Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 25th, 2004, 06:41 AM
sbsd sbsd is offline
Infrequent Poster
 
Join Date: Jul 2004
Posts: 17
Default win32 - svchost

I got some virus that had something to do with Win32. My AntiVirus program didn´t delete it although I have Real-time protection set for "Delete automatically" Anyway, after I virusscanned my temporary internet files I found that virus and the anti-virus program could easily delete it.

I know win32 has something to do with svchost.exe. If I look at Task Manager and then processes I see 5 or sometimes 4 processes called svchost.exe. I use Windows XP, is this normal? 2-3 of them have usename "System". 1 of them have the username "Local service" and one have "Network Service" as username.

If I do a file search on my computer I found one file called svchost.exe in the folder C\WINDOWS\system32.
  #2  
Old July 25th, 2004, 06:55 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: win32 - svchost

Quote:
Originally Posted by sbsd
...If I look at Task Manager and then processes I see 5 or sometimes 4 processes called svchost.exe. I use Windows XP, is this normal?...

This is correct

Cheers
Attached Images
 
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #3  
Old July 25th, 2004, 07:26 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,947
Default Re: win32 - svchost

You have services running from dynamic-link libraries (DLLs). At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can indeed be multiple instances of Svchost.exe running at the same time.

Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:46 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums