Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

 
Reply to this topicStart new topic
> Svdhost.exe ?
eaglehorse
post Nov 27 2007, 01:51 PM
Post #1


Member
**

Group: Members
Posts: 18
Joined: 12-October 07
From: S.C,USA
Member No.: 162,602



I am not familiar with Vista yet. I have a question about a process in vista. This example is pulled out of a HJT log.
[qoute]O4 - HKLM\..\RunServices: [Microsoft Updates] svdhost.exe . It also shows up in other areas of log.[/quote]
My question is it is aparently signed by Microsoft so I am assuming it is a Vista process and not a keyloggeras CC listed.
QUOTE(CC)
Orvell Monitoring 2003 - surveillance software that creates records of everything people do on a computer, ie, spying or monitoring depending upon how you call it. Note - asks for permission to contact the IP address of http://www.protectcom.com/

Next question is does this process have the ability to be hijacked and turn it into a keylogger?
Thanks in advance for help.
Go to the top of the page
 
+Quote Post
figgis41
post Nov 27 2007, 02:55 PM
Post #2


Senior Member
****

Group: Members
Posts: 419
Joined: 7-May 07
From: Hull England
Member No.: 129,329



hi,,, i think this might answer some questions,,,,, have a good read its crazy,,,

http://news.softpedia.com/news/Forget-abou...oft-58752.shtml

by the way a lot of people are reporting that there rigs are doing alot of HDD thrashing when in idal,,,, this is not just down to the new auto defrag on vista its all these vista programs collecting info redy to send off on your next update,,,,,,,,, or i could be a parionoid nutball,,,,,,, i loged onto the black vipers site and closed down all un needed services & hey presto the thrashing stoped,,,,,,
good luck,,,,,,,, figgis41


--------------------
Figgis,,,, LUFC
Go to the top of the page
 
+Quote Post
Jacee
post Nov 27 2007, 10:32 PM
Post #3


Bleeping entraÎner
******

Group: HJT Team Coach
Posts: 1,738
Joined: 24-September 04
Member No.: 2,990



Is this item: O4 - HKLM\..\RunServices: [Microsoft Updates] svdhost.exe showing up in your HJT log?

If it is, you have an SDBot Trojan http://www.sophos.com/security/analyses/w32sdbotni.html
This needs to be taken care of immediately

Please do this first!
From a known, "clean machine" (not the one that's infected), change all your passwords and notify your bank if you have any critical information, such as credit cards or online banking that you've used on the infected machine.

Next,
Download HijackThis™ here:
http://www.trendsecure.com/portal/en-US/th.../hijackthis.php

Right click on it and choose "Run as Administrator". Click 'Do a System Scan and Save log'.
The HJT log will open in notepad.

Copy and paste the contents of the HJT log into a NEW TOPIC in "HijackThis Logs and Malware Removal"
http://www.bleepingcomputer.com/forums/forum22.html
Please be patient as we have a lot of people with malware infections and most all of our HJT Team members work on several forums.




--------------------
MS MVP Windows-Security 2006-2008
Member of UNITE, the Unified Network of Instructors and Trusted Eliminators

Admin PC Pitstop
Go to the top of the page
 
+Quote Post
eaglehorse
post Nov 27 2007, 11:12 PM
Post #4


Member
**

Group: Members
Posts: 18
Joined: 12-October 07
From: S.C,USA
Member No.: 162,602



QUOTE(Jacee)
Is this item: O4 - HKLM\..\RunServices: [Microsoft Updates] svdhost.exe showing up in your HJT log?
If it is, you have an SDBot Trojan http://www.sophos.com/security/analyses/w32sdbotni.html
This needs to be taken care of immediately
Not my log but thanks for the concern. I have XP. This is one I was looking at trying to get use to vista's processes. thumbup.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 9th January 2009 - 03:17 AM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.