Solved

svchiost.exe using all my systems memory please help

Posted on 2016-11-03
26
39 Views
Last Modified: 2016-12-01
see screenshot
svchost.png
0
Comment
Question by:frankbustos
  • 11
  • 5
  • 5
  • +2
26 Comments
 
LVL 28

Expert Comment

by:omgang
ID: 41872538
Right click the svchost.exe process and choose Go To Service(s) from the context menu.  This will show you the running services associated with that process.  Hopefully you can identify the culprit.
OM Gang
0
 
LVL 92

Assisted Solution

by:John Hurst
John Hurst earned 125 total points (awarded by participants)
ID: 41872588
SHCHOST controls many things. A very common cause of it consuming resources is malware.

Get a good commercial AV package, do a full scan and then follow that with Malwarebytes.
0
 
LVL 20

Expert Comment

by:CompProbSolv
ID: 41872797
While it is generally a good idea to do the scanning that John recommended (and I wouldn't discourage it at all here), I'd want to identify exactly which process is using the memory (as suggested by omgang).

You can install Process Explorer from sysinternals to get more details about the individual processes.
0
 
LVL 48

Expert Comment

by:dbrunton
ID: 41873408
I'll second Process Explorer as suggested by CompProbSolv.

Download from here https://technet.microsoft.com/en-us/sysinternals/processexplorer.aspx

It may very well be Malware as suggested by John Hurst (and that would be my first thought) but you can use Process Explorer to identify the file or dll that is causing the problem quickly this way.
0
 

Author Comment

by:frankbustos
ID: 41879055
ok I downloaded process explorer and here is the results, please look at the attachedment.
0
 

Author Comment

by:frankbustos
ID: 41879057
sorry here is the screenshot
process-explorer.png
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41879068
The screen shot was not very illuminating. Can you sort on CPU (not memory) and that will help you see what is using the memory.
0
 

Author Comment

by:frankbustos
ID: 41879077
how about now look at this one
process1.png
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41879102
It seems to point to a virus on your machine (virus scanning running) and then an SVCHOST process I do not see an identifier for.

So back to an earlier post, the cause here appears to be malware.
0
 

Author Comment

by:frankbustos
ID: 41879112
ok i'll scan again and let you know the results.
0
 

Author Comment

by:frankbustos
ID: 41879154
it came back clean from malware.
malware.png
0
 
LVL 92

Expert Comment

by:John Hurst
ID: 41879171
You may have some legacy software running

Try running System File Checker. SFC /SCANNOW from an admin command prompt.

More likely (given the above), you are going to need to back up and re-install Windows
0
 

Author Comment

by:frankbustos
ID: 41879175
I just did that a few days ago. I had windows 7 -32bit and I changed to 64bit. it's a clean system as it is.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 92

Expert Comment

by:John Hurst
ID: 41879176
Wow - very strange.

Try a new, test, Windows User Profile (Account). Log into the new Windows Account and test.
0
 
LVL 20

Expert Comment

by:CompProbSolv
ID: 41879534
In first and third screenshots, SVCHOST was using 1.1-1.5G of RAM.  In the second one it is about a tenth of that.

Do you know what changed?
0
 

Author Comment

by:frankbustos
ID: 41882578
so I ended up formatting the hard drive and re-installing everything then after I installed office 2010 I noticed that svchost took over memory.
0
 
LVL 48

Expert Comment

by:dbrunton
ID: 41882607
So, the problem still exists?

If so then try the Microsoft Malicious Removal Tool https://www.microsoft.com/en-nz/download/malicious-software-removal-tool-details.aspx and see what it finds on your system.
0
 

Author Comment

by:frankbustos
ID: 41882614
yes I did a scan with malware bytes and found Trojan.dropper.fav and pup.optional.downloadadmin I'm doing a scan now with hitman pro and then i'll try Microsoft and keep you posted.
0
 
LVL 20

Expert Comment

by:CompProbSolv
ID: 41882620
Before doing a wipe and reinstall (or major attempts at resolving problems), I typically make a complete copy of the original drive.  It can be done with software or with fairly inexpensive (<$40) hardware tools.  That way I can always get back to where I started if needed.

I would also disconnect it from the internet and reboot.  You may be seeing some effects of it trying to do updates.

In addition to John's scanning suggestion, I'd use TDSSKiller:
https://support.kaspersky.com/viruses/disinfection/5350#block1
Click on "How to disinfect..." then "tdsskiller.exe".
It just looks for rootkits and is very quick to run.

I'd also boot in Safe Mode and see if the issue persists.  I've seen things of this sort that were resolved by disabling the WMI service.
0
 

Author Comment

by:frankbustos
ID: 41882688
I'm doing scans in safemode now, it seems to be working normal in safemode
0
 

Author Comment

by:frankbustos
ID: 41882711
Ok, I did scans in safemode and it's free of malware . I log back into normal mode and I see two svchost.exe starts piking up taking all of memory resources. ARGH
0
 
LVL 48

Expert Comment

by:dbrunton
ID: 41882726
>>  it seems to be working normal in safemode

Something in your Startup is getting loaded then.  Read http://answers.microsoft.com/en-us/windows/forum/all/how-to-get-startup-folder-in-start-all-programs/d3f5486a-16c0-4e69-8446-c50dd35163f1 and the post by Steve Winograd on the location of Startup folders and see what is there.  This isn't necessarily all of the locations where Startup occurs but might help.
0
 

Accepted Solution

by:
frankbustos earned 125 total points (awarded by participants)
ID: 41882731
ok, so I narrowed it down. I went to services and I stopped services one by one. and everytime I stopped the service Windows Updates the memory goes down to normal and as soon as I start it, it goes back to using all memory. So it's a problem with windows updates because it just keeps saying checking for updates but never completes. How do I get updates using another method?
0
 
LVL 48

Assisted Solution

by:dbrunton
dbrunton earned 125 total points (awarded by participants)
ID: 41882749
Have you got SP 1 installed and then the Rollup pack?

This https://support.microsoft.com/en-us/kb/3172605 talks about the Rollup pack and the SP 1 and gives you links to both.
0
 
LVL 20

Assisted Solution

by:CompProbSolv
CompProbSolv earned 125 total points (awarded by participants)
ID: 41882753
There are numerous posts on EE about this.  The solution that usually works is to install some key updates and then use offline WSUS to download and install the other updates.

If you don't get a response with the detail or can't find them here, drop a note and I'll look.
0
 
LVL 48

Expert Comment

by:dbrunton
ID: 41908415
frankbustos for identifying the problem, Update process hogging memory.
John Hurst for suggesting malware on machine.  Some malware was found.
dbrunton for suggestion Service Pack and Rollup pack to be installed.  Unknown if this was done.
CompProbSolv for asking for feedback so he could suggest other links to solve Windows Update problems.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DIal UP Interface 3 30
Flashplayer.hta Download 1 29
Entity Framework 7 31
Remnants of old Homegroup persist 8 14
I recently purchased an HP EliteBook 2540p notebook/laptop. It has two video ports on it – VGA and DisplayPort. HP offers an optional docking station for the 2540p that also has both a VGA port and a DisplayPort. There are numerous online reports do…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now