svchost exe problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by sradwxi, Feb 23, 2007.

  1. sradwxi

    sradwxi Private First Class

    hi guys, first of all hello to everyone
    now my problem if anybody can help it would be very much appreciated
    i have an acer aspire sa80 running windows xp home on aol broadband wirelessly connected,
    its a p4 2.93g with 1.2 gb ram
    i dont have a lot of background programs running, the heaviest is probably aol
    over the last few days i have been having a few problems
    1. internet explorer stops responding for a short while
    2. svchost.exe is running 7 times in task manager
    3. screen layout is going back to windows 98 style
    when internet explorer stops responding another instance of svchost.exe can be found in task manager taking up 90-100% of the cpu usage making the pc unusable
    i can end this instance of the process in task manager as soon as it catches its breath and the pc and internet speed goes back to normal
    the last couple of times i have noticed that the display has been flickering back from the normal xp style, to the old win 98 style, just for a microsecond
    this time it has stayed like that
    ive done a screen shot to show you below:
    http://i40.photobucket.com/albums/e238/sradwxi/screenfaulty.jpg

    http://i40.photobucket.com/albums/e238/sradwxi/screenfaulty2.jpg
    ive downloaded hijack this just incase anybody can tell me what my problem is, i havent a clue where to start
    heres the hijackthis log:

    Edit: Inline log removed

    theres way too much information on there for me to work out
    if anybody could help me it would be much appreciated
    thanx
    carl
    :cry
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI

    Reson you couldnt see your posts, were that the inline Hijackthis logs trip the spam filter and put your thread to moderation status, until an admin gets to it http://forums.majorgeeks.com/announcement.php?f=6

    If you believe this is malware related then we will need you to follow, complete this guide below and attach all the logs


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. sradwxi

    sradwxi Private First Class

    right im having a look thru now, hey by the way i have duplicated this post on the end of my last thread from a while back, i will go in and delete/edit it in a bit, as soon as i can get my head round this hehe
    thanx for quick reply
    carl
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    No problems, I have deleted all the extra posts already ;)

    High CPU in Svchost can be malware of some description, so all the scans and cleanup procedures will give the malware guys a good idea if this is all malware related or not. ( note: multiple SVCHOST.EXEs in Task Manager are not a sign of something wrong, its normal on XP to have multiples )
     
  5. sradwxi

    sradwxi Private First Class

    nice one cheers im just reading thru
    http://forums.majorgeeks.com/showthread.php?t=35407
    upto secondary house cleaning, i had viewpoint media player from that list in add/remove, ill post back here when ive done everything i can find on here
    thanx carl
     
  6. sradwxi

    sradwxi Private First Class

    right ive run thru everything, im attaching a few things here
    nothing esle was found, upto now it seems like its running ok, not had the problem yet but ive only been on for about 10 minutes or so
    carl
     

    Attached Files:

  7. sradwxi

    sradwxi Private First Class

    i take that back ive just experianced the svchost overload again, was running at 97%, i ended the task and the pc returned to normal so whatever is causding it is still there, :cry
    ive just added a copy of my task manager too just incase it helps and its reverting back to the windows 98 style, maybe this is caused by me ending the svchost?????????
    pic of task manager attached
    carl
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post logs from CounterSpy and Panda ActiveScan
     
  9. sradwxi

    sradwxi Private First Class

    i tried, panda wouldnt give me a log, online scan?
    ill run thru them again and see what i can get
    cheers for reply
    carl
     
  10. sradwxi

    sradwxi Private First Class

    right ive attached the original counterspy log, with 4 scan summaries on it
    and also the activescan log
    cheers for help
    carl
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    Using Add or Remove Programs in the Control Panel; uninstall the following:
    nstall Java Runtime Environment (JRE) 6 available here at Major Geeks.

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*).
    Close Notepad.

    Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry.

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:

    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post the following logs:

    ShowNew
    GetRunKey
    HijackThis
     
  12. sradwxi

    sradwxi Private First Class

    hi, right ive gone thru all that, slight problem here though, for some reason i had to reinstall hijackthis, when that started
    counterspy also started installing, and i have a suspicious script being detected now, i cant stop it from trying to install, but ive got the logs anyway
    this counterspy wont reinstall because of a missing file or something
    im lost now
    :cry
     

    Attached Files:

  13. sradwxi

    sradwxi Private First Class

    ??????? anybody here, the counterspy thing is ok, ive posted the logs you asked for
    thanx carl
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to uninstall Viewpoint Media Player as requested in step 0 of the READ & RUN ME.

    Other than that, your logs are clean.

    If CounterSpy is the free trial from the READ ME, uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders that may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    If you are having any other malware problems at this time, please explain what they are.
     
  15. sradwxi

    sradwxi Private First Class

    ive uninstalled vp media player and done the opther things you said, thwe problem im having is the original problem
    when i start up the pc, everything is fine,
    if i try to go on the net its still fine, then all of a sudden the computer stops responding to anything, i cannot open programs or browse web pages
    if i check task manager, after waiting for a few minutes for it to appear i find that there is a system process running and eating my memory,
    (system) svchost.exe will be running at 99 or 100%
    the only way i can get my computer to start working is to kill the svchost
    then shortly afterwards my desktop starts to revert back to the old windows 98 style
    ive got some screen shots just taken a few minutes ago
    one is task manager
    the other is a full screenshot, have a look at the taskbar and start button on the full screenshot
    thanx carl

    http://i40.photobucket.com/albums/e238/sradwxi/taskmanager.jpg
    http://i40.photobucket.com/albums/e238/sradwxi/desktopscreenshot.jpg
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't believe it is malware. I believe it is wuauclt.exe which is Microsoft Windows Update. Stop & Disable the Windows Update Service and then tell me if you are still having problems. If you don't know how to do that, see below.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Automatic Updates
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    You may also want to read this: http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=906329&SiteID=2
     
  17. sradwxi

    sradwxi Private First Class

    ok, right ive been on the pc for a few minutes or so, nothing untoward happening yet, ive just signed into 'microsoft update'
    from start/all programs/microsoft update
    as you guessed, my task manager ran right upto 98%, so your right, what a strange problem is this something to do with the windows software itself,
    i stopped wuauclt.exe in task manager, it didnt change anything, i shut down the ie pages, svchost stayed up there eating the memory.
    i will check out the thread youve linked, if i have any more problems ill come back here and post again
    cheers carl
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the steps from Pati on 06 Dec 2006, 4:17 AM UTC are what is typically used to fix this. Just note that it does not always work! ;) Try it and see what happens. If you still have problems, you will need to address them in the Software Forum since this is not a malware problem.
     
  19. sradwxi

    sradwxi Private First Class

    hi guys, just to let you know, the last steps didnt work, ive been away for a week so thats why ive not replied yet, i will put a post in the software forum as requested
    thanx again guys,
    carl
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good look with this last problem!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds