Question

Problem with High CPU Usage with SVCHost.EXE

Asked by: mnielson323

I am running WinXP Pro and am having very slow and sluggish response times.  I looked at the Task Manager and the services eating up most of my CPU Usage was SVCHost.EXE.  There are actually five different SVCHost.EXE running.  I did a tasklist /svc from DOS and the PID associated with the highest CPU Usage has around 32 services/programs running.  Any reason why this service is doing this.  The System Idle Process used to be in the 90+% usage, now it's less than 5%.

Thanks,

Mike

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2004-04-08 at 08:37:18ID20947897
Tags

cpu

,

usage

,

high

Topic

Windows XP Operating System

Participating Experts
7
Points
135
Comments
24

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. svchost.exe
    Hi all, I have found five svchost.exe listed on my task manager. Originally, i have only 4 of them. According from my friend, if my list has 5 svchost.exe, my computer is being hacked. However, i have no idea how to find out which programs are running which svchost.exe. Even...
  2. svchost.exe
    I see three svchost.exe; One of them is eating a lot of CPU time. Is there a utility that allows to track to which program is a given svchost.exe linked? Thank you, Daniel Bessis
  3. svchost.exe 100% cpu
    Hi Folks, I have a PC running Windows XP Home edition. This Pc stopped working and could not get past the logon screen (you would click on the user then it would just hang loading personal settings). I could start in safe mode, the desktop would load up but i could not acces...
  4. svchost.exe eating up most of my CPU
    My computer really slows down sometimes and when I look at what's running in Windows Task Manager, I see that svchost.exe is eating up most of my CPU. I've searched a little on in on the Internet but I haven't found anything that would point me to a safe solution. I also look...
  5. svchost.exe runs
    XP Pro sr2, AV, FW, CC, & Spyblockers svchost.exe seems to run at random times for several minutes consuming most of my computing power. Svchost is a problem because it interrupts critical business uses. Svchost.exe is rude to start up 100% CPU without notification or c...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 
 

by: sunray_2003Posted on 2004-04-08 at 08:39:21ID: 10784386

You may want to check for spyware and virus first

But also look at these links explaining why there could be multiple svchost

http://www.jsiinc.com/SUBJ/tip4600/rh4660.htm  

http://www.winnetmag.com/Article/ArticleID/20609/20609.html

 

by: mnielson323Posted on 2004-04-08 at 08:49:10ID: 10784465

I already am running Spybot S&D Advanced spyware on a regular basis.  I also keep Windows Updates and NAV up-to-date.  I will, tho, check into ad-ware, CWshredder, and Hijackthis.  THANKS!

 

by: briancassinPosted on 2004-04-27 at 22:49:59ID: 10935769

mnielson323,

just happened to view this I was having almost the same exact problem just wondering if you got your problem resolved ?

 

by: mnielson323Posted on 2004-04-28 at 13:21:27ID: 10943264

Brian,

Well....I hate to say that whatever suggestions I got, just caused more problems.  I did what was suggested to me and immediately started getting POPUP adds, which I now can't get rid of.  Concerning my original problem, it seems to have rectified itself.  My CPU Usage (for System Idle Process) is running in the 90+% - which is great.  I however did nothing to accomplish that.  So, bottom line...I don't know what to tell you.

Sorry.......Mike

 

by: briancassinPosted on 2004-04-28 at 17:24:44ID: 10944756

The reason why I asked is I had the same problem which is caused by a backdoor trojan which was recently discovered April 4th 2004

Check task manager under processes and see if you have a 5 digit number running as a process in the background also go into your registry by going to start run type regedit hit enter and then go to HKEY_LOCAL MACHINE - Software - Microsoft- Windows - Current Version- Run see if their is a 5 digit number listed here (it is a random number) if so then you have the Trojan known as either RDOM.A  ( F-Prot) or Sdown.A by trend micro. Let me know if you find this if you do it has to be gotten rid of it opens a back door of your system to hackers.

Some of the other problems were CPU was at 99% usage with SVCHOST.EXE using 99% of the processor could not access MY Computer, Network Places, the Internet or anything computer would just have the wait icon then refresh the screen all icons would be removed then come back but nothing would happen.

 

by: sugarsteviePosted on 2004-04-28 at 21:00:14ID: 10945715

I experienced this problem on two successive boots of Windows XP earlier today.  Now everything is fine.  An additional symptom is that the computer will not safely shut down -- it gets hung when saving system settings.  I found a suspicious entry in the registry location referenced above, but it looks like 9 random letters as opposed to 5 digit numbers.  The entry points to C:\WINDOWS\AHNUELRYF.exe, but the file is no longer there.

