|
svchost.exe (5.1.2600.0)
Contenuto nel software |
Nome: | Windows XP Home Edition, Deutsch |
Autorizzazione: | commerciale |
Collegamento delle informazioni: | http://www.microsoft.com/windowsxp/ |
Particolari della lima |
Percorso della lima: | C:\WINDOWS\system32 \ svchost.exe |
Data della lima: | 2002-08-29 14:00:00 |
Versione: | 5.1.2600.0 |
Formato di lima: | 12.800 byte |
Il totale di controllo e la lima hashes |
CRC32: | A799DDDB |
MD5: | ADBB 33D5 893B CF08 E75E A54B B566 9205 |
SHA1: | 23C5 5CF3 635D 2F77 B119 F639 853A 0A89 869E 30F3 |
Le informazioni delle risorse di versione |
Nome di azienda: | Microsoft Corporation |
Descrizione della lima: | Generic Host Process for Win32 Services |
Sistema operativo della lima: | Windows NT, Windows 2000, Windows XP, Windows 2003 |
Tipo della lima: | Application |
Versione della lima: | 5.1.2600.0 |
Nome interno: | svchost.exe |
Copyright legale: | © Microsoft Corporation. All rights reserved. |
Nome di schedario originale: | svchost.exe |
Nome del prodotto: | Microsoft® Windows® Operating System |
Versione del prodotto: | 5.1.2600.0 |
svchost.exe è stato trovato nei seguenti rapporti:
|
Backdoor.Litmus.203.b |
Particolari tecnici ...It copies itself as %windir%RandomSvchost.exe. NOTE: %windir% is a variable.... ...LTM2 %windir%RandomSvchost.exe in the registry key... Istruzioni di rimozione ...LTM2 %windir%RandomSvchost.exe from the registry key... ...Scroll through the list, and look for Svchost.exe If you find the file, click... ...LTM2 %windir%RandomSvchost.exe Exit the Registry Editor.... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.litmus.203.b.html |
Backdoor.XTS |
Circa Backdoor.XTS ...to the compromised system. The main module, Svchost.exe, is packed with UPX. Also Known As: Backdoor-ASL... Particolari tecnici ...Drops the following files: %Windows%Svchost.exe %System%Extapi.dll... ...System Important Message. Path: %Windows%Svchost.exe -k ras. Injects Extapi.dll and Sysmsg.dll... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.xts.html |
Spyware.Shopnav.dl |
Particolari tecnici ...File names: Svchost.exe When Spyware.Shopnav is installed,... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/spyware.shopnav.dl.html |
W32.BlueCode.Worm |
Particolari tecnici ...Then, the .dll creates the C:Svchost.exe file and executes it. Svchost.exe performs the infection... ...First, the value Domain Manager C:svchost.exe is added to the registry key... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.bluecode.worm.html |
W32.Jeefo |
Particolari tecnici ...first-generation W32.Jeefo executable. Drop it as Svchost.exe (36,352 bytes) into the %Windir% folder.... ...program parameter that specifies an infected application, which has dropped and run Svchost.exe. It will quit.... ..."PowerManager"="%windir%svchost.exe" in the registry key:... Istruzioni di rimozione ..."PowerManager"="%windir%svchost.exe" Exit the Registry Editor.... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.jeefo.html |
W32.Welchia.Worm |
Particolari tecnici ...Makes a copy of %System%DllcacheTftpd.exe as %System%Winssvchost.exe. NOTE:... ...Service Binary: %System%winssvchost.exe This service will be set to... ...machine and instructs the victim machine to connect and download Dllhost.exe and Svchost.exe from the attacking machine.... ...If the %System%dllcache ftpd.exe file exists, the worm may not download svchost.exe. Checks the computer's operating... ...The worm does not delete the file, %System%WinsSvchost.exe, which is a nonmalicious tftp server.... Istruzioni di rimozione ...values from the registry. Delete the Svchost.exe file. For details on each of these... ...Exit the Registry Editor. 6. Deleting the Svchost.exe file Navigate to the %System%Wins... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html |
Backdoor.Dewin |
Particolari tecnici ...Some variants of this Trojan create the file, %Windows%svchost.exe. Adds the value:... ...SystemReg C:\%Windows%svchost.exe run to the following registry... Istruzioni di rimozione ...or: SystemReg C:\%Windows%svchost.exe run Click Registry, and then click... ...Added reference to minor variant which uses svchost.exe filename. Write-up by:... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dewin.html |
W32.Assarm@mm |
Particolari tecnici ...It determines whether the current file name is %windir%Svchost.exe. If it is, the worm then determines... ...If the current file name is not %windir%Svchost.exe, or if the argument "Install Me!" was passed to the worm, then the worm... Istruzioni di rimozione ...95/98/Me, remove the line run=%windir%svchost.exe from the Win.ini file.... ...similar to the following: run=%windir%svchost.exe If the line exists, select... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.assarm@mm.html |
W32.HLLW.Cozit |
Circa Backdoor.XTS ...It copies itself to the Windows folder as Svchost.exe and changes the registry to run this file whenever you start Windows.... Particolari tecnici ...When W32.HLLW.Cozit is executed, it copies itself to the Windows folder as Svchost.exe. If the HKEY_CURRENT_USERSoftwareKazaaLocalContent... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cozit.html |
W32.Marol@mm |
Particolari tecnici ...%Windir%TempWkCVX.exe %Windir% empSvchost.exe %System%COMD.exe... ..."admy" = "%windir% empsvchost.exe" "MDriver" = "C:losiram.vbs"... Istruzioni di rimozione ..."admy" = "%windir% empsvchost.exe" "MDriver" = "C:losiram.vbs"... ...... Fonte: http://securityresponse.symantec.com/avcenter/venc/data/w32.marol@mm.html |
|
|