SVCHOST-svchost.exe -k netsvcs uses 90% + CPU Usage, slows powerful machine to crawl-Whatsup?

Anonymous
2010-02-24T02:18:43+00:00

SVChost.exe - k netsvcs has crippled my machine like no malwaer ever has. From what I can tell, this has something to do with Windows Update.

Nothing else unsual is running. There is no malware involved. And all updaes are installed Except I cannot update .net. I get the following error message:

"Microsoft .NET Framework 3.5 Service Pack 1 and .NET Framework 3.5 Family Update for .NET versions 2.0 through 3.5 (KB951847) x86"

What can I do? I am frustrated.

Windows for home | Previous Windows versions | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2010-02-27T17:55:51+00:00

Thanks for the help! I followed Joel's advise above & it SEEMS to have resolved the problem. I say SEEMS, because I have seen the problem apparently resolved, only to resume again after a few days. Updated Malwarebytes showed no infection doing a deep scan.

I will be back if proble returns.... for now, issue resolved!

Was this answer helpful?

400+ people found this answer helpful.
0 comments No comments

45 additional answers

Sort by: Oldest
  1. Anonymous
    2014-03-29T14:22:33+00:00

    I was also having the problem with SvcHost stealing nearly all of the servers resources.  Not any longer, though.

    I found posts seemingly EVERYWHERE recommending things that worked, but sometimes only temporarily.  I never discovered the cause, but with so many different suggestions even in Microsoft's various forums, I decided to try something more simple.

    All I did was to run "CHKDSK /R" on just the C: drive of my WHS system.  Six backups later, I'm still good to go ... No more SvcHost hogging all my server's resources.

    I fully realize and admit this did nothing to identify the exact cause of the original problem, and I cannot promise the problem won't reoccur.  But since my server is now working fine again, and since running CHKDSK isn't something potentially harmful, I'd surely recommended trying it to see whether it helps.

    Tony

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2014-04-19T07:13:44+00:00

    Quite a multi-platform(s) ****'t of cross-accessible Div39 EZ tgts ... not to mention lotsa code lines etc. from well..another story.

    My case involves a system sold as "XP 32bt" OEM but in fact it's been hybridized (virtually) into XP/Svr 2003/7, and Idris. The latter was the only of my doing.

    I've come to believe that situations arising like this are increased dramatically due to (for one, two... +) Telecom ('Cable,' 'cellular com', Mems, AOTF, and even SWIR such tools

    My IDRIS platform I customized for one of my machines seems to be -- thus far -- the only thing that will deny or ack or fly under the old, ancient ARPA machines with 300bps acoustic linkups ; - )

    I used a machine totally off all grids ('net,' modem, cellular, RF, and even building electrical systems). That last one MUST be 'cause the jerks (changes of changes of ... of voltages,

    rf, etc.) trip up the only machine I have that does not even use any non-physical or 'airwave' inputs other than 1 or 2 wires with a few old capacitors, resis'tors, etc and one little simpleRF FPGA gate.

    When a Zener diode I got from my days testing MIL/DoD purchases in a HASS chamber. I do not expect ANY of this to be useful to maybe more than .3% of this community, IT DOES WORK FOR ME, gratefully.

    Thanks for the info all.

    With Respect,

    HJHIII, ColonialSon7thATC-ABERDEENmdBICHCTR {{{ AKA: jOE" }}}

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2015-02-20T23:12:01+00:00

    Dear, I'm having this problem since years with no solution. I've downloaded the Hijack This Software and here is the resultant log:

    Logfile of Trend Micro HijackThis v2.0.5

    Scan saved at 11:51:13 PM, on 2/20/2015

    Platform: Windows 7 SP1 (WinNT 6.00.3505)

    MSIE: Internet Explorer v11.0 (11.00.9600.17631)

    Boot mode: Normal

    Running processes:

    C:\Program Files (x86)\Mada CM\cm\UIExec.exe

    C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe

    C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe

    C:\Windows\SysWOW64\RunDll32.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    C:\Users\Ashraf Alfandi\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.yahoo.com/?fr=fp-yie11

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Yahoo

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 

    F2 - REG:system.ini: UserInit=userinit.exe

    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL

    O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

    O3 - Toolbar: Yahoo Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll

    O4 - HKLM..\Run: [QHSafeTray] "C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe" /start

    O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe

    O4 - HKCU..\Run: [UIExec] "C:\Program Files (x86)\Mada CM\cm\UIExec.exe"

    O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload

    O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup

    O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot

    O4 - Global Startup: Bluetooth.lnk = ?

    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm

    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

    O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm

    O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

    O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)

    O9 - Extra button: (no name) - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - (no file)

    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)

    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics

    O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

    O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)

    O23 - Service: BitComet Disk Boost Service (BITCOMET_HELPER_SERVICE) - www.BitComet.com - C:\Program Files\BitComet\tools\BitCometService.exe

    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

    O23 - Service: GCT WiMAX Service (GCTWiMAXService) - Seowonintech CO.Ltd - C:\Windows\system32\GCTWiMaxServiceD.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)

    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: NitroPDFDriverCreatorReadSpool9 (NitroDriverReadSpool9) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe

    O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\NLSSRV32.EXE

    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: 360 Total Security (QHActiveDefense) - Unknown owner - C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe

    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe

    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

    O23 - Service: ZTE AX226 WiMAX Modem Switch Service (ssax226) - Unknown owner - C:\Program Files (x86)\Mada CM\cm\ssax226.exe

    O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe

    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --

    End of file - 9231 bytes

    I would be grateful if you help to solve this problem

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2015-05-23T18:42:30+00:00

    When I try to delete it starts deleting after adminitrative permission and suddenly at the end it say you need trusted installer to perform this action. 1st image shows search result and then I tried to delete the second file. 2nd image shows request for permision and 3rd image shows the progress bar. The 4th image shows the error that I am talking about.  WHAT SHOULD I DO?

    Was this answer helpful?

    0 comments No comments