Computing.Net > Forums > Windows XP > System process taking 99%

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

System process taking 99%

Reply to Message Icon

Name: lordchaoze
Date: April 4, 2007 at 20:17:10 Pacific
OS: Windows XP Home
CPU/Ram: Athlon 64/1Gb
Product: Compq R4225CA
Comment:

Hey guys,

I just like to know what this process is ?

http://img99.imageshack.us/img99/78...

It's taking 99% of the resources! This has never happened to me b4.
I've got no spyware/virus as I've thoroughly scanned everything. That's the only process taking 99% of the resource quite often.



Sponsored Link
Ads by Google

Response Number 1
Name: lordchaoze
Date: April 4, 2007 at 20:17:43 Pacific
Reply:

Oh yah, How do I stop it from taking all the resources


0

Response Number 2
Name: terii
Date: April 4, 2007 at 20:48:46 Pacific
Reply:

I found this on a Google Search. Check it out and see if it is related to your problem.


0

Response Number 3
Name: lordchaoze
Date: April 4, 2007 at 21:02:42 Pacific
Reply:

Unfortunately, no. But thanks for trying though. Appreciate it.


0

Response Number 4
Name: Johnw
Date: April 4, 2007 at 21:19:25 Pacific
Reply:

Not a lot to go on, here are some possibles.

Even though you feel you are clean, double check this way.

Use HiJackThis to track down or check for possible infections.
Here is all the the info needed to empower yourself, anything you are not sure of, put into a search engine like Google.
Read this link 1st, it has step by step.
http://www.wilderssecurity.com/show...
Important: Create a specific folder on your hard drive called HijackThis to keep its backups.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HijackThis. Download and unzip HijackThis.exe into this folder.
http://www.merijn.org/downloads.html Or, http://tomcoyote.com/hjt/ Or, http://www.spywareinfo.com/~merijn/...
If possible run HJT in Normal mode ( not Safe ) with all your normal startup's working.
HijackThis Tutorial - How to Analyse your own log.
http://spywarewarrior.com/viewtopic...
http://hometown.aol.co.uk/jrmc137/h...
http://www.bleepingcomputer.com/tut...
http://www.malwarehelp.org/understa...
HijackThis log file analysis ( online )
http://hijackthis.de/index.php?lang...
Or,
http://startup.networktechs.com/pag...
http://hjt.iamnotageek.com
Malware Prevention: Prevent Re-infection
http://wiki.castlecops.com/Malware_...

Turn off Background Compaction
http://www.oehelp.com/OETips.aspx

Disable Indexing Services
http://www.tweakxp.com/tweakxp/disp...
http://mywebpages.comcast.net/Suppo...
Disable Indexing Services
http://www.tweakxp.com/article37006...
http://mywebpages.comcast.net/Suppo...

Windows Me Super Tweaks
http://www.blackviper.com/WinME/sup...



0

Response Number 5
Name: clammer
Date: April 5, 2007 at 07:42:17 Pacific
Reply:

Go into Task Manager and click "end process" on it; see what happens and if it is some essential service for Windows.

I doubt it is, but at least you can experiment and end its' task to see what happens....

Try running malware & viri scans in Windows safe mode too...


0

Related Posts

See More



Response Number 6
Name: per
Date: April 5, 2007 at 09:22:51 Pacific
Reply:

Use this to start tracking it down.

http://www.microsoft.com/technet/sy...


0

Response Number 7
Name: per
Date: April 5, 2007 at 10:21:24 Pacific
Reply:

This may be better.

http://www.microsoft.com/technet/sy...


0

Response Number 8
Name: lordchaoze
Date: April 5, 2007 at 12:12:34 Pacific
Reply:

I tried to end the process and my computer worked normally again. I've tried this b4. But after an unknown time, it does come back though.


0

Response Number 9
Name: per
Date: April 5, 2007 at 12:23:27 Pacific
Reply:

Go here to check services. http://www.blackviper.com/WinXP/ser...


0

Response Number 10
Name: lordchaoze
Date: April 5, 2007 at 12:33:48 Pacific
Reply:

The thing is, as the picture states, there is no extension on that "service/task"


0

Response Number 11
Name: lordchaoze
Date: April 5, 2007 at 12:45:53 Pacific
Reply:

I've used Process Explorer and this is what I got.

http://server6.theimagehosting.com/...


the "system" is the parent process to all of those other services. But I think it's one of those services under "system" that hogs all the resources. I have to recheck it again whenever the system process hogs the resources, not when it's working normally.


0

Response Number 12
Name: per
Date: April 5, 2007 at 12:46:48 Pacific
Reply:

Did you run this?

http://www.microsoft.com/technet/sy...


0

Response Number 13
Name: lordchaoze
Date: April 5, 2007 at 12:49:55 Pacific
Reply:

broken link

the good one
http://i171.photobucket.com/albums/...


0

Response Number 14
Name: lordchaoze
Date: April 5, 2007 at 12:50:17 Pacific
Reply:

Hey per, yes that's the one.


0

Response Number 15
Name: per
Date: April 5, 2007 at 13:16:52 Pacific
Reply:

If you rt click on the selected service it will show you the processes.


0

Response Number 16
Name: per
Date: April 5, 2007 at 13:23:33 Pacific
Reply:

It may be malware acording to some research I have done. Go here and run the HJT and use the scanner.

http://www.hijackthis.de/index.php?...


0

Response Number 17
Name: Johnw
Date: April 5, 2007 at 16:00:35 Pacific
Reply:

With HiJackThis, make sure you go through the steps 1st, as with Response Number 4, otherwise you will spend days sorting things out.


0

Response Number 18
Name: lordchaoze
Date: April 5, 2007 at 17:01:22 Pacific
Reply:

Ok I'm going to try that now.


0

Response Number 19
Name: lordchaoze
Date: April 5, 2007 at 17:28:39 Pacific
Reply:

Ok I've uploaded the HJT log file.

There is one file that i've been trying to remove (avgfwafu.dll) but it seems impossible, even in safe mode. It's part of the AVG Firewall that i've installed a while ago but is uninstalled now. It's in line "010"

Anyway, this is my log
+++++++++++++++++++++++++++++

Logfile of HijackThis v1.99.1
Scan saved at 8:17:40 PM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Database\Downloads\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {27CA571B-14D3-4937-B387-BE72FA7A0F87} - (no file)
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {ADFFB2EF-2F4A-48AF-924D-7D40AD3EC0AB} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} -
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - http://h20270.www2.hp.com/ediags/gm...
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} -
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} -
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gm...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://driveragent.com/files/driver...
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - (no file)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: MCPClient - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wvusqpn - wvusqpn.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Windows CardSpace (idsvc) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (file missing)
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Net.Tcp Port Sharing Service (NetTcpPortSharing) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe



0

Response Number 20
Name: per
Date: April 5, 2007 at 17:51:16 Pacific
Reply:

Did you paste it in the HJT box at the link as it asks? It will read it for you.


0

Response Number 21
Name: lordchaoze
Date: April 5, 2007 at 17:59:29 Pacific
Reply:

I did it and the majority of them were "safe" to "very safe" and a couple of them were question marks and a couple of entries that could be fixed.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: System process taking 99%

System process taking up 99% CPU www.computing.net/answers/windows-xp/system-process-taking-up-99-cpu/145895.html

SYSTEM process at 99% www.computing.net/answers/windows-xp/system-process-at-99/57934.html

IE and System processes taking 100% www.computing.net/answers/windows-xp/ie-and-system-processes-taking-100/86760.html