Win XP: svchost.exe and spyware
Friday, December 13, 2002 at 12:21 pm Windows XP Annoyances Discussion Forum
Posted by Newbulus_Maximus
(12 messages posted)
When I run a netstat -o, two connections are open to two parasitic search (lop.com)
websites:
Proto Local Address Foreign Address State PID
TCP ankara:1075 207.46.144.86:http CLOSE_WAIT 740
TCP ankara:1080 www4.maxexp.com:http CLOSE_WAIT 740
TCP ankara:1082 www4.maxexp.com:http CLOSE_WAIT 740
TCP ankara:1099 wfix.com:http
When I run task tasklist /svc, to see which process those connections belong too,
it belongs to svchost.exe which is generic because it hosts many applications - which
is why I can't just kill it:
svchost.exe 740 AudioSrv, BITS, Browser, CryptSvc, Dhcp,
dmserver, ERSvc, EventSystem, helpsvc,
lanmanserver, lanmanworkstation, Messenger,
Netman, Nla, RasMan, Schedule, seclogon,
SENS, ShellHWDetection, srservice, TapiSrv,
TrkWks, uploadmgr, W32Time, winmgmt,
WmdmPmSp, wuauserv
I tried to locate the application and it's path that opens these two connections
to no avail. Can anyone give me any idea how to do this? Or suggest a way to get
rid of this spyware?
|
Responses to this message:
|
|
All messages in this thread [show all]
 | Win XP: svchost.exe and spyware (Newbulus_Maximus: Fri, Dec 13, 2002, 12:21 pm) |
| |
| |
| |
Return to the Windows XP Discussion Forum
|
|