Link to home
Start Free TrialLog in
Avatar of JAStillwell
JAStillwellFlag for United States of America

asked on

Trend Micro Worry Free causing System process (PID 4) to hog CPU cycles

Hello,

We have a Windows SBS 2003 network in our own office. The server also runs Trend Micro Worry Free Business Security Advanced v5.1 Build 1142 with two client computers attached (one wired Windows XP Pro, one wireless Windows Vista Business). Both computers exhibit a problem where the CPU cycles reach close to 100%, and both show "System" with a PID 4 hogging the cycles (JPG picture attached). This can occur for a couple minutes up to several hours, where the computer's CPU runs high and you can hear the fans spinning as fast as they can. Both computers are free of viruses and spyware as scans from Trend, and several other antivirus and anti-spyware utilities have shown.

Troubleshooting running processes and applications has led me to remove the Trend client from one computer, then both computers. Both computers stop running high CPU cycles with Trend removed and then System PID 4 starts grabbing CPU cycles almost immediately when re-installing the Trend client. Also, there are no scheduled scans set to run when the computers login, so Trend is not running a scan when the CPU cycles are high.

Besides looking for a newer version of Trend WFBS to install, or dumping Trend and installing something else, does anyone have any suggestions on how to solve this? We have numerous clients using Trend WFBS and nobody has reported this problem. Searching the web, I find no mention of it either. I can't possibly be the only one with this issue, can I? Am I being fooled by the CPU calming down when the Trend client is removed?

The system just calmed down before I ran HijackThis. Here is the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:24 PM, on 3/14/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mstsc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sbs:24554/sites/dcc/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [OE] C:\Program Files\Trend Micro\Client Server Security Agent\TMAS_OE\TMAS_OEMon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.autotask.com
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} (ObjWinNTCheck Class) - https://sbs:4343/officescan/console/ClientInstall/WinNTChk.cab
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) - https://sbs:4343/officescan/console/ClientInstall/setup.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {254AA86E-5655-4518-AA87-185D7CC41801} (LogMeIn Rescue Technician Console) - https://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
O16 - DPF: {2685176A-3502-47BB-B91D-BD28CA2A06A0} (vb6project_Test.AT_ActiveX_Test) - https://www.autotask.net/Public/BrowserDetect/AT_ActiveX_Test.CAB
O16 - DPF: {2F30081A-076B-4BD4-A6B7-566B9AF33EE5} (ATQB_Connect.AutotaskToQB) - https://www.autotask.net/billing/invoices/electronic_transfer/ATQB_Connect.CAB
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} (Encrypt Class) - https://idea-central:4343/officescan/console/html/AtxEnc.cab
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://sbs/ConnectComputer/nshelp.dll
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {69B502DF-D12F-4FD7-9892-D8DFA2D96474} (OfficeScan Management Console) - https://idea-central:4343/officescan/console/html/AtxConsole.cab
O16 - DPF: {9BBB3919-F518-4D06-8209-299FC243FC2A} (Encrypt Class) - https://server:4343/SMB/console/html/root/AtxEnc.cab
O16 - DPF: {9BBB3919-F518-4D06-8209-299FC243FC30} (Encrypt Class) - https://sbs:4343/SMB/console/html/root/AtxEnc.cab
O16 - DPF: {9DCD8EB7-E925-45C9-9321-8CA843FBED3C} (Security Server Management Console) - https://sbs:4343/SMB/console/html/root/AtxConsole.cab
O16 - DPF: {9DCD8EB7-E925-45C9-9321-8CA843FBED40} (Security Server Management Console) - https://sbs:4343/SMB/console/html/root/AtxConsole.cab
O16 - DPF: {A050E865-64E3-431B-8079-F0DFCEA90A2D} (PieChart Class) - https://idea-central:4343/officescan/console/html/AtxPie.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://download-games.pogo.com/online2/pogo/diner_dash_flo_on_the_go/ddfotg.1.0.0.33.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E78DE03F-DC83-40DB-B590-8FD80BE5F7C8} (Security Server Management Console) - https://server:4343/SMB/console/html/root/AtxConsole.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = DigitalCorral.local
O17 - HKLM\Software\..\Telephony: DomainName = DigitalCorral.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = DigitalCorral.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Advanced Monitoring Agent - Remote Monitoring - C:\PROGRA~1\ADVANC~1\winagent.exe
O23 - Service: Advanced Monitoring AutoUpdate - Unknown owner - C:\PROGRA~1\ADVANC~1\updater.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Sprint Con App Svc (CASprint) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Update Service (gupdate1c8fa2d86440862) (gupdate1c8fa2d86440862) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (file missing)
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
O23 - Service: Trend Micro Client/Server Security Agent Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe

--
End of file - 11006 bytes


Thanks for your insight!

Jeff
SystemPID4.JPG
Avatar of soundguymike
soundguymike

Just had a similar problem with trend micro officescan and our domain controller.
Try disabling the trend micro firewall.
Avatar of JAStillwell

ASKER

Soundguymike: I assume you mean to disable it on the main server console so the setting gets dished out to each workstation? Just want to make sure I'm following your instructions correctly.
Soundguymike: I just checked our settings and the Trend firewall is not active on the server or the desktops.

Any other thoughts?
We have the same problem here ...
Updated to the latest version (5.1), still the same problem.
Although we don't have the problem on all clients (different locations).
I'me not 100% sure, but I don't think XP machines have that problem.
Trendmicro doesn't give us solutions .... .
I have the same problem with version 3.6 and 5.1. Both on XP Pro and Vista Business. I can stop the problem if I unload the Trend client. Very frustrating!

Anyone else have any ideas what's up?
I found the solution!
you need to uninstall the 'Altiris' software from the HP machines.
Suppsaws: I'm glad that works for you, but I have HP and Dell computers that show the same problem. Plus the HP doesn't have the Altiris software installed. Guess I'll have to keep searching for a solution!
@JAStillwell, I notice your list of running processes includes Diskeeper. I experienced the same problem (pid 4, the system process, using high CPU). As soon as I stopped the Diskeeper service, the problem went away. Let us know if that solves it for you.
Carehart: I just noticed that about 10 minutes ago on my laptop and thought "I wonder if Diskeeper is causing a problem?". Weird. However, I have two computers (one Vista and one XP Pro) and only one of them has Diskeeper running on it (the Vista machine), however, both have the System PID 4 high cpu problem.

In my previous troubleshooting, I compared the installed software on both, pared down to the bare minimum on both, and narrowed the issue down to Trend Micro Worry Free client software. I can replicate the problem by installing or uninstalling the Trend client software 100% of the time. It would be nice to know what it is doing or what it is conflicting with. If I had Diskeeper installed on both, I would be excited by your idea, but oh well...back to the drawing board.

:)
Well, it's just that both do background operations that are nearly constantly running, it would seem.  I don't run TM, but looking at its site, it seems a security solution. DK is of course a full-time disk defrag solution. Both clearly have the goal of doing their job all the time. Now, it's interesting, I'm running DK 2009, and one of its features is "InvisiTasking", so that it should not be using resources heavily while I am, but it just hasn't proven to work out as expected, obviously.

As for your challenge, I guess you want to know what specifically TM is doing that is taking resources. We'll have to leave that for others.
I replaced the Trend client with AVG Free edition on one of the computers (laptop running Vista Business on the domain). So far, no System PID 4 100% CPU usage.

What's odd to me is that with as popular as Trend is in corporate environments that I would be one of just a couple people having this issue. I'm not running really weird apps. Things like QuickBooks 2007, Microsoft Office 2007, IE7, Firefox. The only odd one I can think of that's consistent across both computers is RoboForm for password management.
I setup a new HP EliteBook 8530w running Windows 7 RC. Running Trend WFBS v5 client with no issues thus far. I would like to know why we have had problems with the older, slower Windows Vista Business and Windows XP Pro computers, though.
Hi,

Update below registry. this will solve the issue

rgd,

abhi


Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmevtmgr]
"Start"=dword:00000004

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tmactmon]
"Start"=dword:00000004


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TMBMServer]
"Start"=dword:00000004
We just got a possible solution from BMAREDTAG, so please don't delete this thread!
Abhi,

I made those registry adjustments and System (PID 4) is still using anywhere from 25% to 65% of the CPU at any given time. The computer is not using 100% of the CPU cycles, but it's using more than it should as the computer I am trying this on is not actively being used.

I'll keep monitoring to see if the CPU usage slows down.

Jeff
ASKER CERTIFIED SOLUTION
Avatar of soundguymike
soundguymike

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SoundsGuyMike,

I just had a chance to try this. Hopefully it works!

Thanks,

Jeff
I have uninstalled the Symantec Virtualization Agent on my HP desktops... and ever since, my problem have disappeared.
On HP laptops this software was not installed, so I deducted this into uninstalling this on my desktops - which did solve my problem.

Symantec Virtualization Agent = Altiris SVS
I try to delete database but system process still gets high cpu. If I disable or uninstall client agent cpu usage goes down, but after reboot or enabled system process takes cpu again. I get the problem only in Windows 7 Business, XP or Vista works without problem.

PD:I update worry free server to last version.