100% Disk Activity : Svchost - NTFS Volume Log File


Recommended Posts

Could anybody help he out to find the issue here please.

 

Description:
r0SKPzd.png

Disk Activity : 100 % for hours

From Perfmon:
Highest Disk Activity by svchost.exe on NTFS Volume Log file 
Im guessing its indexing & Stopped Windows search service, but No immediate change in Disk Activity.


Any thoughts whats happening here or a possible fix please?

Let's start by checking the Health of that 1TB 5400 RPM Drive

 

http://crystalmark.info/download/index-e.html

 

Download the Portable Zip, and then unzip it and run it. 

 

Let us know what the "Health Status is" ... If it says caution, scroll down and tell us which ones have yellow circles.

Type: HDD

Health Status is Good.

 

I started stopping services from task manager, under svchost one by one to to find if i could find the offending service.

As expected on stopping one of the services the disk usage came back to normal, unfortunately in the joy i missed the service name.. 

Some windows service was causing non stop writes..

 

Disk activity has been 100% for a few days, thought indexing was going on and ignored it..

Pretty sure windows used up a considerable amount of  the HDD rewrites , reducing HDD life..

 

Issue solved. Waiting for it to reoccur to find the service name.

 

Thanks @Eric & @+warwagon

  On 18/03/2017 at 13:54, Eric said:

Anything in the event log? What kind of drive is it, SSD or standard?

Expand  

Not sure how to do an Event log analysis..

  On 18/03/2017 at 16:16, rezurect said:

Type: HDD

Health Status is Good.

 

I started stopping services from task manager, under svchost one by one to to find if i could find the offending service.

As expected on stopping one of the services the disk usage came back to normal, unfortunately in the joy i missed the service name.. 

Some windows service was causing non stop writes..

 

Disk activity has been 100% for a few days, thought indexing was going on and ignored it..

Pretty sure windows used up a considerable amount of  the HDD rewrites , reducing HDD life..

 

Issue solved. Waiting for it to reoccur to find the service name.

 

Thanks @Eric & @+warwagon

Not sure how to do an Event log analysis..

Expand  
 
 

Judging by the drive model number it's a regular spinning hard drive and not an SSD, so it didn't really use up any HDD rewrites as that's not an issue with hard drives as it is with an SSD.

 

So which service did you kill which stopped it? Typically the "Windows update service" causes the highest CPU usage with Svchost

 

If it turns out to be the case you may want to clear the c:\windows\softwaredistribution folder out. But you'll have to stop the windows update service first.

  On 18/03/2017 at 16:21, warwagon said:

Judging by the drive model number it's a regular spinning hard drive and not an SSD, so it didn't really use up any HDD rewrites as that's not an issue with hard drives as it is with an SSD.

 

So which service did you kill which stopped it? Typically the "Windows update service" causes the highest CPU usage with SVChost.

Expand  

Kind of missed the service name in joy of seeing Disk activity drop to normal..

CPU usage was normal all the while

 

Will post back if it occurs again, and i get the service name

  On 18/03/2017 at 14:29, warwagon said:

Let's start by checking the Health of that 1TB 5400 RPM Drive

 

http://crystalmark.info/download/index-e.html

 

Download the Portable Zip, and then unzip it and run it. 

 

Let us know what the "Health Status is" ... If it says caution, scroll down and tell us which ones have yellow circles.

Expand  

UNrelated:

 

I tried Crystal mark on my External Seagate HDD

Status : Caution

 

2XEv6I0.png

 

Drive failure coming up?

  On 18/03/2017 at 16:29, rezurect said:

UNrelated:

 

I tried Crystal mark on my External Seagate HDD

Status : Caution

 

2XEv6I0.png

 

 

Expand  
 

That means that there is currently one or more bad sectors on that drive.

I had this happening with Windows Defender when downloading a lot of large files.  It would CONSTANTLY be scanning those files.  Killed a hard drive before I took time to figure it out.  It was on a media server that I'm not on a lot.  I could disable Defender, but it would be same issue when it started back on after restart, so I permanently disabled it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • The viewing figures in season 2 plummeted after 1 of the main characters died in season 2 episode 1. I think hbo is regretting listening to him so they got rid of him.
    • Google Workspace now lets you use custom AI Gems directly in Docs, Gmail, and more by Paul Hill Google Workspace users can now access Gems from the side panel of Google Docs, Slides, Sheets, Drive, and Gmail. Previously, Gems could only be accessed from the Gemini app directly. For anyone not familiar with Gems, they’re a more advanced feature in Gemini where you can make your own chatbots, powered by Gemini, with custom instructions. If you’re interested in learning more about them, check out my editorial from April, where I argue custom AI bots are the best thing about generative AI and how to create your own bots. The decision to make Gems available across Google Workspace has the potential to significantly speed up people’s workflows if they’ve started using Gems already. If you’ve never made a Gem, Google has several pre-made ones including a Brainstormer, Writing editor, Coding partner, and Learning guide. Google Workspace users can leverage Gems in an almost infinite number of ways. For example, imagine if you’re a teacher in whatever country and you have to make lesson plans for your class that must follow a certain structure, you can use natural language to program a gem to expect certain inputs from you (such as grade, subject, topic etc) and get an output that follows the required guidelines. If you’re a journalist, you could create a gem to quickly strip out the key bits of news from a press release or if you’re a student you can create a bot to break down complicated subjects into something easier to understand. The possibilities are nearly endless and now the Gems you make are even more accessible. Google mentioned that Gems can be accessed via the side panel of all supported Workspace applications and can be used across Workspace capabilities including @ mentioning, accessing files and folders, and more. If you need to create a Gem, you’ll still need to do that on the Gemini website. To get started with Gemini in Google Workspace, just click the “Ask Gemini” (spark button) in the top-right corner. Google said that the Gems feature rollout is an extended rollout which means it might take more than 15 days to get the feature. Admins out there do not need to do anything and there are no specific admin controls in the side panel for Gems or Gemini.
    • Microsoft changes hit Teams Android devices: Disable Entra ID policy to restore sign-in by Paul Hill As part of its Secure Future Initiative, Microsoft has deployed a new Entra ID Conditional Access policy targeting Device Code Flow authentication. Unfortunately, it has led some Microsoft Teams-certified Android devices (Teams Rooms on Android, Teams Phones, Teams Panels, and Teams Displays) to be logged out and signing back in can be a bit fiddly so guidance has been shared. Microsoft said that it shared previous guidance which explained how to exclude Android devices, but it seems some admins didn’t catch this as many devices were not excluded and have been signed out. It’s important to realize that this is not a bug, it’s a security feature. However, the move could have been better communicated. To sign the devices back in, you can do so manually. However, if the devices are remote you’ll need to follow these steps: By disabling the “Block device code flow” policy in step 1, it will change everything back to how it was before Microsoft decided to enable it to boost security. This will allow you to get those affected Android devices logged back in again. Also pay special attention to step 2 which says you might need to reboot your device three times. Once you have your Android devices logged in again, it’s probably a good idea to follow Microsoft’s previous guidance and add these to an exclusion list before re-enabling the “Block device code flow” policy. Microsoft recommends only allowing DCF where it’s absolutely necessary and then blocking it elsewhere. The best thing to do is to add your Teams Android device to the exclusion list - this will allow these devices to operate normally, while boosting overall security. If you’re an admin and have been impacted by this, be sure to take proactive measures to avoid disruptions in the future.
    • Can someone help me with writing a batchfile using notepad to tell me to start a vpn plz? I would greatly appreciate any help  
  • Recent Achievements

    • Reacting Well
      SteveJaye earned a badge
      Reacting Well
    • One Month Later
      MadMung0 earned a badge
      One Month Later
    • One Month Later
      Uranus_enjoyer earned a badge
      One Month Later
    • Week One Done
      Philsl earned a badge
      Week One Done
    • Week One Done
      Jaclidio hoy earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      437
    2. 2
      ATLien_0
      158
    3. 3
      +FloatingFatMan
      149
    4. 4
      Nick H.
      65
    5. 5
      +thexfile
      62
  • Tell a friend

    Love Neowin? Tell a friend!