Computing.Net > Forums > Security and Virus > 100%CPU usage + Norton not working

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

100%CPU usage + Norton not working

Reply to Message Icon

Original Message
Name: nidz_treasure
Date: November 25, 2003 at 02:59:32 Pacific
Subject: 100%CPU usage + Norton not working
OS: windows 2000 professional
CPU/Ram: P4/128KB
Comment:

I have been encountering this problem of SVCHOST.exe virus from the last few days. Whenever i connect to the internet, this error comes up and then copy/paste doesn't work, Msoffice doesn't work properly and the computer has to be restarted.
If i don't use the internet then there is no problem.
FixWelch from symantec doesn't show any virus.
Further, there is a NPROTECT.EXE process running as shown in task manager.Is this a virus?
And what about rape.exe. this process along with svchost.exe is taking all teh CPU and i'm being shown 100% CPU usage.
My system has become very slow. Norton is simply not working. No task bar icon is shown. Ans when i try to open it, it disappears instantly.
Please help me.
Its really important.


Report Offensive Message For Removal


Response Number 1
Name: tamtam
Date: November 25, 2003 at 03:41:54 Pacific
Reply: (edit)

Hi Nidz,

download,update and run CWShredder and Spybot search and Destroy
at http://www.safer-networking.org/index.php?lang=en&page=download
at http://www.spywareinfo.com/~merijn/
Dowload also Highjack This from the same site
run a scan and post the scan on this site.
The tech guys will say you what to do further.You might download Ad Aware also http://majorgeeks.com/download.php?det=506

succes


Report Offensive Follow Up For Removal

Response Number 2
Name: Chris B
Date: November 25, 2003 at 14:24:41 Pacific
Reply: (edit)

This sounds very similar to whats happening to me..copy & paste not working, FixWelch saying theres no sign of the virus, Norton not scanning, slow system...can you not move files about in explorer either? It's a pain in the arse, I tried Search & Destroy but had no luck, gonna try CWShredder next. Good luck sorting it nidz mate, and if u do, PLEASE tell me what u did!


Report Offensive Follow Up For Removal

Response Number 3
Name: Chris B
Date: November 25, 2003 at 14:31:23 Pacific
Reply: (edit)

Just found out, the cut n paste not working might be due to RPC being stopped in the services. Run services.msc, then scroll to RPC and right click, and hit 'start'. It sorted out my cut n paste problem. Now to sort out the other 1000 problems :-(


Report Offensive Follow Up For Removal

Response Number 4
Name: Moossee
Date: December 1, 2003 at 07:36:01 Pacific
Reply: (edit)

I just Googled "rape.exe" and it comes up as the Hybris worm. Your process could be this (or something else packaged with a name to tempt).

Check out what Norton has to say about Hybris:

http://securityresponse.symantec.com/avcenter/venc/data/w95.hybris.worm.html

I know that many infections try to disable NAV and lots of other AV software. When I installed Norton Internet Security 2004 the first thing it did was to scan for infections which would interfere with its installation.

Good luck


Report Offensive Follow Up For Removal

Response Number 5
Name: nidz_treasure
Date: December 19, 2003 at 10:22:34 Pacific
Reply: (edit)

Hi tamtam,
I downloaded all the softwares u wrote. The spybot search n destroy scan shows red icons for some cookies and some data source object exploit-registry change.
I can't make out wat all this means and wat i shud do with them.
I'll post the scan of the other software tmoro.
Meanwhile see if u cud identify my prob.


Report Offensive Follow Up For Removal


Response Number 6
Name: nidz_treasure
Date: December 19, 2003 at 10:31:20 Pacific
Reply: (edit)

HI again,
this is the scan report from HijackThis.
Now tell me wat i shud do further.


Logfile of HijackThis v1.97.7
Scan saved at 12:04:25 AM, on 12/20/2003
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\rape.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\Program Files\Winamp\Winampa.exe
C:\WINNT\System32\WINCFG32.EXE
C:\WINNT\System32\mdm.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\ymsgr_tray.exe
C:\Documents and Settings\Nidhi Gupta\Desktop\VirusTools\hijackthis\HijackThis.exe
C:\WINNT\System32\mspaint.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hotmail.com/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [TASK MANAGER] taskmgr.exe
O4 - HKLM\..\Run: [NAV CfgWiz] C:\PROGRA~1\NORTON~1\Cfgwiz.exe /R
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Winsock2 driver] WINCFG32.EXE
O4 - HKLM\..\Run: [Configuration Loader] rape.exe
O4 - HKLM\..\RunServices: [TASK MANAGER] taskmgr.exe
O4 - HKLM\..\RunServices: [Configuration Loader] rape.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\RunOnce: [Winsock2 driver] WINCFG32.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab



Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software