XP Windows / Automatic Updates SVCHOST.exe 100% CPU .. MS did something.


Recommended Posts

Regardless of EOL they still should fix it because there will still be companies holding on as long as they can as well as individuals and the least you can do is let them have whatever updates are available until there are no more.

 

After EOL they assume the risk and not MS..

:face palm:

Why? Unless you use IE or Office (the MU CPU usage bug makes it impossible to keep Office updated on older machines) I don't think that much could happen if your XP has at least the latest service pack installed. Adobe Flash, Reader and third party browsers update themselves separately so the surface attack area is already quite reduced.

Seen this in a recent XP SP3 VM that was not configured to use WSUS.

 

I installed the certificate revocation optional / recommended update and it seemed to sort itself out in my case.

 

I've seen Animalware service, Windows Security Essentials, McAfee Antivirus etc also cause this issue though during a botched definition update.

Seen this in a recent XP SP3 VM that was not configured to use WSUS.

 

I installed the certificate revocation optional / recommended update and it seemed to sort itself out in my case.

 

I've seen Animalware service, Windows Security Essentials, McAfee Antivirus etc also cause this issue though during a botched definition update.

 

This one? http://www.microsoft.com/en-us/download/details.aspx?id=39802

Well slip streaming is a great way to handle this. I guess the best way to avoid this problem and continue to use XP will be to slipstream all updates after XP SP-3 including the very last ones MS makes up until the cut off date.

After April 2014 no more XP updates except paid hot fixes for companies. So at the point if the slip stream is done right then every fresh install will have SP-3 and all the updates after. There will be no need run Windows or Microsoft update at all and should be disabled.

Just make sure to have as much protection as possible to mitigate attacks. Disable unnecessary services and if possible perform any registry tweaks that are for security purposes, disable file and print sharing if stand alone machine.

Also some programs like Nlite let you remove certain Windows components not needed that could also reduce the attack surface.

  • Like 2

I have struggled with this problem for a while. However, today, after trying almost every apparent solution suggested in various forums, and having given up and set Updates to OFF, and disabling the update service, I tried once more just to see what happened.

If anyone with this problem...  100% CPU on svchost.exe, (in my case, specifically relating to updates) uses Process Explorer, as I do, they should see the related process, Wuauclt.exe.

Instead of killing the svchost process, I decided to try killing the wuauclt process instead..   Aha....   it did not die, or should I say, it died only to be resurected immediately, and immediately the system started to download updates, with no more high CPU hogging..

I have no idea why this worked, but as nothing else has, I consider this may be a 'fix' of some sort...

Hi. Typically Wuauclt.exe. is what I see also. I am telling you this problem goes back years but it was also hit or miss for me because some machines had this behavior and others did not.

I forget though if it had to do with Windows Update or Microsoft Update. There is a difference and I always choose Microsoft Update as it gives you more updates than the standard Windows Update.

In the end like I said once there are no more updates it is best to slip stream them all into a CD with SP-3 and remove unnecessary components and every fresh install will be up to date so to speak :)

Think  Micro XP where Nlite and others can strip out things. Also don't forget to disable Auto Update.

  • 2 weeks later...

Once again It's a recent thing. Which is why I thought I was using bad media at first. When I would do a clean install I would check for updates via windows update and the bar would go across for maybe 10 / 15 seconds and then go to the next step. Wonder my surprise when one day 10 / 15 seconds turned into minutes with 100% usage on every new install.

I had the same problem.

 

end of last I install reinstall xp with service pack 3 in a dualboot system and it refused to even check for update saying could not find the page.

 

had to manually download windows updater and install and it just stayed at scanning for updates.

 

only way I got around it was install xp with service pack 2 and windows update worked. and installed service pack 3 and still worked and fully updated the system.

Could is possibly be something with the Microsoft Update website and/or whatever applet they force people to install before running the update scan?  Or I guess since the WU service phones home, and it might be getting a command to bust ass while doing the update scan.

 

My thought is that if this is something recent, then obviously it isn't a specific update to the core OS since the PCs we're talking about aren't up-to-date.

 

Regardless, this is something Microsoft really needs to fix.  It can't be that difficult and may not even require an software update or anything.

Hi to all. This problem is now very common. Absolutly every fix fails on multiple machines.

The only common demominator I can see is that its always lowly single core CPU's

Any fresh XP install, SP3 just immediatly goes 100% on the WU site.

I had success a couple of months ago with a Core2Duo, but since then have had many P4 and 1.6 Celeon boxes that fail.

I know it probably isn't CPU specific, but from an engineering point of view it's like the engine just cannot cope?

MSEssentials also causing this 100cpu in its updates on many PC's I'm seeing (low spec) as well.

Whats going on?

Use sysinternals procexp to check which service inside of service host is actually using the CPU, and then use procmon or windbg to figure out why its hogging CPU.

 

+1

It's so obvious to me what's going on, and someone else also mentioned it

 

It's a combination of scanning through a few hundred updates and refreshing the WU database at the same time

 

I bet that given enough time to complete it would go away on it's own since it's the first run of it, there's no need for a full rescan and DB update after that and should run normally

I'm not buying this.

Here is my real world experiment yesterday and today.

Dell Optiplex 320 lowly 1.6 Celeron, 1gb RAM

XP Pro SP3, 100%cpu on fresh build as soon as WU site visited

Left all night, still just scanning.

Tried all fixes, same.

Suspicious of my media maybe?

So, tried XP Home SP3, SAME fault.

As I type I am now looking at an installation of 7 Pro, it's at the WU site, CPU spiked for a mo, now its all perect, nicely doing the updates with a healthy CPU rate.

This is IMHO 100% MS Update site with XP.

Nick

Just did a brand new, fresh install of XP yesterday on an ancient E-Machine. One of the first things I ALWAYS do on a fresh install is disable auto update under both sections. In services and the automatic update icon in control panel.

 

No such issue on that machine yesterday, other than taking 6 hours, it felt like, to get them all.

 

Of course,

I ALWAYS disable automatic updates on EVERY computer of mine anyway. The ONLY thing I EVER allow to do anything automatically is my AV updates, when I actually use an AV, that is!!

 

Auto updates are WAY more trouble than they're worth, especially when 16 different things are starting up trying to do that at same time, IMO.

Why? Unless you use IE or Office (the MU CPU usage bug makes it impossible to keep Office updated on older machines) I don't think that much could happen if your XP has at least the latest service pack installed. Adobe Flash, Reader and third party browsers update themselves separately so the surface attack area is already quite reduced.

 

Sorry, but that's just a "stick my head in the sand and pretend it doesn't exists" approach to safety.

 

What happens when the next Blaster or Nachi comes along that makes use of a vulnerability in Windows to infect your machine without user intervention.  The Windows firewall is not infallible you know, especially the antiquated one in XP. I've seen malware able to disable it in the past. It can take AV vendors several days, if not weeks to push out definition updates for new viruses as quite often it depends on sample submissions.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If its the devs fault you would think Unreal would help M$ take full advantage of Unreal and work with them to fix the performance issues. Otherwise they are catching unwarranted bad press.
    • Thanks for the advice guys, I'll give my current GPU a clean and then run the benchmarks to see how similar it is. Hopefully a bit of a clean-out will help it last a bit longer.
    • Pretty sure those will still be in this game. The series' well-explored psychosis themes will return as well.
    • "performance issues? what performance issues?!"
    • Microsoft making much needed change to Windows 11, 10 Patch Tuesday security updates by Sayan Sen Recently, Microsoft delivered its latest Defender patches for Windows 11 ISOs. These definitions are released from time to time alongside the general security updates available during Patch Tuesday. Speaking of Defender, the company has now announced another important change that affects how security updates are delivered to enterprise devices running Windows. According to a recent announcement, Microsoft Defender for Endpoint's endpoint detection and response (EDR) updates will no longer be bundled with the monthly Windows security updates or Patch Tuesdays. Instead the company is shifting delivery of these updates to Microsoft Update, bringing EDR servicing in line with several other Microsoft Defender components. If you recall, Microsoft last year moved PowerShell updates to Microsoft Update (MU) as well since it provides automatic updates for Microsoft products and services. Thus the move is intended to allow Microsoft to deliver EDR improvements and security enhancements independently of the OS's regular monthly update cycle; this should enable faster deployment of protection updates without requiring organizations to wait for the next Patch release. For those unfamiliar, Microsoft Defender for Endpoint's EDR capabilities are designed to help organizations detect, investigate, and respond to advanced threats across managed devices. Keeping these components updated is critical for maintaining protection against evolving attack techniques. The rollout has already began for Windows 10 devices in late May 2026 (last month) and Microsoft says it will gradually expand support to Windows 11 and the remaining supported Windows versions over the coming months. The company expects deployment across Windows 10 and Windows 11 to be completed by fall 2026 or around Q3 of this year. Once the transition is complete, EDR updates will be delivered through Microsoft Update using KB5005292, provided the required prerequisite updates have already been installed. Microsoft is also introducing a new Defender Update Service as part of the change. Following installation of the first update, devices will automatically create a new directory located at %ProgramData%\Microsoft\Microsoft Defender\Defender Update. Microsoft notes that restarts may occasionally be necessary in case of "rare" failure scenarios. For most organizations, the tech giant says no action will be required as long as Microsoft Update is already permitted within their update management strategy. Admins who rely on manually deployed update packages, however, will need to adjust their processes to ensure the new Defender update package is included. Microsoft also recommends reviewing internal documentation and notifying helpdesk and security operations teams about the updated delivery mechanism to avoid confusion during the transition. As a prerequisite, the tech giant notes that systems must be running Sense version 10.8798.25857.1000 or later and have one of the following Windows updates (or later) installed: Win11 24H2 KB5062660 (2025-07 Cumulative Update Preview) Win11 23H2 KB5062663 (2025-07 Cumulative Update Preview) Win11 22H2 KB5062663 (2025-07 Cumulative Update Preview) Win10 22H2 KB5062649 (2025-07 Cumulative Update Preview) Win10 1809 KB5063877 (2025-08 Cumulative Update) Server 2019 KB5063877 (2025-08 Cumulative Update) Server 2022 KB5063880 (2025-08 Cumulative Update) Server 2025 KB5063878 (2025-08 Cumulative Update) As always, organizations should verify that their update policies align with the new servicing approach before the broader rollout reaches all supported Windows platforms later this year. In case of major problems, the EDR update can be rolled back to the inbox version stored in %ProgramFiles%\\Windows Defender Advanced Threat Protection (ATP) using: MpCmdRun.exe -RevertMde -Product Edr -ToVersion Inbox For those who have access to the Microsoft 365 Admin Center portal, you can view the message here under ID MC1381119.
  • Recent Achievements

    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
    • Dedicated
      Conjor earned a badge
      Dedicated
    • Week One Done
      Windows Guy earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      493
    2. 2
      PsYcHoKiLLa
      248
    3. 3
      Steven P.
      73
    4. 4
      +Edouard
      69
    5. 5
      neufuse
      68
  • Tell a friend

    Love Neowin? Tell a friend!