svhost.exe always read/write disk
Hi, My windows 7 home premium 64 bit always read/write disk. I have turned off all possible server process. Such as antivirsus, super fetch, and windows search. But it doesn't stop. I use 'procmon' tool and find that it's svhost.exe:
12:41:29.8677386 PM svchost.exe 804 RegQueryKey HKLM\System\CurrentControlSet\Control\DeviceClasses SUCCESS Query: HandleTags, HandleTags: 0x0
12:41:29.8677660 PM svchost.exe 804 RegOpenKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS Desired
Access: Query Value
12:41:29.8677934 PM svchost.exe 804 RegQueryKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS Query:
HandleTags, HandleTags: 0x0
The device instance corresponding to the registry item is: PCI\VEN_8086&DEV_3B64&SUBSYS_036D1025&REV_06\3&11583659&0&B0
Do you have any idea about how to solve it? Thank you!
September 4th, 2010 7:51pm
That is because system services are running in background. To confirm which services are running, please:
1. Open cmd with administrator.
2. Enter:
Tasklist –svc
3. Check the services that are load by each svchost process.
Is the svchost process slow down the system performance?Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 7th, 2010 11:12am
Same thing:
21:19:04.3644764 System 4 RegOpenKey HKLM\SOFTWARE\TOSHIBA\OpticalDiscAPL SUCCESS Desired Access: All Access
21:19:04.3645356 System 4 RegQueryValue HKLM\SOFTWARE\TOSHIBA\OpticalDiscAPL\MountMode NAME NOT FOUND Length: 48
21:19:04.3645553 System 4 RegCloseKey HKLM\SOFTWARE\TOSHIBA\OpticalDiscAPL SUCCESS
20:55:27.9882319 svchost.exe 816 RegOpenKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS Desired Access: Query Value
20:55:27.9882536 svchost.exe 816 RegQueryKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS Query: HandleTags, HandleTags: 0x0
20:55:27.9882747 svchost.exe 816 RegOpenKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5}\##?#PCI#VEN_8086&DEV_3B64&SUBSYS_FF001179&REV_06#3&11583659&0&B0#{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS Desired
Access: Query Value
20:55:27.9882983 svchost.exe 816 RegCloseKey HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5} SUCCESS
20:55:27.9883180 svchost.exe 816 RegQueryValue HKLM\System\CurrentControlSet\Control\DeviceClasses\{e2d1ff34-3458-49a9-88da-8e6915ce9be5}\##?#PCI#VEN_8086&DEV_3B64&SUBSYS_FF001179&REV_06#3&11583659&0&B0#{e2d1ff34-3458-49a9-88da-8e6915ce9be5}\DeviceInstance SUCCESS Type:
REG_SZ, Length: 122, Data: PCI\VEN_8086&DEV_3B64&SUBSYS_FF001179&REV_06\3&11583659&0&B0
svchost.exe 816 DcomLaunch, PlugPlay, Power
March 9th, 2011 1:31pm