svchost.exe

  • Thread starter Thread starter M Guyder
  • Start date Start date
M

M Guyder

I looked at the running processes and found 12 svchost.exe running. Can
anyone please explain this?

TX
mary
 
Where do I get "procexp" ?

Stubby said:
SvcHost.exe is a program that launches specific functions from a .DLL
file. You might use it to startup an FTP Server, a TELNET Server, but skip
a terminal server. That would result in two instances of SvcHost. Get a
copy of procexp (sp?) to examine the service structure.
 
Process Explorer is an excellent utility but the built in Task Manager has
this feature in Vista. Right click on the svchost instance you want and pick
Go to service(s). The services loaded in that process will be highlighted.
 
M Guyder said:
They all read - Host Process for Windows Service

Host Process for Windows Service is SVChost.exe.

If SVChost.exe is not running out of the C:\Windows\System32 folder, then
it's a Trojan, which you can tell which folder SVChost.exe is running out of
with Process Explorer.

BTW, I have 13 SVChost.exe(s) running, because that's what SVChost.exe does
is host processes, which can be legit or non-legit (like malware).

<http://www.windowsecurity.com/artic...d_Rootkit_Tools_in_a_Windows_Environment.html>
 
You can also see the path in Task Manager. Click on View then Select
columns. Image Path Name shows where the file was loaded from. Command Line
shows the command line that was used to load it.
 
They all SEEM to be ligit, but isn't this a bit of OVERKILL. Shouldn't one
instance oft he utility run all the services?

Some of these seem to be unneeded. I just do not like all the memory it is
using
 
I did get Process Explorer aand ran it but It is beyond my scope of
understanding

Even if you understood it, you couldn't change how Vista works at that
level.

Did you happen to notice that it was mentioned that you could see
pretty much the same thing as Process Explorer shows just by making
full use of the Task Manager?

Right click any instance of svchost, select Services and all the blue
highlighted items are being handled by that one.
 
This was mentioned in a previous reply, tx

Oddly, I anm now at work and there is not one instance of this exe file
running on my computer !!!
 
In the Vista Task manager click on the button that says "Show processes from
all users". In XP put a check mark in the box.
 
Tx evry1 for your input. I will not belabor this issue.

The reason I was asking is because I can be doing something and my compute
is running in the background a mile a min. I look at the Processess running
and see where svchost.exe is using 64,000 in one instance and 50,000+ in
another. Thought this mite be the reason for the puter running.
 
Back
Top