Forum Home
Press F1
 
Thread ID: 78876 2007-05-01 03:41:00 System proccess in XP using 99% resources on startup. JohnstonDJ (12197) Press F1
Post ID Timestamp Content User
545889 2007-05-01 03:41:00 Now onto my home computer (I am starting to feel like a complete idiot), when my system restarts my computer is immensly slow and opening up the taskbar it shows the "System" process taking up 99%. It does it like 19 out of the 20 times it starts.

It doesn't do it when I come back from hibernation only when its a fresh restart which make me think something is causing it. (It also doesn't do it in safe-mode which makes me think this also). However I keep my startup very clean, and pretty much contains:

* Comodo Personal Firewall (freeware program; highly suggest, I believe it is one of the better free firewalls)

* Comodo Antivirus

* Comodo I-Vault

* Daemon Tools

And all the typical windows stuff. I've closed all the stuff that come with the computer and the like. I'm really at a loss to whats causing it, because it's not actually tied to any specific proccess, just the generic "System" proccess, and it's extremely annoying as I have to restart a few times to get a workable system. I thought it might have been a hardware problem, but it only does it of a fresh restart and not a hibernate restart, so I thought that kinda ruled that out.

A Comodo Anti-virus scan, an ad-aware personal scan, and an spybot scan all come back clean.
JohnstonDJ (12197)
545890 2007-05-01 03:49:00 I wouldnt use Comodo AV for the time being.

I think its still in beta, so would most probably be a bit buggy.
Speedy Gonzales (78)
545891 2007-05-01 15:33:00 look under the task manager processes list and tell us EXACTLY which process or processes are usin all the cpu time.......... drcspy (146)
545892 2007-06-25 02:45:00 Sorry to revive old thread, but it is getting really bad now. I can't use hibernate at all, which used to work perfectly, and it takes more starts now to get a usable system. I have stopped all TSR's loading when Windows loads, and it still does the same. Here's my listed processes running while I write this post:

[img=http://imajr.com/th/Clipboard01_135034.jpg] (imajr.com)


(Please Note two caveats about this system, which may be of interest.:

* The System has had it's primary partition's NTFS resized to make use of the space wasted from the backup partition. I had a couple of months use fine, with this system after this before it started doing this, but I thought I should state this anyway.

* The computer is in an unheated room, which gets down to about 9 degrees. So it is possible that the cold might be doing something to it.
JohnstonDJ (12197)
545893 2007-06-25 02:48:00 Get hijackthis in my sig put it in its own folder.

Run it click on scan and save a log. Copy and paste the log here. That jpeg link is too small to see.
Speedy Gonzales (78)
545894 2007-06-25 02:58:00 HiJackThis Logfile:


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:05:46 p.m., on 25/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\IrfanView\i_view32.exe
C:\Program Files\Comodo\Firewall\cpf.exe
C:\Program Files\GetRight\getright_.exe
C:\Downloads\Firefox Downloads\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ie.redirect.hp.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = ie.redirect.hp.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = ie.redirect.hp.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: DiABLO - {487CA274-DDC9-45CA-BF51-2017CE8D6D8A} - C:\Program Files\Comodo\i-Vault\i-Vault.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Games\Poker.com\Poker.exe (file missing) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - security.symantec.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{038977AE-A624-4FA4-8EAB-5D19D536141E}: NameServer = 210.55.24.8 210.55.24.9
O17 - HKLM\System\CS3\Services\Tcpip\..\{038977AE-A624-4FA4-8EAB-5D19D536141E}: NameServer = 210.55.24.8 210.55.24.9
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe

--
End of file - 5206 bytes


You Can click on the thumbnail of the image, to see a bigger one, where you can see the details :-).

Thank you for any help.
JohnstonDJ (12197)
545895 2007-06-25 03:06:00 Log looks ok but run hijackthis again tick these entries and then fix checked.

Close browser/s.

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Games\Poker.com\Poker.exe (file missing) (HKCU)

You're right the pic did go bigger.

Umm. is Comodo i-vault the release version? Not a beta?

And did u remove Comodo AV?? Since it is or was a beta?
Speedy Gonzales (78)
545896 2007-06-25 03:33:00 Didn't see this thread first time around, but now I have, I would suggest dumping the Comodo AV (as Speedy says). I was running Comodo AV, firewall and i-Vault on my second PC and I suffered the same problems you did. 90% of the time it would start up and the response time for a key press or mouse click was around 10 - 15 minutes. The only solution was a hard reboot. The rest of the time it ran fine. Since I uninstalled Comodo AV I have not had a recurrence.

However, my i-Vault (which claims to have a lifetime licence) has expired and wants a valid activation code. Also my Comodo firewall seems to get corrupted within the launch manager (or whatever it's called) and is listed in the left hand pane as "C" instead of "Comodo Personal Firewall". All in all, it's just too flaky for me, so I'm probably going to get something else.

BTW - I now use Avast AV and am pretty happy with it.
Miami Steve (2128)
545897 2007-06-25 05:17:00 Log looks ok but run hijackthis again tick these entries and then fix checked.

Close browser/s.

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Games\Poker.com\Poker.exe (file missing) (HKCU)

You're right the pic did go bigger.

Umm. is Comodo i-vault the release version? Not a beta?

And did u remove Comodo AV?? Since it is or was a beta?

Fixed those problems. It was the beta, but have since uninstalled it as, it picked nothing up ever and was kind of a resource whore.


Didn't see this thread first time around, but now I have, I would suggest dumping the Comodo AV (as Speedy says). I was running Comodo AV, firewall and i-Vault on my second PC and I suffered the same problems you did. 90% of the time it would start up and the response time for a key press or mouse click was around 10 - 15 minutes. The only solution was a hard reboot. The rest of the time it ran fine. Since I uninstalled Comodo AV I have not had a recurrence.

However, my i-Vault (which claims to have a lifetime licence) has expired and wants a valid activation code. Also my Comodo firewall seems to get corrupted within the launch manager (or whatever it's called) and is listed in the left hand pane as "C" instead of "Comodo Personal Firewall". All in all, it's just too flaky for me, so I'm probably going to get something else.

BTW - I now use Avast AV and am pretty happy with it.

Yeah when I first got into Comodo software I thought it was excellent, but quite a few bugs with the software, and how much resources it can pull has started to make me feel less happy about the software. But I personally have trouble finding a firewall which is free, so customizable.

Safe Mode now also does it, however I booted into Knoppix and it had no problem's so I don't think it's hardware.

I think I'm just gonna back up my data, and do the notoriously hated format, and reinstall.
JohnstonDJ (12197)
545898 2007-06-25 05:51:00 Comodo firewall is OK, BUT it can and will block ports to programs, even tho you've given them access, which is a PITA! Its security is pretty tight .

I found this out with Yahoo, and Mirc (2 PC's here have Comodo firewall installed) .

Its OK WHEN I log on here to the net (I can DCC) . Its WHEN I log the other PC onto the net, and I'm in Mirc, her firewall blocks DCC . Even tho I've added the TCP ports for DCC on mine and hers .

V3 of Comodo firewall, MAYBE out at the end of this month or next month I think . It should be a bit better with a better interface, and hopefully better options!
Speedy Gonzales (78)
1 2