why is my svchost.exe doing this?
Sunday, March 14, 2004 by Lord Vimal | Discussion: WinCustomize Talk
long time no see
i love wincustomize 
ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???
Note: i guessed my internet act by looking at the status: Bytes recd, sent, etc... and that two lil blue comps in the system tray.
now WHY???

Thanks for helping out!
When i terminated SVCHOST.exe, after about a min, the GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???
Bye! will be back soon
to see the replies...
Reply #42 Monday, March 15, 2004 3:33 AM
| ypager.exe is the executable program for Yahoo Messenger. Actually it is a Helper app for the Yahoo Messenger... as the links I posted show...It is also something being used to tunnel into users computers...again as the links I posted show |
No... Ypager.exe is the executable for Yahoo Messenger. It is not a helper, it is the program used to launch Yahoo Messenger. The actual Ypager.exe, normally installed in the C:/Program Files/Yahoo!/Messenger/ directory is NOT being used as a tunnel into users' computers. The trojan which sometimes uses the name Ypager.exe installs itself in the Windows System directory and in the registry under a completely different key. That trojan and how to detect it is what the link you provided actually shows. The file location of the Ypager.exe file and more importantly the registry entry are the keys to recognizing the difference.
Furthermore, that trojan is almost 2 years old, had a very low infection rate in an extremely limited geographical area if you research a bit more on the link you provided. Before advising someone to remove something from their computer, it might be advisable to do some simple checks to make sure of what you are advising them to remove.
When you see hoofprints, don't automatically start looking for zebras.
[Message Edited]
Reply #43 Monday, March 15, 2004 5:37 AM
. Of course, I do have 320Gb of storage on which to put my backups....Another advantage of DI 7 is you do your backups in Windows, and can even carry on working

