1.    14 Jan 2016 #1
    Join Date : Jan 2016
    Posts : 4
    windows 10

    svchost CPU usage at 55%


    not sure since when and how ( must have been recently ), but my windows 10 got probably infected, whenever i start pc, my cpu usage jumps to 55% ±. After I open task manager, i can see this ( attachment ) :
    the PID of "faulty" service is always different and if I stop the process, i am ok until next reboot. Windows defender detected nothing after full scan, I have never downloaded any exe files or opened some bad web page, only .mp4, .avi files and games from Steam.
    Should I format and reinstall windows, just to be sure or is there some other tool to find out what happens / fix my problem ? I have no important data or work on my pc, so format is ok, I just dont want to spend several hours reinstalling everything
    Attached Thumbnails Attached Thumbnails fsdgf.jpg   gdghfg.jpg  
      My ComputerSystem Spec
  2.    14 Jan 2016 #2
    Join Date : Apr 2015
    Posts : 12,942
    W10Prox64

    Quote Originally Posted by buxanto View Post
    not sure since when and how ( must have been recently ), but my windows 10 got probably infected, whenever i start pc, my cpu usage jumps to 55% ±. After I open task manager, i can see this ( attachment ) :
    the PID of "faulty" service is always different and if I stop the process, i am ok until next reboot. Windows defender detected nothing after full scan, I have never downloaded any exe files or opened some bad web page, only .mp4, .avi files and games from Steam.
    Should I format and reinstall windows, just to be sure or is there some other tool to find out what happens / fix my problem ? I have no important data or work on my pc, so format is ok, I just dont want to spend several hours reinstalling everything
    Hi buxanto and welcome to Tenforums.

    I wouldn't go reinstalling just yet, there are a few things you can do:

    Let's check for infection
    -download and run RKILL
    This is a little program that will stop any malicious running processes temporarily until next boot. After running, it places a text file on your desktop - paste that info here.

    - download, install and run Malwarebytes Antimalware Free
    Update the definitions and go into settings and select the box to scan for Rootkits as well as everything else that is already checked. Do a custom scan and select your entire C: drive.

    Let us know if it finds anything. Reboot if asked to. If you do reboot, run RKILL again.

    Depending on your response, I'll give you next steps.
      My ComputerSystem Spec
  3.    14 Jan 2016 #3
    Join Date : Jan 2016
    Posts : 4
    windows 10
    Thread Starter

    well thank you man, seems like my pc was indeed sick, unfortunatelly, i did run rkill again and it overwrote the previous report, which said that I had 1 bad process running ( svchost.exe ) and some wvsvcv ( some windows protection service ) not running. after running malwarekiller software from ur post, it detected 17 items, i deleted them all and after reboot, no more cpu running at 55-60%, no uknown random svchost.exe service running in the background. so again, thank you very much, although i would love to know, how that shiet got into my pc, because as I wrote above, i dont download .exe files, i must have clicked on some bad web page or something wtf
    Attached Thumbnails Attached Thumbnails gdd.jpg  
    svchost CPU usage at 55% Attached Files
      My ComputerSystem Spec
  4.    14 Jan 2016 #4
    Join Date : Apr 2015
    Posts : 12,942
    W10Prox64

    Quote Originally Posted by buxanto View Post
    well thank you man, seems like my pc was indeed sick, unfortunatelly, i did run rkill again and it overwrote the previous report, which said that I had 1 bad process running ( svchost.exe ) and some wvsvcv ( some windows protection service ) not running. after running malwarekiller software from ur post, it detected 17 items, i deleted them all and after reboot, no more cpu running at 55-60%, no uknown random svchost.exe service running in the background. so again, thank you very much, although i would love to know, how that shiet got into my pc, because as I wrote above, i dont download .exe files, i must have clicked on some bad web page or something wtf
    Bitcoin Miner is NOT good. Not good at all. I am going to guess that you have some outdated Java or Flash or Silverlight, of which an infected web page took advantage when you visited it.

