svchost.exe|exe.tsohcvs

  • Thread starter Thread starter Steve Miller
  • Start date Start date
S

Steve Miller

Two part question...possibly related?

In my processes I have two svchost.exe's running. One,
when I end it, shuts down windows. The other, when I end
it, does nothing but pop back up on the process screen
after a few seconds.I tried ending the "process tree" for
that same one and it took a little longer but it popped
back up. My firewall says I shouldn't allow it internet
access so I don't. I would like to get rid of it. I have
tried Trojan scans with no results. I have searched the
hard drives for two svchost.exe's but only come up with
one.

Recently I did a port scan and found that port 135 is
open. This has something to do with DCOM. But even with
the information below I am unable to find DCOM on my
computer (winXP, Award BIOS). Could someone tell me how to
find the "OLE/COM Object Veiwer" and what is
the "File.System Configuration dialog box". Is the period
a typo?

I cut this from a microsoft faq:

A. The HKEY_LOCAL_MACHINE\Software\Microsoft\OLE registry
key has "EnableDCOM" as a named value. By default this
value is set to "Y." To disable DCOM, change this value
to "N." You can do this in the OLE/COM Object Viewer with
the File.System Configuration dialog box. Changing this
value requires you to restart your computer.

If EnableDCOM is not set to "Y," then all cross-computer
calls are rejected (the caller, typically, receives an
RPC_S_SERVER_UNAVAILABLE return code).

One final question. I always go to windows updates and do
my updating manually. Will I still be able to do this with
DCOM disabled?
 
Although this is the MS Access forum - try taking a look
at the Welchia virus - go to Norton and download their
removal tool for this virus.
 
Back
Top