Spyware/Virus issue... ? 1

Technical User
Aug 27, 2007
I'm running an AMD Athlon 3000+ 64 processor (1.81GHz), 1GB RAM, ASUS Mobo, and also a GeForce 7600GS video card.

I'm not sure what happened but out of nowhere my computer's CPU Usage is hovering at 50-85% at any given time, just idling. I've run four different spyware removers, two AV apps, two registry repairers, and even reinstalled my video card drivers because that was the last change. I'm completely stumped as to what could be wrong here.

Here is my HijackThis log, if anybody would be so kind as to help me identify which are not needed.

Logfile of HijackThis v1.97.7
Scan saved at 10:13:03 PM, on 8/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: *.line6.net
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) -
Download the latest version of Hijack This, yours is very ancient.

I didn't see any examples of malware in your current log.

What is Task Manager telling you about Process running with high CPU cycles.

What is showing in your Event Viewer?

What happens in Safe Mode?

What happens in Normal Mode with another user?

If Safe Mode is OK go down this path.

310353 - How to Perform a Clean Boot in Windows XP

316434 - HOW TO: Perform Advanced Clean-Boot Troubleshooting in Windows XP

310560 - How to Troubleshoot By Using the Msconfig Utility in Windows XP

Some general things to try.

See if System Restore will get you back to a restore point before your problem with Windows.

Try running ChkDsk to check your drive for errors. Right-click your Drive icon/ Properties/ Tools/ Error Checking. Select both boxes.

Run the System File Checker program from the Run Box by typing.....Sfc /Scannow in it and have your XP CD handy.

HOW TO: Verify Unsigned Device Drivers in Windows XP

If they don't work you could try repairing windows by running it over itself. You will lose all your windows updates but your files will be untouched.

How to Perform an In-Place Upgrade (Reinstallation) of Windows XP (Q315341)

I'm not 100% sure...but you may want to deactivate the BitTorrent.

I use uTorrent myself and usually set my share ratio limit to < 3% per torrent instead of the defaulted 150%. I also keep an eye on the READ/WRITE stats under the "speed" tab. I've also noticed that uTorrent (and possibly BitTorrent) will continue to run in the background even if I manually close/exit the program from the taskbar.

If it doesn't help, you may want to consider uninstalling it; then reinstalling it as/when needed.

FYI - it's not malware as noted by linney, it's just a hog by design.


--> It's a bird! It's a plane! No, it's an OS update patch! Ahh!! <--
BitTorrent is rarely in use, I decided to get rid of it; you're just seeing what I was not able to remove outside of HijackThis.

Safe Mode is perfectly fine - 0-2% CPU Usage on both Admin and user account.

Task Manager shows all normal processes, nearly all of them are Windows or Network Services. I recognize all running processes.

I only have one user account on this machine.

I had debated the Clean Boot, but wasn't entirely sure if it would be the best of ideas, as it seemed to me that some necessary services or applications would need certain components, etc.

I did try to go through a System Restore; this problem barely started today, and my machine creates a restore point nearly every day. No difference for any restore point.

I'm going to run a check disk right now, and let it run while I sleep. I have a feeling that it'll come up with a blank report as all of my other scans have :(

Lastly, after letting my machine sit for three hours it finally dropped down to the normal 0-2% CPU Usage in the Task Manager. I did nothing, and have been very paranoid about anything running in the background to update - I even downloaded all Windows Updates available to ensure that the wuaucl was not running (and it wasn't) and disabled my AV software.

I will let you know if the problem persists after the check disk.

Also, thanks for the updated HijackThis! Here's a new log from that version:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:56:58 PM, on 8/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) -
End of file - 4780 bytes
The log still seems to be clear of malware from what I can see.

I don't agree with you about troubleshooting using the MsConfig and clean boot procedure, I find that invaluable in these type of situations. As it is Safe Mode is OK, so something that is not running then but normally does seems to be causing a problem.

