Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 26, 2013, 02:09:29 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664102
Posts
70639
Topics
153609
Members
Latest Member:
Hefusase
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
General Security Questions and Comments
100% cpu load, reason unknown.
« previous
next »
Pages:
[
1
]
Author
Topic: 100% cpu load, reason unknown. (Read 7266 times)
Maniak2000
Comodo's Hero
Offline
Posts: 307
100% cpu load, reason unknown.
«
on:
March 31, 2012, 12:54:01 AM »
Hello all. Not sure if this is the right sub forum for this type of questions, so please move it if necessary.
Yesterday I was asked to look at the PC remotely by my friend to check thinks (you know, check for viruses, clean stuff etc). I noticed it was running very slow, I looked at task manager it said cpu load was 100% but when I sorted the prosecces by cpu usage, no process was using 100% cpu or even close, while idling. (System Idle proccess was at 80 - 90% I think and other processes didn't add up to anywhere near 100%, show processes from all users are checked). I scanned the system with MBAM, super antispyware, Hitman pro, CCE, TDSS killer and Emsisodt emergency kit. apart from bunch of tracking coockies everything turned up clean. No malware or even unknown entries in Killswitch and Autorun analyzer.
Wierd thing I noticed, according to Windows task manager, Process explorer and killswitch CPU hog (the cilprit) is whatever program I start, I mean if I start CCE, it will use 60 and up % cpu, if I start process explorer then it will use 60% and up of CPU etc.
I don't think it's HDD PIO mode problem.
Since it was remote connection I couldn't use safe mode or boot cd.
Os on that PC is Win 7 x32
CPU is Pentiom 4 2.93 Ghz
4 gb Ram
I've run out of ideas, any help?
«
Last Edit: March 31, 2012, 01:10:10 AM by Maniak2000
»
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: 100% cpu load, reason unknown.
«
Reply #1 on:
March 31, 2012, 04:23:42 PM »
Maybe it's just a bunch of temp, logs and other stuff that has build up over time that's slowing down the pc. You can use ccleaner or even comodo system cleaner <-----either case, save a backup of whatever gets cleaned. That way if something bad happens(not likely, it can always be put back the way it was before starting)
I posted a portable version of ccleaner here, if you want to try that out.
CCleaner.zip
(1234.05 KB - downloaded 1 times.)
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Maniak2000
Comodo's Hero
Offline
Posts: 307
Re: 100% cpu load, reason unknown.
«
Reply #2 on:
March 31, 2012, 05:43:58 PM »
I used Ccleaner for disk and registry clean-up, and defragmented all drives with Auslogics disk defrag..... no effect on CPU load...... it still says 100% load with whatever I start being cpu hog....
There are no unknown devices or devices with error(s) in device manager (there were 2 devices without drivers, but I found apropriate drivers for them).
«
Last Edit: March 31, 2012, 05:46:24 PM by Maniak2000
»
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: 100% cpu load, reason unknown.
«
Reply #3 on:
March 31, 2012, 05:59:38 PM »
Has any software been updated recently??
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: 100% cpu load, reason unknown.
«
Reply #4 on:
March 31, 2012, 06:14:33 PM »
You say you
don't think
it is HDD PIO mode problem. Did you check to be 100% sure? It can really contribute to hight CPU usage.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Maniak2000
Comodo's Hero
Offline
Posts: 307
Re: 100% cpu load, reason unknown.
«
Reply #5 on:
April 01, 2012, 12:51:21 AM »
Let's see... updated \ installed software: MBAM free, Emsisoft emergency kit, CCE, Super antispyware, Hitman pro (on demand only), TDSSkiller, Ccleaner, Auslogics Disk Defrag.
Installed drivers for 2 unknown devices, one of them was Asus acpi and other was RTL8187_Wireless.
HDD is listed as ST3200826AS ATA Device, appears to be SATA HDD and I think PIO problem are only for IDE HDDs
Cd-rom is listed as _NEC DVD_RW ND-4551A ATA Device, so I don't think is the problem, no disk was present in cd-rom drive......if that matters.
Logged
MetalMaster
Newbie
Offline
Posts: 1
Re: 100% cpu load, reason unknown.