Reply #44 Monday, March 15, 2004 6:55 AM

Reply #45 Monday, March 15, 2004 8:21 AM
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???
Looks to me that the IP Address before the TwoCows domain is a private network IP address behind the RIPE-NET Firewalls...
Passing though TwoCows for some reason...
Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...
| No... Ypager.exe is the executable for Yahoo Messenger. It is not a helper, it is the program used to launch Yahoo Messenger. The actual Ypager.exe, normally installed in the C:/Program Files/Yahoo!/Messenger/ directory is NOT being used as a tunnel into users' computers. The trojan which sometimes uses the name Ypager.exe installs itself in the Windows System directory and in the registry under a completely different key. That trojan and how to detect it is what the link you provided actually shows. The file location of the Ypager.exe file and more importantly the registry entry are the keys to recognizing the difference. |
Yep I stand corrected, ypager is in fact the messenger and it should show up in the process (task_list) list as Ymsgr_tray under NT (NT4, 2000, XP and 2003 )
That is if it is not one that has been modified in some manner, which can be put on ones system from any download and installation of any application off the net if it is modified or created to do so upon installation.
| Furthermore, that trojan is almost 2 years old, had a very low infection rate in an extremely limited geographical area if you research a bit more on the link you provided. Before advising someone to remove something from their computer, it might be advisable to do some simple checks to make sure of what you are advising them to remove. When you see hoofprints, don't automatically start looking for zebras. |
Furthermore you totally went past my first possibility suggested that it is in fact acting as a data-miner... nice...
Adam if you think that something that is 2, 3, 5 8 years past when it comes to trojan, virus and worms is nothing to worry about then you will learn some seriously hard things over time. As far as Limited geographical are goes that is also something that is on one point something to consider and on another something totally inane. Your speaking of the interenet where Russia is only a matter of moments away from the USA. I could list over 200 sites with such black hat, script kiddy and jerk off apps on them which include that decompile/re-compile of the ypager...
As far as simple checks go and your suggestion that advising Vimal to remove the offending app, clean, reinstall and take better control of his system before advising him to do so. I did some simple checks, I traced the IP address back to the private network which his system was attempting to connect with which is outside the Yahoo network from what can be found without contacting RIPE-NET's admins. (That isn't up to me to do and it is moot when doing what was suggested is done because it should not continue was completed)
Zebra tracks have squat to do with a application attempting to use an unknown or act as it's own http (web) proxy server. If he did not configure it to do so for a specific reason ( if he had done this he would damn well know it, and if it was setup to do this he would have had to have set it up, sp it lends to the application NOT functioning in the normal manner which lends to it being MODIFIED in some manner )
Microsoft compiles information on everyone using msmsgr... I do not see why Yahoo wouldn't do it also...
Remove it, and run a tsr registry monitor such as ad-watch, or some other registry monitor so you know exactly when something is trying to change your registry and if you do not know what it is, or you are not installing anything youcan refuse to let the change happen. Then scan and clean before the fact and total infection...
from the sounds of the traffic you describe I would read this link... Link
If anything resembles the info on that link, disconnect from the net and scan/clean your system, log back on and then change your IM application passwords at least...
good luck
On Vimal's system YPager is in fact passing through as it is or is running through a HTTP:port 80, 8080, 1080 (not sure exactly which because I am not on his system to check it) proxy server. ( Hence the refereces to tunneling, which is exactly what is taking place by description and definition)
Further on in my post to him I described what to do, which was to make sure he cleaned his system of it, ran a check and then logged back into the service. I am sorry I did not hold his hand or paint a glowing green floressent line on the screen with the blow by blow steps in doing this. But I figured anyone able to log onto the net, make use of a message board and read would have be able to put it together without doing that.
Uninstall ypager.exe, clean the registry, clean any left over files off the drive, reboot, make sure that your AV aoftware is open and active, reinstall ypager from a new download off Yahoo. Log banc in and everything that possibly could be wrong should be fine.
Better?
[Message Edited]
Reply #46 Monday, March 15, 2004 11:39 AM
| Yep I stand corrected, ypager is in fact the messenger and it should show up in the process (task_list) list as Ymsgr_tray under NT (NT4, 2000, XP and 2003 ) |
That depends on how Yahoo is configured to load. If Yahoo is not configured to load at startup, or has been exited completely and is subsequently launched from a Quicklaunch or Desktop icon, it will show in the task list as YPager.exe.
As for the rest of your latest post, I am not sure whom you are trying to impress, but you appear to be addressing your post to me. Or perhaps you're simply venting frustration. I'm not sure what the purpose is, and frankly I don't care. From your first post in this thread, you siezed upon the PWSteal.BStroj trojan based on limited information which none of us is even sure is correct. We are after all, talking about someone whom does not even know what svchost, hhsetup, and htpatch are and couldn't be bothered to update his OS with hotfixes because he's self-admittedly too lazy. I do find it interesting that he has posted twice saying that he had run stinger and Norton AV and made no comment in either case about finding either the PWSteal.BStroj trojan or any other virus/trojan/etc related to YPager.exe.
I'm not trying to engage in some type of pissing contest here. All I was trying to do was point out that given the information we had from Lord Vimal, or perhaps the lack thereof, there are numerous alternative explanations for what is/was going on with his system.
I have been impressed by your knowledge from the first few times I visited this board and saw some of your posts, IP, and nothing, including what has been posted in this thread, has altered my initial impression. If you feel I have somehow slighted you by correcting some information that was posted here, then I apologize. That was not my intent. All I was attempting to do was to correct some information which I felt was posted in error. We all have made mistakes from time to time, and often those mistakes are caused by us receiving incomplete and incorrect information from the person we are trying to help.
[Message Edited]
Reply #47 Monday, March 15, 2004 5:45 PM
eh, no pissing contest here either, sides all it doesn't is stain the desktop and if your bad of aim there is no telling what will happen to the monitor or other hardware sittin ear it

seriously, I do apologise for it.
Reply #48 Monday, March 15, 2004 5:52 PM

Reply #49 Tuesday, March 16, 2004 10:55 AM
well, i just installed a firewall. blocked internet access to few programs, now its fine.i guess, there was a program: yupdater.exe, denied access to it.and also denied access to SVCHOST.exe (Generic process) from acting as a server.
and now its fine 
Thanks for all your help though. Hey, regarding the free Microsoft Update CD, how can i get it?? any links??
Thanks
-=[ Vimal ]=-
Reply #50 Tuesday, March 16, 2004 11:00 AM
Bye!

Reply #51 Tuesday, March 16, 2004 5:34 PM
| i guess, there was a program: yupdater.exe, denied access to it.and also denied access to SVCHOST.exe (Generic process) from acting as a server. |
Just so you know, assuming that yupdater.exe was the original file you received from Yahoo!, this program needs to have access to the net in order to function. It is the program which checks for updates and security fixes for Yahoo! Messenger. If you plan to continue using Yahoo! Messenger, I would seriously recommend that you allow access to this program and install the updates as they become available. All messenger programs, especially those that permit file transfers of any kind, are targeted by hackers and other mischief makers. Update patches and fixes come out frequently to help fight those vulnerabilities.
By the way, disabling access for SVCHOST.exe may also prevent some of your software from functioning, but without knowing what else is on your computer, I can't say that for sure... You'll find out when you get the error message, if it applies to you.
Of course, updates, patches and hotfixes only work if you actually download and install them.

Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #41 Monday, March 15, 2004 1:31 AM