Re: svchost/tasklist

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 06/30/05


Date: Wed, 29 Jun 2005 19:04:25 -0400

From: "Adrian Bailey" <dadge@hotmail.com>

| I want to check that all my running svchosts are genuine, so I tried to run
| tasklist in msdos, but it doesn't work. Any ideas?
|
| Thanks, Adrian
|

It's not a DOS program.

The problem is that the name SVCHOST.EXE is used by *many* forms of malware.

Malware files that use that name will NOT be in %windir%\system32

So if the file is located in %windir% or %windir%\sytem then it it has a very high
probability of being malware.

The best way to check is to scan the system using anti virus/anti malware software.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: hard drive problem
    ... entire malware files. ... But if a program had access to the IDE disk interface it could force ... A malware program would have no idea where to look for such fragments. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: www.free-virusscan.com
    ... HJT and Deckard's utility create log files of startup loactions where malware use to load ... The forums I posted have personnel who are trained at a malware university of sorts. ... the forum administratorcan then provide the malware files to the various anti malware ...
    (microsoft.public.security.virus)
  • Re: is this real?
    ... Enable your firewall. ... Lanwench points out that a genuine 835732 exists, ... then it's most likely to be malware. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Re: Synchronization Manager
    ... >>If it is the genuine MS file and not malware, ... The following tip applies to XP also, and maby W2K. ... Prev by Date: ...
    (microsoft.public.win2000.registry)