Click here to get back home

System Service Inspector shows an ID/String

 HomeNewsGroups | Search | About
 microsoft.public.security.virus    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
System Service Inspector shows an ID/String Howard 01-09-2008
Posted by Howard on January 9, 2008, 11:07 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Volodymyr Shcherbyna on January 10, 2008, 8:40 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Howard on January 10, 2008, 11:54 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Volodymyr Shcherbyna on January 10, 2008, 11:59 am
Please log in for more thread options

| Hi David, After reading your answer to this post i went to Task Manger
| and found five (5) svchost.exe services running - 3 Network Services ,
| and 2 System. Now after seeing your answer and checking
| Process Library and finding out this svchost.exe could be used by a
| Trojan, How can i find out the path's of these services in Task Manger
| like in your example? Thanks Ron (Defender)
|

It is common to have multiple SVCHOST.EXE processes running. Each load
specifcommunication
capabilities of the OS.

Like I said, it is not the name of the file that is important, it is the Fully
Qualified
Name and Path to that file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Ivan on February 21, 2008, 3:50 am
Please log in for more thread options
> Volodymyr Shcherbyna wrote:
> > Look at it's properties. What is the name of service executable file name?
>
> The property/path is "C:\Program Files\Bonjour\mDNSResponder.exe"
>
> The Bonjour folder contains the .exe plus <mdnsNSP.dll>
>
> The Add/Remove window does not show any application named Bonjour.
> Yikes!

http://en.wikipedia.org/wiki/Bonjour_(software) <- all information is
here

Similar ThreadsPosted
"Messenger Service" pop up box July 31, 2006, 11:27 pm
Messenger Service Popups July 19, 2005, 2:33 am
XP Service Pack 2 Uninstalled? June 13, 2006, 10:30 pm
Windows NetBIOS Messenger Service May 31, 2005, 3:55 pm
how to remove "service manager" virus? May 11, 2006, 10:30 pm
Where does AVG's Resident Shield 'service' run? November 27, 2007, 10:58 am
McAfee virus removal service - Genuine? February 27, 2008, 3:19 am
Virus create an unknown user, service, enccrypted files August 9, 2006, 5:42 am
Virus create an unknown user, service, enccrypted files August 9, 2006, 6:04 am
*sobbing quetly* trojan in my winxp pro service pro serv. pack 1 December 10, 2007, 10:32 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap