why is my svchost.exe doing this?

Sunday, March 14, 2004 by Lord Vimal | Discussion: WinCustomize Talk

hi everyone.
long time no see i love wincustomize

ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???

Note: i guessed my internet act by looking at the status: Bytes recd, sent, etc... and that two lil blue comps in the system tray.

now WHY???

Thanks for helping out!
When i terminated SVCHOST.exe, after about a min, the GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???

Bye! will be back soon to see the replies...
First Previous Page 1 of 3 Next Last
Lord Vimal
Reply #1 Sunday, March 14, 2004 12:08 AM
still svchost.exe is accessing that akamai site. is there any way to stop this?
yrag
Reply #2 Sunday, March 14, 2004 12:11 AM
You sure that's not part of your ISP...?



Powered by SkinBrowser!
yrag
Reply #3 Sunday, March 14, 2004 12:18 AM
OK....let's try this...do you have a Firewall?



Powered by SkinBrowser!
Essencay
Reply #4 Sunday, March 14, 2004 12:19 AM
GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???


might be mistaken...but this sounds like explorer.exe crashed then reloaded itself when you ended the svchost.exe service

http://support.microsoft.com/?kbid=314056 from MS explains what it is
DavidK
Reply #5 Sunday, March 14, 2004 12:22 AM

run either Ad Aware or Spy Bot - they should get rid of it...

Ad Aware: http://lavasoft.element5.com/software/adaware/

Spy Bot: http://www.safer-networking.org/

Essencay
Reply #6 Sunday, March 14, 2004 12:24 AM
http://www.computerhope.com/issues/ch000517.htm is a more user friendly explanation
DavidK
Reply #7 Sunday, March 14, 2004 12:25 AM

btw - it's not svchost.exe doing it, it's more likely a data mining mind-melding shape-shifting reptillian cookie...

nasty buggers...

DavidK
Reply #8 Sunday, March 14, 2004 12:27 AM

oh also - download stinger (new version today)

http://vil.nai.com/vil/stinger/

if it is a virus stinger should catch it.

yrag
Reply #9 Sunday, March 14, 2004 12:28 AM
hummm....my guess is he's not answering 'cause he wacked his connection. Love it when peeps just terminate things and then ask "...what was that anyway?"


data mining mind-melding shape-shifting reptillian cookie






Powered by SkinBrowser!
Lord Vimal
Reply #10 Sunday, March 14, 2004 1:25 AM
hey my connections fine
will download stinger and see i am on a 56k, so it might take some time.

yrag: i have only the inbuilt firewall in Windows XP enabled. is that ok? or should i get ZoneAlarm?
yrag
Reply #11 Sunday, March 14, 2004 1:28 AM
The ZA free version is better then XP firewall. You can stop these apps from accessing the net by taking away server rights in your firewall settings.
Lord Vimal
Reply #12 Sunday, March 14, 2004 1:39 AM
lol , stinger is just under 1 mb. i will scan when i am offline and kill any virus

thanks!
DavidK
Reply #13 Sunday, March 14, 2004 1:47 AM
don't forget the spy-bot/ad-aware bit too... they get all the spyware off your machine.
IPlural
Reply #14 Sunday, March 14, 2004 4:40 AM

Domain Name: AKAMAI.COM
Registrar: TUCOWS INC.
Whois Server: whois.opensrs.net
Referral URL: http://domainhelp.tucows.com
Name Server: YH.AKAMAI.COM
Name Server: YG.AKAMAI.COM
Name Server: YC.AKAMAI.COM
Name Server: USE1.AKAM.NET
Name Server: EUR1.AKAM.NET
Name Server: ASIA2.AKAM.NET
Name Server: NS1-2.AKAM.NET
Name Server: NS1-3.AKAM.NET
Name Server: NS1-42.AKAM.NET
Name Server: EUR2.AKAM.NET
Name Server: NS1-137.AKAM.NET
Name Server: USE3.AKAM.NET
Status: REGISTRAR-LOCK
Updated Date: 17-nov-2003
Creation Date: 17-aug-1998
Expiration Date: 16-aug-2007

