CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Rootkit problem - high memory use by svchost.exe?

 
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Conjurer

Sergeant
Sergeant


Joined: Dec 23, 2003
Posts: 90


PostPosted: Thu Jun 26, 2008 2:19 am    Post subject: Rootkit problem - high memory use by svchost.exe?
Reply with quote

I have recently noticed an issue with my sound degrading on me when listening to Itunes and other players, steaming music, and even with the Windows system TA DA at start up and shut down.

When I look in the Task Manager I am seeing a lot of high CPU usage and the spikes correspond with when the sound garbles on me.

I haven't pinned it down to one specific thing, but I did see the svchost.exe pulling memory usage of 29,564K and the Peak Mem Usage was 144,276K. Is that normal. Could there be a trojan here?

How do I isolate the problem from here?


My system is:
Win XP Pro Version 2002 Service Pack 2
CPU: Pentium 4 CPU 2.40GHz
1.43GB of RAM

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1838
Location: Japan
Premium

PostPosted: Thu Jun 26, 2008 3:34 am    Post subject:
Reply with quote

What process uses high CPU?

Back to top
View users profile Send private message Visit posters website
Conjurer

Sergeant
Sergeant


Joined: Dec 23, 2003
Posts: 90


PostPosted: Thu Jun 26, 2008 3:42 am    Post subject: high usage
Reply with quote

It bounces around
right now it is downloading a Microsoft update for SP3 and running between 38 and 75%.

firefox is around 29%

Those are the big ones currently. But it gives me CPU use of 100%

And 36 processes running.

Back to top
View users profile Send private message Visit posters website
Conjurer

Sergeant
Sergeant


Joined: Dec 23, 2003
Posts: 90


PostPosted: Thu Jun 26, 2008 3:43 am    Post subject:
Reply with quote

Svchost.exe just jumped to 99% right after I posted this message.

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1838
Location: Japan
Premium

PostPosted: Thu Jun 26, 2008 4:12 am    Post subject:
Reply with quote

Try to find out what's using svchost so heavily; Process Explorer can do that; download from http://technet.microsoft.com/en-us/sysinternals/default.aspx

Back to top
View users profile Send private message Visit posters website
Conjurer

Sergeant
Sergeant


Joined: Dec 23, 2003
Posts: 90


PostPosted: Thu Jun 26, 2008 4:37 am    Post subject:
Reply with quote

This looks weird. I rebooted. Now I have a process named "System" it is using about 15% of the CPU.

In process explorer there is no information like Description, company name, etc. It just shows "System" and CPU running around 12-13%. And PID is 4

Is that legitimate?

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1838
Location: Japan
Premium

PostPosted: Thu Jun 26, 2008 4:53 am    Post subject:
Reply with quote

When I look at the Process Explorer, I can see 'System' at the top of the hierarchy, not as a process itself. It does not use any CPU by itself. Yours does?

Back to top
View users profile Send private message Visit posters website
Conjurer

Sergeant
Sergeant


Joined: Dec 23, 2003
Posts: 90


PostPosted: Thu Jun 26, 2008 5:00 am    Post subject:
Reply with quote

Well it was, but I was playing some stream through Itunes. When I turn the music off it drops down to none.

So that doesn't seem to be the issue.

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can report post to moderators in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer