OldFatGuy Mar 8, 2024 @ 3:38am
Windows Services Question
First, I am a complete know nothing about these confounded machines, so please be gentle.

I have been experiencing some things that makes me believe something nefarious is afoot, and if necessary I will expand, but to start things off, can anyone tell me if this is accurate because I'm just not sure it is. I will quote what I'm asking about, and, if it works, post a link to where I found it. Here's the quote:

"Although utcsvc.exe is a legitimate system component, it still can be used to disguise malicious programs. And if you find the CPU consumption is higher than 30% and the file size is bigger than 53KB, there is a high risk of virus infection."

And the link: https://www.minitool.com/news/service-host-utcsvc.html

I was having issues, noticed this came up at the top of the CPU usage list, right clicked it task manager, clicked the "Search Online" option, and this was the one listed at the top of the search results.

My file size is 55kb. Which is bigger than 53kb (last time I checked anyway, I mean I know math is hard, but dammit 55 is still greater than 53. So, does this mean I have "a high risk of virus infection?"

I followed the instructions and disabled the service. I then ran Malwarebyte scans at least 7 times. All 7 came back with the "good news" of zero files showing up as malware. Is the 53 number just outdated, or does the 55 indeed mean something is wrong? Because it's that same file that comes up no matter which service host you click on in task manager, they all point to this file that is greater than 53.

Reason for asking is because I'm still seeing some issues, although it does seem to be improved. And I can't swear by it as it may just be a perception thing, but it seems when I have these issues, closing Steam fixes them. In fact, in one game (Motorsport Manager), every time I've run into the massive frame rate drops (which shouldn't happen in the menu part of this game), I've shut down Steam, restarted it, and it worked right... until it didn't and I repeated the process.

I'm at a loss what with my AV software giving me a clean bill of health and Malwarebytes also giving me the same.

Sorry for the length and thank you for any help.

OldFatGuy
Last edited by OldFatGuy; Mar 8, 2024 @ 3:43am

Something went wrong while displaying this content. Refresh

Error Reference: Community_9734361_
Loading CSS chunk 7561 failed.
(error: https://community.fastly.steamstatic.com/public/css/applications/community/communityawardsapp.css?contenthash=789dd1fbdb6c6b5c773d)
Showing 1-9 of 9 comments
OldFatGuy Mar 8, 2024 @ 4:02am 
Originally posted by smallcat:
I think the different in sizes should be just from rounding . Anyway , if Defender thinks you re clean you re . Defender has 100% detection rate . So , no viruses . Your issues root from something else .
Rounding? If it were a rounding issue, wouldn't it then be 52 or 54 (depending on if the rounding difference was up or down)? Not sure rounding explains 55. The article is dated some 15 months ago, so maybe it's outdated I suppose, but I don't know how to find out.

Thanks for the reply.
OldFatGuy Mar 8, 2024 @ 4:25am 
Ok, yeah, as I feared I just don't understand this stuff well enough to even get help. I was under the impression that file size was something that was static (unless edited) and involved the hard drive, didn't know it had anything to do with memory allocation, dynamic or otherwise.

I'll stop here. Does me no good to read replies when i don't even have the basic understanding to interpret them.

Thanks for trying though. If the issues continue, I'll look for help elsewhere.
Raoul Mar 8, 2024 @ 4:49am 
Originally posted by smallcat:
Defender has 100% detection rate . So , no viruses . Your issues root from something else .

Sadly not true https://www.av-comparatives.org/tests/malware-protection-test-september-2023/
Defender is still pretty bad for offline tests.

If you want to double check your system can recommend the free one time Eset online scan: https://www.eset.com/int/eset-online-scanner/

If you do want the best possible active protection then bitdefender is the way to go right now.
Last edited by Raoul; Mar 8, 2024 @ 4:52am
A&A Mar 8, 2024 @ 5:33am 
It depends on the Windows build and potentially windows updates to affect utcsvc.exe. It is also hard to tell if there is malware or not, even the 30% CPU usage mentioned is not properly told because each system has a different amount of cores and different frequancy and the readings will be different. The easiest way is to monitor behavior for creating suspicious network connections.
Last edited by A&A; Mar 8, 2024 @ 5:34am
A&A Mar 8, 2024 @ 5:52am 
Originally posted by smallcat:
It s a core Windows legit service , every good AV should check it properly . I doubt any AV will make a mistake on it .

I always disable Telemetry .
Shouldn't windows defender be good enough to detect any difference in OS files like it can do with localhost file?
Last edited by A&A; Mar 8, 2024 @ 5:52am
Mine is 55kb also. :csdsmile:
AD Mar 8, 2024 @ 4:59pm 
Originally posted by OldFatGuy:
Ok, yeah, as I feared I just don't understand this stuff well enough to even get help. I was under the impression that file size was something that was static (unless edited) and involved the hard drive, didn't know it had anything to do with memory allocation, dynamic or otherwise.

I'll stop here. Does me no good to read replies when i don't even have the basic understanding to interpret them.

Thanks for trying though. If the issues continue, I'll look for help elsewhere.
File dont change size randomly, but they dont have to be edited by the user. Since its an exe, I guess its possible Windows Update may have changed it, for example. You can scan again with some other AV if you really want, but you have already scanned quite a bit so I dont think you need to worry.

Disclaimer: I am not an expert.
emoticorpse Mar 8, 2024 @ 6:51pm 
Find out what it is. Look at it's PID in Resource Manager, then track it to the PID of that service in Task Manager "Services" tab?

I'd say disable it or whatever if you're not sure. I don't think it's required, because I don't see any service in my list of services matching that, unless I'm missing something.
Bastard Emperor Mar 8, 2024 @ 7:33pm 
53kb to 55kb is a difference of 2000 bytes, this is tiny and unlikely to be a sign of an infection.

I don't know what AV you're running but I only trust one these days and it's called Malwarebytes.

Download the program, install and run a scan. It will detect almost all known variations of all infections, malware, addware etc.

Please make sure that all other anti-virus software has been uninstalled prior to installing Malwarebytes.

To clean up your system and make things faster, try using CCleaner which will clean all temp files and also has a useful registry clean option.

Both these programs can be used in a limited capacity for free but if you want full protection I'd def. consider buying them as I did.
Showing 1-9 of 9 comments
Per page: 1530 50

Date Posted: Mar 8, 2024 @ 3:38am
Posts: 9