CPU Usage Abnormal

AeromavAeromav Philippines Member
edited December 2011 in Science & Tech
Greeting Icrontic. I have a problem on my laptop recently. it's like its controlling itself (something happens even if
it's idle). When i look at the task manager the cpu usage has abnormally going up and down even there's no open apps and the computer is idle. Based on what ive read on the forums in the net it may be
caused by malware. Can someone please review my HJT logfile. By the way when i first run HJT it opens message box saying (For some reason your system denied write access to the Hosts file. If any hijacked domains are
in the file, HijackThis may not be able to fix this). Thanks in advance.

Comments

  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited November 2011
    Aeromav wrote:
    Greeting Icrontic. I have a problem on my laptop recently. it's like its controlling itself (something happens even if
    it's idle). When i look at the task manager the cpu usage has abnormally going up and down even there's no open apps and the computer is idle. Based on what ive read on the forums in the net it may be
    caused by malware. Can someone please review my HJT logfile. By the way when i first run HJT it opens message box saying (For some reason your system denied write access to the Hosts file. If any hijacked domains are
    in the file, HijackThis may not be able to fix this). Thanks in advance.

    We do not do security analysis anymore, sorry. However, there are some things that HJT told me that are not purely security which might cause at least some of what you have so I will help with that part.

    I can tell you that you might do well to run Avast! Free or paid and also CCleaner and Registry Mechanic. Also run AVG after the Avast! run, but if you run AVG Free you need to update it as far as version and definitions.

    I personally recommend Registry Mechanic 2012 trial or paid version over CCleaner, but Tushon (I respect him) would strongly recommend CCleaner. Running BOTH Registry Mechanic and CCleaner one time each will not hurt. Both will get rid of the registry entries that lead to missing files-- Windows will run better with those registry entries long gone(among other things Windows will stop trying to FIND all those missing files in its spare time).

    The Free File Downloader I kinda wonder about, but mostly because I am unfamiliar with it and because free downloaders tend to do other things sometimes (bitTorrent will set it self up as a file downloader and uploader, automatically). I would uninstall it, get GetRight or some such (I use FTP Voyager now, but it is technical to use while GetRight is easy to use).

    The other thing I do not see is a firewall, and if you have XP you might find a two-way firewall useful. Vista has one, but I still have ESET's firewall enabled.

    Good Luck and Happy Thanksgiving (I am American, share my joy please!).
  • AeromavAeromav Philippines Member
    edited November 2011
    Thanks for the reply. Well ill try to run avg again to see If theres an infection or not. I'm also using ccleaner before turning my computer off. Tried also cleaning the registry last night, run ccleaner thrice. Ive installed spybot search and destroy, update and run it but it did not detect anything. Do you think that the cause of the problem is the file csrss.exe? I've read some forums in the net that csrss.exe is a trojan. I cannot delete this file.
    One thing more sometimes when I boot my laptop it goes on the windows boot mAnager first. And I noticed that when I open a new txt doc and the problem occur it types the date on the txt document then the CPU usage goes abnormal. Hope you understand my English. Thanks again for the reply. Happy thanksgiving.
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited November 2011
    Aeromav wrote:
    Thanks for the reply. Well ill try to run avg again to see If theres an infection or not. I'm also using ccleaner before turning my computer off. Tried also cleaning the registry last night, run ccleaner thrice. Ive installed spybot search and destroy, update and run it but it did not detect anything. Do you think that the cause of the problem is the file csrss.exe? I've read some forums in the net that csrss.exe is a trojan. I cannot delete this file.
    One thing more sometimes when I boot my laptop it goes on the windows boot mAnager first. And I noticed that when I open a new txt doc and the problem occur it types the date on the txt document then the CPU usage goes abnormal. Hope you understand my English. Thanks again for the reply. Happy thanksgiving.

    Well, it can become infected, but AVG can clean it-- csrss.exe needs to be there though. The abnormal thing as to CPU use can be traced to what is explained at the link, but you will lose all sorts of personal settings doing that process of deleteing and remaking a user profile as explained below at the link:

    http://www.computerhope.com/issues/ch000916.htm explains it as simply as I could, so will let computerhope.com have the credit.

    John.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    edited November 2011
    Take a look at the instructions I posted here, and then post your logs. We don't officially have a spyware help section anymore (it was gone before I showed up), but I'm happy to help people when I know I'll have time. Make sure you run HJT as admin (through the right-click menu) to get accurate results. Here is a site that talks about the hosts file location and how to view it (you can post the contents here if you want to be sure it is okay)
    I personally recommend Registry Mechanic 2012 trial or paid version over CCleaner, but Tushon (I respect him) would strongly recommend CCleaner. Running BOTH Registry Mechanic and CCleaner one time each will not hurt. Both will get rid of the registry entries that lead to missing files-- Windows will run better with those registry entries long gone(among other things Windows will stop trying to FIND all those missing files in its spare time).

    Thanks! We all have our different experiences with products and reasons for recommending one or the other. Both won't hurt.

    csrss.exe: After running combofix and malwarebytes, you can run the following from a run prompt (windows key + r) to repair any critical windows files (of which, csrss.exe is one) that may have been affected by a virus.
    sfc /scannow

    Keep in mind that sometimes, computers will just have spikes in CPU usage for odd reasons that are in no way bad, just special.
  • AeromavAeromav Philippines Member
    edited November 2011
    Tushon wrote:
    Take a look at the instructions I posted here, and then post your logs. We don't officially have a spyware help section anymore (it was gone before I showed up), but I'm happy to help people when I know I'll have time. Make sure you run HJT as admin (through the right-click menu) to get accurate results. Here is a site that talks about the hosts file location and how to view it (you can post the contents here if you want to be sure it is okay)



    Thanks! We all have our different experiences with products and reasons for recommending one or the other. Both won't hurt.

    csrss.exe: After running combofix and malwarebytes, you can run the following from a run prompt (windows key + r) to repair any critical windows files (of which, csrss.exe is one) that may have been affected by a virus.


    Keep in mind that sometimes, computers will just have spikes in CPU usage for odd reasons that are in no way bad, just special.


    Thanks guys for the replies. I've scanned my laptop with AVG ang malwarebytes but it detected
    nothing. also tried "sfc /scannow" it didn;t work. I've attached another HJT log running it as
    administrator and a CBS Log. I also attached a txt doc. thats what my computer does when the problem
    occur. it types the date continously and the cpu usage goes abnormal. it will only stop if i
    press a botton on the keyboard. Thanks in advance.
  • AeromavAeromav Philippines Member
    edited November 2011
    one thing more I also attached
    a screen shot of my desktop. i just want to ask if the csrss.exe and rundll32.exe doesnt
    really have a username. Thanks again in advance.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    edited November 2011
    Did you run combofix? That doesn't look like the log I typically see from it (it will probably be on the root of your C: drive), but maybe one of the sub-logs. In the task manager, right-click on the processes with no names and "Open File Location". Depending on where they are can tell us about the likelihood they are normal.
  • AeromavAeromav Philippines Member
    edited December 2011
    Tushon wrote:
    Did you run combofix? That doesn't look like the log I typically see from it (it will probably be on the root of your C: drive), but maybe one of the sub-logs. In the task manager, right-click on the processes with no names and "Open File Location". Depending on where they are can tell us about the likelihood they are normal.


    Sorry for the late reply. Yes I've run combofix. attached is the log from combofix. But it run only in reduced functionality mode. When i installed combofix it pops up an error message "date error change your setting", something like that.

    Tried also right clicking the file (with no username) and clicking open file location in the task manager. It does nothing. The csrss.exe and the two rundll32.exe. But when I try the other files it goes to the folder where they are.

    Thanks again in advance.
  • Straight_ManStraight_Man Geeky, in my own way Naples, FL Icrontian
    edited December 2011
    Aeromav wrote:
    Sorry for the late reply. Yes I've run combofix. attached is the log from combofix. But it run only in reduced functionality mode. When i installed combofix it pops up an error message "date error change your setting", something like that.

    Thanks again in advance.

    UPDATE AVG to latest definition set and run, please. Combofix says it is out of date. AVG 2012 is available now, also. That might be what Combofix is yelling about.

    John.
  • TushonTushon I'm scared, Coach Alexandria, VA Icrontian
    edited December 2011
    Aeromav wrote:
    Sorry for the late reply. Yes I've run combofix. attached is the log from combofix. But it run only in reduced functionality mode. When i installed combofix it pops up an error message "date error change your setting", something like that.

    Tried also right clicking the file (with no username) and clicking open file location in the task manager. It does nothing. The csrss.exe and the two rundll32.exe. But when I try the other files it goes to the folder where they are.

    Thanks again in advance.

    There are several very suspect entries (see the "BlindDial" stuff near the bottom for example), but your overall problems (and the lack of fixing by the various tools) lead me to believe the best recommendation would be a backup of appropriate data and re-imaging your machine with a fresh copy of Windows
  • AeromavAeromav Philippines Member
    edited December 2011
    Tushon wrote:
    There are several very suspect entries (see the "BlindDial" stuff near the bottom for example), but your overall problems (and the lack of fixing by the various tools) lead me to believe the best recommendation would be a backup of appropriate data and re-imaging your machine with a fresh copy of Windows



    Thanks for the help Tushon. I guess i'll just reinstall Windows to my laptop. It's just I'm busy nowadays thats why i can't start doing it.

    More power to Icrontic.


    Thanks again. :)
Sign In or Register to comment.