help im running some svchost.exe

Discussion in 'other security issues & news' started by drakon3rd, Aug 25, 2005.

Thread Status:
Not open for further replies.
  1. drakon3rd

    drakon3rd Registered Member

    Joined:
    Aug 25, 2005
    Posts:
    3
    can u tell me which if they all should be running

    Image Name PID Services
    ========================= ====== =============================================
    System Idle Process 0 N/A
    System 4 N/A
    smss.exe 604 N/A
    csrss.exe 652 N/A
    winlogon.exe 676 N/A
    services.exe 720 Eventlog, PlugPlay
    lsass.exe 732 PolicyAgent, ProtectedStorage, SamSs
    svchost.exe 900 DcomLaunch, TermService
    svchost.exe 968 RpcSs
    svchost.exe 1064 AudioSrv, BITS, CryptSvc, Dhcp, dmserver,
    ERSvc, EventSystem,
    FastUserSwitchingCompatibility, helpsvc,
    lanmanserver, lanmanworkstation, Netman,
    Nla, NwSapAgent, RasMan, Schedule, seclogon,
    SENS, SharedAccess, ShellHWDetection,
    TapiSrv, Themes, TrkWks, W32Time, winmgmt,
    wscsvc, WZCSVC
    svchost.exe 1176 Dnscache
    svchost.exe 1324 Alerter, LmHosts, RemoteRegistry, SSDPSRV,
    WebClient
    spoolsv.exe 1480 Spooler
    explorer.exe 1752 N/A
    winampa.exe 1820 N/A
    rundll32.exe 1852 N/A
    jusched.exe 1908 N/A
    avgcc.exe 1916 N/A
    qttask.exe 1940 N/A
    aim.exe 2024 N/A
    ctfmon.exe 128 N/A
    avgamsvr.exe 1084 Avg7Alrt
    avgupsvc.exe 1112 Avg7UpdSvc
    nvsvc32.exe 1304 NVSvc
    svchost.exe 1976 stisvc
    wdfmgr.exe 1800 UMWdf
    wscntfy.exe 1588 N/A
    alg.exe 2144 ALG
    taskmgr.exe 3164 N/A
    msn.exe 3632 N/A
    msnmsgr.exe 3844 N/A
    cmd.exe 2412 N/A
    tasklist.exe 2420 N/A
    wmiprvse.exe 2452 N/A
     
  2. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,694
    Location:
    Texas
    What little icons, in the system tray do you see, after startup? Bottom right near the clock. Also google the entries!

    rico
     
  3. Tassie_Devils

    Tassie_Devils Global Moderator

    Joined:
    May 8, 2002
    Posts:
    2,514
    Location:
    State Queensland, Australia
    Hi drakon3rd, welcome to wilders :)

    OK, The vast majority of those would be legit obviously, but others need to be checked out.

    Legit eg: jusched.exe is a process installed alongside Sun Microsystem's Java2 suite.

    Now, a good place to start is http://www.liutilities.com/products/wintaskspro/processlibrary/ scroll down to 'Top applications listed in wintasks process library' see if you can find your process, click for more information on it.

    Also go here: http://startup.iamnotageek.com/ There are 99 :) pages of startup apps, descriptions, etc. for you to research.

    Another place to look [but you will have to Register, it's free] is Bleeping Computers, which also has a comprehensive lists of startups. http://www.bleepingcomputer.com/ [pic attached]

    If you do this, and can rule out the vast majority, then resubmit those you are unsure of, someone would be able to help further, but from just having a quick look over you list personally, I could not vouch for a few of them as probably don't have those installed. You need to see what they are for, do you have a program installed that uses those, and is it necessary for them to be actually running without the program running.

    EDIT: arrgghh Upon re-reading your post headlines, I see you were really asking about the NUMBER of svchost.exe.. lol....

    see my 3rd post below. Still, check out the rest of the services.

    Cheers, TAS
     

    Attached Files:

    Last edited: Aug 25, 2005
  4. Tassie_Devils

    Tassie_Devils Global Moderator

    Joined:
    May 8, 2002
    Posts:
    2,514
    Location:
    State Queensland, Australia
    Example: At Iam Not a Geek site, you put in the app in the search box on right hand side and hit go.

    I searched there for this entry "wscntfy.exe" and get this [pic attached]. So therefore you'd have to search further elsewhere.

    Google gives: Process File: wscntfy or wscntfy.exe Process Name: Microsoft Windows Security Center ... wscntfy.exe is a part of the Microsoft Windows Security system.
    So therefore you have the Windows Security Centre [WSCNT] running. :D

    Cheers, TAS
     

    Attached Files:

  5. Tassie_Devils

    Tassie_Devils Global Moderator

    Joined:
    May 8, 2002
    Posts:
    2,514
    Location:
    State Queensland, Australia
    svchost.exe running... Yes, having several of those running is normal...

    as long as you don't see a missmatch in wording... like scshost/scvhost/etc. They look similar but are bad.

    mine...

    Sorry about misinterpreting your first post, just that I saw the complete list of process, and you asked at top should I have all these running, then I realised you were talking about the heading you put on the thread.

    Cheers, TAS
     

    Attached Files:

Loading...
Thread Status:
Not open for further replies.