-

Name: www-8cc.akamai.com
IP Address: 80.67.70.22
Location: Unknown
Network: 80-RIPE



OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL

ReferralServer: whois://whois.ripe.net

NetRange: 80.0.0.0 - 80.255.255.255
CIDR: 80.0.0.0/8
NetName: 80-RIPE
NetHandle: NET-80-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: AUTH62.NS.UU.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate:
Updated: 2003-09-19

OrgTechHandle: RIPE-NCC-ARIN
OrgTechName: RIPE NCC Hostmaster
OrgTechPhone: +31 20 535 4444
OrgTechEmail: [email protected]


Looks to me that the IP Address before the TwoCows domain is a private network IP address behind the RIPE-NET Firewalls...
Passing though TwoCows for some reason...

Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...

Microsoft compiles information on everyone using msmsgr... I do not see why Yahoo wouldn't do it also...
Remove it, and run a tsr registry monitor such as ad-watch, or some other registry monitor so you know exactly when something is trying to change your registry and if you do not know what it is, or you are not installing anything youcan refuse to let the change happen. Then scan and clean before the fact and total infection...





from the sounds of the traffic you describe I would read this link... http://www.symantec.com/avcenter/venc/data/pwsteal.bstroj.html

If anything resembles the info on that link, disconnect from the net and scan/clean your system, log back on and then change your IM application passwords at least...


good luck
Lord Vimal
Reply #15 Sunday, March 14, 2004 5:33 AM
hi all
i just ran a test with stinger, found lots, which i already know, and found one which i didnt know for a long time. hhsetup.exe.. hmm..
removed it, now its fine no internet activity.
i am gonna get a firewall too. ZoneAlarm.
and i found this one in the registry, strange: (RUNONCE)

C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE

an AutoUpdater. Norton doesnt say its a virus, and when i right click that EXE no EXE details
but i didnt it anyway..

and one more program: htpatch.exe. whats this one??
\Windows\System32\htpatch.exe

nothing else
Thanks a lot.
Fuzzy Logic
Reply #16 Sunday, March 14, 2004 5:41 AM
Both hhsetup.dll and htpatch.exe are part of Windows. The hhsetup.dll can be used for remote attacks though if not patched. Do you keep Windows updated?
Lord Vimal
Reply #17 Sunday, March 14, 2004 5:46 AM
and i found this one too. the Process "System" had opened a port 445(local) 1571(remote) to remote IP: 68,73,201,123 with host name:
adsl-68-73-201-123.dsl.sfldmi.ameritech.net
now what is this one? a hacker???

how come did he gain control of my system process??
Lord Vimal
Reply #18 Sunday, March 14, 2004 8:50 AM

no i dont keep windows updated. just because i am lazy... my internet connection is so slow that i even hate downloaing 1MB. 5 MB ZoneAlarm took 30 min of my precious time
anyway ZoneAlarm is nice..
Sput
Reply #19 Sunday, March 14, 2004 9:10 AM
no i dont keep windows updated. just because i am lazy...


...would you be too lazy to lock your doors when you leave the house? Consider it worse to leave Windows unpatched and connected to the net as your inviting billions of potential attackers into your "home" whenever you connect.

An unpatched Windows XP system is compromised in under 10 minutes of being connected to the interenet acording to research done by a honey net research group...that's without taking any steps to draw attention to itself too (though without any firewall). A sobering statistic, you might like to balance against your "lazyness"....
White_Moth
Reply #20 Sunday, March 14, 2004 9:25 AM
An unsecured machine is an outrage, as it makes Internet usage for the rest of us more difficult. Refusing to secure a machine is akin to being a lowlife hacker, as you become a tool for them.



Powered by SkinBrowser!

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01