 

by: briancassinPosted on 2004-04-28 at 21:55:45ID: 10945959

sugarstevie I would say scan your system good

use

http://housecall.trendmicro.com

 

by: mnielson323Posted on 2004-04-29 at 06:54:22ID: 10949348

briancassin (and sugarstevie),

First, thanks for the replies.  Second, I followed the instructions to get to the HKEY_ (never been there before - and by the way, AWESOME instructions), but found NOTHING.  There weren't any 5 or even 9 digit numbers.  There were a few processes with strings of LETTERS, but none with numbers.  But lastly, I will go ahead and run that URL scan.

Thanks again,

Mike
 

 

by: Chris_McMahonPosted on 2004-05-07 at 22:09:31ID: 11020439

I called Microsoft on this a few months back. It's kind of a tough fix.
I am looking for my notes...

 

by: mnielson323Posted on 2004-05-11 at 19:14:05ID: 11046246

briancassin (and sugarstevie),

I ran that scan from the URL you sent...nothing found.

Chris,

Thanks for checking.  Hope you find something.

Mike

 

by: briancassinPosted on 2004-05-11 at 19:48:16ID: 11046396

check the first link in this to see if this is a possibility they have a tool that checks for it...

This is the Sasser worm (or a variant).
See the following links for removal tools and more information:

http://www.microsoft.com/security/incident/sasser.asp
http://securityresponse.symantec.com/avcenter/venc/data/w32.sasser.removal.tool.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SASSER.A

Security Patch in response to this vulnerability:
http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx


Also try this go to the site listed below and download the program run it and post the log report up here... I will look through it and see if their is anything suspicious.

http://www.tomcoyote.com/hjt/

 

by: sugarsteviePosted on 2004-05-20 at 21:00:12ID: 11123815

Mike,

I too experienced the same problem you did, as I previously commented.  I recently did a scan with Lavasoft's AdAware 6.0.  It found 18 problems that SpyBot did not find.  You might try downloading and running this specific adware detection software and see if it helps.  My machine has not hung since I ran the scan.

-Steve

 

by: sugarsteviePosted on 2004-06-13 at 17:45:16ID: 11302389

Mike,
The previous report that Ad-aware discovered malware that was causing the problem was erroneous.  The system continued to experience the problem.  Svchost runs a whole slew of services on behalf of the system – so the trick was to find which one was running away.  I downloaded a tool called Process Explorer from http://www.sysinternals.com/ntw2k/freeware/procexp.shtml.  It will report the process ID and in the case of the svchost process, all services attached to it. At Control Panel - Admin Tools – Services, I selectively stopped each service to see which one was causing the load (then start them again if stopping had no effect).  In my case, I found that the System Restore Service (srservice – srsvc.dll) was running away at 99%.  I have disabled the service, and the condition has not surfaced again.  That doesn’t solve the problem of what is wrong with this particular service, but at least the machine will no longer become crippled.
-Steve

 

by: Chris_McMahonPosted on 2004-06-13 at 17:49:31ID: 11302410

Ok found my notes here was the problem and solution I had... it wasn't spyware.

http://support.microsoft.com/default.aspx?scid=KB;EN-US;317843

 

