Svchost.exe high cpu usage - Dcom terminated

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #11

    Jacee,

    Here is the log that was reported AFTER cleaning and restarting.


    # AdwCleaner v3.016 - Report created 04/01/2014 at 16:35:34
    # Updated 23/12/2013 by Xplode
    # Operating System : Windows 7 Ultimate (64 bits)
    # Username : Newnew7 - NEWNEW7-PC
    # Running from : C:\Users\Newnew7\Downloads\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    [!] Folder Deleted : C:\ProgramData\boost_interprocess
    [!] Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\afurladvisor@anchorfree.com
    File Deleted : C:\Users\Newnew7\AppData\Roaming\Mozilla\Firefox\Profiles\psf71shf.default\invalidprefs.js

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
    Key Deleted : HKCU\Software\anchorfree

    ***** [ Browsers ] *****

    -\\ Internet Explorer v8.0.7600.16385


    -\\ Mozilla Firefox v26.0 (en-US)

    [ File : C:\Users\Newnew7\AppData\Roaming\Mozilla\Firefox\Profiles\psf71shf.default\prefs.js ]


    *************************

    AdwCleaner[R0].txt - [1537 octets] - [04/01/2014 16:29:13]
    AdwCleaner[S0].txt - [1438 octets] - [04/01/2014 16:35:34]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1498 octets] ##########
      My Computer


  2. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #12

    Good :)

    Now download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
    Save any unsaved work. TFC will close ALL open programs including your browser!
    Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
    Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
    Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

    Let me know how your computer is running now.
      My Computer


  3. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #13

    Upon reboot svchost.exe is sitting at 120,000k memory, and after 3 minutes or so it is up to 140k. So it appears its still not cured.


    Edit: Its now down to 65,000k after waiting a little longer, ill monitor it and see how it changes, after a while is when it gets bad, and goes upwards to 1,000,000k.

    And just during the time it took me to edit this, it jumped back up to 192,000k
      My Computer


  4. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #14

    Download Process Explorer to get a better "monitor" on what program is causing the problem:
    Process Explorer
      My Computer


  5. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #15

    Well, I go under the svchost.exe, and I hit properties, then go to threads, and it has the most usage at ntdll.dll!Rt!UserThreadStart

    Hopefully I'm allowed to post links, but heres a screenshot.

    edabb54f58d225242b6516536dcb0862.png
      My Computer


  6. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #16

    Download CKScanner by askey127 from HERE
    Important - Save it to your desktop.
    Doubleclick CKScanner.exe and click Search For Files. It will appear as tho' it's doing nothing, so please have patience!
    After a very short time, when the cursor hourglass disappears, click Save List To File.
    A message box will verify the file saved.
    Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
      My Computer


  7. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #17

    Jacee,
    Here is the contents you requested.

    CKScanner 2.4 - Additional Security Risks - These are not necessarily bad
    c:\program files (x86)\electronic arts\dark age of camelot\effects\alb_ecrack1_hit.nif
    c:\program files (x86)\electronic arts\dark age of camelot\effects\crackles1.dds
    c:\program files (x86)\electronic arts\dark age of camelot\effects\lavapool_crackle_erupt.nif
    c:\program files (x86)\electronic arts\dark age of camelot\effects\lavapuddle_crackle.nif
    c:\program files (x86)\electronic arts\dark age of camelot\items\dragon_egg_cracks.dds
    c:\program files (x86)\electronic arts\dark age of camelot\items\egg_dragon_a_cracked.nif
    c:\program files (x86)\electronic arts\dark age of camelot\items\egg_dragon_h_cracked.nif
    c:\program files (x86)\electronic arts\dark age of camelot\items\egg_dragon_m_cracked.nif
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\alb_demonhall_walllavacrack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\alb_demonhall_walllavacrack_glow.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\bd1oldwcrack2.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\bd1oldwcrack3.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\bd1oldwcracked.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\cracks_detail.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\df_crackglow.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\dnifs\oceanusglasscrack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\a_cracksdetailb.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\a_floorcrack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\a_floorcrack_dk.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\barnaclecrack_detail.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\crackeddetail.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\cracks.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\cracksdetaila.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\cracksdetailb.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\cracksdetailc.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\cracks_.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\fomortowercrack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\hwallcrack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\hwallcracktan.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\impact_crack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\meteor_crack.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\meteor_crack_a.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\orange_lrg_brickcracked.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\orange_wall_basebcracks.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\nifs\test_crackrock.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\atcrackdrt1.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\crackedmuddy.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\crackedmuddy2.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\crackedsand.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\h_rock_cracked.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\terraintex\v_ground_cracked.dds
    c:\program files (x86)\electronic arts\dark age of camelot\zones\zone026\nifs\a_floorcrack_dk.dds
    c:\program files (x86)\electronic arts\shards\effects\alb_ecrack1_hit.nif
    c:\program files (x86)\electronic arts\shards\effects\crackles1.dds
    c:\program files (x86)\electronic arts\shards\effects\lavapool_crackle_erupt.nif
    c:\program files (x86)\electronic arts\shards\effects\lavapuddle_crackle.nif
    c:\program files (x86)\electronic arts\shards\items\dragon_egg_cracks.dds
    c:\program files (x86)\electronic arts\shards\items\egg_dragon_a_cracked.nif
    c:\program files (x86)\electronic arts\shards\items\egg_dragon_h_cracked.nif
    c:\program files (x86)\electronic arts\shards\items\egg_dragon_m_cracked.nif
    c:\program files (x86)\electronic arts\shards\zones\dnifs\alb_demonhall_walllavacrack.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\alb_demonhall_walllavacrack_glow.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\bd1oldwcrack2.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\bd1oldwcrack3.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\bd1oldwcracked.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\cracks_detail.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\df_crackglow.dds
    c:\program files (x86)\electronic arts\shards\zones\dnifs\oceanusglasscrack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\a_cracksdetailb.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\a_floorcrack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\a_floorcrack_dk.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\barnaclecrack_detail.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\crackeddetail.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\cracks.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\cracksdetaila.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\cracksdetailb.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\cracksdetailc.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\cracks_.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\fomortowercrack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\hwallcrack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\hwallcracktan.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\impact_crack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\meteor_crack.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\meteor_crack_a.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\orange_lrg_brickcracked.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\orange_wall_basebcracks.dds
    c:\program files (x86)\electronic arts\shards\zones\nifs\test_crackrock.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\atcrackdrt1.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\crackedmuddy.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\crackedmuddy2.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\crackedsand.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\h_rock_cracked.dds
    c:\program files (x86)\electronic arts\shards\zones\terraintex\v_ground_cracked.dds
    c:\program files (x86)\electronic arts\shards\zones\zone026\nifs\a_floorcrack_dk.dds
    scanner sequence 3.ZZ.11.KGNALZ
    ----- EOF -----
      My Computer


  8. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #18

    Woah!

    Download Security Check by screen317 from here http://screen317.spywareinfoforum.org/SecurityCheck.exe or here http://screen317.spywareinfoforum.org/
    Save it to your Desktop.
    Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    A Notepad document should open automatically called checkup.txt.
    Please post the contents of that document.

    Next:
    • Please download http://go.microsoft.com/fwlink/?linkid=52012 MGADiag and save it to your desktop.
    • Double click the icon on your desktop.
    • Push
    • Push
    • Go to Start -> Run and type in "Notepad"
    • Go to Edit -> Paste in notepad.
    • Copy and paste that log here.
      My Computer


  9. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #19

    Here is the contents of the first scan, ill reply with the next scan afterwards.


    Results of screen317's Security Check version 0.99.78
    Windows 7 x64 (UAC is disabled!)
    Out of date service pack!!
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.75.0.1300
    Java 7 Update 45
    Adobe Flash Player 11.9.900.170
    Mozilla Firefox (26.0)
    ````````Process Check: objlist.exe by Laurent````````
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 16% Defragment your hard drive soon! (Do NOT defrag if SSD!)
    ````````````````````End of Log``````````````````````


    And my C drive is in fact a SSd, so I cannot defrag that bit.
      My Computer


  10. Posts : 13
    Windows 7 ultimate x64
    Thread Starter
       #20

    And here is the log of the second scan by MGADiag

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: N/A, hr = 0xc004f012
    Windows Product Key: *****-*****-YG69F-9M66D-PMJBM
    Windows Product Key Hash: /kehptF9HHVxM5d8dUnqgcfndXw=
    Windows Product ID: 00426-OEM-8992662-00497
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 6.1.7600.2.00010100.0.0.001
    ID: {AFECA955-AC66-477D-9FB5-58DD5ACB36AE}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7600.win7_rtm.090713-1255
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->
    File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\npwatweb.dll[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070003]
    File Mismatch: C:\Windows\system32\wat\watweb.dll[Hr = 0x80070003]

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{AFECA955-AC66-477D-9FB5-58DD5ACB36AE}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-PMJBM</PKey><PID>00426-OEM-8992662-00497</PID><PIDType>2</PIDType><SID>S-1-5-21-303199133-4123285901-1159312895</SID><SYSTEM><Manufacturer>System manufacturer</Manufacturer><Model>System Product Name</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>1015</Version><SMBIOSVersion major="2" minor="7"/><Date>20120502000000.000000+000</Date></BIOS><HWID>71BA3607018400FE</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-MPC</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Software licensing service version: 6.1.7600.16385

    Name: Windows(R) 7, Ultimate edition
    Description: Windows Operating System - Windows(R) 7, OEM_SLP channel
    Activation ID: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8
    Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Extended PID: 00426-00178-926-600497-02-1033-7600.0000-3512013
    Installation ID: 008771568806232474422623332340813845000493139382513485
    Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
    Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
    Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
    Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
    Partial Product Key: PMJBM
    License Status: Licensed
    Remaining Windows rearm count: 3
    Trusted time: 1/6/2014 5:49:04 PM

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: N/A
    HealthStatus: 0x0000000000000000
    Event Time Stamp: N/A
    ActiveX: Not Registered - 0x80040154
    Admin Service: Not Registered - 0x80040154
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: NAAAAAEAAwABAAEAAAACAAAAAwABAAEAhFG6aXcWdMQKU2THlhOegMrEqXk6ix5KhSQucw==

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes
    Windows marker version: 0x20001
    OEMID and OEMTableID Consistent: yes
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC ALASKA A M I
    FACP ALASKA A M I
    HPET ALASKA A M I
    MCFG ALASKA A M I
    SSDT SataRe SataTabl
    SSDT SataRe SataTabl
    SSDT SataRe SataTabl
    BGRT ALASKA A M I
    SLIC HPQOEM SLIC-MPC
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 12:22.
Find Us