    Please download Ccleaner and go to the uninstall tab on the left - this gives a list of all programs installed on your computer. There is a link at the bottom right to save to text file. Please do that, and paste the text in here for me to evaluate.

    Additionally, Zeusbot is a very bad bitcoin mining program, as it also steals data & logins from your system. It may be prudent to start changing your passwords from a clean system, while we finish up with your infected one. Not sure yet if this is what you had, but it's a good possibility.

    Next I would like you to run an ESET Online Scan. You should be able to save to text file anything it finds.
    Last edited by simrick; 14 Jan 2016 at 15:44.
      My ComputerSystem Spec
  5.    14 Jan 2016 #5
    Join Date : Jan 2016
    Posts : 4
    windows 10
    Thread Starter

    eset found 1 item, i suppose i should format asap, my system is infected badly
    svchost CPU usage at 55% Attached Files
      My ComputerSystem Spec
  6.    14 Jan 2016 #6
    Join Date : Apr 2015
    Posts : 12,942
    W10Prox64

    Quote Originally Posted by buxanto View Post
    eset found 1 item, i suppose i should format asap, my system is infected badly
    Have you noticed any encrypted files in your documents?

    EDIT:
    C:\Windows\System32\config\systemprofile\AppData\Roaming\Origin\update.vbe VBS/Kryptik.DC trojan cleaned by deleting

    These Kryptik trojans are password stealers. They grab your passwords and then open a backdoor to bitcoin miners, clikfraud malware or DDoS botnets.

    If you are willing then yes, I would completely wipe/format and reinstall.
    Then I would setup a password manager like LastPass. Please change all your passwords from a CLEAN system, and I mean EVERY PASSWORD.

    Still evaluating your installed programs, will report back.

    EDIT#2:
    Not seeing any glaring problems in your installed programs list. No idea how this malware got in, sorry.
    Last edited by simrick; 14 Jan 2016 at 15:34.
      My ComputerSystem Spec
  7.    14 Jan 2016 #7
    Join Date : Jan 2016
    Posts : 4
    windows 10
    Thread Starter

    it is ok, thank you, tommorow or on saturday i will do big undusting and formating + password changes
      My ComputerSystem Spec
  8.    14 Jan 2016 #8
    Join Date : Apr 2015
    Posts : 12,942
    W10Prox64

    Quote Originally Posted by buxanto View Post
    it is ok, thank you, tommorow or on saturday i will do big undusting and formating + password changes
    Cheers!
      My ComputerSystem Spec

 


Similar Threads
Thread Forum
svchost.exe_MapsBroker stopped working
I have been experiencing irritating problems which are normally resolved by restarting; maybe 5 minutes. I ran Reliability Report and found that most days svchost.exe_MapsBroker, version: 10.0.10586.0, time stamp: 0x5632d7ba stopped working /...
Performance & Maintenance
Poor Performance from Windows 10 - High CPU usage from SVCHOST
Evening Folks, I just recently installed Windows 10 on my Dell Inspiron Laptop and so far I am not impressed at all - in fact, I am very seriously debating one of two actions - re-install Windows 7 or switching to an entirely different OS. The...
Performance & Maintenance
SVCHOST eating up memory
What services of svchost should I disable? I think it's eating up my memory. I think if the computer has 2GB RAM, it should have only like 30-40% usage but I have 63% 5059650597
Performance & Maintenance
Error in system32/svchost.exe
Since upgrading my laptop to Windows 10, I continually receive a window message saying: Error in C:/Windows/System32/svchost.exe Missing entry: MapNetworkDrive Can anyone help with this error please? Thanks, Skeeter
Installation and Upgrade
Extremely HIGH CPU Usage (SVCHost)
So, basically I upgraded to Windows 10, and it's been a huge nightmare. To start with, I didn't enjoy the experience and tried to downgrade, but I was informed the backup was corrupted (it was using a different file structure or something) and...
Performance & Maintenance
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 11:07.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums