PDA

View Full Version : I need help with svchost.exe



Hellow
07-09-2007, 01:33 AM
Ok, i believe that this is a virus. I have 6 copies of scvhost.exe running in task manager. Two of them are network services, two are system services, and one is a local service. I have scanned my computer with my security suite but i still get ads. Zone Alarm says that scvhost.exe request permission to axcess the internet. My computer often tops out at 100% cpu usage and its a copy od scvhost.exe. Any ideas how to fix this???

Blue_Frog
07-09-2007, 09:38 AM
Hey Reggie --

First off, i have 6 instances of SVCHOST.exe running on my computer, and i know that i'm not infected with anything. However, having done a quick check on Google, it appears that a file with the same name can also be dropped into your system as a trojan.

From an earlier thread about viruses I posted in, heres some information to go by to help you along. I can try to help point you in the right direction for cleaning your computer if you like http://petoftheday.com/i/our_smilies/smile.gif



Having said that, once a virus is detected in your computer - depending on the virus type (virus, worm, trojan, etc.), theres several ways to tackle the problem. Could you give us a little information>

- What was the full name of the infected file that it found (filename.***)
- What was the full virus name?
- What operating system do you have (windows xp home, windows 2000, etc.)?
- What is the antivirus you currently have on your computer, the software version, and what is the date of the virus definitions (the most recent update?)

This way we could help to point you in the right direction for removal -- and depending on the problem, Symantec (Norton) has a ton of free tools on the website to help remove the problem.

------

Also ... some links
Symantec Free Online Scanner (only tells you the infection name, does not clean)
http://security.symantec.com/sscv6/...id=ie&venid=sym (http://security.symantec.com/sscv6/default.asp?productid=symhome&langid=ie&venid=sym)

Symantec Trialware Page (30 days free)
http://www.symantec.com/home_homeof...loads/index.jsp (http://www.symantec.com/home_homeoffice/downloads/index.jsp)

McAfee Trialware Page (30 days free)
http://www.mcafee.com/us/downloads/index.html (http://www.mcafee.com/us/downloads/index.html)

E-Trust Innoculate Trialware Page (30 days free)
http://www3.ca.com/solutions/Collat...CT=19506&ID=271 (http://www3.ca.com/solutions/CollateralList.aspx?CCT=19506&ID=271)

E-Trust Free Online Scanner (scans not cleans)
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx (http://www3.ca.com/securityadvisor/virusinfo/scan.aspx)


*** Note: Do not install more than one antivirus on your computer at a time - they will conflict with each other based on the way they interact with your operating system ***


Also, since we're touching on virus problems, an entire other class of problems can come up with Spyware, Ad-ware, etc. Try ...

Lavasoft Adaware
http://www.majorgeeks.com/Ad-Aware_...sonal_d506.html (http://www.majorgeeks.com/Ad-Aware_SE_Personal_d506.html)

Spybot Search and Destroy
http://www.majorgeeks.com/SpyBot-Se...troy_d2471.html (http://www.majorgeeks.com/SpyBot-Search_&_Destroy_d2471.html)

Blue_Frog
07-09-2007, 09:43 AM
Here are a couple of links about SVCHOST.exe that might be useful to read -- \

What is SVCHOST -- http://support.microsoft.com/kb/314056

More -- http://www.neuber.com/taskmanager/process/svchost.exe.html

About svchost using 100% CPU -- http://searchwincomputing.techtarget.com/tip/0,289483,sid68_gci1249678,00.html

Hellow
07-09-2007, 11:20 AM
The thing is is that this dosent occur on my laptop, only on my desktop. I have just eliminated a herd of viruses, malwarem and adware on my desktop but it still does it. It also jumps to 100% cpu power often, sometimes locking up forcing me to restart. It gets on my nervs becaues i have had my desktop for 5 years and it has worked unfailingly. Ok im on the internet on my desktop wjich is setting right next to me and my old home page was www.google.com/ig and now its www.example.net/some/place/. oes that help ya out any?

Blue_Frog
07-09-2007, 11:30 AM
The thing is is that this dosent occur on my laptop, only on my desktop. I have just eliminated a herd of viruses, malwarem and adware on my desktop but it still does it. It also jumps to 100% cpu power often, sometimes locking up forcing me to restart. It gets on my nervs becaues i have had my desktop for 5 years and it has worked unfailingly. Ok im on the internet on my desktop wjich is setting right next to me and my old home page was www.google.com/ig (http://www.google.com/ig) and now its www.example.net/some/place/ (http://www.example.net/some/place/). oes that help ya out any?

Well, the last thing sounds like a browser hijack. I assume that even when you change the default page in "Tools - Internet Options" (if using IE), it changes right back after the program restarts? There are tons of malware programs that do this unfortunately, so picking one is like a needle in a haystack hunt without names.


A couple ?s

1. What antivirus do you have? What are the virus data definitions date?
2. What anti-spyware program are you using? What is the spyware data definitions date?

These programs are only as good as the most current updates.

