SvcHost.exe using high bandwidth

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rippinazz, Mar 27, 2012.

  1. Rippinazz

    Rippinazz Private E-2

    i have noticed that svchost.exe has recently been hogging alot of the bandwidth on my computer. At times it climbs to about 50% even when no applications have been opened. I have performed the steps for removing malware that are listed on this site along with running a couple other scans and everything shows as being clean.

    Also can anyone help me look over my highjackthis log to see if i need to fix anything there?

    Maybe im just being paranoid but all the svchost activity is starting to make me nervous. :confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We don't need or want Hijackthis logs. You need to attach logs from the below tools that were requested in our cleaning procedure in order for us to provide you proper support:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • RootRepeal
    • MGtools
     
  3. Rippinazz

    Rippinazz Private E-2

    Sorry bout that here are the logs requested.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested log from running MGtools. It is not what you attached. See the procedure. It asked you to attach C:\MGlogs.zip
     
  5. Rippinazz

    Rippinazz Private E-2

    Ok we're almost there. New to this. I believe i got it this time. MGlogs.zip now attached. THanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs it does not appear that you are having malware problems. It may just be what you are running. I will give you a few things to try inorder to attempt finding out what may be the root cause.

    First uninstall the below:
    æTorrent
    Ask Toolbar

    Then immediately reboot your PC.

    After reboot see if your problem has gone away. If it has not, then uninstall the below:
    Avast
    Comodo Dragon
    Comodo GeekBuddy

    Then again reboot your PC and see what you status is. No matter what happens continue with the below and do not reinstall anything we have uninstall ( at least not yet ). Do not continue with the below unless you have uninstall everything listed above.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Rippinazz

    Rippinazz Private E-2

    Ok...i had already uninstalled the ask toolbar before i read your reply and after i rebooted it seemed that Svchost went from about 47-50% to about 80-90%. and now the CPU usage is idling higher than before at about 3-4%.

    I now uninstalled Utorrent and Svc host is still a steady 80-90%. and CPU is now goes back and forth between 0-2%.

    One last question about doing the next steps.
    I have been using Comodo Firewall Summary screen to gauge the svchost activity and traffic percentage. How will i see if anything is better after uninstalling Comodo. Also by uninstalling both my firewall and my virus protection wont that leave me open for more trouble.

    Huh...now im wondering. Am i going about this the wrong way. What i mean by that is im wondering if checking the comodo traffic summary the best way to go about gauging the svchost activity. I just checked my network tab in taskmanager and with Svchost activity at 80% in comodo, it still doesn't register very much network utilization (0%-.2%).

    I appologize in advance if im wasting your time. Im new to all this.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it isn't.

    Is svchost.exe showing as always using all of your CPU time or is it only when you click on things or run programs. Like when you open your browser for just one example. If it is just a temporary observation while you are actively using your PC, then you need to ignore it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds