!!svchost!!

compfusion

New Member
Someone told me its a virus, someone said evryone has it, what is it and how do i get rid of it if its bad?

Also, whats system idle process cuz thats taking up 70% cpu usage or is that just the leftover usage?'

thx
 

PC eye

banned
svchost is a variation where viruses will take on the name of essential system files while being found either in the system32 folder or in other locations. ghostfacesuk has touched upon one variation at the link there. A few other descriptions of the actual system process as well as different trojans can be seen at the links here as well.
http://www.neuber.com/taskmanager/process/svchost.exe.html
http://www.processlibrary.com/directory/files/svchost/index.php
http://windowsxp.mvps.org/svchost.htm

The system idle process itself is a function included in Windows to give the cpu a task while no programs/games are running. Normally that should be seen at 99% or 100% with nothing running in the background besides the expected background services included with Windows. At 70% some software you have currently installed or some virus/spyware infection would be the only reason to see the lower percentage there with that running unnoticed in the background. The normal svchost.exe file is part of Windows itself.
 

compfusion

New Member
the site says multiple sometimes go on at a time but i have 7 and one is using a lot of memory, i ended it, these just started coming and slowing down my comp like 2 days ago how do i kill them before they take overrr!!
 

PC eye

banned
If this is something only now being seen in the last few days the first step would be to run a few virus/spyware scans on the system there. One free online scan can be done at http://security.symantec.com/sscv6/...d=22&pkj=NCGSCKMRKRFPECDMEYI&setjsax=1&bhcp=1

The high percentage seen in the task manager of cpu usage by the system idle process is expected to be seen. With too many svchost listings appearing and seeing a sudden slowdown it certainly won't hurt to use the tools available to see if you did catch a bug. Ewido now owned by Grisoft has a free trojan scanner at http://www.ewido.net/en/download/

Do you have any antivrus, spyware, adware programs already? If not a few links can be added here. Grisoft's AVG 7.5 and Anti-Spyware Free both can be found at http://free.grisoft.com/doc/5390/lng/us/tpl/v5#avg-anti-spyware-free
Avira AntiVir is available at http://www.free-av.com/ and another free version of the antivirus program Avast is available at http://www.avast.com/eng/download-avast-home.html Despite how good any of these are at spotting things they seem unable to remove them. One tool good for temp use only is Trend Micro's PC-cillin. You will need that in order to run House Call. http://housecall.trendmicro.com/
 

ssemo

New Member
Someone told me its a virus, someone said evryone has it, what is it and how do i get rid of it if its bad?

svchost.exe is a normal process.but it could be use by a virus.check out if you have a svchost.exe except c:\windows\system32\svchost.exe. if so,del them in safemode. and change the regitry to stop it from running when system boots up.check here:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Also, whats system idle process cuz thats taking up 70% cpu usage or is that just the leftover usage?'

I think it normal.:)
 

PC eye

banned
svchost.exe is a normal process.but it could be use by a virus.check out if you have a svchost.exe except c:\windows\system32\svchost.exe. if so,del them in safemode. and change the regitry to stop it from running when system boots up.check here:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run


I think it normal.:)

When looking over the svchost items seen in the task manager here 5 will be seen in the running processes. With nothing but XP background services running the system idle process is always seen at 99% here. The two extra svchost items being seen and the lower 70% suggests "something else" is also running in the background like a virus or trojan of some type or maybe even a bad install of some program.
 
Top