Computing.Net > Forums > Security and Virus > SVCHOST.EXE virus???

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

SVCHOST.EXE virus???

Reply to Message Icon

Name: Ryan
Date: December 16, 2003 at 05:50:13 Pacific
OS: Windows XP (SP1)
CPU/Ram: P3 1GhZ/256 RAM
Comment:

hi guys,

ok well, this virus problem is fixed first of all. i have zonealarm running in the background, and sometimes it asks me to allow SVSHOST.exe access to the internet. now the question is, how do i know that SVCHOST.exe is genuine? is there i can find out? because i recently healed/deleted a virus in this folder:

C:\Windows\Systems32\Wins\Svchost.exe

any suggestions on how to tell?



Sponsored Link
Ads by Google

Response Number 1
Name: ranchhand
Date: December 16, 2003 at 07:22:56 Pacific
Reply:

svshost.exe is a system file used for various purposes depending on what program calls on it:

http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/Q250/3/20.ASP&NoWebContent=1

and

http://www.grtg.org/stuff/computers/windows/svchost_exe.php



0

Response Number 2
Name: elric
Date: December 16, 2003 at 09:08:39 Pacific
Reply:

G'day,

svchost.exe can also be altered/ compromised by viruses or spyware.
Check that the version that you have in your windows/system directory is valid.
If not, delete it and restore the original.
regards and seasons greetings,
Elric


0

Response Number 3
Name: iceblue
Date: December 17, 2003 at 04:20:33 Pacific
Reply:

Ryan, it looked like svShost was a typo, just checking on that.. as there are many variants. I kept getting thrown by the sheer number, and ended up making a shortlist. It looks like a case of "Dude, Where's my Virus???" but here goes.

**The legitimate files are found in the WINNT folder, and in the System32 folder
These are:
c:\ Winnt\Svchost.exe ; c:\ System32\svchost.exe

WARNING: These are vital Windows system file, and should not be touched!


>>>>>>>>>>>>>>>>>>>>>>>

SVC variants – Trojans, viruses and hijackers
These are usually found in the Windows folder and are often in plural form.

c:\windows\svchosts eg. Troj/Hostidel.B
c:\windows\svchostc.exe
c:\WINDOWS\svchost32.exe eg. Nachi Worm.
c:\Windows\system\svchosts.exe eg. Sdbot-N / Troj/Sdbot-Z virus!

However, there are these to check for in the system folders.
C:\WINDOWS\SYSTEM\svchost32.exe eg. BackDoor-AQT
C:\WINDOWS\SYSTEM32\svchosts.exe eg. IRC-Sdbot trojan

Restart your computer, and delete these files in your Windows folder.

There are numerous variants of these floating around; observe carefully:
SCV variants:
c:\windows\scvhost.exe……….. scvhost.exe is a result of the W32/GAOBOT worm
c:\windows\SCVHOSTS.EXE……….Windows Print Spooler (SCVHOSTS.EXE);
>>>>>>>>>>>>>>>>>>

HTH, and hope it is all correct – let me know if not; and feel free to add in any other variations you have come across, as I’m happy to update this info.



0

Response Number 4
Name: ryan
Date: December 17, 2003 at 04:29:07 Pacific
Reply:

thanks iceblue. yeah it was a typo. it is svchost.exe. anyway, i was just wondering. just one more thing: how can tell from ZONEALARM, that svchost.exe is a virus or not when ZA asks for svchost.exe to access the internet? if there is way, please tell me. if there isn't, it's alright.

Ryan


0

Response Number 5
Name: iceblue
Date: December 17, 2003 at 04:29:45 Pacific
Reply:

ARRRGH...goddamn typo /cut and paste crap!!
[Damn I hate corrections]; but they are neccessary -coming in next post....]


0

Related Posts

See More



Response Number 6
Name: iceblue
Date: December 17, 2003 at 04:37:40 Pacific
Reply:

ok -answering that last one first...
I haven't got ZA, so intuitively i would say you can't tell easily, if it's a similar format to Sygate.

Best way to reveal the full path of running processes is by Process Explorer from Sysinternals (or a similar proggie).
http://www.sysinternals.com/ntw2k/freeware/procexp.shtml

Keep this in mind:
There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started.
It is normal for win processes to use cpu and normal for several concurrent svchost processes to happen. I have 4 or 5 usually.

The legit file for your XP system is

C:\WINDOWS\System32\svchost.exe

*note the slight change from the previous post above by the dipstick with the name similar to mine.......



0

Response Number 7
Name: iceblue
Date: December 17, 2003 at 04:44:31 Pacific
Reply:

Lets try that again.....

**For XP systems, the legitimate files are found in the System32 folder
These are:

C:\WINDOWS\System32\svchost.exe

WARNING: This is a vital Windows system file, and should not be touched!


>>>>>>>>>>>>>>>>>>>>>>>

SVC variants – Trojans, viruses and hijackers
These are usually found in the Windows folder and are often in plural form.

c:\windows\svchosts eg. Troj/Hostidel.B
c:\windows\svchostc.exe
c:\WINDOWS\svchost32.exe eg. Nachi Worm.
c:\Windows\system\svchosts.exe eg. Sdbot-N / Troj/Sdbot-Z virus!

However, there are these to check for in the system folders.
C:\WINDOWS\SYSTEM\svchost32.exe eg. BackDoor-AQT
C:\WINDOWS\SYSTEM32\svchosts.exe eg. IRC-Sdbot trojan

Restart your computer, and delete these files in your Windows folder.

There are numerous variants of these floating around; observe carefully:
SCV variants:
c:\windows\scvhost.exe……….. scvhost.exe is a result of the W32/GAOBOT worm
c:\windows\SCVHOSTS.EXE……….Windows Print Spooler (SCVHOSTS.EXE);
>>>>>>>>>>>>>>>>>>

HTH, and hope it is all correct – let me know if not; and feel free to add in any other variations you have come across, as I’m happy to update this info.


0

Response Number 8
Name: iceblue
Date: December 17, 2003 at 04:58:22 Pacific
Reply:

Each win service has a unique PID which is shown in Process Explorer, along with the full path of the service like C:\WINDOWS\System32\svchost.exe

You can compare the PIDs and check which service is running at any given time and whether it is the legit file in operation.

*Note - Sygate does have a toggle between Applications and Connections, in the 'View' tab which shows the PID and full path of the running service....Does ZA have this capability?


0

Response Number 9
Name: Ryan
Date: December 17, 2003 at 05:46:31 Pacific
Reply:

i don't think so. haven't really checked it out? is SYGATE free? i'll get process explorer as well. and out of all the TROJAN REMOVAL TOOLS out there, which in your opinion, is the best?

Ryan


0

Response Number 10
Name: iceblue
Date: December 17, 2003 at 13:51:03 Pacific
Reply:


Sygate has a free version.
Process Explorer is freeware.
The consensus in this forum for trojan protrction appears to be TDS-3 closely? followed by TrojanHunter...

http://www.diamondcs.com.au/tds/
(I'm not an expert in anti-troj proggies, and TDS-3 is on my to do list)


0

Response Number 11
Name: teri_smile
Date: December 28, 2003 at 17:53:34 Pacific
Reply:

hello,
lve been reading the above and got totally lost ..lm having problems with svchost.exe l rebooted my pc after some divx tools and it went all wild, my processor is at 100% and using a lot of memory, lm not brilliant at pcs l only know this because l openend up the xp windows task manager.l have ended the svchost that is chewing the processor but l still cant do anything ..also the client session manager closes because of a problem.

How ever in safety mode the proccessor and memory are ok ..its just when l boot up normally ..the computer is in over load ..l dont know if this is a virus ..help anyone ??



0

Response Number 12
Name: iceblue
Date: December 29, 2003 at 01:54:14 Pacific
Reply:

teri_smile
happy to help;
after running Spybot and HijackThis could you repeat the comments above, and summarise the results of the Spybot scan and post the Hijack log in a NEW thread, thanks

details at;
http://www.computing.net/security/wwwboard/forum/6433.html


0

Response Number 13
Name: phrogdriver
Date: January 27, 2004 at 17:06:20 Pacific
Reply:

I have two instances of svchost showing up in my Windows folder on my XP machine:

svchost in C:\Windows\System32

as well as:

svchost.exe-3530F672.PF in C:\Windows\Prefetch

Is this ok, or do I have issues I need to address (at the risk of opening myself up to a whole bunch of jokes...)


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: SVCHOST.EXE virus???

svchost.exe virus www.computing.net/answers/security/svchostexe-virus/10276.html

svchost.exe, Virus or Normal www.computing.net/answers/security/svchostexe-virus-or-normal-/15229.html

svchost.exe virus www.computing.net/answers/security/svchostexe-virus/7403.html