Sony Vaio with XP Home on AMD4 1Ghz system freezes with svchost.exe using 100% CPU at various times including whenever the internet connection program opens the modem port. Suggestions?


Additional, perhaps relevant history- The system initially began freezing after downloading MS critical updates. After several hard reboots, the system began continuously rebooting and had to be restored with the recovery disks including reinstalling the OS.

After web connection and download of updated virus protection files from Trend Micro for PCCillin 2000, a scan detected MS_Blast.a, MS_Blast.e, and Nachi.a viruses?!? I downloaded the security patches and MSBlast repair and the viruses (apparently) have been removed/repaired. However, the svchost.exe using 100% and freezing system problem remains.

Thanks.

Dani AI

Generated

Short diagnosis and priorities — a svchost.exe process running at 100% on XP is usually either (a) a legitimate Windows service that’s busy (Windows Update/automatic-update activity, RPC/DCOM activity), or (b) a service host that’s been abused by a worm or injected DLL (Blaster/Welchia variants famously exploited an RPC/DCOM vulnerability). Because the system was restored from recovery media and then showed MSBlast/Nachi detections, treat the machine as unpatched and potentially still compromised; don’t reconnect to the Internet until you can apply the security fixes. (learn.microsoft.com)

Quick, repeatable diagnostics to identify the offending svchost instance:

  • From a working admin command prompt map PIDs to services:

    tasklist /svc /fi "imagename eq svchost.exe"
    netstat -ano
    • Use Process Explorer to hover or open the svchost properties -> Services/DLLs tab to see the exact service names and DLLs loaded. That tells whether the heavy CPU belongs to a known service (BITS, wuauserv, RPCSS) or something abnormal. For live network inspection use TCPView or netstat to see remote endpoints. (learn.microsoft.com)

Cleaning and recovery workflow (offline-first):

  • If Windows will not stay usable, build bootable rescue media on a clean PC (Microsoft Defender Offline or a vendor rescue ISO such as ESET/Dr.Web/Kaspersky) and run full offline scans/repairs before attaching the machine to the Internet. After removal, install the MS03-026/MS03-039/824146 fixes (and Service Pack updates) before reconnecting; Microsoft and major AV vendors published Blaster/Welchia removal guidance/tools. (learn.microsoft.com)

Practical cautions and next steps: ’s suggestion to scan with anti-spyware and gather a HijackThis log was sensible — but do not use “fix all” blindly. If XP is still SP1 on that recovery image, some modern one-line fixes (for example netsh winsock reset) require SP2; follow the XP-specific repair steps in Microsoft guidance and run sfc /scannow where possible to repair system files. If multiple rootkit/remnant artifacts remain, a clean reinstall from patched media is the safest option. ()

Recommended Answers

All 8 Replies

You may still have some remnants of the worms left behind.
Download & instal Adaware from http://majorgeeks.com/download.php?det=506
& update it B4 scanning.
In settings under 'scanning,' have it set to
'scan within archives,'
'scan active processes,'
'scan registry,'
'deepscan registry'
'scan my IE Favourites for banned URL's,'
'scan my host's file.'
Also in tweaks under 'cleaning engine' set it to 'Automatically try to unregister objects prior to deletion.'
Remove what it finds by placing a check in the box to the left of the object.
Download & instal Spybot S&D from Update it B4 scanning.
After the scan is complete, have spybot fix everything marked RED.
On the page that first opens when you start Spybot there is an option to immunise, you should do this. In the immunise section there is also a link to download Spywareblaster. Download that & you can keep it updated by selecting the same link that you use to download it.
Download HijackThis from & unzip it into it's own, permanent folder, not a temporary one. Start HJT & press the scan button. When the scan is finished the scan button will change to save. Save the log to a text file & paste it into the body of your post. DO NOT FIX ANYTHING YET.

Member Avatar for Member #2466

Sometimes, Spybot won't grab everything in a worm. For those instances, go to symantecs website and download the patches for the netsky.d, welchia, and blaster worm. All of those worms could be causing your problem. Apply the patches, just in case.

In order to download anything, I have to download on another system and burn a cd because I can't log on with the affected system. Is there a way to download Adaware and update before transferring to the affected system?

Thanks for the quick reply. I probably won't be able to try your recommendations until Sunday and I'll report back.

You might be able to do it after updating by installing first, update it, copy the exe to disk along with the whole folder that the exe created. Install the exe on the affected machine then copy the folder over. The current reference file is 271, so when your done just check that it is at least that one.

I have been unable to post with either an attachment or the full Hijack this log.

Logfile of HijackThis v1.97.7
Scan saved at 10:13:24 AM, on 3/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\System32\ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\Atiptaxx.exe
C:\WINDOWS\System32\WScript.exe

R0 - HKCU\Software\Microsoft\Internet Explorer
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.sony.com/vaiopeople[/url]
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [PaperPort 8.0 SE Registration Reminder] "C:\Program Files\Scansoft\PaperPort\WebEreg\NAVBrowser.exe" -r "C:\Program Files\Scansoft\PaperPort\WebEreg\navLoad.ini"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Real-time Monitor.lnk = ?
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - [url]

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Apoint\Apoint.exe

C:\WINDOWS\System32\Atiptaxx.exe

C:\WINDOWS\System32\WScript.exe

C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe

C:\Program Files\Scansoft\PaperPort\pptd40nt.exe

C:\Program Files\Apoint\Apntex.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\System32\ctfmon.exe

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.