Welcome to the North American Subaru Impreza Owners Club Sunday November 22, 2009
Home Forums *** WikiNASIOC *** Products Store Modifications Upgrade Garage
NASIOC
Here you can view your subscribed threads, work with private messages and edit your profile and preferences Home Registration is free! Visit the NASIOC Store NASIOC Rules Search
Find other members Frequently Asked Questions Calendar Archive NASIOC Upgrade Garage Logout

Go Back   NASIOC > NASIOC Miscellaneous > Off-Topic

Welcome to NASIOC - The world's largest online community for Subaru enthusiasts!
Welcome to the NASIOC.com Subaru forum.

You are currently viewing our forum as a guest, which gives you limited access to view most discussions and access our other features. By joining our community, free of charge, you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is free, fast and simple, so please join our community today!

If you have any problems with the registration process or your account login, please contact us.
* Registered users of the site do not see these ads.
Reply
 
Thread Tools Display Modes
Old 03-14-2004, 03:06 PM   #1
meebs
Scooby Specialist
 
Member#: 3251
Join Date: Dec 2000
Chapter/Region: NWIC
Location: Bonney Lake, WA
Vehicle:
2004 WRX Wagon
JBP

PWN3D does someone have me by the cahones??

Everytime I start up my comp, there are 4 instances of svhost.exe in the processes tab of the task manager. One owned by LOCAL SERVICE, nothing going on there. One owned by NETWORK SERVICE, again nothing going on. The last two are owned by SYSTEM, one is 4 megs, like the others, and the last one is 19 Megs.

The last one causes my net connection to hit something, somewhere at a constant 1.7k/sec, and use about 2% of my cpu. If I kill it, my connection is fine, and it quells the network activity... but then my soundcard "goes away". And in sound options it offers "Modem #0 Line Playback" and Modem #0 Handset Playback"...

ZAPRO shows that it is "generic host processes for Win32 services", that has activity.

Plus, my router has been saying this once every 6 hours or so...

"DoS Attack type : UDP Bomb!!"

Norton Antivirus reports everything is ok... I'm going to go buy the "system works" package soon.
Have I been pwned??
meebs is offline   Reply With Quote
Old 03-14-2004, 03:17 PM   #2
Skyline
Scooby Specialist
 
Member#: 6074
Join Date: Apr 2001
Location: New York
Vehicle:
2002 Impreza WRX
Sedona Red Pearl

Default

Oh yeah! Well... I have 5 svhost.exe processes running!



(I wouldn't worry about it. Just make sure your NAV is updated, and you also run Spybot.)
Skyline is offline   Reply With Quote
Old 03-14-2004, 03:37 PM   #3
pjcoregon
Scooby Specialist
 
Member#: 15384
Join Date: Feb 2002
Location: -=OT BLAMESTORMING=-
Vehicle:
OT Imprezadent of
Winesnobbery-red division

Default

No, you are likely fine (you have Zone ALarm, a router, and NAV running)... that makes for a pretty well protected machine.

Svchost, as the name implies, stands for "Service Host". Components are often implemented as services - a geek name for programs that run in the background, and aren't necessarily associated with whomever is logged into the machine.
pjcoregon is offline   Reply With Quote
Old 03-14-2004, 03:38 PM   #4
Gil
NASIOC Supporter
 
Member#: 20872
Join Date: Jul 2002
Chapter/Region: Tri-State
Location: Rah-cha-cha, NY
Vehicle:
t3h rubber-neckers
must die!

Default

what do these background programmes do?
Gil is offline   Reply With Quote
Old 03-14-2004, 03:39 PM   #5
Neek
Scooby Specialist
 
Member#: 3400
Join Date: Jan 2001
Chapter/Region: South East
Location: Boca Raton, FL
Vehicle:
2008 BMW 335i Conv.
2007 Triumph Speed Triple

View Member's FaceBook Profile
Default

I have no idea what you said, but I know that the word you want is cojones
Neek is offline   Reply With Quote
Old 03-14-2004, 03:51 PM   #6
pjcoregon
Scooby Specialist
 
Member#: 15384
Join Date: Feb 2002
Location: -=OT BLAMESTORMING=-
Vehicle:
OT Imprezadent of
Winesnobbery-red division

Default

Quote:
Originally posted by gil_ong81
what do these background programmes do?
they can be a generic processes like the print spooler (for printing), the plug and play process to recognize new devices, etc.
pjcoregon is offline   Reply With Quote
Old 03-14-2004, 04:05 PM   #7
catass
Scooby Specialist
 
Member#: 31976
Join Date: Jan 2003
Location: Philadelphia, PA
Vehicle:
2004 WRX STi
World Rally Blue

