"System" process problem. [Archive] - Chevelle Tech

: "System" process problem.


71Avido
Oct 20th, 05, 8:16 PM
My computer has a recurring problem with the "System" process in the task manager.
After I reformat I go along merrily or a couple months until my comp slows down.
I take a look at the "System" process in the task manager and every 3 seconds or so it will jump to exactly 45% cpu usage.
I end the process and it goes back down to 0% like it should be but the "System" process never dissapears at all.
I know that peticular process is supposed to be there all the time, but I dont know why it does what its doing.
I have uninstalled nearly everything and I'm at whits end, I really dont want to have to reformat.
Anyone have a fix for this problem or can at least explain what is actually happening?

-SS454-
Oct 20th, 05, 8:39 PM
For one, you should NOT end this process. I assume its the System process, and not a trojan or something renaming itself as System.exe. Its a bit unknown of what is causing the 45% cpu usage, but it could be virus/trojan/spyware. I know things like webcams can make the system process use CPU power, so I'm not sure if it would use some for a USB harddrive.

I recommend you do a complete virus scan (make sure definitions are up to date). If you dont have it, download Adaware SE Personal 1.06 (free), and be sure to update the definitions right off the bat. You could also try programs such as Swat-It, or HiJackThis.

Other than that your going to have to figure out what your doing just before it starts hogging the CPU power, what your doing at the time it is hogging the power, etc. Anything you perhaps installed prior to it starting to do this. 45% CPU usage is a hefty bit of power, and not only does it slow ur computer down, it can get your CPU pretty hot.

71Avido
Oct 20th, 05, 9:05 PM
I ran a fully updated nortons virus scan twice over the whole system, adaware 3 times. And still does it.
When ive had this problem before i got lazy and just reformatted, im really trying to avoid it this time.
I know i have plenty of cooling power as i am running 7 case fans and a 90MM cpu fan with a heatsink rated 1ghz over my actual cpu speed.

Logfile of HijackThis v1.99.1
Scan saved at 9:10:41 PM, on 10/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LIUtilities\WinTasks\wintasks.exe
C:\Documents and Settings\Matt\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [WordPerfect Office 1215] C:\Program Files\WordPerfect Office 12\Programs\Registration.exe /title="WordPerfect Office 12" /date=060905 serial=WS12WTX-9999998-UYR lang=EN
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: DfLogon - C:\WINDOWS\SYSTEM32\LogonDll.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DF5Serv - Unknown owner - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

-SS454-
Oct 20th, 05, 9:58 PM
You have a lot of processes running that I've never seen before. So I started looking them up.

hphmon03.exe is your HP printer, you could try ending this process or unplugging your printer all together.

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe that is a wierd one, and searching that brings up a lot of links about ppl complaining of PC issues and viruses. I dont know what its for, but I would look into it if I were you.

explorer.exe, pretty normal except i noticed it said .EXE. So..... Note: explorer.exe is also registered as a process which is the w32.Codered and the w32.mydoom.b@mm viruses. These viruses are distributed via the Internet through e-mail and comes in the form of an e-mail message, in the hopes that you open it’s hostile attachment. The worms have their own SMTP engine which means it gathers E-mails from your local computer and re-distributes itself. In worst cases these worms can allow attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding these processes

O23 - Service: DF5Serv - Unknown owner - C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe (file missing) A configuration restoration utility, for whatever your use is. I dont know anything about it, but the fact it found it, and saw file missing caught my attention

By looking at the Norton files you have running, I wonder if you have Norton 2004 or older? I know these are resourse hogs, and if you only have 256 MB of RAM, I wonder if its perhaps a virtual memory issue.

I've never used HijackThis, so unfortunatly thats about as much info as I can give with the details you gave me.

SS_Sean
Oct 20th, 05, 10:50 PM
Looking at your logfile I don't see anything that jumps out at me as being out of the ordinary. You do have a lot of programs running that probably aren't necessary. Take the above advice. Also, all those little IM programs you have running can be combined into one program called Trillian. Trillian runs all the IM programs at one time, one location, one program. Give it a try.

Again, I didn't see anything out of the ordinary as far as the logfile, but I'm not a true expert at reading these. Just a lot of personal experience of my own in solving these problems.

71Avido
Oct 20th, 05, 10:58 PM
I FIXED IT WOO FIRST TIME IN A LONG TIME!
Turns out it WAS the printer, well not the printer so much as it was the card reader built into the printer.
For some reason it was trying to install a raid driver when i had no raid devices connected.
I uninstalled the printer, unplugged it, uninstalled the raid driver, uninstalled the ports that the printer itself installed and bam works like a charm once again.
Im so happy now.
Thanks for the help!

-SS454-
Oct 20th, 05, 11:21 PM
Glad everything is working okay :)

Mike
Oct 21st, 05, 6:53 PM
You might want to look at this program:
http://www.sysinternals.com/Utilities/ProcessExplorer.html