svchost using all available memory on startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anon-39e606dd11, Feb 21, 2015.

  1. Anon-39e606dd11

    Anon-39e606dd11 Anonymized

    Hello. First, I'd like to thank you in advance for your time.

    I have a desktop running Windows 7 64bit with 2GB RAM. I know this is below the minimum you recommend, but it worked fine for more than a year before this problem started. Unfortunately, the problem appeared many months ago and I don't remember what I was doing at the time. It took me a while to recognize it was an actual problem and what was the source.

    The problem: the most noticeable symptom is the fact that a svchost process will randomly use up all the remaining memory that is not used by other programs (it may reach 1.2GB if I'm not running anything else). This "spike" will last for several minutes, using full memory and 100% R/W on disk time, and it makes my computer unusable during this time - any action I try to execute, even as small as minimizing a window, will take 30 seconds to a minute to be recognized. Eventually the amount of RAM used will quickly go down, settling at around 30MB and allowing me to use the computer again.
    This problem usually happens shortly after startup, but it may happen randomly at other times. It also happens after I return the computer from a suspension/hibernation state, as if I had just started it normally. If I let my computer sit for a while on the login screen, it appears this problem will have already started when I login, presenting me with a black screen for about a minute and taking several minutes until everything starts up (desktop icons appearing, etc.).
    The services associated with this svchost process are: Appinfo, Browser, gpsvc, iphlpsvc, LanmanServer, MMCSS, ProfSvc, RasMan, Schedule, seclogon, SENS, ShellHWDetection and Themes.
    A strange side effect I noticed is the fact that the computer will take a long time on the "Waiting" screen before the option to input my password for my user appears. If I have more than one user in the computer, this delay happens after I choose the user (and before the option to input the password).

    I use Microsoft Security Essentials as my antivirus. When I started noticing problems, I ran several full scans, all with nothing found. I installed and run MalwareBytes and MalwareBytes Antirookit (Beta), and found nothing with either of them. After doing a repair with my Windows installation CD, it seemed to be fixed on startup, but the infection returned when I rebooted.

    On late December, I backed up my files and installed Windows 7 again. I deleted all the existing partitions and formatted the disk before I installed it. The problem seemed to disappear at first, but after a few reboots (in which I installed Windows updates, copied over all my files, and installed a few programs) it appeared again.

    I ran everything on your "Read & Run Me First" thread (I will post the logs along with this), and the svchost process still has "spikes" that fill up all the remaining memory, but the memory usage seems to go down after a few seconds instead of minutes like before. I'm not convinced that my computer is clean, hence why I'm posting this.

    A note on the logs I posted: my Windows version is in Portuguese, and some of the programs seem to write in Portuguese in the logs. I was able to change the language on TDSSKiller, but not on RogueKiller (and noticed some logs generated by MGTools are in Portuguese too). I hope this is not a problem, but I'd be happy to run the scans again if you let me know how I can generate the logs in English.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there NewDreams, and welcome. :)

    I am not seeing any signs of malware whatsoever in those logs. You should post in the software forum. Best of luck!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  3. Anon-39e606dd11

    Anon-39e606dd11 Anonymized

    Thank you for checking it, and I'm sorry if I wasted your time with these - I was convinced it was a malware problem, but if the logs are clean then at least I don't have to worry about that. I'll try the Software forum.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome, best of luck with it all.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds