svchost process consuming a lot of space in Ram
Created: 21 Apr 2009 | 7 comments
svchost a windows process which used to take about 1200k of ram space now takes 7000k space .
I have not installed any third party software.
Kindly suggest any remedy.
Blog Entry Filed Under:
The Security Community Blog is the perfect place to share short, timely insights including product tips, news and other information relevant to the Security community. Any authenticated Connect member can contribute to this blog.
Comments 7 Comments • Jump to latest comment
use process explorer and see whats running under the svchost, it might be windows update which is casuing it but troublshoot
Yes,
Download Process Explorer from Microsoft website and then run it.
In the process, right click SVCHOST.exe process and go to properties. Look for the actual location of file.
It could be threat also.
Also check your registry entry HKLM>Software>Microsoft>Windows>CurrentVersion>Run
Look for any suspicious file.
If found submit it to https://submit.symantec.com/gold or https://submit.symantec.com/platinum
rgrds,
SAM
Processor explorer free sysinternals tools will help you to analyze the threads
it runs even after i disconnect network cable
When a virus still runs after disconnecting from the network, it has some rootkit on it.
Run procmon and check what DLL hooks onto it.
Any unknown or looks suspicious DLL, do submit it to Symantec submission.
Else check the svchost file . See if it was run from a non-normal location ie c:\windows\system or c:\windows .
If yes, do submit it also.
-- Got new virus ? Try update your defs here : ftp://ftp.symantec.com/AVDEFS/norton_antivirus/rap... --
try formatting the primary partition .Remember dont open the other partitions until you install symantecAV
then install Symantec Av and run run a virus check .I doubt other partitions may contain a virus.
try formatting the primary partition .Remember dont open the other partitions until you install symantecAV
then install Symantec Av and run run a virus check .I doubt other partitions may contain a virus.
Would you like to reply?
Login or Register to post your comment.