Re: long sytem freeze



ok, I in search I have found 3 svchost.exe with locations as follows:

C:\WINDOWS\$NtServicePackUninstall$
C:\WINDOWS\ServicePackFiles\i386
C:\WINDOWS\system32

does it mean that first 2 are fake/malicious?
if it is malware -
how do I remove them ? - just go to the folder and delete them?
how do I protect my PC in the future ?
I already have NIS (AV, firewall etc)

next interesting thing:
in my task manager I see 6 (six) svchost.exe :))
3 from system
2 from network service
1 from local service
they all using 0% CPU and peak mem usage below 6000K
except for one from system which had 181000K and is using currently 26788K
???

I will reboot my PC now to give you feedback if it still takes time to
reboot

--
lb
"Daave" <dcwashNOSPAM@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:OQ1KwQkbJHA.4380@xxxxxxxxxxxxxxxxxxxxxxx
"lesiofamily" <blm333@xxxxxxx> wrote in message
news:e33xQbibJHA.4412@xxxxxxxxxxxxxxxxxxxxxxx
using process explorer
I can see few svchost but they use 0% CPU
the highest is system idle process with 99-100% CPU usage
command line is blank, description blank, company name blank

I checked my other PC
system idle process takes approx 86- 97% CPU - for me it looks high but
it 10% less than my first PC
any comments?

Are we talking about a sporadic problem? That is, perhaps you were not
experiencing the "long system freeze" during the above timeframe? Does
your problem present itself during bootup usually?

If it is sporadic, Process Explorer will give you useful information, but
you need to be looking at it *during* the grinding of the gears (not
afterward). And since in another post you indicated that one of your
instances of svchost was through the roof memory-wise, the Bleeping
Computer tutorial should be helpful.

There have been reports of svchost.exe run amok after a particular
security update was applied. How up-to-date are you with your Windows
Updates? What Service Pack level are you at? Can you recall when you
started experiencing this particular problem as well as anything
significant that occurred at around that time?

Finally, I don't recall whether or not you confidently ruled out malware.
Sometimes an instance of svchost.exe running *is* malicious. Svchost.exe
is a valid file *if* it is in the correct location, which should be:

C:\WINDOWS\system32

If you have another svchost.exe in another loaction, it's surely malware.

Search your entire C: drive for svchost.exe. In "More advanced options,"
be sure to check "Search system folders" and "Search subfolders." Again,
if you see another instance of svchost.exe where it doesn't belong, you
have a malware infection!

Last idea: You stated you had NIS 2008. Norton is well-known for producing
the kind of behavior you are describing. Configure a clean boot (which
means, among other things, you will be temporarily disabling NIS 2008) and
see if your problem goes away. For more info:

http://support.microsoft.com/kb/310353

If your problem does go away, you should be able to use the process of
elimination to determine the cause. It wouldn't surprise me if it's
Norton.



.



Relevant Pages

  • Norton IS 2005 Breaks Email
    ... Norton Internet Security 2005 is installed on a newly rebuilt W2k SP4 ... Standard software ... without issue which includes NIS 2005. ... This error appears to ALWAYS be associated with a CPU Usage ...
    (microsoft.public.outlook.installation)
  • Norton IS 2005 ccApp.exe breaks email
    ... Norton Internet Security 2005 is installed on a newly rebuilt W2k SP4 ... Standard software ... without issue which includes NIS 2005. ... This error appears to ALWAYS be associated with a CPU Usage ...
    (microsoft.public.win2000.security)
  • Re: long sytem freeze
    ... will process explorer show the culprit few seconds later - but when I can ... except for my security program which is NIS ... I can see few svchost but they use 0% CPU ... I don't recall whether or not you confidently ruled out malware. ...
    (microsoft.public.windowsxp.general)
  • Re: long sytem freeze
    ... will process explorer show the culprit few seconds later - but when I can ... I can see few svchost but they use 0% CPU ... I don't recall whether or not you confidently ruled out malware. ... You stated you had NIS 2008. ...
    (microsoft.public.windowsxp.general)
  • Re: Norton System Works 2007
    ... of Norton can be more tricky. ... very effective but suggest *not* to use the 'Clean the Registry' option. ... Real-time AV applications - for viral malware. ...
    (microsoft.public.windowsxp.general)

Quantcast