explorer.exe x2 and svchost.exe x 16

BMXer Dan

New Member
Right, first of all, sorry if this has been posted before or in the wrong section

To start off my machine is:
___________________________________________

Acer Aspire 5630 Laptop,
T5500 Intel Core2 Duo Processor 1.66GHz,
2G Ram,
Windows Vista Home Premium x32 (Service Pack 1)
___________________________________________

I dont know whats wrong or if its normal with Vista but when nothing else is running there will be just the one explorer.exe...

But, if i open say My Documents or My Computer to open a file a second explorer.exe decides to show up in task manager and is slightly larger in size compared to the original one.

The first one currently sits there at roughly about 11,500k
When the second one comes along its about 15,000k in size and the window takes about 2-4 seconds to load/display folders etc sometimes longer. It also becomes larger every window you open resulting in slower load times.

From the task manager, if i close the smaller of the two explorer.exe's naturally the whole task bar at the bottom closes and you can't access the start menu etc.
But, if i close the other, slightly larger explorer.exe, it just closes that window.

I have run several anti-virus scans, spyware scans etc and have all returned nothing, so i am assuming that it might be somehting that has slipped through my scanners un-seen unless this is normal behaviour that i have not noticed before.

Also lately my CPU usage had been fluxuating a lot between 0% and 20% when no windows are open, it can also shoot up to between 80% - 90% when opening a window and will then resume its fluxuating idle state until i open or close another window or file.

If i click "Show process from all users" in the task manager another problem i see that might be related or compleetly seperate is displayed.

I have 16 svchost.exe's, yes thats right, 16.... (screenshot available) they all range in size the largest being roughly 50,000k and the smallest being 200k. This can't be normal?

I have included two screenshots of my task manager just for visual aid of the explorer.exe problem and a screenshot of the svchost.exe problem.

Thanks in advance for any help

Dan
 

Attachments

  • one explorer.jpg
    one explorer.jpg
    134 KB · Views: 222
  • two explorer.jpg
    two explorer.jpg
    140.2 KB · Views: 158
  • svchost.jpg
    svchost.jpg
    157.2 KB · Views: 542

My Computer

System One

  • CPU
    T5500 Intel Core2 1.66GHz
    Memory
    2 GB
16 svchosts is certainly a tad suspicious, especially the multiple instances running under networkservice. Can you paste the output from running this command on a CMD prompt?
tasklist /svc /fi "imagename eq svchost.exe"
 

My Computer

C:\Users\Daniel>tasklist /svc /fi "imagename eq svchost.exe"

Image Name PID Services
========================= ======== ============================================
svchost.exe 900 DcomLaunch, PlugPlay
svchost.exe 968 RpcSs
svchost.exe 1140 CryptSvc, Dnscache, KtmRm, NlaSvc, TapiSrv,
TermService
svchost.exe 1156 WinDefend
svchost.exe 1272 Audiosrv, Dhcp, Eventlog, lmhosts, wscsvc
svchost.exe 1312 AudioEndpointBuilder, EMDMgmt, IPBusEnum,
Irmon, Netman, PcaSvc, SysMain,
TabletInputService, TrkWks, UxSms,
WdiSystemHost, Wlansvc, WPDBusEnum, wudfsvc
svchost.exe 1328 AeLookupSvc, BITS, Browser, CertPropSvc,
EapHost, IKEEXT, iphlpsvc, LanmanServer,
MMCSS, ProfSvc, RasMan, Schedule, seclogon,
SENS, SessionEnv, ShellHWDetection, Themes,
Winmgmt, wuauserv
svchost.exe 1508 gpsvc
svchost.exe 1592 EventSystem, fdPHost, FDResPub,
LanmanWorkstation, Mcx2Svc, netprofm, nsi,
SSDPSRV, SstpSvc, upnphost, W32Time,
WebClient
svchost.exe 632 BFE, DPS
svchost.exe 1028 AppHostSvc
svchost.exe 2204 PolicyAgent
svchost.exe 2400 stisvc
svchost.exe 2464 W3SVC, WAS
svchost.exe 2576 WerSvc
svchost.exe 3556 SDRSVC

C:\Users\Daniel>
 

My Computer

System One

  • CPU
    T5500 Intel Core2 1.66GHz
    Memory
    2 GB
no one know how to solve my problems? =[

In that list, you can see the names of the various services running in the svchost instances. I'd suggest now doing some research to check whether all of those are legit and expected based on the way your machine is used.

A lot of those names are familiar to me, but some are not, for what that's worth (my memory is questionable!). As much as it would appear dumb for malware to conveniently install itself as a service - with a unique name - before you launch into troubleshooting the Explorer issue you need to be confident whether the high number of svchosts is normal under your circumstances or not.
 

My Computer

Back
Top