Svchost got attacked ?

Discussion in 'other anti-malware software' started by lunarlander, Aug 29, 2017.

  1. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Hi,

    Can someone check their Windows 10 Home Creators Update Event Viewer ? I have an application error Event ID 1000 in the Application Log. The faulting application name is svchost_AppReadiness. and the faulting module is ntdll.dl

    It might have occurred during a Windows Update but the log entry was on Aug 3, 2017 a few weeks ago so I can't remember what I was doing then.

    I was doing Windows Update on another Win10 Home machine yesterday, and the same error occured.

    If I can get a member to verify for me that this error also occured on their machine, then I need not worry. Simply create a filter for Event ID 1000 and Application log.
     
    Last edited: Aug 29, 2017
  2. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,954
  3. guest

    guest Guest

    I have seen it too after installing a windows update some time ago, the service of AppReadiness has crashed.
    There is nothing to worry about :)
    Code:
    analysis of the dmp-file in the CrashDumps-directory (svchost.exe.[xxx].dmp)
    
    FAULTING_SERVICE_NAME:  AppReadiness
    FAILURE_PROBLEM_CLASS:  SVCHOSTGROUP_AppReadiness_HEAP_CORRUPTION
    
     
    Last edited by a moderator: Aug 29, 2017
  4. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Hi mood,

    Yours is different from mine. My Event ID 1000 was for svchost_AppReadiness. Maybe they are the same, as yours probably happened when it was a different Windows version & build. Was yours a Event ID 1000 too ?

    Hi Brummelchen,

    In my experience, applications rarely crash. It could be a buffer overflow. And svchost is network reachable, which makes more of a danger signal. And AppReadiness runs under the System account.
     
    Last edited: Aug 29, 2017
  5. guest

    guest Guest

    Yes, it was. In the Event-log i can see:
    Code:
    Event-ID 1000
    faulting application: svchost.exe_AppReadiness, Version: 10.0.15063.0
    faulting module: ntdll.dll, Verson: 10.0.15063.447
    ... application: C:\Windows\System32\svchost.exe
    ... module: C:\Windows\SYSTEM32\ntdll.dll
     
  6. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Hi mood,

    Can you do a Windows update now and see if my error occurs? I re-imaged the HD and just did a Windows Update, and the error is re-occurring. But it could just mean that the attackers attacked again, rather than it being an safe-to-ignore event.
     
  7. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,220
    Location:
    UK
  8. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Thanks stapp.

    What you linked to is the same error as mine. Good to know that it is normal and not an attack. Thanks everyone for their help.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.