Reply
Thu 31 Mar, 2005 08:09 pm
I've just been readin' this from
www.processlibrary.com. And it says that svhost is actually a worm called W32.Mydoom.I@mm.
What's that about? i thought it was meant to be an essential process?
Then again this other website
here thinks it's a worm called Sdbot-Pf.
According to my task manager the SYSTEM is running about 4 instances of that process. Is that normal? Or am i just being paranoid
Look carefully; "svchost" or "svhost"? Note the legitimate Windows process is "svchost", whereas the known baddie, "svhost" lacks the "c". Yuckware frequently hides behind filenames or extensions that closely resemble legitimate Windows components.
Its normal to see multiple instances of "svchost", but before you totally give up on paranoia, there's no reason to assume a baddie might not be lurkin' behind an instance of the otherwise legitimate process. Are you experiencin' any symptoms that would lead you to suspect the presence of yuckware?
These virus people certainly do their best to confuse you in every possible way

. I checked, and you're right it is "sv
Chost" which is running.
The comps hasn't been doing anything out of the ordinary so thats why i asked the question in the first place, I assume that if there was a virus, at least the
Microsoft Malicious Software Removal Tool tool would have found them.
Maybe I just need glasses