SVCHOST taking up 99% CPU usage


Recommended Posts

The otehr day my internet using programs (firefox, msn messenger) started to lagg, it was after downloading kazaa lite and kazaa lite plus plus. Neither of which really worked for me. Anyway, when my internet started to freeze up, i checked the system processes and saw that SVCHOST.exe was at 99% cpu usage! I can end the process fine and it solves the problem, but i do not want to have to do this everytime i boot my computer. adaware and symantec antivirus came up with nothing. Also, whenever i try to get inot Control Panel, windows explorer has to close...i dont know if they are related, but i have been without control panel for about a month now. Does anybody know what can help me?

Link to comment
https://www.neowin.net/forum/topic/371406-svchost-taking-up-99-cpu-usage/
Share on other sites

The otehr day my internet using programs (firefox, msn messenger) started to lagg, it was after downloading kazaa lite and kazaa lite plus plus.  Neither of which really worked for me.  Anyway, when my internet started to freeze up, i checked the system processes and saw that SVCHOST.exe was at 99% cpu usage!  I can end the process fine and it solves the problem, but i do not want to have to do this everytime i boot my computer.  adaware and symantec antivirus came up with nothing.  Also, whenever i try to get inot Control Panel, windows explorer has to close...i dont know if they are related, but i have been without control panel for about a month now.  Does anybody know what can help me?

586516878[/snapback]

This is a tough one.

Here's what you can try:

- Get it to lag again

- Open services.msc

- Sort services by "Status" column, so that the "Started" ones are on top

- Take note of all the services running, right them down if you need to

- Kill the svchost.exe process that is using 99% cpu usage

- Hit the refresh button in the services toolbar, or f5

- Find which service is no longer "Started" that was before

Report back on which one it is.

okay, i did what you said, i wrote down everything, then ended that task, and the lit shifted when i refreshed that page...DNS Client, thats the one that wasnt in the list this time. But, it looks important, domain name mumbojumbo and the such. Computer seems to work fine without it, but i dunno, its a network service, is it possible that that may leave me open for more attackers?

the DNS Client wont leave you open for more attackers, i doubt that if that really was the cause, it had anything to do with hackers.

You kinda need DNS Client, as this is the service that resolves DNS requests.

However I'd like to add my 2cents, if someone hacks your machine, their remote admin prog is usually called svchost.exe or explorer.exe or something that doesnt look suspicious in your task list.

Patch your machine, run a virus update, an adware update and check your firewall. If you run IIS, ensure you are secure (run iislockdown)

svchost.exe is the windows system host application for running system services for xp. It's likely that you recently installed something that was attached to a windows service and it is sucking up all your cpu cycles. Take a look at your running windows services (Control Panel -> Administrative Tools -> Services) and see if anything looks odd or out of place. Then again, since you are probably asking this, it's not exactly a good idea to messing witht hat kind of stuff.

I would check and see what you have running at start up. Some programs invoke svchost.exe on startup.

svchost.exe is the windows system host application for running system services for xp. It's likely that you recently installed something that was attached to a windows service and it is sucking up all your cpu cycles. Take a look at your running windows services (Control Panel -> Administrative Tools -> Services) and see if anything looks odd or out of place. Then again, since you are probably asking this, it's not exactly a good idea to messing witht hat kind of stuff.

I would check and see what you have running at start up. Some programs invoke svchost.exe on startup.

586520304[/snapback]

He already said it's the DNS client service.

Alot of times script kiddies will use "rootkits" and things to take control of your PC. Its very usefull to name the executable file svchost as theres like 4 concurent copies running in windows alone. So its much more likely to go unnoticed. I would honestly format the machine if you are unable to find where the exe is located. Of course it could actually be a windows issue, and svchost is a very important file. and unfortunatly its not a file you can just replace off of the XP cd, or from someone elses computer as it has specific information related to your hardware.

It's not a foreign exe. It's possible it got infected, but I doubt it. I've had it happen as well, and it was not a virus/trojan.

jesterman: The only thing I can suggest is to run repair from your XP disc. All your settings and data will remain in place, it'll just replace the system files.

This is probably because you installed the Supertrick during the Kazaa installation, which creates a HOSTS file with many false entries for the purpose of ad blocking.

A large HOSTS file can cause DNS Client problems such as you describe.

This is probably because you installed the Supertrick during the Kazaa installation, which creates a HOSTS file with many false entries for the purpose of ad blocking.

A large HOSTS file can cause DNS Client problems such as you describe.

586524988[/snapback]

if i did download the supertrick thing, how would i remove that host file?

  • 3 weeks later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • But it opens the floodgates to anyone who gets a refund instead of a replacement (since refund will buy you a 1/3rd of the capacity it did years ago)
    • He has planned to file a lawsuit in small claims court so it'll only be a $1000 lesson assuming he wins. That's likely a fraction of what Samsung spends on toilet paper on a daily basis.
    • Windows Server gets DNS over HTTPS (DoH) support by Usama Jawad For the past few months, Microsoft has been previewing DNS over HTTPS (DoH) for Windows DNS Server, touting it as a foundational upgrade for zero-trust enterprise networks. It essentially introduces encrypted, authenticated DNS for the networks rather than transmitting DNS traffic in clear. Now, the company has introduced the general availability (GA) of this feature. The GA of DoH encourages organizations to deploy the solution in production environments without implementing a new client-to-resolver architecture. DoH helps improve the overall security of the network and reduces the risk of spoofing due to its zero-trust design. This is a significant change because pretty much every interaction with the network requires interfacing with DNS. DoH offers several advantages over standard DNS traffic, such as encryption using HTTPS, preventing unauthorized inspection, man-in-the-middle attacks, and traffic analysis. Since it leverages TLS certificates so that clients can verify the identity of the DNS server, it prevents spoofing through this authentication mechanism. Additionally, it's built on the DoH standard defined by the Internet Engineering Task Force (IETF), which means that it should work with modern RFC 8484-compliant clients. Finally, it integrates into the existing network architecture seamlessly and can even run in parallel with standard DNS, so that customers can migrate to the new technology at their own pace. Microsoft says that in the past few months of preview, DoH has become more stable, and customers can confidently deploy it in production environments with proper guidance. Microsoft has emphasized that migrating to DoH is necessary for organizations that are moving toward zero-trust DNS solutions. Windows clients already support DoH, but the latest availability on Windows Server provides encrypted DNS to all endpoints. The company has also mentioned that "while this release focuses on encrypting client-to-resolver communication, support for encrypted communication between Windows DNS Server and upstream DNS resolvers is planned for a future update." You can follow Microsoft's guidance to deploy DoH here, but keep in mind that you need a Windows Server 2025 installation with the latest Patch Tuesday updates installed.
    • Lol I had one of these turn faulty in Jan, guess it wasn't just bad luck lol
    • I'm team Rossmann all the way. I have the exact same NVME, altough not in an array like him.
  • Recent Achievements

    • Week One Done
      davidbazooked earned a badge
      Week One Done
    • One Month Later
      Jamswaz earned a badge
      One Month Later
    • Week One Done
      Jamswaz earned a badge
      Week One Done
    • Rookie
      Marzoid went up a rank
      Rookie
    • Community Regular
      coch went up a rank
      Community Regular
  • Popular Contributors

    1. 1
      +primortal
      511
    2. 2
      PsYcHoKiLLa
      184
    3. 3
      +Edouard
      159
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      75
  • Tell a friend

    Love Neowin? Tell a friend!