Default

If you have winxp type "tasklist /svc" in a cmd window. It will show you which services each svchost.exe is running. In win2k I believe it's tlist instead of tasklist.
catass is offline   Reply With Quote
Old 03-14-2004, 04:08 PM   #8
adeliciouspizza
Scooby Specialist
 
Member#: 7844
Join Date: Jun 2001
Location: NorthEast Wisconsin
Vehicle:
05 STI CGM
SUBYSHOP.COM FTW

Default

http://vil.nai.com/vil/stinger
http://www.safer-networking.org/index.php?page=download
http://download.com.com/3000-2144-10...age&tag=button

those 3 free tools are all you need. make sure you update spoybot & adware before you scan as they are both pretty out of date when first installed. also, you should run 'msconfig' (xp has it, 2k does not but there is a version available for download). that will show you exactly what is being loaded when you start your computer and is an invaluable tool to secure your system. pm me if you have any questions.

edit: oops, almost forgot. make sure all available critical and reccomended updates are installed. check http://windowsupdate.microsoft.com if you arent sure. also, run the ms baseline security analyzer to check to make sure you dont have any gaping security flaws. you can get it here: http://www.microsoft.com/technet/sec...on123121120120
adeliciouspizza is offline   Reply With Quote
Old 03-14-2004, 04:15 PM   #9
pjcoregon
Scooby Specialist
 
Member#: 15384
Join Date: Feb 2002
Location: -=OT BLAMESTORMING=-
Vehicle:
OT Imprezadent of
Winesnobbery-red division

Default

Quote:
Originally posted by weitek
http://vil.nai.com/vil/stinger
http://www.safer-networking.org/index.php?page=download
http://download.com.com/3000-2144-10...age&tag=button

those 3 free tools are all you need. make sure you update spoybot & adware before you scan as they are both pretty out of date when first installed. also, you should run 'msconfig' (xp has it, 2k does not but there is a version available for download). that will show you exactly what is being loaded when you start your computer and is an invaluable tool to secure your system. pm me if you have any questions.
svchost can run without an indentifiable reference... it can also be launched from with a dll and may not have an obvious program it is associated with... the only app that I know that will specifically identify them for you is WinTasks 4.
pjcoregon is offline   Reply With Quote
Old 03-14-2004, 04:19 PM   #10
meebs
Scooby Specialist
 
Member#: 3251
Join Date: Dec 2000
Chapter/Region: NWIC
Location: Bonney Lake, WA
Vehicle:
2004 WRX Wagon
JBP

Default

thanks for the replies.
meebs is offline   Reply With Quote
Old 03-14-2004, 04:28 PM   #11
GZoomer
NASIOC Supporter
 
Member#: 664
Join Date: Dec 1999
Location: minocqua,wi USA
Vehicle:
2003 Legacy GT
Black

Talking

at the command prompt with out any other programs running type "netstat". This will bring up a list of currrent network connections. On most computer the only connection you should see are you computer connecting back to your self. If you see connection to address other that your self start terminating services and check the the list after each service is killed. If you computer is owned by someone else Norton or most of the other utils that I'm aware of will not find it. Best way to deal with this is grab the original media that came with the computer. Backup all your data files and reformat. Disclaimer I'm not responsible for any data lose or lose of functionality of you computer. Good luck.
GZoomer is offline   Reply With Quote
Old 03-14-2004, 05:05 PM   #12
pjcoregon
Scooby Specialist
 
Member#: 15384
Join Date: Feb 2002
Location: -=OT BLAMESTORMING=-
Vehicle:
OT Imprezadent of
Winesnobbery-red division

Default

Quote:
Originally posted by GZoomer
at the command prompt with out any other programs running type "netstat". This will bring up a list of currrent network connections. On most computer the only connection you should see are you computer connecting back to your self. If you see connection to address other that your self start terminating services and check the the list after each service is killed. If you computer is owned by someone else Norton or most of the other utils that I'm aware of will not find it. Best way to deal with this is grab the original media that came with the computer. Backup all your data files and reformat. Disclaimer I'm not responsible for any data lose or lose of functionality of you computer. Good luck.
reformatting and starting over is just about the worst suggestion you could make for him.

you are correct regarding netstat... it will show active connections

he has zone alarrm pro running (ZAPRO)... it can and does stop outward bound connections and does resolve the addresses for your connections... which is a lot easier than using netstat (he would still need to do an address translation).

Norton does get rid of trojans as long as it is kept up to date (which it does on its on)... other than running spybot and adawar... there really isn't much he shold worry about.
pjcoregon is offline   Reply With Quote
Sponsored Links
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


Message Board Statistics All times are GMT -4. The time now is 01:31 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©1999 - 2009, North American Subaru Impreza Owners Club, Inc.