svchost eating up memory

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by eleasmom, Feb 28, 2012.

  1. eleasmom

    eleasmom Private E-2

    I'm about 90% sure this is a virus/trojan issue, and maybe 10% thinking it might be a driver or software issue.

    This is probably way more than you need to know, but maybe something in all of this will help.

    This is a Dell Vostro 1500 laptop, running Windows XP, 32 bit.

    About a month ago, I started noticing things getting sluggish, and then it started not recovering from standby or hibernation. Shortly after that, I started getting a "You need a different audio codec" message in Divx, but only after the computer had been running for a while (a couple of hours). (And this was on files that had worked perfectly well previously.) I updated the codec, but it didn't help. The only thing that helped was to reboot. I don't remember downloading anything in particular around that time, but I probably did. I do often download updates to this or that driver, or this or that "useful tool." I will only DL zips or "tools" from "trusted sources," but who knows...

    The computer continued to run more and more slowly, and now it's pretty much useless. Last night I started digging around, and I found out that there's a svchost that seems to be causing the problem (details below). It starts out OK, about 20,000K memory, and after about 30 seconds starts sporadically increasing in memory usage. Eventually it gets up to about 600,000K, and then it shuts down the computer. (Now it takes about three minutes. Last night it was taking about ten minutes.) It doesn't use up much of the CPU, except sometimes at the very beginning it takes 90-99% for about 20 seconds, and then when it reaches 500,000K - 600,000K, it goes to 90-99%.

    I tried shutting down processes within the svchost, and the only one that stopped the memory escalation was shutting down the DHCP. Also, if I shut down my wireless, either using the hard-switch on the computer, or by disabling the wireless at the network-setup level, the memory escalation also stops. (And, yes, the issue also happens when the wireless is shut down and I'm plugged into a hard-ethernet line, so it's not the wireless.) As the memory escalation is going on, I'm hearing the computer crunching away, so something is going on inside there on the hard-drive.

    I've uninstalled everything I can possibly uninstall. I've watched the processes in Windows Task Manager, and I've tried ending process trees as much as possible without completely shutting down the computer, and the ones that keep coming back are Google Updater (and I UNINSTALLED the bugger through Control Panel, so it shouldn't be there at all!), and wmiprvse. It seems like whenever the memory starts shooting back up, one or the other puts itself back into the task manager.

    And, the other thing, and I don't know quite enough about how things work to know if this is supposed to happen or not, is that I happened to notice that Documents and Settings/Network Service/Local Settings/Temporary Internet Files/Content IE5 has a bunch of folders, with a bunch of brand new files (of all sorts) that are dated pretty much "right now." I don't use IE. At all. And I certainly didn't use it "just now." And, some of the files have names of things that I certainly didn't browse to just now, even in Firefox, like "recipe" or "carnival vacation upgrade."

    Here's the details of the svchost that's using up the memory:

    Windows Audio - C:\WINDOWS\System32\audiosrv.dll
    Computer Browser - C:\WINDOWS\System32\brower.dll
    CryptSvc - C:\WINDOWS\System32\cryptsvc.dll
    DHCP Client - C:\WINDOWS\System32\dhcpcsvc.dll
    Error Reporting Service - C:\WINDOWS\System32\ersvc.dll
    Com+ Event System - C:\WINDOWS\System32\es.dll
    Help and Support - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
    Server - C:\WINDOWS\System32\srvsvc.dll
    Workstation - C:\WINDOWS\System32\wkssvc.dll
    Network Connections - C:\WINDOWS\System32\netman.dll
    Network Location Awareness - C:\WINDOWS\System32\mswsock.dll
    Remote Access Connection - C:\WINDOWS\System32\rasmans.dll
    Task Scheduler - C:\WINDOWS\System32\schedsvc.dll
    Secondary Logon - C:\WINDOWS\System32\seclogon.dll
    System Event Notification - C:\WINDOWS\System32\sens.dll
    Windows Firewall/Internet Connection Sharing - C:\WINDOWS\System32\ipnathlp.dll
    Shell Hardware Detection - C:\WINDOWS\System32\shsvcs.dll
    System Restore Service - C:\WINDOWS\System32\srsvc.dll
    Telephony - C:\WINDOWS\System32\tapisrv.dll
    Themes - C:\WINDOWS\System32\shsvcs.dll
    Distributed Link Tracking Client - C:\WINDOWS\System32\trkwks.dll
    Windows Time - C:\WINDOWS\System32\w32time.dll
    Windows Management Instrumentation - C:\WINDOWS\System32\WMIsvc.dll
    Security Center - C:\WINDOWS\System32\wscsvc.dll
    Automatic Updates - C:\WINDOWS\System32\wuauserv.dll
     

    Attached Files:

  2. eleasmom

    eleasmom Private E-2

    Fifth log:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You have not uninstalled Google. It still has two services running and that's because you still have the below installed.

    Google Earth
    Google Update Helper

    But those are probably not the reason for your problem. There is a good chance that you have a TDL infection that has added an infected partition to your harddisk. See the partition in red below
    Code:
    Partition Disk #0, Partition #0 
    Partition Size 86.26 MB (90,445,824 bytes) 
    Partition Starting Offset 32,256 bytes 
    Partition Disk #0, Partition #1 
    Partition Size 109.21 GB (117,259,591,680 bytes) 
    Partition Starting Offset 90,478,080 bytes 
    [COLOR=red][B]Partition Disk #0, Partition #2 [/B][/COLOR]
    [B][COLOR=red]Partition Size 2.50 GB (2,681,441,280 bytes) [/COLOR][/B]
    [B][COLOR=red]Partition Starting Offset 117,350,069,760 bytes [/COLOR][/B]
    
    Do you have your Windows XP boot CD?

    Also run the below scans.



    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now please download ListParts by Farbar
    Run the tool, click Scan and attach the log (Result.txt) it makes.
     
  4. eleasmom

    eleasmom Private E-2

    Oh, well, silly me, I didn't realize that Google Earth would keep calling GoogleUpdate, or that there was some *other* Google Update Helper thing, after I uninstalled Google Update through Control Panel. Pretty soon I'll be finding Google toilet paper in my bathroom, too, lol...

    Yes, I do have a boot disk.

    Here are the three logs. After I ran tdsskiller and it asked me to reboot, I said yes, but the computer wouldn't shut down properly, so I had to do a hard shut-down. I don't know if that matters. And, after re-starting, I'm still getting the memory issue.
     

    Attached Files:

  5. eleasmom

    eleasmom Private E-2

    Well now something a bit different, sigh.

    This morning, when I turned the computer on, the svchost IMMEDIATELY climbed to 400,000K at CPU 50%. I was trying to get on here to see if I had a reply, so I didn't turn the wireless off right away. Once I did turn it off, I got an error, that actually did look like a true Windows error, a nice square box in the middle, in plain Windows font, that said, "Windows thinks your computer is at risk and needs Data Execution Protection." When I clicked No Thank You, I got a "Windows has encountered an error, and we would like you to send a report" message, with a "Send" "Don't Send" button. It actually looked real. (I chose Don't Send.)

    Then, when I turned off the wireless, the svchost KEPT CLIMBING. In the past, it has stopped climbing as soon as I turned off the wireless.

    Please tell me it's not putting back on all the stuff I spent all day yesterday cleaning off of the computer? :-(

    (BTW, at that point I rebooted, and now it seems to be back to "normal" for what it was doing yesterday. Waiting a few minutes, and then slowly climbing at low CPU.)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then make sure you know how to boot from it to get into the command prompt of the Recovery Console before doing the below because you will need to do this at the end of the steps. You will also be required to make another special boot CD for the G-Parted program being mentioned.

    Follow the instructions in the below link which is designed to cover all versions of Windows. You need to make sure you follow the steps given for Windows XP.

    Using G-Parted to Repair Windows Partition Infections


    Also where the above instructions say this
    The infected partition size for you is the 2.50 GiB ( aka 2.50 GB)

    And where the instructions say this
    You need to substitute in 109.21 GB
     
  7. eleasmom

    eleasmom Private E-2

    Wow, I feel like I just performed brain surgery by reading instructions from a mail-order catalog. I especially loved the part where I had to enter the fixmbr and fixboot commands in Recovery Console, and it came up and asked me, "Are you sure? I mean, are you really, really sure you want to do this? Because if you don't know what you're doing, your computer might blow up in your lap, leaving your legs bloody stumps, and then it will set fire to your house, and then Freddy Krueger will come after your mother." Ack. Yes, Mr. Computer Man, the guy from the internet told me it'll be OK. LOL...

    Oh, and, BTW, G-Parted won't download from that site. It says "no mirror site." I had to torrent it. (Yup, I know, that's how a person gets viruses in the first place. Torrenting random files from unknown sources. I figured at this point, I was ready to throw the computer out the window, anyway, so it hardly made a difference...)

    Well, so far, so good. I've had things running for about 15 minutes, and no memory or CPU issues with svchost. Things seem to be running and loading smoothly and quickly.

    Fingers crossed, knock on wood.

    And, I'm sure this has been said a million times, but there need to be more people like you in the world. I'm an RN, and I hear all the time, "Thank God for our RN's." I take my medical knowledge for granted - "It's just what I do." But to the people who don't have that knowledge, what I can offer is magical. I hope you know that this is the same thing. A person is hurting, angry, frustrated, and it doesn't really matter what the source of that pain is. If someone can step in and take it away, God bless that person.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We are happy we could help.

    Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds