| View previous topic :: View next topic |
| Author |
Message |
Conjurer
Sergeant

 Joined: Dec 23, 2003 Posts: 90
|
Posted: Thu Jun 26, 2008 2:19 am Post subject: Rootkit problem - high memory use by svchost.exe? |
|
|
I have recently noticed an issue with my sound degrading on me when listening to Itunes and other players, steaming music, and even with the Windows system TA DA at start up and shut down.
When I look in the Task Manager I am seeing a lot of high CPU usage and the spikes correspond with when the sound garbles on me.
I haven't pinned it down to one specific thing, but I did see the svchost.exe pulling memory usage of 29,564K and the Peak Mem Usage was 144,276K. Is that normal. Could there be a trojan here?
How do I isolate the problem from here?
My system is:
Win XP Pro Version 2002 Service Pack 2
CPU: Pentium 4 CPU 2.40GHz
1.43GB of RAM
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1838 Location: Japan
|
Posted: Thu Jun 26, 2008 3:34 am Post subject: |
|
|
What process uses high CPU?
|
|
| Back to top |
|
 |
Conjurer
Sergeant

 Joined: Dec 23, 2003 Posts: 90
|
Posted: Thu Jun 26, 2008 3:42 am Post subject: high usage |
|
|
It bounces around
right now it is downloading a Microsoft update for SP3 and running between 38 and 75%.
firefox is around 29%
Those are the big ones currently. But it gives me CPU use of 100%
And 36 processes running.
|
|
| Back to top |
|
 |
Conjurer
Sergeant

 Joined: Dec 23, 2003 Posts: 90
|
Posted: Thu Jun 26, 2008 3:43 am Post subject: |
|
|
Svchost.exe just jumped to 99% right after I posted this message.
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1838 Location: Japan
|
|
| Back to top |
|
 |
Conjurer
Sergeant

 Joined: Dec 23, 2003 Posts: 90
|
Posted: Thu Jun 26, 2008 4:37 am Post subject: |
|
|
This looks weird. I rebooted. Now I have a process named "System" it is using about 15% of the CPU.
In process explorer there is no information like Description, company name, etc. It just shows "System" and CPU running around 12-13%. And PID is 4
Is that legitimate?
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1838 Location: Japan
|
Posted: Thu Jun 26, 2008 4:53 am Post subject: |
|
|
When I look at the Process Explorer, I can see 'System' at the top of the hierarchy, not as a process itself. It does not use any CPU by itself. Yours does?
|
|
| Back to top |
|
 |
Conjurer
Sergeant

 Joined: Dec 23, 2003 Posts: 90
|
Posted: Thu Jun 26, 2008 5:00 am Post subject: |
|
|
Well it was, but I was playing some stream through Itunes. When I turn the music off it drops down to none.
So that doesn't seem to be the issue.
|
|
| Back to top |
|
 |
|
|