PC Review


Reply
Thread Tools Rate Thread

Suddenly getting hundres of svchost.exe connections

 
 
Doc
Guest
Posts: n/a
 
      24th Jul 2012
Suddenly getting 400 - 500 plus svchost.exe connections per Comodo
firewall. What could this be indicative of? Currently running a scan
with Malwarebytes, MSE and Superantispyware. Getting a lot of hits
already with SAS.

Thanks for all input.
 
Reply With Quote
 
 
 
 
Doc
Guest
Posts: n/a
 
      24th Jul 2012
On Jul 24, 5:08*pm, Doc <docsavag...@yahoo.com> wrote:
> Suddenly getting 400 - 500 plus svchost.exe connections per Comodo
> firewall. What could this be indicative of? Currently running a scan
> with Malwarebytes, MSE and Superantispyware. Getting a lot of hits
> already with SAS.
>
> Thanks for all input.



Malwarebytes found Trojan.Agent.EXPD1. Could this be a culprit?
 
Reply With Quote
 
 
 
 
Beauregard T. Shagnasty
Guest
Posts: n/a
 
      24th Jul 2012
Doc wrote:

> Suddenly getting 400 - 500 plus svchost.exe connections per Comodo
> firewall. What could this be indicative of? Currently running a scan
> with Malwarebytes, MSE and Superantispyware.


Has to be asked: These scans .. all at the same time?

> Getting a lot of hits already with SAS.


Disable the firewall and go offline when you scan.

--
-bts
-This space for rent, but the price is high
 
Reply With Quote
 
Max Wachtel
Guest
Posts: n/a
 
      25th Jul 2012
On 07/24/2012 05:08 PM, Doc wrote:
> Suddenly getting 400 - 500 plus svchost.exe connections per Comodo
> firewall. What could this be indicative of? Currently running a scan
> with Malwarebytes, MSE and Superantispyware. Getting a lot of hits
> already with SAS.
>
> Thanks for all input.
>


you need a bigger rubber
--
Meet the new boss,Same as the old boss
 
Reply With Quote
 
(PeteCresswell)
Guest
Posts: n/a
 
      25th Jul 2012
Per David H. Lipman:
>The question is is it the legitimate OS file or a trojan using that name.
>
>For example SVCHOST.EXE running from c:\windows or %temp%\SVCHOST.EXE are
>not legitimate processes.
>
>SVCHOST.EXE (and variants such as SCVHOST.EXE) is one of the most used names
>in malicious processes. Often malware can inject into the legitimate
>process as well.


That's a "Keeper". Thanks.

FWIW, not that I know enough to make much sense out of it, but
AnVir seems to offer up some pretty detailed information on such
processes. e.g. http://tinyurl.com/c4wfdwl which resolves to
https://picasaweb.google.com/1081497...05648331060898

Click the little "+" icon and use the mouse roller go zoom in to
where it's readable.
--
Pete Cresswell
 
Reply With Quote
 
Doc
Guest
Posts: n/a
 
      26th Jul 2012
I loaded Hijackthis and started getting a BSOD on reboot. Reinstalled
an image of the drive created with DriveimageXML from a couple of
weeks before the problem started but was still getting the same issue
with the link redirects. Now I've formatted the drive and will load
the same image and see what happens.

People who write the code that causes this crap should be summarily
executed.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why am I suddenly getting getting this "unknown publisher" error? Fred Hebert Microsoft Access Macros 0 21st Dec 2006 06:32 PM
Suddenly slow ado.net connections =?Utf-8?B?R2Vvcmdl?= Microsoft ADO .NET 5 3rd Jun 2006 01:10 AM
suddenly can't configure network connections =?Utf-8?B?QW5kcmV3IFRob21hcyBCbGFrZQ==?= Windows XP Networking 1 18th Jan 2006 06:41 PM
Win2000 Server SP4 suddenly dropping SMB connections Saah Microsoft Windows 2000 Networking 1 17th Aug 2005 10:23 AM
Remote Desktop Connections Suddenly Lost =?Utf-8?B?Q0o=?= Windows XP Work Remotely 3 14th Jan 2005 04:38 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:02 AM.