CPU 100% AND shortcuts when i type!!ARGH!
-
CPU 100% AND shortcuts when i type!!ARGH!
Hi all, I am new and have read the rules and searched the forum to aid my problem. I found one thread similar but not too much.
I have included a Hijackthis log file at the end.
I have ran Spybot and AVG as well as online trojan scans like at Symantec and Trojanscan. Nothing shows up.
I avoid MS products and use Netscape for browsing and Pegasus for mail.
My spec:
2.6 AMD
512mb ram
120gb
AS Rock motherboard
XP Home
Basically, probs started yesterday, I turn PC on and mouse cursor flashes. It is invisible more than it is visible. Emails I was typing no longer entered the characters I was pressing.
I CTRL - DEL - ALT and saw that CPU was jamming on 100%. Rebooting has no effect. I ran Spybot and an AVG virus scan to no avail.
I ran msconfig and saw nothing untoward except empty and unticked entries at the bottom. By unticked I mean they were not selecetd to start on startup and by empty I mean they were unnamed. No identification of what ther were. Only there location which was in software/MS/currentversion/run.
Nothing untoward in registry - not current version/run anyway. I suspected a worm but found nothing.
I went to view CPU usage in Task Manager and found saw that it was through the roof!
It seems whatever I am using at that time sends CPU thru the roof for a long time and then it reoccurs!
So if my browser is open, then netscp.exe - Netscape - sends it up to 99%!
Another time TskMgr.exe was at 99%!!!
When I send/receive mail, my mail program used 70%. IE too.
Even in idle, with nothing open CPU shoots up. I opened Task Manager to monitor things. Having it open and in the bottom right corner of my screen meant I didn't need to stare at TM all the time. I could carry on with tasks and keep an eye on it.
It was always filling the icon green - ie: 100% CPU.
Even with nothing open, it was Taskmgr that was 99%.
If it's Netscape, IE, mail or whatever, that process sends CPU thru the roof.
When the system jars, and the mouse disappears, I find that quickly pressing Alt and Tab brings it back immediately.....only for it to disappear again.
I did searches all last night on Google and found info relating to CPU usage, Sasser worms, Blaster virus etc and I DL all the fixes, Windows Updates and hot fixes etc but to no avail.
Whatever it is, it isn't anyone app that is doing this. it is everything I run.
This follows hot on the heels of a prob I got a few days earlier - and still have so I dunno if they are related.
Basically, when I type certain letters like I, R, E, U, L etc, the PC acts as though I have pressed them in conjunction with the MS key. So R opens Run, L locks the PC, U opens Narrator and E opens My Computer.
Imagine typing an email and seeing no text has been typed just 100 windows open!
The only fix I found was to press the MS key again but it always comes back. Sometimes immediately and I have to compose letters by copying and pasting individual letters from old emails!
USB ports are used for broadband modem and Logitech Webcam.
I would really appreciate some help as I am going mad - with both problems!
LOGFILE:
Logfile of HijackThis v1.98.2
Scan saved at 18:23:56, on 29/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
C:\WINDOWS\System32\wpabaln.exe
C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\Program Files\Overnet\overnet.exe
C:\WINDOWS\system32\utilman.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\PMAIL\WINPM-32.EXE
C:\Documents and Settings\Ice 9\Local Settings\Temp\Temporary Directory 1 for hijackthis_198.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.co.uk/"); (C:\Documents and Settings\Ice 9\Application Data\Mozilla\Profiles\default\tu639o7p.slt\prefs.j s)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchpl ugins%5CSBWeb_01.src"); (C:\Documents and Settings\Ice 9\Application Data\Mozilla\Profiles\default\tu639o7p.slt\prefs.j s)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/Sha...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1093748530421
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F23A14F7-D6F5-4E9A-A7CC-F0A7993B0499}: NameServer = 212.23.3.11 212.23.6.35
Many Thanks
Ice_9