SVCHOST-svchost.exe -k netsvcs uses 90% + CPU Usage, slows powerful machine to crawl-Whatsup?

Anonymous
2010-02-24T02:18:43+00:00

SVChost.exe - k netsvcs has crippled my machine like no malwaer ever has. From what I can tell, this has something to do with Windows Update.

Nothing else unsual is running. There is no malware involved. And all updaes are installed Except I cannot update .net. I get the following error message:

"Microsoft .NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update for .NET versions 2.0 through 3.5 (KB951847) x86"

What can I do? I am frustrated.

Windows for home | Previous Windows versions | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2010-02-27T17:55:51+00:00

Thanks for the help! I followed Joel's advise above & it SEEMS to have resolved the problem. I say SEEMS, because I have seen the problem apparently resolved, only to resume again after a few days. Updated Malwarebytes showed no infection doing a deep scan.

I will be back if proble returns.... for now, issue resolved!

Was this answer helpful?

400+ people found this answer helpful.
0 comments No comments

45 additional answers

Sort by: Newest
  1. Anonymous
    2012-07-09T20:50:59+00:00

    >>  SVChost.exe - k netsvcs has crippled my machine like no malware ever has. From what I can tell, this has something to do with Windows Update.

     

    Posted 7/9/2012:

    For me it turned out to be a Boot sector virus.  It happened to me suddenly.  And Windows updates would not download.  Here is my shortcut from two days of trial-and-error to remove this virus. .  The short-cut solution takes about an hour.

     

    Search on the Internet for [Norton Power Eraser].  Download it.  Install it.  And first run it in Normal mode.  Select the Option in the box to the left--.Scan for Risks.  Click Restart to perform a rootkit scan.  After the Restart, PowerEraser comes back up with a list of suspected files.  For the first cut, uncheck all of the suspected files except the topmost suspect which will be something like "BootRecord1".

     

    The Capture System Restore point CheckBox will be checked.

     

    Click the Fix button.

     

    The next message will be scary.  It will say something like "Remove the Boot Record".  What it means is "Repair the Boot record."

     

    Give Norton your feedback Good or Bad in the final screen when your system comes back up.

     

     

     

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2012-04-14T20:23:07+00:00

    I had the same problem (on another computer).  I had tried a lot of the solutions stated here.  Nothing worked and the frustration level was high.  However, the solution proved to be finding and killing a boot-sector Trojan virus.  The virus name is "tdlphaze.1"  I have Norton Antivirus but the regular program did NOT find it and kill it.  After Norton said it found nothing, I clicked on the link, "I still have problems."  The result was downloading something called "Norton Power Eraser" that DID find the boot sector virus and removed it.  The computer has been operating like new ever since then.  Find something that will go for and kill this particular boot-sector virus.  (There are apparently several versions with suffixes "-2," -3," etc.)

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2012-04-11T01:43:52+00:00

    Thank you for posting. Please be advised that we no longer analyze Hijack This log files. If you think your computer is infected I would advise you to follow the instructions below.

    Click http://www.malwarebytes.org/mbam/program/mbam-setup.exe[HERE](http://www.kqzyfj.com/click-6279332-11114059). Download Malwarebytes. Update Malwarebytes and perform a quick scan.  Choose to quarantine anything found. Once complete click HEREand download Superantispyware Portable. Perform a quick scan again quarantining anything found. Reboot your computer in normal mode and perform a quick scan with Malwarebytes.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2012-04-11T01:25:11+00:00

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 8:16:02 PM, on 4/10/2012

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\WLTRYSVC.EXE

    C:\WINDOWS\System32\bcmwltry.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe

    C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe

    C:\Program Files\IDT\WDM\sttray.exe

    C:\WINDOWS\system32\AESTFltr.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe

    C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe

    C:\WINDOWS\system32\WLTRAY.exe

    C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Intel\ASF Agent\ASFAgent.exe

    C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe

    C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe

    C:\WINDOWS\system32\igfxext.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    C:\Program Files\Google\Update\GoogleUpdate.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files\Norton AntiVirus\Engine\18.7.1.3\ccSvcHst.exe

    C:\Program Files\Norton PC Checkup\Engine\2.0.15.91\SymcPCCULaunchSvc.exe

    C:\Program Files\Norton PC Checkup\Engine\2.0.15.91\ccSvcHst.exe

    C:\Program Files\Microsoft\BingBar\SeaPort.EXE

    C:\Program Files\Norton PC Checkup\Engine\2.0.15.91\ccSvcHst.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Documents and Settings\Home\Application Data\StretchClockStats\IE\StretchClockStatsUpdater.exe

    C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe

    C:\Program Files\Norton AntiVirus\Engine\18.7.1.3\ccSvcHst.exe

    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    C:\WINDOWS\system32\SearchIndexer.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\system32\msiexec.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\SearchProtocolHost.exe

    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USREL/1

    R3 - URLSearchHook: Vgrabber Toolbar - {b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} - C:\Program Files\Vgrabber\prxtbVgra.dll

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

    O2 - BHO: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: StretchClockStats - {6904D1AA-C3D8-479D-A0F3-F096C6690FC3} - C:\Documents and Settings\Home\Application Data\StretchClockStats\IE\StretchClockStats.dll

    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.7.1.3\IPS\IPSBHO.DLL

    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll

    O2 - BHO: Vgrabber - {b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} - C:\Program Files\Vgrabber\prxtbVgra.dll

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

    O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O3 - Toolbar: Vgrabber Toolbar - {b2ed7faf-72a0-46d1-9d9d-602226f5cb9f} - C:\Program Files\Vgrabber\prxtbVgra.dll

    O3 - Toolbar: Conduit Engine  - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe

    O4 - HKLM..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg

    O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM..\Run: [DellControlPoint] "C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"

    O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe

    O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe

    O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

    O4 - HKLM..\Run: [DellConnectionManager] "C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe"

    O4 - HKLM..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16

    O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe

    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

    O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKUS\S-1-5-19..\Run: [Update] rundll32.exe "C:\Documents and Settings\Home\Application Data\Office Genuine Advantage\Office Genuine Advantage\hmlxkn.dll",DllRegisterServer (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20..\Run: [Update] rundll32.exe "C:\Documents and Settings\Home\Application Data\Office Genuine Advantage\Office Genuine Advantage\hmlxkn.dll",DllRegisterServer (User 'NETWORK SERVICE')

    O4 - Global Startup: Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe

    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe

    O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe

    O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe

    O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe

    O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: lxcg_device -   - C:\WINDOWS\system32\lxcgcoms.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\18.7.1.3\ccSvcHst.exe

    O23 - Service: Norton PC Checkup Application Launcher - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.15.91\SymcPCCULaunchSvc.exe

    O23 - Service: Common Client Job Manager Service (PCCUJobMgr) - Symantec Corporation - C:\Program Files\Norton PC Checkup\Engine\2.0.15.91\ccSvcHst.exe

    O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe

    O23 - Service: Smith Micro Connection Manager Service (SMManager) - Smith Micro Software, Inc. - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe

    O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\drivers\audio\r213367\stacsv.exe

    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    O23 - Service: StretchClockStats Updater (StretchClockStatsUpdater) - Unknown owner - C:\Documents and Settings\Home\Application Data\StretchClockStats\IE\StretchClockStatsUpdater.exe

    O23 - Service: NTRU TSS v1.2.1.29 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe

    O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe

    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --

    End of file - 13730 bytes

    Was this answer helpful?

    0 comments No comments