eplorer.exe cpu usage 100%

All of a sudden my pc started to freeze,task manager says that explorer.exe is at 100% and not dropping started to uninstall programmes & discovered that it was comodo firewall pro,did all the usual spyware & anti vrius stuff turned up nothing.re installed comodo and it started again. now pulling whats left of my hair out please help

also included hjt log
thanks
dan

Logfile of HijackThis v1.99.1
Scan saved at 15:56:36, on 09/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Documents and Settings\dad\My Documents\click me my pass is rtol\magisoft\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Documents and Settings\dad\My Documents\click me my pass is rtol\magisoft\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Documents and Settings\dad\My Documents\click me my pass is rtol\magisoft\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} - http://www.solidworks.com/plugins/edrawings/download.cfm?Release=rel
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095014872233
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {CA8A9780-280D-11CF-A24D-444553540000} (Adobe PDF Reader) - http://activex.microsoft.com/objects/ocget.dll
O16 - DPF: {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_04) -
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup161.cab
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: cpuidle - Unknown owner - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\CPUIDLE\srvany.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Comments

  • kryystkryyst Ontario, Canada
    edited October 2007
    If this is an isolated (or semi-isolated, but random) occurrence then it's likely nothing to worry about. It happens sometimes that you get a leak when browsing that'll cause your firewall or browser to make your CPU spike to 100. Firefox used to do this fairly regularly. I don't see anything in your log that looks troublesome.
  • edited October 2007
    it is not a spike,cause once it gets there is doesn't come back down & my memory usage goes to 884mb & doesn't drop back either
  • kryystkryyst Ontario, Canada
    edited October 2007
    danmiluk wrote:
    it is not a spike,cause once it gets there is doesn't come back down & my memory usage goes to 884mb & doesn't drop back either

    Not a spike a leak. A leak will cause it to spike up to 100% and generally sit there until you kill the process.
  • edited October 2007
    kryyst wrote:
    Not a spike a leak. A leak will cause it to spike up to 100% and generally sit there until you kill the process.


    so how is this resolved cause i've been doing different things all day,if comodo firewall,is not allowed to load at start up i seem to have no problems as so as it is allowed to run at start up it is as soon as it runs i cpu goes to 100% & stays there
  • ThraxThrax 🐌 Austin, TX Icrontian
    edited October 2007
    So uninstall comodo and reinstall.
  • edited October 2007
    Thrax wrote:
    So uninstall comodo and reinstall.


    hi thrax,
    i've done that, unistalled it removed all folders,& all reg entries, re -installed it low & behold it does the same thing all over again
  • JokkeJokke Bergen, Norway Icrontian
    edited October 2007
    Then use something else.
  • edited October 2007
    Jokke wrote:
    Then use something else.

    that's ok if i knew it was only that programmed then on the other hand what has caused the problem if there has been something else removed knowing why would be a god send
  • edited October 2007
    i re installed sp 2 don't know where it went to but didn't make any difference.

    everything is good after i found somthing in my start up i've googled it but to no avail


    xrt_jjvc.exe


    this file was created on the first day i was having trouble now where this has come from i have no idea placed it in the bin removed it from start up menu in msconfig rebooted pc

    everything ran as if therre was no problkems what so ever

    this was in a compressed folder called

    xrt_collect.zip



    i've googled that & could not find that either i maybe barking up the wrong tree but if this was designed to make you think that the firewall was the problem therefore forcing you to close it down then it has done its job
    luckily enough i have been using another pc to be online extremly baffled by all of this.
    any thoughts on what to do

    thanks for your help
    danny
  • kryystkryyst Ontario, Canada
    edited October 2007
    rename those files to something else, reboot and see if anything throws a fit. If not delete them. I can't find any reference to them anywhere.
  • edited October 2007
    kryyst wrote:
    rename those files to something else, reboot and see if anything throws a fit. If not delete them. I can't find any reference to them anywhere.

    i ran it through virusscan.jotti not a thing.removimg it the start menu has not caused any hissy fit yet pc looks to be clean if it was running at start up i would have thought it would be someplace in my hjt log but its not
  • edited October 2007
    danmiluk wrote:

    this was in a compressed folder called

    xrt_collect.zip

    I found a message today on a computer I cleaned an unknown virus/something out of yesterday. The error was "Could not copy the file xrt_collect" file or folder already exists." Searched the drive, no variation on the file name found. Looks like something is trying to create this filename or similar. Not good...

    Googling it, your post above was the only hit. This virus I cleaned yesterday remains nameless, the files it ran were unknown to Google et al. I used killbox to clean them out. Rebooted yesterday, ran up AVG, found nothing.

    How are you going now?
    DK
  • LeonardoLeonardo Wake up and smell the glaciers Eagle River, Alaska Icrontian
    edited October 2007
    It looks to me that your problem is way beyond any firewall-induced anomaly. I've moved your thread to the Spyware Removal sub-forum. If I'm in error, someone can move it back to software for you.
  • edited October 2007
    stuft wrote:
    I found a message today on a computer I cleaned an unknown virus/something out of yesterday. The error was "Could not copy the file xrt_collect" file or folder already exists." Searched the drive, no variation on the file name found. Looks like something is trying to create this filename or similar. Not good...

    Googling it, your post above was the only hit. This virus I cleaned yesterday remains nameless, the files it ran were unknown to Google et al. I used killbox to clean them out. Rebooted yesterday, ran up AVG, found nothing.

    How are you going now?
    DK

    pc is running fine a bit wary about going on password protected sites really don't know about it.

    i ran avg anti virus,adawre,spybot,also virruscan.jotti

    everything comes up with nothing
    was the pc you cleaned yours or someone elses
    it was only when my firewall was not working is when i came across it
    ther was another file that came with maybe you should search it aslo
    xrt_jjvc.exe
    probilly worth a look
  • edited October 2007
    danmiluk wrote:
    pc is running fine a bit wary about going on password protected sites really don't know about it.

    i ran avg anti virus,adawre,spybot,also virruscan.jotti

    everything comes up with nothing
    was the pc you cleaned yours or someone elses
    it was only when my firewall was not working is when i came across it
    ther was another file that came with maybe you should search it aslo
    xrt_jjvc.exe
    probilly worth a look

    The computer was a clients W2K machine with old, old NAV 14 months out of date. That was Part A of the problem. Theirs wasn't a firewall problem, didn't have the 100% CPU issue. Trojans/viruses were installed in a drive-by redirection hijack of a website they used sometimes for work. Naive users, not their fault.

    I used AVG free on the spot the day I found your post, found nothing, but the next day installed CA VET AV with that (next) days updates and found a virus. Also ran Spybot which found 3 more. Adaware found nothing much. So timing is everything.

    They were a combo of trojans and virus emailers. I used the nifty Killbox utility to remove two files that wouldn't go away - it will allow you to set a file for deletion on reboot, with a second option to replace it with a dummy file which you can delete later - a lifesaver.

    They had a Sony product driver installed so of course I found a rootkit-stlye hidden file. Removed by logging on as Administrator and deleting the whole \local settings\temp directory under the user folder.

    I can't post links yet, but if you need links to stuff reply in the forum and I will let you know where to look.

    Thanks for the update, I will check for that second file.
    Good luck.
  • edited October 2007
    Leonardo wrote:
    It looks to me that your problem is way beyond any firewall-induced anomaly. I've moved your thread to the Spyware Removal sub-forum. If I'm in error, someone can move it back to software for you.

    Sorry Leonardo, I replied via a link, missed your post.
  • edited October 2007
    the biggest problem i have is that if nothing was able to catch it or trace but it was able to knock out my firewall or bypass it i still don't know if there are any traces left on pc. accept for all the things i have found they are now deleted.if there are other files associated with this then i probably not know.
Sign In or Register to comment.