why is my svchost.exe doing this?

hi everyone.
long time no see i love wincustomize

ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???

Note: i guessed my internet act by looking at the status: Bytes recd, sent, etc... and that two lil blue comps in the system tray.

now WHY???

Thanks for helping out!
When i terminated SVCHOST.exe, after about a min, the GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???

Bye! will be back soon to see the replies...
19,889 views 51 replies
Reply #1 Top
still svchost.exe is accessing that akamai site. is there any way to stop this?
Reply #2 Top
You sure that's not part of your ISP...?



Powered by SkinBrowser!
Reply #3 Top
OK....let's try this...do you have a Firewall?



Powered by SkinBrowser!
Reply #4 Top
GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???


might be mistaken...but this sounds like explorer.exe crashed then reloaded itself when you ended the svchost.exe service

http://support.microsoft.com/?kbid=314056 from MS explains what it is
Reply #5 Top

run either Ad Aware or Spy Bot - they should get rid of it...

Ad Aware: http://lavasoft.element5.com/software/adaware/

Spy Bot: http://www.safer-networking.org/

Reply #6 Top
http://www.computerhope.com/issues/ch000517.htm is a more user friendly explanation
Reply #7 Top

btw - it's not svchost.exe doing it, it's more likely a data mining mind-melding shape-shifting reptillian cookie...

nasty buggers...

Reply #8 Top

oh also - download stinger (new version today)

http://vil.nai.com/vil/stinger/

if it is a virus stinger should catch it.

Reply #9 Top
hummm....my guess is he's not answering 'cause he wacked his connection. Love it when peeps just terminate things and then ask "...what was that anyway?"


data mining mind-melding shape-shifting reptillian cookie






Powered by SkinBrowser!
Reply #10 Top
hey my connections fine
will download stinger and see i am on a 56k, so it might take some time.

yrag: i have only the inbuilt firewall in Windows XP enabled. is that ok? or should i get ZoneAlarm?
Reply #11 Top
The ZA free version is better then XP firewall. You can stop these apps from accessing the net by taking away server rights in your firewall settings.
Reply #12 Top
lol , stinger is just under 1 mb. i will scan when i am offline and kill any virus

thanks!
Reply #13 Top
don't forget the spy-bot/ad-aware bit too... they get all the spyware off your machine.
Reply #14 Top

Domain Name: AKAMAI.COM
Registrar: TUCOWS INC.
Whois Server: whois.opensrs.net
Referral URL: http://domainhelp.tucows.com
Name Server: YH.AKAMAI.COM
Name Server: YG.AKAMAI.COM
Name Server: YC.AKAMAI.COM
Name Server: USE1.AKAM.NET
Name Server: EUR1.AKAM.NET
Name Server: ASIA2.AKAM.NET
Name Server: NS1-2.AKAM.NET
Name Server: NS1-3.AKAM.NET
Name Server: NS1-42.AKAM.NET
Name Server: EUR2.AKAM.NET
Name Server: NS1-137.AKAM.NET
Name Server: USE3.AKAM.NET
Status: REGISTRAR-LOCK
Updated Date: 17-nov-2003
Creation Date: 17-aug-1998
Expiration Date: 16-aug-2007

-

Name: www-8cc.akamai.com
IP Address: 80.67.70.22
Location: Unknown
Network: 80-RIPE



OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: Singel 258
Address: 1016 AB
City: Amsterdam
StateProv:
PostalCode:
Country: NL

ReferralServer: whois://whois.ripe.net

NetRange: 80.0.0.0 - 80.255.255.255
CIDR: 80.0.0.0/8
NetName: 80-RIPE
NetHandle: NET-80-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS.RIPE.NET
NameServer: NS3.NIC.FR
NameServer: SUNIC.SUNET.SE
NameServer: AUTH62.NS.UU.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate:
Updated: 2003-09-19

OrgTechHandle: RIPE-NCC-ARIN
OrgTechName: RIPE NCC Hostmaster
OrgTechPhone: +31 20 535 4444
OrgTechEmail: [email protected]


Looks to me that the IP Address before the TwoCows domain is a private network IP address behind the RIPE-NET Firewalls...
Passing though TwoCows for some reason...

Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...

Microsoft compiles information on everyone using msmsgr... I do not see why Yahoo wouldn't do it also...
Remove it, and run a tsr registry monitor such as ad-watch, or some other registry monitor so you know exactly when something is trying to change your registry and if you do not know what it is, or you are not installing anything youcan refuse to let the change happen. Then scan and clean before the fact and total infection...





from the sounds of the traffic you describe I would read this link... http://www.symantec.com/avcenter/venc/data/pwsteal.bstroj.html

If anything resembles the info on that link, disconnect from the net and scan/clean your system, log back on and then change your IM application passwords at least...


good luck
Reply #15 Top
hi all
i just ran a test with stinger, found lots, which i already know, and found one which i didnt know for a long time. hhsetup.exe.. hmm..
removed it, now its fine no internet activity.
i am gonna get a firewall too. ZoneAlarm.
and i found this one in the registry, strange: (RUNONCE)

C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE

an AutoUpdater. Norton doesnt say its a virus, and when i right click that EXE no EXE details
but i didnt it anyway..

and one more program: htpatch.exe. whats this one??
\Windows\System32\htpatch.exe

nothing else
Thanks a lot.
Reply #16 Top
Both hhsetup.dll and htpatch.exe are part of Windows. The hhsetup.dll can be used for remote attacks though if not patched. Do you keep Windows updated?
Reply #17 Top
and i found this one too. the Process "System" had opened a port 445(local) 1571(remote) to remote IP: 68,73,201,123 with host name:
adsl-68-73-201-123.dsl.sfldmi.ameritech.net
now what is this one? a hacker???

how come did he gain control of my system process??
Reply #18 Top

no i dont keep windows updated. just because i am lazy... my internet connection is so slow that i even hate downloaing 1MB. 5 MB ZoneAlarm took 30 min of my precious time
anyway ZoneAlarm is nice..
Reply #19 Top
no i dont keep windows updated. just because i am lazy...


...would you be too lazy to lock your doors when you leave the house? Consider it worse to leave Windows unpatched and connected to the net as your inviting billions of potential attackers into your "home" whenever you connect.

An unpatched Windows XP system is compromised in under 10 minutes of being connected to the interenet acording to research done by a honey net research group...that's without taking any steps to draw attention to itself too (though without any firewall). A sobering statistic, you might like to balance against your "lazyness"....
Reply #20 Top
An unsecured machine is an outrage, as it makes Internet usage for the rest of us more difficult. Refusing to secure a machine is akin to being a lowlife hacker, as you become a tool for them.



Powered by SkinBrowser!
Reply #22 Top
would you be too lazy to lock your doors when you leave the house


i dont, but, when u leave ur house, still ur house is accessible to the world. but my computer is not , since i am on a dialup
and now i guess, i have disabled SVCHOST.exe to act as a server. so, this should offer some protection

Anyway, the last update i installed for WinXP was the patch to the Blaster virus!! lol

Cheers!
Vimal
Reply #23 Top

http://support.microsoft.com/?kbid=314056

that article is from the microsoft knowledge base.
Describes what exactly svchost does and why it is doing it.
Reply #24 Top
Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...


ypager.exe is the executable program for Yahoo Messenger.
Reply #25 Top
dont, but, when u leave ur house, still ur house is accessible to the world. but my computer is not , since i am on a dialup


This mitigates a little, but it's still akin to opening every door and window to your house and putting up big neon signs saying "everyone welcome" each time you dial up.

If you choose to do this, then you shouldn't be surprised when nefarious individuals take advantage of your generous hospitality to help them selves to your wallet, and some decide to take up residence in your spare room and are difficult to kick out again...
[Message Edited]