«
Reply #6 on:
April 01, 2012, 03:08:24 AM »
Hello all,
I'm interested in how to sort this problem out. My desktop (W7-64bit, Q6600 4core 2.4Ghz, 8GB RAM, nice Gigabyte MB, and no overclock) is having the same issue. A full mode virus scan taxes my CPU so badly that basic functions like opening a window bogs down. CPU spikes and stays from high 80s to 100% load the entire scan duration. The scan process renders my computer unusable until it is complete. I have the latest updated Pro version of CIS installed. Also something to note, my RAM usage never goes above 50-60% during this time.
What I find interesting is I have the free version of CIS on my laptop(HP dv6-3050us, 4core, W7-64bit, 8GB RAM) and it runs nearly the opposite. My RAM gets taxed and my CPU rarely spikes to high 80's. It is also completely usable and barely has lag.
Something is up for sure. What is this HDD PIO mode problem?? Is there a setting I've chosen I can change somewhere? This is the only program short of Prime95 that taxes my CPU so much.
Cyber high-fives to anyone that can help. Thanks
Logged
Maniak2000
Comodo's Hero
Offline
Posts: 307
Re: 100% cpu load, reason unknown.
«
Reply #7 on:
April 01, 2012, 03:54:02 AM »
PIO is sort of last resort transfer mode for HDD, if anything else is unavailable, it works but it's very CPU demanding and pretty slow..... That's how I understand it anyway, correct me if I'm wrong.
You can see your current transfer mode with system info programs like Speccy (
http://filehippo.com/download_speccy/
) hard drives section. Mine is using Sata III mode (see screenshot).
I'm pretty sure the problem PC is using Sata I mode...... but I'll double check that when I'm able to connect to it.
MetalMaster, if your CPU spikes only when you're doing antivirus scan, parhaps you got some other antivirus or antimalware or some sort of real-time scanner running along with CIS (Windows defender for example). Or parhaps remains of a previous anti-virus \ security suite you were using wasn't complete deleted. These are some uninstall tools for popular security products, if you were using any of these before CIS, they might clean things up
http://kb.eset.com/esetkb/index?page=content&id=SOLN146
Spec.JPG
(90.36 KB, 800x597 - viewed 12 times.)
Logged
Maniak2000
Comodo's Hero
Offline
Posts: 307
Re: 100% cpu load, reason unknown.
«
Reply #8 on:
April 02, 2012, 05:59:22 AM »
Here is some info I got from that pc:
System specs by speccy
http://speccy.piriform.com/results/7DaspOq754NJO45Y5IAwEBI
HijackThis log and GMER log - if anyone can read those
Hope this helps.
HijackThis.log
(4.12 KB - downloaded 3 times.)
Gmer.log
(8.27 KB - downloaded 6 times.)
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: 100% cpu load, reason unknown.
«
Reply #9 on:
April 02, 2012, 06:21:40 PM »
Looking into the hardware specs Speccy says the SATA transfer mode is SATA III where the hard drive is SATA 1. That's odd. Can you check that BIOS setting match SATA modes between motherboard and hard drive?
I checked your Gmer log. The entries for the registry. Are they in red when looking in the Gmer interface? Red means they are hidden. Can you show a screenshot? I attached an image of that part of the registry that Gmer is pointing to from my Windows 7
Another thing that I notice is the very limited amount of services running. Is this a stripped, nLite, version of Windows 7? May be there are services not running that should be running. It is possible to strip Windows with nLite and make it no longer function like it should.
Gmer registry.png
(139.24 KB, 1280x984 - viewed 7 times.)
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Maniak2000
Comodo's Hero
Offline
Posts: 307
Re: 100% cpu load, reason unknown.
«
Reply #10 on:
April 03, 2012, 02:54:35 AM »
I can't really check the bios remotely......can I? But I could try to tell someone over there to check it for me over the phone. What should I ...... or they be looking for exactly?
There weren't any red entries in GMER interface so I just saved the log and posted it here.
They seem to have Win 7 Ultimate x32 on that Pc, I have no idea if it's stripped nLited or anything..... Is there any specific services that could affect CPU usage when not running, I should look out for?
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: 100% cpu load, reason unknown.
«
Reply #11 on:
April 03, 2012, 12:25:54 PM »
There is nothing I can add to help you diagnose over the phone. For the BIOS you need to be hands on and just see if you see anything unusual. We still could be looking at an error by Speccy.
Can you check in Gmer under the registry tab for the entries that are in the logs?
My remark about a possible stripped version was me totally thinking out loud. I can give nothing to specifically look for. Better ask the user or the person who installed for the user.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.047 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com