Jump to content

Recommended Posts

There are usually a few processes named svchost.exe.  If you're worried about trojan activity, check this out. 

Win XP?

-Open task manager (Ctrl + Shift + Esc)

-Processes tab

-View > Select Columns

-enable "PID (Process Identifier)" and click ok

-now go to command prompt (start > run > "CMD" > ok)

-type netstat -ano

You can match the PID to the svchost in task manager.  Not sure what the IP is?  WHOIS

You can also try booting into safe mode or safe mode with networking to see if it does the same dance.

Link to comment
https://testmy.net/ipb/topic/18473-svchostexe/#findComment-217638
Share on other sites

×
×
  • Create New...