Hello,
We have a Windows SBS 2003 network in our own office. The server also runs Trend Micro Worry Free Business Security Advanced v5.1 Build 1142 with two client computers attached (one wired Windows XP Pro, one wireless Windows Vista Business). Both computers exhibit a problem where the CPU cycles reach close to 100%, and both show "System" with a PID 4 hogging the cycles (JPG picture attached). This can occur for a couple minutes up to several hours, where the computer's CPU runs high and you can hear the fans spinning as fast as they can. Both computers are free of viruses and spyware as scans from Trend, and several other antivirus and anti-spyware utilities have shown.
Troubleshooting running processes and applications has led me to remove the Trend client from one computer, then both computers. Both computers stop running high CPU cycles with Trend removed and then System PID 4 starts grabbing CPU cycles almost immediately when re-installing the Trend client. Also, there are no scheduled scans set to run when the computers login, so Trend is not running a scan when the CPU cycles are high.
Besides looking for a newer version of Trend WFBS to install, or dumping Trend and installing something else, does anyone have any suggestions on how to solve this? We have numerous clients using Trend WFBS and nobody has reported this problem. Searching the web, I find no mention of it either. I can't possibly be the only one with this issue, can I? Am I being fooled by the CPU calming down when the Trend client is removed?
The system just calmed down before I ran HijackThis. Here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:24 PM, on 3/14/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\tasken
g.exe
C:\Windows\system32\Dwm.ex
e
C:\Windows\Explorer.EXE
C:\Windows\WindowsMobile\w
mdSync.exe
C:\Program Files\Java\jre6\bin\jusche
d.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.e
xe
C:\Program Files\Skype\Phone\Skype.ex
e
C:\Program Files\Common Files\Intuit\QuickBooks\QB
Update\qbu
pdate.exe
C:\Windows\System32\mobsyn
c.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\mstsc.
exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
C:\Windows\system32\Search
FilterHost
.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://companywebR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://sbs:24554/sites/dcc/default.aspxR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://companywebR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
BBC1D38A37
E} - C:\Program Files\Microsoft Office\Office12\GrooveShel
lExtension
s.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmd
Sync.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
d.exe"
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [OE] C:\Program Files\Trend Micro\Client Server Security Agent\TMAS_OE\TMAS_OEMon.e
xe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
e" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
Update\qbu
pdate.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustom
izeIEMenu.
html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1
\Office12\
EXCEL.EXE/
3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~1\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~1\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
6} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
9} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C
5DBF3571F4
9} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-0
0400523e39
a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowTo
olbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~1\Offic
e12\REFIEB
AR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone:
http://www.autotask.comO16 - DPF: {00134F72-5284-44F7-95A8-5
2A619F7075
1} (ObjWinNTCheck Class) -
https://sbs:4343/officescan/console/ClientInstall/WinNTChk.cabO16 - DPF: {08D75BC1-D2B5-11D1-88FC-0
080C859833
B} (OfficeScan Corp Edition Web-Deployment SetupCtrl Class) -
https://sbs:4343/officescan/console/ClientInstall/setup.cabO16 - DPF: {0E5F0222-96B9-11D3-8997-0
0104BD12D9
4} (PCPitstop Utility) -
http://www.pcpitstop.com/betapit/PCPitStop.CABO16 - DPF: {254AA86E-5655-4518-AA87-1
85D7CC4180
1} (LogMeIn Rescue Technician Console) -
https://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cabO16 - DPF: {2685176A-3502-47BB-B91D-B
D28CA2A06A
0} (vb6project_Test.AT_Active
X_Test) -
https://www.autotask.net/Public/BrowserDetect/AT_ActiveX_Test.CABO16 - DPF: {2F30081A-076B-4BD4-A6B7-5
66B9AF33EE
5} (ATQB_Connect.AutotaskToQB
) -
https://www.autotask.net/billing/invoices/electronic_transfer/ATQB_Connect.CABO16 - DPF: {35C3D91E-401A-4E45-88A5-F
3B32CD72DF
4} (Encrypt Class) -
https://idea-central:4343/officescan/console/html/AtxEnc.cabO16 - DPF: {485D813E-EE26-4DF8-9FAF-D
EDF2885306
E} (NSHelp Class) -
http://sbs/ConnectComputer/nshelp.dllO16 - DPF: {4EFA317A-8569-4788-B175-5
BAF9731A54
9} (Microsoft Virtual Server VMRC Advanced Control) -
http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cabO16 - DPF: {69B502DF-D12F-4FD7-9892-D
8DFA2D9647
4} (OfficeScan Management Console) -
https://idea-central:4343/officescan/console/html/AtxConsole.cabO16 - DPF: {9BBB3919-F518-4D06-8209-2
99FC243FC2
A} (Encrypt Class) -
https://server:4343/SMB/console/html/root/AtxEnc.cabO16 - DPF: {9BBB3919-F518-4D06-8209-2
99FC243FC3
0} (Encrypt Class) -
https://sbs:4343/SMB/console/html/root/AtxEnc.cabO16 - DPF: {9DCD8EB7-E925-45C9-9321-8
CA843FBED3
C} (Security Server Management Console) -
https://sbs:4343/SMB/console/html/root/AtxConsole.cabO16 - DPF: {9DCD8EB7-E925-45C9-9321-8
CA843FBED4
0} (Security Server Management Console) -
https://sbs:4343/SMB/console/html/root/AtxConsole.cabO16 - DPF: {A050E865-64E3-431B-8079-F
0DFCEA90A2
D} (PieChart Class) -
https://idea-central:4343/officescan/console/html/AtxPie.cabO16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-E
EB3FF2ECD1
9} (CPlayFirstddfotgControl Object) -
http://download-games.pogo.com/online2/pogo/diner_dash_flo_on_the_go/ddfotg.1.0.0.33.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E78DE03F-DC83-40DB-B590-8
FD80BE5F7C
8} (Security Server Management Console) -
https://server:4343/SMB/console/html/root/AtxConsole.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B
5AE0DC75AC
9} (Performance Viewer Activex Control) -
https://secure.logmein.com/activex/ractrl.cab?lmi=100O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = DigitalCorral.local
O17 - HKLM\Software\..\Telephony
: DomainName = DigitalCorral.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = DigitalCorral.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
CB6248B04C
D} - C:\Program Files\Microsoft Office\Office12\GrooveSyst
emServices
.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
830C7DD7F5
D} - C:\PROGRA~1\COMMON~1\Skype
\SKYPE4~1.
DLL
O23 - Service: Advanced Monitoring Agent - Remote Monitoring - C:\PROGRA~1\ADVANC~1\winag
ent.exe
O23 - Service: Advanced Monitoring AutoUpdate - Unknown owner - C:\PROGRA~1\ADVANC~1\updat
er.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: Sprint Con App Svc (CASprint) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkSe
rvice.exe
O23 - Service: Google Update Service (gupdate1c8fa2d86440862) (gupdate1c8fa2d86440862) - Google Inc. - C:\Program Files\Google\Update\Google
Update.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FC
S\Intuit.Q
uickBooks.
FCS.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - Unknown owner - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (file missing)
O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version4\
TeamViewer
_Service.e
xe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
O23 - Service: Trend Micro Client/Server Security Agent Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmProxy.exe
--
End of file - 11006 bytes
Thanks for your insight!
Jeff