Microsoft
Software
Hardware
Network
Question : Problem: svcost.exe process killing machine, hijackthis log included
i have a laptop that keeps running an svchost process which kills all my CPU usage and locks the machine down.
Below, I've included the hijackthis log off the machine, any input would be greatly greatly appreciated.
Andvanced thanks, Ari
Logfile of HijackThis v1.99.1
Scan saved at 10:43:34 AM, on 5/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
C:\Program Files\Intel\Wireless\Bin\W
LKeeper.ex
e
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\
Binn\sqlse
rvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NI
CCONFIGSVC
.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\HPZipm
12.exe
C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
C:\WINDOWS\TEMP\XS1467.EXE
C:\Program Files\Intel\Wireless\Bin\Z
cfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless
\Bin\1XCon
fig.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\WINDOWS\system32\hkcmd.
exe
C:\WINDOWS\system32\igfxpe
rs.exe
C:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
C:\Program Files\Intel\Wireless\Bin\i
frmewrk.ex
e
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quicks
et.exe
C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe
C:\Program Files\Real\RealPlayer\Real
Play.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
exe
C:\Program Files\NetWaiting\netWaitin
g.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.1128.54
62\GoogleT
oolbarNoti
fier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.
exe
C:\WINDOWS\system32\igfxsr
vc.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\msiexe
c.exe
C:\Program Files\DellSupport\DSAgnt.e
xe
C:\Program Files\Trend Micro\Client Server Security Agent\pccnt.exe
C:\Documents and Settings\daniel\Desktop\Hi
jackThis.e
xe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fw
link/?Link
Id=69157
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fw
link/?Link
Id=54896
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fw
link/?Link
Id=54896
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fw
link/?Link
Id=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
3.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A
07C3DB8F77
7} - c:\Program Files\GoogleAFE\GoogleAE.d
ll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-1
0AC9BABA46
C} - C:\Program Files\Canon\Easy-WebPrint\
Toolband.d
ll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
3.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [DellCleanup] c:\DELL\WINCLEAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bi
n\jusched.
exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\i
frmewrk.ex
e /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quicks
et.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
Service\is
uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MS
KDetct.exe
/uninstall
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2
.0\OpwareS
E2.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaitin
g.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.1128.54
62\GoogleT
oolbarNoti
fier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.e
xe" /startup
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
Update\qbu
pdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\
Resource.d
ll/RC_AddT
oList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\
Resource.d
ll/RC_HSPr
int.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\
Resource.d
ll/RC_Prev
iew.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\
Resource.d
ll/RC_Prin
t.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_03\bi
n\npjpi142
_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_03\bi
n\npjpi142
_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00134F72-5284-44F7-95A8-5
2A619F7075
1} (ObjWinNTCheck Class) -
https://sbserver.sbroome.l
ocal:4343/
officescan
/console/
C
lientInsta
ll/WinNTCh
k.cab
O16 - DPF: {08D75BB0-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupINICtrl Class) -
https://sbserver.sbroome.l
ocal:4343/
officescan
/console/
C
lientInsta
ll/setupin
i.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
https://sbserver.sbroome.l
ocal:4343/
officescan
/console/
C
lientInsta
ll/setup.c
ab
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fw
link/?link
id=39204
O16 - DPF: {35C3D91E-401A-4E45-88A5-F
3B32CD72DF
4} (Encrypt Class) -
https://sbserver.sbroome.l
ocal:4343/
SMB/consol
e/html/roo
t/
AtxEnc.c
ab
O16 - DPF: {5EFE8CB1-D095-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment ObjRemoveCtrl Class) -
https://sbserver.sbroome.l
ocal:4343/
officescan
/console/
C
lientInsta
ll/RemoveC
trl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.co
m/microsof
tupdate/v6
/V5Control
s/en/
x86/c
lient/muwe
b_site.cab
?114865004
7593
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = SBroome.local
O17 - HKLM\Software\..\Telephony
: DomainName = SBroome.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = SBroome.local
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
1\GOEC62~1
.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxde
v.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\L
gNotify.dl
l
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
on.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NI
CCONFIGSVC
.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\W
LKeeper.ex
e
Answer : Problem: svcost.exe process killing machine, hijackthis log included
probably MS automated updates is causing the issue. Known problem but even the MS patch does not always fix it.
Random Solutions
Problem: power save/reboot for no reason
Problem: Why do all computers on my network default to Google FRANCE????
Problem: ATA and SATA2
Problem: Need Hardware Reccomendations for Domain Controller
Problem: Use my Windows Mobile 5.0 Phone Edition phone as USB modem for my PC
Problem: Cisco 2611 to Netscreen 5XP Vpn Problem
Problem: Imaging XP to external drive and restore back from external drive
Problem: Can I use an Iphone purchased from a foreign country in India
Problem: Sound is scratchy, distorted, and sometimes system hangs for a few seconds
Problem: Suggestions welcomed: Jumbo frames w/ 1gb connections