I hope however now that the activity has settled down it stays that way. Let us know so we can continue troubleshooting.
as Linney mentioned, the log is CLEAN, but you can clean out your PC autostarts by deleting the following, as they are not needed:

nVidia, but not necessary at startup:
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

Sun JAVA updater, update manually:
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

QT - QuickTime, does not need to run in the BACKGROUND...
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

Nero Filter Checker, it's not necessary anymore:
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

Not dangerous but also NOT necessary:
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Yahoo Companion?
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

question: which version of DAEMONTOOLS are you using? some of the older versions had problems, and does it need to be running ALL the time in the BACKGROUND? or only when you need it?
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033


"If it works don't fix it! If it doesn't use a sledgehammer..."
I greatly appreciate everybody's input. [love2]
As stated by two other users, my machine is rather clean of malware (at least, to the naked eye).

My CPU Usage a still runs upward to 85% just idling, so whenever I load ANYTHING fullscreen, it becomes very choppy.
This problem temporarily died down, leading me to think that it may have been okay but it came back.

Through SpyEraser I found 10 registry keys for an application called "Remotely Anywhere" which I've never installed. Removing these keys, however, made no difference. I'm still hovering between 40-85% CPU Usage.
Because this problem dies down and comes back, I'm lead to believe that SOMETHING is running in the background but I absolutely cannot see it. The only thing that I could think is that a MS service is running and the Task Manager isn't reporting it, but this does not seem possible.

To answer a few questions:
Yahoo has been wiped out, but I removed that startup key to be safe.
I have killed ALL processes with the user account's username (except explorer.exe of course) and kept ONLY "SYSTEM" "NETWORK SERVICE" and "LOCAL SERVICE" yet my CPU Usage is high.
I have killed ALL startup items yet this problem still persists.


One possibility?
The reason that I updated my video card drivers, aside from them being old at the time, was because the video game BioShock was too intense for my machine. The game crashed my computer numerous times before I upgraded.
The first time my computer rebooted, it appeared as though my USB ports were fried because the keyboard was not being recognized. Unplugging the machine and plugging it back in resolved that....
The persistent problem that I have now is that my machine freezes on the mobo's splash screen.
This may be related to the issue, but it started happening a week before the high CPU Usage problem, so I'm not entirely sure.
One malware to consider is a Rootkit infection. AVG has a free Rootkit program that's supposed to be quite good.

There will be other rootkit checkers if you Google for them.

I'd also be looking at the motherboard problem.

PC Freezing - Hard to explain (see details)

xp freeze troubleshooting
No rootkit found :(

On a side note, I cleared up about 15GB of unnecessary files that I was procrastinating from, and now the CPU Usage peaks at 40%.

I'm very near a full reinstall, but I'm holding onto every little shred of hope that it doesn't come to that :(

I'll look into the mobo link once this is taken care of :)
Does something like Process Monitor from give you more details or help?

I still come back to the fact that the problem is not apparent in Safe Mode, so if you have disabled all starting process from Normal Mode and the problem still exists, then the only things which DON'T load in Safe Mode but DO if Msconfig is used are Drivers.

HOW TO: Verify Unsigned Device Drivers in Windows XP
try ccleaner to clean the temp files
remove the antivirus that you have and try Avast Home. its free and very good

if you have a spare drive load windows on to that and see if you get the memory spikes
what you are describing sounds alot like a hardware issue. ram and/or CPU that has got very hot has a tendency to spike the usage.
so does DMA settings for the harddrive controller. if it has defaulted into a non-Ultra DMA setting(PIO MODE)(does this after 6 consecutive errors) it will spike and the system will be slow

I am kinda leaning toward bad ram

this is another program that may help
jv16 PowerTools

It is not free but is one of the best out there.
well worth the money

I think after the full install you will end up with the same issue after a bit
firewolfrl", as per usual there is a lot of good stuff in your post, however, how do you see the fact that there appears to be no problems in Safe Mode for "nation543"?

I did see that fact....lol....

and here is my reasoning

if it is ram, the chipsets and /or the CPU and it is running 16 bit code with no problems and is running 32bit code with some issues the system will start to use a high CPU load

I just breakdown the components of a computer in a pure electronic mode without considering the software

If per say the CPU as example has one corrupt element that such as a low voltage or short due the a DVD drive that is cross-feeding the IDE controller. then lets add that the corrupt element is a small part of the controlling element that the 32 bit processing happens...that portion goes into an endless loop and causes the CPU to run a little bit hotter and act as though its under a heavy load

now lets add SAFE MODE
Safe Mode hits the electronics a little bit different. for the most part it runs as a 16 bit software and it may not access any of the bad portion of 32 bit corrupt element. there for no endless loop and no CPU load.
this is why when ram is bad you can run somewhat normal in safe mode sometimes
this corrupt element can go away if the device causing the issue is removed

I wonder if the video card is underpowered? that will cause a high CPU load.

nation543 needs to have everything unplugged except the video card and bootable harddrive that means all the IDE ribbons and SATA cables . also unplug all the power to these devices...don't forget to unplug every PCI card and USB plug

then boot and see if the issue is still there. if it is still there it maybe a software as linney thinks it is or it may be within the Motherboard itself. I kinda think outside the box and look beyond the software approach. I look at it this way I have a fifty fifty chance to be right....lol

Do listen to Linney and the others....they have been posting advice for a long time and they are a wealth of info. even I have to concede to their knowledge at times....LOL

I have only ever posted once in the hardware forum, and everybody died of shock when I did, which shows you just how much I know about the hardware side of things. Mind you I did get a star for that one post, so I'm batting at 100% on hardware matters.

Thanks for your explanation and further suggestions, I shall no doubt be referring to them in the future.

linney said:
I have only ever posted once in the hardware forum, and everybody died of shock when I did, which shows you just how much I know about the hardware side of things. Mind you I did get a star for that one post, so I'm batting at 100% on hardware matters.

That was a good one...

thank you linney for the first chuckle of the day... ;)


"If it works don't fix it! If it doesn't use a sledgehammer..."
OMG that is funny Linney
I once used a 9 volt battery and a capacitor to make a shock chair for a marine on a ship I was on. it was set up to get a marine that had pulled a practical joke on me before. in deployment for 6 plus months we had been playing practical jokes on each other for that length of time.
you can imagine my chagrin when the marine commander sat in the chair. I was Navy and he asked my command to "borrow me for one week. first he had me make another one for him then I and my marine partner had the most intense work-out in our lives for that week. because the one marine was working out with me ....all the marines not on duty worked out.My shop ended coming down and working out too....what a tradition I sure started.

I should have become a software geek instead....LOL

I sure would like to know what you have found out so far?
At this time, the only problems that I am experiencing is a delay in launching applications such as IE, or Bioshock and other full screen games.

I have been considering updating the RAM and video card, as they're sub-par; a 7800 or 7900 would be grand, but I'm strapped for cash so I'm trying not to do anything that I'm not literally forced to do.

It appears that either my OS was getting overwhelmed because I was running at about 20% HDD capacity, or something was corrupted in the myriad of apps and files that I cleared; I'm now running at around 45-50% capacity and not experiencing severe problems.

look I have read many post's here and I came out with this solution....I had problems with my CPU, high CPU and Kernel almost 100% everytime but I read somewhere here that in task manager at the "Processes" tab the System Idle Process tells how much CPU is not used:D so I just looked at the CPU colume and I must tell you that this colum helped me find the problem in my computer. the problem was my ESET NOD32 antivirus and I'm extreamly happy that I found out...When I activate NOD32 after some sec on the "Processes" tap at NOD32 the CPU was going like 100% so I stoped NOD32 and everything came to normal.....I read somewher here that some Realtime protected antivirusis may do somthing like this and I think NOD32 is one of them so I will try another antivirus and see what the concusions are ;) .....I forgot to mention SMTP ?! I read somewhere here that in antivirus you shold stop SMTP or how that guy said checking for every file or folder that si in or geting in, I dont know about this one but I hope I helped, cuz I made this user only to help you guys cuz I found my problem ;)
