Results 1 to 10 of 10
  1. #1
    BigGreen's Avatar
    BigGreen is offline Anabolic Member
    Join Date
    Aug 2002
    Location
    12,000 feet above it all
    Posts
    4,345

    nasty svchost.exe

    In my task manager I show several svchost.exe tasks running but one in particular appears to be malicious/compromised. The line on it is as follows svchost.exe (image name), System (user name), 54 (cpu), 21, 544k (mem usage) and CPU usage is at 100%. It's that 33-55 range on the cpu value that has me most concerned (well, the 100% cpu usage as well).

    Essentially, I'm wondering how to locate and remove that specific svchost.exe. Whatever it is seems to have my command prompt shortcut frozen/inoperable as well, so I'd really like to find this thing and get it the hell off my comp.

  2. #2
    Beretta726's Avatar
    Beretta726 is offline Junior Member
    Join Date
    Apr 2006
    Location
    East Coast
    Posts
    59
    it's probably spyware. AD-Aware SE personal and SpyBot are good removal tools. Microsoft also has a free removal program. Always a good idea to run more than one spyware protection program. Running the virus scan wouldn't hurt either. TrendMicro has a program called CWshredder. It finds alot of the things that the other programs don't.

  3. #3
    guest589745 is offline 2/3 Deca 1/3 Test
    Join Date
    Apr 2005
    Posts
    7,964
    I have 7 svchost.exe 's on my PC right now and have no idea how/what one to get rid of.

    Bump.

  4. #4
    oldman's Avatar
    oldman is offline Anabolic Member
    Join Date
    Sep 2005
    Posts
    2,224
    This is NOT spyware this is a process used by the Windows OS.

    At any one time you could have 5-10+ running at the same time there is nothing wrong with it and if you kill them off you will shut down your PC.

    download and run http://www.safer-networking.org/ S&D

    And

    http://www.lavasoft.de/software/adaware/

    and you will clear out anything bad. Update and run at least once per week and you will keep your PC's running faster and cleaner.

    also run a firewall like zonealarm will help block auto-install .exe files that you will get hit with by going to malicious websites.

    ~Old

  5. #5
    BigGreen's Avatar
    BigGreen is offline Anabolic Member
    Join Date
    Aug 2002
    Location
    12,000 feet above it all
    Posts
    4,345
    thanks all for the advice so far. Here's the deal:

    I've run ad-aware, spybot search and destory, spysweeper AND norton antivirus scans (all in safe mode) as well as the online scan of housecall and still nothing. While running in safe mode, task manager shows normal processes: ie, system idle taking up most of the cpu and total cpu usage at 3-25% as things boot up. Under "normal" log on conditions (not safe mode) I show normal process distribution (for lack of a better term) for thirty to forty seconds, then suddenly it shoots up to 100% CPU usage with it split almost exclusively between "system" (NOT system idle, as should be the case and IS in safe mode) and a random svchost. Clearly something isn't right, but whatever that something is seems to slip under the radar of all of those fine spyware programs.

    I don't fileshare on this comp at all (I keep a crappy, older comp for that sole purpose) and the only thing that's happened in the last year with this one is a few days ago an email with an executable attachment was sent to my school email, which automatically opens such attachments when you open the email (huge problem at the school that they intend to fix) through the off campus web based email. Since these problems started a day or so after that opening, i assume that's the issue, but still the programs pick up nada.

    Any further suggestions?

  6. #6
    oldman's Avatar
    oldman is offline Anabolic Member
    Join Date
    Sep 2005
    Posts
    2,224
    If your anti-spy and such is not finding anything I am guessing you have some sort of Trojan than got in and has already done damage and removed itself or is in a hidden process. Since you are on XP have you tried doing a restore to a prior point when you know this was not happening.

    Some of these are next to impossible to find. Sorry hard to do long distance but you could always bring to a PC repair and see if they can flush it out.

    ~Old

  7. #7
    Prada's Avatar
    Prada is offline Anabolic Member
    Join Date
    Nov 2005
    Location
    Tampa,Montreal,Paris
    Posts
    4,186
    Personally I am a big fan of AVG Antivirus by Grisoft

  8. #8
    StoneGRMI's Avatar
    StoneGRMI is offline Giggity Giggity Giggty!
    Join Date
    Dec 2004
    Location
    Michigan
    Posts
    4,336
    Blog Entries
    6
    Microsoft® Live OneCare is a great new all-in-one Antivirus/adware/system checkup/firewall that I have been using for about a month. I have no complaints yet.

  9. #9
    BigGreen's Avatar
    BigGreen is offline Anabolic Member
    Join Date
    Aug 2002
    Location
    12,000 feet above it all
    Posts
    4,345
    To all: thanks for all the advice. I ended up becoming so frustrated that I spent the afternoon wiping out my hard drive and starting over from scratch altogether. Now that the task is done (having sorted through missing individual drivers and downloading those) it's like having a brand new computer. I can NOT believe how smooth this thing is now. It was a llllong afternoon, but this thing has not run this well in MONTHS. That said, to ensure this doesn't happen again, I've made sure ALL of my MS updates are up to snuff, and I plan on running ad-aware and spybot far more frequently.

  10. #10
    cfiler's Avatar
    cfiler is offline Anabolic Member
    Join Date
    Jul 2003
    Location
    Training my ninja Degu
    Posts
    7,185
    Good stuff, glad it all worked out for you.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •