1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

SVChost question

Discussion in 'Windows XP' started by Herd72, 2008/05/10.

  1. 2008/05/10
    Herd72

    Herd72 Inactive Thread Starter

    Joined:
    2004/06/23
    Messages:
    105
    Likes Received:
    0
    I am getting multiple instances of svchost when I check the task manager. One of them will use 98-100 percent of the CPU and thus everything take eons to open almost like being locked up. I can delete that one and all is well but it comes back. I am running WinXP-SP3 and have 2GB of ram and an ASUS motherboard. Any help would be greatly appreciated! I am pasting a HJT scan below.
    Thanks again,
    Jim in WV

    Logfile of HijackThis v1.99.1
    Scan saved at 4:22:52 PM, on 5/10/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ

    Antivirus\CAVRID.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE
    C:\Program Files\CA\eTrust Internet Security Suite\cctray\cctray.exe
    C:\WINDOWS\system32\kmw_run.exe
    C:\Program Files\Western Digital Technologies\Spindown\ExSpinDn.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    D:\data\product\xtras\mssysmgr.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\WINDOWS\system32\KMW_SHOW.EXE
    C:\Program Files\Common Files\ArcSoft\Connection

    Service\Bin\ACService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ

    Antivirus\ISafe.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\PROGRA~1\Iomega\System32\AppServices.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ

    Antivirus\VetMsg.exe
    C:\Program Files\Webroot\Washer\WasherSvc.exe
    C:\Program Files\Memeo\AutoBackup\MemeoBackup.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\CA\eTrust Internet Security Suite\ccprovsp.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

    http://localhost:3476/cgi-bin/ncgir.exe?ONAMX=menu/index.html&DNAMX=ncgir

    .exe?html/fire_profile.html
    O2 - BHO: Adobe PDF Reader Link Helper -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

    Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA

    Corporation\NvMixer\NVMixerTray.exe "
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security

    Suite\eTrust EZ Antivirus\CAVRID.exe "
    O4 - HKLM\..\Run: [EPSON Stylus C88 Series (Copy 1)]

    "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" /P32 "EPSON

    Stylus C88 Series (Copy 1)" /O6 "USB001" /M "Stylus C88 "
    O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\eTrust Internet Security

    Suite\cctray\cctray.exe "
    O4 - HKLM\..\Run: [EPSON Stylus C88 Series]

    "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" /P23 "EPSON

    Stylus C88 Series" /O5 "LPT1:" /M "Stylus C88 "
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI

    Technologies\ATI.ACE\Core-Static\CLIStart.exe "
    O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
    O4 - HKLM\..\Run: [WD Spindown Utility] "C:\Program Files\Western Digital

    Technologies\Spindown\ExSpinDn.exe "
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program

    Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [EPSON Stylus C88 Series (Copy 2)]

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE /P32 "EPSON

    Stylus C88 Series (Copy 2)" /O6 "USB002" /M "Stylus C88 "
    O4 - HKLM\..\Run: [ISUSPM Startup]

    c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"

    /background
    O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager]

    D:\data\product\xtras\mssysmgr.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media

    Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [EPSON Stylus CX9400Fax Series]

    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICFA.EXE /FU

    "C:\WINDOWS\TEMP\E_SA2.tmp" /EF "HKCU "
    O4 - HKCU\..\Run: [updateMgr] "c:\Program Files\Adobe\Acrobat

    7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_9 -reboot 1
    O4 - Startup: Memeo AutoBackup Launcher.lnk = ?
    O4 - Global Startup: PowerReg Scheduler.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network

    Diagnostic\xpnetdiag.exe (file missing)
    O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager

    Control) -

    http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.0.6.

    4.cab
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll

    (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

    C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program

    Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common

    Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -

    C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner -

    C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -

    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\eTrust

    Internet Security Suite\ccprovsp.exe
    O23 - Service: CAISafe - Computer Associates International, Inc. -

    C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ

    Antivirus\ISafe.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

    Corporation - c:\Program Files\Common

    Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Iomega App Services - Iomega Corporation -

    C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown

    owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: LiveUpdate - Symantec Corporation -

    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program

    Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
    O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software,

    Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
     
  2. 2008/05/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Jim

    Multiple instances of svchost are usual - I currently have 6 showing in Task Manager.

    However one running at 100% is not good news and I am moving your thread to the Removing Spyware & Viruses forum.

    The first thing the guys there will request is an HJT log from the latest version of HJT - get it here and post another log.
     

  3. to hide this advert.

  4. 2008/05/10
    Herd72

    Herd72 Inactive Thread Starter

    Joined:
    2004/06/23
    Messages:
    105
    Likes Received:
    0
    Thanks,
    I will look over there and maybe I can get it sorted out.
    Jim in WV
     
  5. 2008/05/11
    telephonics

    telephonics Inactive

    Joined:
    2008/02/23
    Messages:
    125
    Likes Received:
    0
    Svchost

    I suspect that the adobe updater is your problem. Typically this p[rogram never completes so the CPU is consumed trying. Open your adobe program. Then open C Drive and go Programfiles\Common Files\Adobe\Updater 5. When the update screen appears click on the Preferences button. Uncheck the automatically check for updates check box and click ok.
    Once this is done you'll have to update Adobe manually.
     
  6. 2008/05/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    ...or better, yet, switch to FoxIt.
     
  7. 2008/05/12
    Herd72

    Herd72 Inactive Thread Starter

    Joined:
    2004/06/23
    Messages:
    105
    Likes Received:
    0
    I think you solved it!

    Brilliant! The Adobe advice was spot on! I did as you said and it seems to have solved the problem!
    Many thanks!
    Jim
    :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.