Once they are both updated the most current, then run scans on your system. Write down what the infections are (the names of the Viruses / Trojans / Malware / Spyware / etc.) -- this information is necessary to help clean out the systems.

If you can add that information here, that would be great :)

Hellow
07-09-2007, 12:07 PM
Anti - virus: AVG Anti Virus free edition
Signatures: 06/08/2007

Anti - spyware: Spybot Search and Destroy
Signatures: 06/08/2007

I had to use Trend Micro's Houescall to get rid of my infectons because neither program listed above found them. I dont remember the names of them, though.

Blue_Frog
07-09-2007, 12:20 PM
Anti - virus: AVG Anti Virus free edition
Signatures: 06/08/2007

Anti - spyware: Spybot Search and Destroy
Signatures: 06/08/2007

I had to use Trend Micro's Houescall to get rid of my infectons because neither program listed above found them. I dont remember the names of them, though.

Do the programs you listed above have a way of accessing their Log files from the menus? I don't have either of those programs installed, so maybe poke around in them and see if you can locate infection logs. You could look back in the logs to get the names. Quite often, some of the malware is awfully tricky to remove, and many of the AV/Spyware companies have created tools specific to those threats.

I've seen it quite often where you remove the spyware, and after the reboot it comes right back regardless of how often you clean it out, because its hooked your system -- so having the right name and hoping for a threat specific tool is the best bet.

You could also give the Symantec Online scanner a try (at least to see if it finds a name of something), as well as downloading and installing the Adaware (both links above) and see if it finds anything. Don't install a second AV on your system tho, they tend to conflict with each other based on the way that they want to interact with your OS.

crow_noir
07-10-2007, 12:05 AM
I have AdAware in addition to those. (No conflicting between any of the programs.)

Have you also run a scan in Safe Mode? (I just skimmed this thread)

If you don't know how to do that here's how. Shut off your computer. Turn it back on. After the name brand of your computer comes up (or you see the little blinking cursor on the black screen) press F8. You'll only have about a second or two to look for this before your computer goes into the rest of its start up process. ...If you do it right it's pretty self explanatory. You may have to press F8 a second time to bring up the menu that has Safe Mode on it.

I was amazed at how many things were caught when i did that for the first time. (And i had done all three scans before shutting down.)

Make sure to clear your cache and cookie files before shutting down.


Anti - virus: AVG Anti Virus free edition
Signatures: 06/08/2007

Anti - spyware: Spybot Search and Destroy
Signatures: 06/08/2007

I had to use Trend Micro's Houescall to get rid of my infectons because neither program listed above found them. I dont remember the names of them, though.

Hellow
07-10-2007, 10:40 AM
Yes, i know how to startup in safe mode. The only problem is, I cant get my computer to shut down! I believe i am going to just buy a new desktop because a virus ran my computer so hard it partially melted its CPU because i havent cleaned inside of it in a year. And it was made in 2002 so it is VERY outdated. The cost of repairs on my computer would total at around $550 but the cost of a brand new computer is $300. So its not worth it. So to anyone who will be wondering why im not on here very often is because i travel a lot dring summer break with my family and i dont have a bluetooth cellphone to hook up to my laptop and my desktop is fried so i wont be on here very often until i get a new desktop. Also, all of my files are trapped on my computer because a virus has locked my computer from the internet. And im not even going to think about pluging my jumpdrive into that thing then into my laptop because my laptop would be ruined.

Catlady711
07-10-2007, 09:30 PM
http://www.processlibrary.com/directory?files=svchost.exe


SVCHOST.EXE
Description: svchost.exe is a system process belonging to the Microsoft Windows Operating System which handles processes executed from DLLs. This program is important for the stable and secure running of your computer and should not be terminated.

Recommendation: svchost.exe should not be disabled, required for essential applications to work properly. It is highly recommended to Run a Free Performance Scan to automatically optimize memory, CPU and Internet Settings.


To check any process running on your cpu......

http://www.processlibrary.com/directory/a

crow_noir
07-10-2007, 11:21 PM
Shouldn't it shut down if you unplug it? I've had to do that a few times.


Yes, i know how to startup in safe mode. The only problem is, I cant get my computer to shut down! I believe i am going to just buy a new desktop because a virus ran my computer so hard it partially melted its CPU because i havent cleaned inside of it in a year. And it was made in 2002 so it is VERY outdated. The cost of repairs on my computer would total at around $550 but the cost of a brand new computer is $300. So its not worth it. So to anyone who will be wondering why im not on here very often is because i travel a lot dring summer break with my family and i dont have a bluetooth cellphone to hook up to my laptop and my desktop is fried so i wont be on here very often until i get a new desktop. Also, all of my files are trapped on my computer because a virus has locked my computer from the internet. And im not even going to think about pluging my jumpdrive into that thing then into my laptop because my laptop would be ruined.

Hellow
07-11-2007, 10:51 AM
Yes, but i never do it because when i did it once my computers hard disk crashed. I guess i will just buy a new computer as soon as i can get enough money.