by: sugarsteviePosted on 2004-08-08 at 10:43:46ID: 11747154

Mike,
     I finally got the bottom of what was causing System Restore Service running under SVCHOST to saturate the CPU at 100%.  I'll document it here for any unlucky soles who may encounter the same problem.
     Svchost runs a whole slew of services on behalf of the system – so the trick was to find which one was running away. I downloaded a tool called Process Explorer from http://www.sysinternals.com/ntw2k/freeware/procexp.shtml. It will report the process ID of each process in memory, and in the case of the svchost process, all services attached to it. At Control Panel - Admin Tools – Services, I selectively stopped each service to see which one was causing the load (then later started it again if stopping had no effect). In my case, I found that the System Restore Service (srservice – srsvc.dll) was running away at 99%.
     Next I opened a support case with Microsoft.  We used numerous tools to troubleshoot the service.  One of the more valuable tools was FILEMON, available at http://www.sysinternals.com/ntw2k/source/filemon.shtml.  It shows all files that are touched during the monitor period.  We also used the proprietary USERDUMP tool from Microsoft, which is not available for download, and for which I had no tool to analyze the results.
     Microsoft determined that the latest restore point in the SRService database was corrupt, and the service was getting hung when it tried to delete one of its files.  The restore points comprising the SRService database are stored on my machine at the following location:  C:\System Volume Information\_restore{2EDE8FBE-CD64-4AC6-BB82-21229910E44C}
The solution was to manually remove all restore points in the SRService database, using Windows Explorer.  Here are the steps to accomplish this.
1. Boot the machine with SRService disabled (Select Start / Control Panel / Administrative Tools / Services.  Double click System Restore Service, and set Startup Type to Disabled, then click OK. Re-boot.  You may have to rename srsvc.dll, even in the DLL cache, to keep it from starting - it's fairly persistent.)
2. You must grant access to the System Volume Information folder on C: (Article 309531).
   2a. Get a command prompt and type the following, including quotes:
   cacls "C:\System Volume Information" /E /G username:F
   2b. (To undo these permissions later when finished, type the follwing)
   cacls "C:\System Volume Information" /E /R username
3. Move the offending folder, in my case C:\System Volume Information\_restore{2EDE8FBE-CD64-4AC6-BB82-21229910E44C}\RP140", to a temporary location
4. reboot
5. Right click My Computer, and select Properties.  This automatically starts SRService and changes its startup  from disabled to automatic
6. Click the System Restore tab
7. Select “Turn Off System Restore” and click apply.  Notice the _restore… folder disappears in the System Volume Information folder.  Warning: all restore points are deleted.
8. Go back and uncheck “Turn Off System Restore” then click apply.  Notice the _restore… folder appears in the System Volume Information folder (No, the previous restore points don’t  re-appear.)
9. SRService should no longer hog the CPU!

Regards,
Steve

 

by: Abdu_AllahPosted on 2004-10-06 at 07:56:29ID: 12238309

mnielson323 I have the same problem, so which one of the spyware in the accepted answer solve this problem?

Thanks.

 

by: mnielson323Posted on 2004-10-06 at 08:21:49ID: 12238642

Abdu Allah,

Unfortunately I don't recall how my problem was resolved.  I read all of the previous comments.  The last one got to be so detailed, I gave up on it.  However, the problem appears to have gone away (knock on wood).  I still have like 6 SVCHOST.EXE processes running, but their CPU usage is way low, if not 0%.  In the meantime, I do run Spybot1.3 Search & Destroy on a regular basis.  I couldn't tell you, tho, if that has fixed everything.  I have all of the latest updates applied - Windows XP SP2, NAV, and Lavasoft Ad-Aware6.0.  At this point, my response time isn't bad.  Sorry I couldn't be of more assistance.

Mike


 

by: Abdu_AllahPosted on 2004-10-06 at 11:14:57ID: 12240585

Sorry mnielson323, my English did not let me understand you well, Spybot1.3 is a name of spyware or what?

 

by: mnielson323Posted on 2004-10-06 at 11:25:51ID: 12240716

Yes....Spybot1.3 S&D is a great tool to find unwanted files/folders/registries in your system.  It is safe to download and install and use.  Check out this link:  http://www.safer-networking.org/en/index.html.

 

by: Abdu_AllahPosted on 2004-10-06 at 11:52:59ID: 12240993

Ok mnielson323, Thank you very much.

 

by: Abdu_AllahPosted on 2004-10-08 at 12:35:19ID: 12262241

mnielson323, Are you sure that Spybot1.3 S&D who has fixed this problem!
I used it but the problem is still exist!
I discovered that it is a common problem, and no one find solution for it,
Have a look here:
http://www.techsupportforum.com/showthread.php?s=fc4ba1018a5da354ba29359d844b1788&p=75968#post75968

http://www.winportal.com/chat_sin.asp?ObjectID=8675

http://forum.pcvsconsole.com/viewthread.php?tid=8191&page=3

 

by: Phuza123Posted on 2005-02-15 at 11:48:33ID: 13317325

I had the same problem with SVCHOST eating 99% of my CPU. The problem only occurred when I connected to my DSL connection at home and not when I was connected to the office LAN. I tried every damn solution I found on the net and was about to format and reinstall my XP Professional. As I was cleaning up I uninstalled TuneUp Utilities and the problem disappeared. It seems TuneUp had tried to optimise my computer for broadband access and was causing this issue.
Thanks for all the inputs guys and good luck to those still in dealing with the misery of SVCHOST

 

by: GetStartPosted on 2005-09-06 at 09:15:35ID: 14830212

need a solution !!!!

Please open the question...

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...