my girlfriends machine is a 1.3 pentium 3, 512 ram, xp home system
it work fine and then all of a sudden the scvhost will shoot up to 99% cpu usage and cause the system to slow to a crawl.
i have scanned for a virus, a trojan, both spybot and adaware and all have come up clean.
i did the decombobulater, changed the rpc permissions to "restart the service".
here is a copy of the hijack log:
Logfile of HijackThis v1.97.7
Scan saved at 10:10:48 PM, on 12/6/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Documents and Settings\Jim\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\system32\svchost.exe
F1 - win.ini: load=???
??? ???
?
???
F1 - win.ini: run=???
??? ???
?
???
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: axscanner -
http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: axscannerruntime -
http://www.pestscan.com/scanner/axscannerruntime.cab
O16 - DPF: First Class Solitaire by pogo -
http://temp38.pogo.com/applet/solita...-ob-assets.cab
O16 - DPF: Jungle Gin by pogo -
http://gin.pogo.com/applet/gin/gin-ob-assets.cab
O16 - DPF: mscomctl -
http://www.pestscan.com/scanner/mscomctl.cab
O16 - DPF: msvcp71 -
http://download.pestpatrol.com/Downl...ts/msvcp71.cab
O16 - DPF: msvcr71 -
http://download.pestpatrol.com/Downl...ts/msvcr71.cab
O16 - DPF: Payday FreeCell by pogo -
http://freecell.pogo.com/applet/free...-ob-assets.cab
O16 - DPF: Pop Fu by pogo -
http://popfu.pogo.com/applet/popfu/popfu-ob-assets.cab
O16 - DPF: ppctlcab -
http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: Spades by pogo -
http://spades12.pogo.com/applet/spad...-ob-assets.cab
O16 - DPF: Squelchies by pogo -
http://squelchies.pogo.com/applet/sq...-ob-assets.cab
O16 - DPF: Sweet Tooth TM by pogo -
http://temp83fe.pogo.com/applet/swee...-ob-assets.cab
O16 - DPF: Tumble Bees by pogo -
http://jumbee.pogo.com/applet/jumbee...-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo -
http://turbo12.pogo.com/applet/turbo...-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo -
http://whackdown.pogo.com/applet/wha...-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
http://office.microsoft.com/officeup...ntent/opuc.cab
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) -
http://www.otxresearch.com/OTXMedia/OTXMedia.dll
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.co...941.6139930556
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cab
any help would REALLY be appreciated! i'm ready to toss this box on the street!