why is my svchost.exe doing this?
Sunday, March 14, 2004 by Lord Vimal | Discussion: WinCustomize Talk
long time no see
i love wincustomize 
ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???
Note: i guessed my internet act by looking at the status: Bytes recd, sent, etc... and that two lil blue comps in the system tray.
now WHY???

Thanks for helping out!
When i terminated SVCHOST.exe, after about a min, the GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???
Bye! will be back soon
to see the replies...
Reply #4 Sunday, March 14, 2004 12:19 AM
| GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this??? |
might be mistaken...but this sounds like explorer.exe crashed then reloaded itself when you ended the svchost.exe service
http://support.microsoft.com/?kbid=314056 from MS explains what it is
Reply #5 Sunday, March 14, 2004 12:22 AM
run either Ad Aware or Spy Bot - they should get rid of it...
Ad Aware: http://lavasoft.element5.com/software/adaware/
Spy Bot: http://www.safer-networking.org/
Reply #6 Sunday, March 14, 2004 12:24 AM

Reply #7 Sunday, March 14, 2004 12:25 AM
btw - it's not svchost.exe doing it, it's more likely a data mining mind-melding shape-shifting reptillian cookie...
nasty buggers...
Reply #8 Sunday, March 14, 2004 12:27 AM
oh also - download stinger (new version today)
http://vil.nai.com/vil/stinger/
if it is a virus stinger should catch it.
Reply #9 Sunday, March 14, 2004 12:28 AM
Reply #10 Sunday, March 14, 2004 1:25 AM

will download stinger and see
i am on a 56k, so it might take some time.yrag: i have only the inbuilt firewall in Windows XP enabled. is that ok? or should i get ZoneAlarm?
Reply #11 Sunday, March 14, 2004 1:28 AM
Reply #12 Sunday, March 14, 2004 1:39 AM

thanks!
Reply #13 Sunday, March 14, 2004 1:47 AM
Reply #14 Sunday, March 14, 2004 4:40 AM
Domain Name: AKAMAI.COM
Registrar: TUCOWS INC.
Whois Server: whois.opensrs.net
Referral URL: http://domainhelp.tucows.com
Name Server: YH.AKAMAI.COM
Name Server: YG.AKAMAI.COM
Name Server: YC.AKAMAI.COM
Name Server: USE1.AKAM.NET
Name Server: EUR1.AKAM.NET
Name Server: ASIA2.AKAM.NET
Name Server: NS1-2.AKAM.NET
Name Server: NS1-3.AKAM.NET
Name Server: NS1-42.AKAM.NET
Name Server: EUR2.AKAM.NET
Name Server: NS1-137.AKAM.NET
Name Server: USE3.AKAM.NET
Status: REGISTRAR-LOCK
Updated Date: 17-nov-2003
Creation Date: 17-aug-1998
Expiration Date: 16-aug-2007
-
Name: www-8cc.akamai.com
IP Address: 80.67.70.22
Location: Unknown
Network: 80-RIPE
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL
ReferralServer: whois://whois.ripe.net
NetRange: 80.0.0.0 - 80.255.255.255
CIDR: 80.0.0.0/8
NetName: 80-RIPE
NetHandle: NET-80-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: AUTH62.NS.UU.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate:
Updated: 2003-09-19
OrgTechHandle: RIPE-NCC-ARIN
OrgTechName: RIPE NCC Hostmaster
OrgTechPhone: +31 20 535 4444
OrgTechEmail: [email protected]
Looks to me that the IP Address before the TwoCows domain is a private network IP address behind the RIPE-NET Firewalls...
Passing though TwoCows for some reason...
Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...
Microsoft compiles information on everyone using msmsgr... I do not see why Yahoo wouldn't do it also...
Remove it, and run a tsr registry monitor such as ad-watch, or some other registry monitor so you know exactly when something is trying to change your registry and if you do not know what it is, or you are not installing anything youcan refuse to let the change happen. Then scan and clean before the fact and total infection...
from the sounds of the traffic you describe I would read this link... http://www.symantec.com/avcenter/venc/data/pwsteal.bstroj.html
If anything resembles the info on that link, disconnect from the net and scan/clean your system, log back on and then change your IM application passwords at least...
good luck
Reply #15 Sunday, March 14, 2004 5:33 AM
i just ran a test with stinger, found lots, which i already know, and found one which i didnt know for a long time. hhsetup.exe.. hmm..
removed it, now its fine
no internet activity.i am gonna get a firewall too. ZoneAlarm.
and i found this one in the registry, strange: (RUNONCE)
C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE
an AutoUpdater. Norton doesnt say its a virus, and when i right click that EXE no EXE details

but i didnt it anyway..
and one more program: htpatch.exe. whats this one??
\Windows\System32\htpatch.exe
nothing else

Thanks a lot.
Reply #16 Sunday, March 14, 2004 5:41 AM
Reply #17 Sunday, March 14, 2004 5:46 AM
adsl-68-73-201-123.dsl.sfldmi.ameritech.net
now what is this one? a hacker???
how come did he gain control of my system process??

Reply #18 Sunday, March 14, 2004 8:50 AM

no i dont keep windows updated. just because i am lazy... my internet connection is so slow that i even hate downloaing 1MB. 5 MB ZoneAlarm took 30 min of my precious time
anyway ZoneAlarm is nice..

Reply #19 Sunday, March 14, 2004 9:10 AM
| no i dont keep windows updated. just because i am lazy... |
...would you be too lazy to lock your doors when you leave the house? Consider it worse to leave Windows unpatched and connected to the net as your inviting billions of potential attackers into your "home" whenever you connect.
An unpatched Windows XP system is compromised in under 10 minutes of being connected to the interenet acording to research done by a honey net research group...that's without taking any steps to draw attention to itself too (though without any firewall). A sobering statistic, you might like to balance against your "lazyness"....

Reply #20 Sunday, March 14, 2004 9:25 AM
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!








Reply #1 Sunday, March 14, 2004 12:08 AM