the svchost.exe is an exe that is used by many things and you may want to back track your steps to determine the last app, SP or whatever you've installed. That is usually the culprit.
regards,
Main Topics
Browse All TopicsMy computer really slows down sometimes and when I look at what's running in Windows Task Manager, I see that svchost.exe is eating up most of my CPU. I've searched a little on in on the Internet but I haven't found anything that would point me to a safe solution. I also looked at the detail behind it using Process Explorer, but couldn't pin point exactly what was causing all that CPU drainage.
Could you help?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi Lucynka,
scvhost with high CPU usage is normally caused by spyware. Try installing and running Spybot and Ad-aware:
SpyBot-S&D : http://www.webattack.com/d
Ad-aware : http://www.webattack.com/d
Also run Hijackthis and post the log here
HijackThis : http://www.webattack.com/d
n Windows XP, you can get a list of running services by going to Start | Run | type "CMD" | click OK. Type "tasklist /svc" (sans quotes) and then press Enter. Now you will have a list of every DLL running under each svchost.exe instance.
See this article from MS for more info:
http://support.microsoft.c
A Description of Svchost.exe in Windows XP
scvhost at a high lvl could be a virus, btu this is highly unlikely unless it was running as a service. here is a good list of XP services to wade through for information: http://www.theeldergeek.co
Furthermore, 2 common services which take up alot of resources are those of antiviruses (the can hit the 50% mark plus!) and also the Microsoft Indexing Service. When a re-index is taking place, this can make your CPU redline.
The best ways to resolve the last 2 I mentioned is:
1) Put more memory in the XP machine. Best eprformance is experienced at 1GB and higher, although 512MB should be sufficient
2) Turn off all of the services which you dont need (see list above I've referred)
Good luck,
Pgx();
Try downlooading Process Explorer from Sysinternals...
http://www.sysinternals.co
you can see which Dll's are loading with teh svchost in question, teh path t loads from etc. Under View, check Show Lower pane, and also click teh button to show .dll's. You can get alot more info than just basic services this way.
>>>>Are you fully current and protected with AV and anti-spyware protection?
yes
>>>>Put more memory in the XP machine
I love memory! And so I have 1 GB.
>>>>>SpyBot-S&D and Ad-aware
I have both and run them once a week or so. The trouble with SpyBot is that it always comes up with the same problems - most often it's Avenue A. Inc and DoubleClick. I keep removing them and they come right back. Any ideas how to remove them permanently??
I've ran HijackThis and am ready to post the results. Should I just paste them here? Or use the analyzer first? I forgot where I can do that...
I'm also running a free scan from this website and will post the results here.
http://housecall65.trendmi
Here are the contents of the HiJackths output:
Logfile of HijackThis v1.99.1
Scan saved at 1:40:14 PM, on 8/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\ZoneLa
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\NMSSvc
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Common Files\Lanovation\PrismXL\P
C:\WINDOWS\system32\fxssvc
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_06\bin
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
C:\WINDOWS\system32\ctfmon
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\MICROS~3\OFFIC
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
C:\DOCUME~1\ADMINI~1\LOCAL
R1 - HKLM\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
N3 - Netscape 7: user_pref("browser.search.
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-5
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OUTLOOK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {511073AD-BE56-4D43-AE68-9
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-6
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRN
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\P
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLa
"Any ideas how to remove them permanently??"
Install and run this 'hosts' file manager program.
http://www.mvps.org/winhel
If you donate a couple of bucks he will email you notification of every update.
Great applications - I've been using it for over a year now.
Spybot has a function to use a custom HOSTS file without the need to pay for updates. . Under Tools>Hosts>Add Spybot hosts File. (may be off on the exact verbage a tad...) . May be worth extra protection in case the MVPS hosts misses anything....Never have too much protection.
As for the hosts file there at the site, Open the .zip file and copy the the contents to your desktop. Launch MVPS.bat, and it should do all the work for you.
As for the logfile posted... I didnt see a whole lot that needs to be removed. Nothing malicious anyway..Maybe some house cleaning to optimize the performance a bit. Haev you had a chance to load proces explorer, and then look at the SVCHOST.EXE to see what is loading with it?
>>>Launch MVPS.bat, and it should do all the work for you.
When I double click on it, a black screen appears for a moment and then disappears. That's all. Should there be something else that happens?
Thanks for the tip on the SpyBot option.
>>>house cleaning
Another program I use regularly is CCleaner. I'm surprised I still need house cleaning... What does it miss?
>>>Under Tools>Hosts>Add Spybot hosts File
I see an option "Lock Hosts file read-only as protection against hijackers" Is that what you mean??
Go to Tools (at the top) click advanced. Now, under the left side bar, click tools, and put a check next to everything except optout. That displays these advanced tools. Click on Hosts file, and at the tiop, it says "Add Hosts file", or similar...(again running off memory here...). That will appened to teh hosts file. And before doing this, you should see a large list of entries in the hosts file in the main screen on the right. Those are from MVPS.bat. The bat file is dos, and just does it's thing and disappears. But if you dont see all the 127.0.0.1 entries before adding Spybot's hosts file, then we will need to do it manually.
We still haevnt addressed the Svchost.exe eating the cpu yet, have we? Did I fall asleep recently? It happens ....
Sorry - I've been out of the loop.
The MVPS.bat file works in about 2 seconds and then closes.
Check to make sure:
Location of hosts file:
Windows XP = C:\WINDOWS\SYSTEM32\DRIVER
Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\
Win 98/ME = C:\WINDOWS
Open the hosts file with Notepad.
The first two lines should look like this:
# This MVPS HOSTS file is a free download from: #
# http://www.mvps.org/winhel
The file size should be 493 KB, dated 27 Aug.
>>>>But if you dont see all the 127.0.0.1 entries before adding Spybot's hosts file, then we will need to do it manually.
Got it! It has lots of 127.0.0.1 entries. Do I have to do anything else with it?
>>The first two lines should look like this:
it looks like you've described..
>>>We still haevnt addressed the Svchost.exe eating the cpu yet, have we?
No, I guess we haven't directly. We've been making sure that I can detect spyware if that's the reason for it... And I still have to learn to use the Process Explorer to get some more info about it. I will do what was suggested above.
Lucynka,
Now that you've got your Hosts file in place, let take a look at what starts up when you log into your computer.
From the Start button, select Run and then type in msconfig (hit the enter key).
When the Utility Screen opens go to the last tab and it will show you all of the processes that start up automatically.
Review those to make sure they are what you want and 'disable' any you don't want.
Just a note...Along with Googling for those startup items...Watch the paths that they startup in. That helps you know what they are. Most of the driver helpers like igfxtray, can be removed from starting up with Windows...
Like Your Antivirus software also, make sure those dont get removed from startup etc..
Business Accounts
Answer for Membership
by: younghvPosted on 2006-08-30 at 08:10:12ID: 17420988
Hi Lucynka,
Are you fully current and protected with AV and anti-spyware protection?
If all your security apps are updated, you may want to boot to Safe Mode (tap F8 during boot up) and do a full system scan - while in Safe Mode.
Good Luck,
Vic