svchost using up entire memory

Status
Not open for further replies.

arcticflare

Journeyman
A process called scvhost.exe has been taking up 100% cpu usage slowing down my system entirelyly. worse still, the process refuses to end even after a considerable period of time. What could be the prob??
My sys runs on winxp sp2.
 

Kiran.dks

Technomancer
'svchost' is a critical system process. Never try to kill it. However some malwares do disguise as 'svchost' and keep running in the system. Post your HijachThis log file here for analysis.
 
OP
arcticflare

arcticflare

Journeyman
sorry, but it's svchost. here's the logfile
Logfile of HijackThis v1.99.1
Scan saved at 1:52:43 PM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime Alternative\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Opera\Opera.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\SRIKAN~1\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Service Pack 3 Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FLASHGET\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33B94141-5CBC-4BAE-9993-288F7FAF1D2F}: NameServer = 10.50.50.1,202.250.56.6
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
 

Kiran.dks

Technomancer
Oh yes! In a hurry, I misread his post. scvhost.exe is a Gaobot virus!

Just download this removal tool and Scan entire PC.

SCVHOST.EXE REMOVAL TOOL
__________
Ok...it was all confusions for me & vishal because of the subject showing svchost.exe

I analysed the log file and found no problems at all.
Try to reduce the number of start-up programs. How much RAM do you have?
Also suggest to increase RAM. I guess system is slow on resources since you say svchost.exe is taking too much time.
 
Last edited:

Choto Cheeta

Rebooting
@Vishal @Kiran

i am not sure about authors problem but in many systems of our cafe u get this problem... at the time of Start up or Log in to a user autometic update scanner under svchost.exe use a lot of system resourse...

take a look at this ms KB... I am in Need of that Patch... but its looks like its a paid patch... :( as we have a volume licance i contacted local MS office they replied this kind of patches are paid support... :(

*support.microsoft.com/kb/916089/en-us

turning offf the auto update helps but i dont want to do that !!!
 
Last edited:

Kiran.dks

Technomancer
sarandigit said:
the task manager in my system shows four svchost.exe. are the other three viruses?

Nope. Don't worry. All the four are System services. Infact I have five running on my lappy! :)
__________
saurav_cheeta said:
@Vishal @Kiran
i am not sure about authors problem but in many systems of our cafe u get this problem...
turning offf the auto update helps but i dont want to do that !!!

Good find Saurav. Infact I remember seeing a alternative solution earlier sometime.
I will let u know ASAP.
__________
Saurav.....

Note that this is to be done if svchost.exe crashes with a error message.

I don't think so this applies to articflare. Because he didn't report any svchost error message. Anyways, if he has noticed it...he too can implement it.

Perform these steps leaving the svchost crash dialog open.

1. Click Start->Run, type "services.msc" (without quotation marks) in the open box and click OK.
2. Double click the service "Automatic Updates".
3. Click on the Log On tab, please ensure the option "Local System account" is selected and the option "Allow service to interact with desktop" is unchecked.
4. Check if this service has been enabled on the listed Hardware Profile. If not, please click the Enable button to enable it.
5. Click on the tab "General "; make sure the "Startup Type" is "Automatic". Then please click the button "Start" under "Service Status" to start the service.
6. Repeat the above steps with the other service: Background Intelligent Transfer Service (BITS)

Step 4: Re-register Windows Update components and Clear the corrupted Windows Update temp folder
================================

1. Click on Start and then click Run,
2. In the open field type "REGSVR32 WUAPI.DLL" (without quotation marks) and press Enter.
3. When you receive the "DllRegisterServer in WUAPI.DLL succeeded" message, click OK.
4. Please repeat these steps for each of the following commands:

REGSVR32 WUAUENG.DLL
REGSVR32 WUAUENG1.DLL
REGSVR32 ATL.DLL
REGSVR32 WUCLTUI.DLL
REGSVR32 WUPS.DLL
REGSVR32 WUPS2.DLL
REGSVR32 WUWEB.DLL

After the above steps are finished. Sicne temporary folder of Windows Update may be corrupted. We can refer to the following steps to rename this folder that

1. Click Start, Run, type: cmd and press Enter. Please run the following command in the opened window.

net stop WuAuServ

(note, you might need to reboot before the net stop command will work)

2. Click Start, Run, type: %windir% and press Enter.
3. In the opened folder, rename the folder SoftwareDistribution to SDold.
4. Click Start, Run, type: cmd and press Enter. Please run the following command in the opened window.

net start WuAuServ

UPDATE: This post has received a ton of comments. One, in particular, suggests an easier fix for this problem:

1.Go 2 the start menu
2.Right click "my computer"
3.Click "properties" then the "automatic updates" tab
4.Choose "turn off automatic updates"
5.Reboot your computer
6.Go back to start menu and in all programs go to "windows update" you have to be connected to the internet.
7.Manually update windows.
8.Turn your automatic updates back on.

More info: Click here
 
Last edited:

Choto Cheeta

Rebooting
@Kiran

as i wrote before... its not crashing... and with our present net connection and config those effected systems takes only around 120 to 150 seconds to complete its update scan.. after that every things resume to normal...

also when u have a 40 to 50 pc running.. its not allways possible to manually update... and why should u do that as when u have paid for all those copies...

vishal has a technet subscription... may be he can get his hand on that patch free of cost... :))

we are still talking with Local MS... as its not possible to pay for each and every (infact 20 of them) efected systems...
 

Choto Cheeta

Rebooting
sre06 said:
in my case i have a name called svcchost is it a virus or wht pls help me

Svcchost.exe is Trojan/Backdoor. Kill the process svcchost.exe form Task Manager. Remove Svcchost.exe from Windows startup... and Delete x:\WINDOWS\System32\svcchost.exe ... file ...

Get Spybot Search n Distroy... run a scan... :)
 

Kiran.dks

Technomancer
sre06 said:
in my case i have a name called svcchost is it a virus or wht pls help me

It seems like svc,scv,svcc mania goin around here! Yep. svcchost.exe is a W32/Rbot-FUM, a Spyware worm. As saurav said, install spybot and perform system scan.
All worms leaves registry entries...
Don't forget to perform a registry scan using Ccleaner..www.ccleaner.com.
 

anandk

Distinguished Member
arcticflare : ur hjt logfile is clean. hope ur xp is fully updated.

the legit ms svchost.exe file is located in the folder c:\windows\system32. in other case, svchost.exe is a virus, spyware, trojan or worm !

one of the services startups is probably causing this problem. try disabling 'Telephony' service and see :rolleyes: if it helps. in any case it is only used for fax/modem.

when svchost.exe uses 100% cpu it either means a) u either have malware on pc or b)ur system is currently vulnerable to a particular type of exploit known as the "rpc buffer overflow".

since ur logfile appears clean, the second posblity shud also be addressed.
so do this too :
make sure ur xp fw is turned on. also open control panel >network connections >select the connection that corresponds to your internet connection, right click on that and select properties, then select the advanced tab, n make sure that 'protect my computer and network by limiting or preventing access to this computer from internet' is checked.

sre06 : ya, ur svcchost.exe is :evil: trojan/backdoor. kill the process (using ur task manager) svcchost.exe and and remove svcchost.exe from windows startup, then delete it. else just use 'delete doctor' or 'unlocker' to delete the nasty file !

i also suggest u scan in SAFE MODE ur pc, with ur av and a good anti-spy like avg anti-spy. also clean up ur pc junk with 'ccleaner' periodically.
 

: SPiRiT :

Broken In
we basically require 4 instances on svchost.exe.. And @ARTICFLARE how u sure the file called SVCHOST.EXE is using "100%" of cpu the task bar jus shows memory usage in Kb...
 

Choto Cheeta

Rebooting
@: SPiRiT :

at the task manager process tab u can see individual programs... :)

also u can break them up to see Individual Processes with a small tool called Process Explorer...
 

: SPiRiT :

Broken In
YEAH BUDDY . know that.. but they dont show the CPU Usage in PC only memory usage yeah the CPU column is there but then SYSTEM IDLE CAN NEVER BE 100% there too..
 
Status
Not open for further replies.
Top Bottom