:38:00 Ok, thanks.

System is the Image

SYSTEM is the User Name

CPU usage is about 94%

Ended the process but it arrived back instantly. ?:|
Winston001 (3612)
268113 2004-09-02 02:07:00 I can't see it in that list you posted but I am wondering if the Indexing service might be the problem? Seems unlikely but you could disable it anyway (Black Viper's site will tell you how to) .

If you want to post a list of what is running you can download HijackThis, do a scan with it then click on the Config button down the bottom right then Miscellaneous Tools . On the next page click on "Open process manager" and see what is listed in there .
Susan B (19)
268114 2004-09-02 03:08:00 Thanks Susan. Indexer is off so must be something else.

Here is what Hijackthis found

Logfile of HijackThis v1.98.2
Scan saved at 2:05:51 p.m., on 2/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\WINDOWS\system32\HPConfig.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\Fast.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\WINDOWS\System32\fast.exe
C:\WINDOWS\System32\carpserv.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Opera75\opera.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us4nb.hpwis.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SolidConverter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\ExploreExtP DF.dll
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\Speech\Dragon\web_ie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: SolidConverter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\ExploreExtP DF.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\System32\fast.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BrowserBrand] C:\Program Files\ONLINE~1\XTRA\brand.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [InvalidDelete] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\KYE\Setup.exe /Delete C:\Program Files\Genius NetScroll+ Mini Traveler Mouse
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\System32\wweb32.dll/lookup.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {9329D8E0-FDB5-4708-A306-5D8C20FB5984} (AutoDetect.AutoDetectCtrl) - secure2.landonline.govt.nz

I'm totally bewildered!
Winston001 (3612)
268115 2004-09-02 03:59:00 Out of desperation, also here is the list provided by Open Process Manager in Hijackthis. The only significant change to my system was at the weekend when I edited the Registry (based on MS advice) to enable my password to be retained in OE. It worked.

Process list saved on 2:59:15 p.m., on 2/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)

[full path to filename] [file version] [company name]
C:\WINDOWS\System32\smss.exe 5.1.2600.1106 Microsoft Corporation
C:\WINDOWS\system32\winlogon.exe 5.1.2600.1106 Microsoft Corporation
C:\WINDOWS\system32\services.exe 5.1.2600.0 Microsoft Corporation
C:\WINDOWS\system32\lsass.exe 5.1.2600.1106 Microsoft Corporation
C:\WINDOWS\system32\svchost.exe 5.1.2600.0 Microsoft Corporation
C:\WINDOWS\System32\svchost.exe 5.1.2600.0 Microsoft Corporation
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\spoolsv.exe 5.1.2600.0 Microsoft Corporation
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe 6.0.1.696 GRISOFT s.r.o
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe 1.2.0.0 OLYMPUS Corporation
C:\WINDOWS\system32\HPConfig.exe 3.0.1.8 Hewlett-Packard
C:\WINDOWS\System32\svchost.exe 5.1.2600.0 Microsoft Corporation
C:\WINDOWS\Explorer.EXE 6.0.2800.1221 Microsoft Corporation
C:\WINDOWS\system32\ZoneLabs\vsmon.exe 5.1.11.0 Zone Labs Inc.
C:\WINDOWS\System32\Fast.exe 5.1.3564.0 Microsoft Corporation
C:\Program Files\HPQ\One-Touch\OneTouch.EXE 1.6.8.0 Dritek System Inc.
C:\WINDOWS\System32\fast.exe 5.1.3564.0 Microsoft Corporation
C:\WINDOWS\System32\carpserv.exe 1.0.0.1 Conexant Systems, Inc.
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe 6.0.0.515 GRISOFT s.r.o.
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe 5.1.11.0 Zone Labs Inc.
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe 2.4.2.2 OLYMPUS Corporation.
C:\Program Files\WordWeb\wweb32.exe 2.2.0.0 Antony Lewis
C:\WINDOWS\System32\wuauclt.exe 5.4.3790.2182 Microsoft Corporation
C:\Program Files\Opera75\opera.exe 7.0.3778.0 Opera Software
C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe 1.98.0.2 Soeperman Enterprises Ltd.
C:\Program Files\Outlook Express\msimn.exe 6.0.2800.1123 Microsoft Corporation
Winston001 (3612)
268116 2004-09-02 04:06:00 Havent got a lot of time to do a complete rundown on the data provided,so just as an experiment can u disable everything under start up(via spybot start-up panel) reboot and see if the problem has disapeared?

If it has then re-enable them one by one untill the culpret is identified.

And that xtra browser branding has no need to be run.
metla (154)
1 2 3