svchost.exe

  • Thread starter Thread starter oldad
  • Start date Start date
O

oldad

In Quick Access when checking Task Mgr Processes :

SVCHOST.EXE is shown as SVCHOST,COM Trojan.32Neshuta and should be immediately deleted.

There are 6 of these listed in Processes
4 in System
1 in Local Service
1 in Network Service

MS Malicious Malware Removal tool, Trend Micro Internet Security and a few free Trojan scans donot detect these so I question as to the difference in .EXE and .COM whether the SVCHOST.EXE is really a trojan

Would appreciate any advice and or comments re this

Thanks in advance
 
In Quick Access when checking Task Mgr Processes :

SVCHOST.EXE is shown as SVCHOST,COM Trojan.32Neshuta and should be
immediately deleted.

There are 6 of these listed in Processes
4 in System
1 in Local Service
1 in Network Service

MS Malicious Malware Removal tool, Trend Micro Internet Security and a few
free Trojan scans donot detect these so I question as to the difference in
..EXE and .COM whether the SVCHOST.EXE is really a trojan

Would appreciate any advice and or comments re this

Thanks in advance

see this symantec article
http://www.sarc.com/avcenter/venc/data/w32.neshuta.html

D/L and run these from safe mode
http://www.trendmicro.com/download/dcs.asp
get the latest pattern files here
http://www.trendmicro.com/download/viruspattern.asp
next run this
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

rgds
Roberto
 
Thanks Roberto,
Still not convinced SVCHOST.EXE is a trojan as searach shows it as a generic host process for win32 services and Company is Microsoft Corporation.

Searach for SVCHOST.COM shows nothing.

Regards...oldad


In Quick Access when checking Task Mgr Processes :

SVCHOST.EXE is shown as SVCHOST,COM Trojan.32Neshuta and should be
immediately deleted.

There are 6 of these listed in Processes
4 in System
1 in Local Service
1 in Network Service

MS Malicious Malware Removal tool, Trend Micro Internet Security and a few
free Trojan scans donot detect these so I question as to the difference in
.EXE and .COM whether the SVCHOST.EXE is really a trojan

Would appreciate any advice and or comments re this

Thanks in advance

see this symantec article
http://www.sarc.com/avcenter/venc/data/w32.neshuta.html

D/L and run these from safe mode
http://www.trendmicro.com/download/dcs.asp
get the latest pattern files here
http://www.trendmicro.com/download/viruspattern.asp
next run this
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

rgds
Roberto
 
In Quick Access when checking Task Mgr Processes :

SVCHOST.EXE is shown as SVCHOST,COM Trojan.32Neshuta and should be immediately deleted.

There are 6 of these listed in Processes
4 in System
1 in Local Service
1 in Network Service

MS Malicious Malware Removal tool, Trend Micro Internet Security and a few free Trojan scans donot detect these so I question as to the difference in .EXE and .COM whether the SVCHOST.EXE is really a trojan

Would appreciate any advice and or comments re this

Please, what is "Quick Access"?
 
Back
Top