Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 12:18:56 PM

Login with username, password and session length

663582 Posts
70564 Topics
145216 Members

Latest Member: millar

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Virus/Malware Removal Assistance
| | |-+  svchost.exe
« previous next »
Pages: [1] Go Down Print
Author Topic: svchost.exe  (Read 6229 times)
Bracca
Comodo Loves me
****
Offline Offline

Posts: 103


« on: January 13, 2009, 11:44:39 AM »

Yeah spotted a svchost.exe on proces menu. Actually there are 6 of them. All different size. What caught my attention was that 2 of them are, according to the proces menu, web based and the rest are System based. How do i know which ones could be possible malware and which one(s) are needed? One of them is listening to the port 135, One was a active TCP Out connection from my ip adress to my ip adress. Weird.

Edit: Search function found 3 svchost.exe files. One in System32, one in $NTServicePackUninstall$ and the last one is in a suspicious looking folder, Windows\ServicePackFiles\i386.
OS is XP with Servicepack 3 installed in it.
« Last Edit: January 13, 2009, 11:59:21 AM by Bracca » Logged
Arjunprasad
Newbie
*
Offline Offline

Posts: 13



« Reply #1 on: July 04, 2009, 12:59:40 PM »

I suggest you to determine what services are running under a SVCHOST.EXE process. For detailed information on how to determine what services are running under a SVCHOST.EXE process, please click on the link below and read them completely:

http://www.bleepingcomputer.com/tutorials/tutorial129.html
Logged
hatevirus
Newbie
*
Offline Offline

Posts: 20


« Reply #2 on: July 18, 2009, 01:22:18 AM »

winamp is running under the svchost.exe.
low ram and low cpu in use.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16695



« Reply #3 on: July 18, 2009, 12:55:42 PM »

Or try svchost analyser: http://www.neuber.com/free/svchost-analyzer/ .
Logged

Ronny
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 13180


Volunteer Moderator


« Reply #4 on: August 02, 2009, 07:29:59 AM »

Sysinternals Process Explorer can show you all you need to know:
http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Logged

Volunteer Moderator
Any concerns? Please send me a PM or review the Forum Policy -  update Jan 3rd 2013!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.05 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com