Lord Vimal Lord Vimal

why is my svchost.exe doing this?

why is my svchost.exe doing this?

hi everyone.
long time no see i love wincustomize

ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???

Note: i guessed my internet act by looking at the status: Bytes recd, sent, etc... and that two lil blue comps in the system tray.

now WHY???

Thanks for helping out!
When i terminated SVCHOST.exe, after about a min, the GUI (Luna) disappeared, the classic was on, then Luna returned back. whats this???

Bye! will be back soon to see the replies...
19,932 views 51 replies
Reply #26 Top
Lord Vimal - It's already been addressed about not applying service packs and security updates, so I won't even go there. Go to the Microsoft site and order the 'Updates' CD. It covers all operating systems and is inclusive thru Feb 2004. The CD is free as well as the shipping charges....



Powered by SkinBrowser!
Reply #27 Top
ypager.exe is the executable program for Yahoo Messenger.


Actually it is a Helper app for the Yahoo Messenger...

as the links I posted show...

It is also something being used to tunnel into users computers...

again as the links I posted show
Reply #28 Top
hmm. Sounds like to me you need to go on some computator medication. Your computer is sick. I would stop using yahoo messenger, get it off of the puter. Then run your antivirus or stinger. Then run spybot. then manually scan the registry (use find if you are lazy like me). Then I would shutdown. Pray. The restart the computer and hope you got rid off the bad stuff. Then If you have to use yahoo messenger get it again, but I would suggest you find an alternate program to do the same stuff.
Reply #29 Top
hmmmmmmm

When all else fails, Reformat the HD and Reinstall XP

(I do it every 6 months...)
Reply #30 Top
When all else fails, Reformat the HD and Reinstall XP (I do it every 6 months...)


Have you got some way of preserving your nstalled 3rd party apps (i.e Office, Stardock stuff etc) ?

This is the single, biggest pain that deters me from regular re-installs (I don't know how you put up with it actually).

For example, I recently got back my new pC that was damaged in a lightning storm - it was under warranty plus insured so it all had to be done through the 'proper channels'. So the PC store that fixed it replaced my HDD (among other things) managed to copy the entire contents of the old HDD (preserving partitions) and re-installed XP on the C partition.

On the face of it all my apps are still there, but none will work, of course, because all the registry associations are gone. Totally less than useful!

Do you, Kona, (or anyone else for that matter) have a way around this? I recall in the old days there were apps that took snapshots of the registry when you changed it but they were very cumbersome IMHO.

Sorry about hijacking the thread




Powered by SkinBrowser!
Reply #31 Top
Got a spare Hard Drive sittin' around?



Powered by SkinBrowser!
Reply #32 Top
Have you got some way of preserving your nstalled 3rd party apps (i.e Office, Stardock stuff etc) ?This is the single, biggest pain that deters me from regular re-installs (I don't know how you put up with it actually).


yes... I reinstall my OD componets one by one. I keep the serial in the email it came in on the MSN server.

Takes alot of time but I love a freshly installed XP.

most of my downloaded freeware programs i put on a CD R

Reply #33 Top
hmmmmmm I hate reinstalling xp. But in the last 3 months I have done it a grand total of 5 times. woohoo that was fun >

I say reinstall as a last resort. But if you do reinstall make sure you format your disk so it is all nice and fresh. I wouldn't reinstall over this matter though.
Reply #34 Top
I say reinstall as a last resort. But if you do reinstall make sure you format your disk so it is all nice and fresh. I wouldn't reinstall over this matter though.


KILLDISK works awesome. Nothing like a good wipe.

But as Travis (or he who has many nicks) says, do not format and reinstall unless YOU REALLY HAVE TO. I have lots of time on my hands so i have no life. Reinstalling takes hours.


[Message Edited]
Reply #35 Top
But as Travis (or he who has many nicks) says, do not format and reinstall unless YOU REALLY HAVE TO. I have lots of time on my hands so i have no life. Reinstalling tales hours.


yes many names have I. I have gotten to reinstalling windoze in about an hour. Experience helps in this matter. But I wouldn't practice installing windows to get proficient at it, unless you get paid to install windows.
Reply #36 Top

Reinstalling takes hours.

understatement of the week... it takes me a whole day to a couple days to get back to normal

Reply #37 Top
Backup up you C:\ partition to a second hard drive with a program like Drive Image....it takes about 20-30 minutes to restore ...So if I lose the hard drive with the C:\ partition...I can easily restore it or if I lose the hard drive with the backup...I can easily create a new backup
Reply #39 Top
If I lose both...I'm like DavidK...a couple of days to get things back to normal
Reply #40 Top
Kona0197 - ya beat me to it. For those who wish to re-install often, I can't recomend DriveImage by Powerquest enough....but Norton Ghost is equally good/better (though I think more expensive last time I looked?...though, that may have just been for the bulk purchase we were looking for).

We have to install XP on machines almost daily, and with a stack of CDs comprising an image, this can cut down getting back to having our 11Gb base image installed, with Office, and approx 600 specialist apps to minutes. Initially building that image and ensuring everything was configured correctly took months...
Reply #41 Top
when you know what goes on the puter and have a stack of cds with the proggys on em. It sure elps. The only problem comes with putting the stuff on cds. It took me a week to get all the stuff onto cds in the correct order. But as I said before I can reinstall windows in an hour with object desktop, office xp, firefox, thunderbird, and several other apps. however, If I install my mp3 collection back on that takes an additional 3 hours due to the slowness of decompressing the rars they are in.
Reply #42 Top
ypager.exe is the executable program for Yahoo Messenger. Actually it is a Helper app for the Yahoo Messenger... as the links I posted show...It is also something being used to tunnel into users computers...again as the links I posted show


No... Ypager.exe is the executable for Yahoo Messenger. It is not a helper, it is the program used to launch Yahoo Messenger. The actual Ypager.exe, normally installed in the C:/Program Files/Yahoo!/Messenger/ directory is NOT being used as a tunnel into users' computers. The trojan which sometimes uses the name Ypager.exe installs itself in the Windows System directory and in the registry under a completely different key. That trojan and how to detect it is what the link you provided actually shows. The file location of the Ypager.exe file and more importantly the registry entry are the keys to recognizing the difference.

Furthermore, that trojan is almost 2 years old, had a very low infection rate in an extremely limited geographical area if you research a bit more on the link you provided. Before advising someone to remove something from their computer, it might be advisable to do some simple checks to make sure of what you are advising them to remove.

When you see hoofprints, don't automatically start looking for zebras.

[Message Edited]
Reply #43 Top
Drive Image 7.0 works flawlessly. My files and software currently come to 30Gb - takes about 25mins to backup or restore, as opposed to installing software and recovering files from CDs which is a two day job . Of course, I do have 320Gb of storage on which to put my backups....

Another advantage of DI 7 is you do your backups in Windows, and can even carry on working
Reply #44 Top
Fuzzy...yes...that still amazes me....how it can lift itself up by its own shoe laces....but it works...
Reply #45 Top
ok, now, whenever i connect to the internet, even if i am not browsing ANY site or not doing anything, i find lot of internet activity. lots of bytes are recd per second, this never used to happen before.
so, i downloaded "Active Ports" program to check my ports. i found some familiar processes like msmsgs.exe, avant.exe (browser), ypager.exe with "Connection Established",
i found even SVCHOST.exe on. i just ran a check on the host it is connected to, it says::
64.124.83.150.akamai.com:http
now what is this site? when i went, it said some sort of Internet business. well, this sort of thing is ruining my surfing.
so, i TERMINATED that instance of SVCHOST.exe to find that the internet activity had reduced... hmm. is this some problem???




Looks to me that the IP Address before the TwoCows domain is a private network IP address behind the RIPE-NET Firewalls...
Passing though TwoCows for some reason...

Most probable that ypager is as suggested a dataminer, or at worse a trojan, an open tunnel into your system with the ypager being a http:proxy...



No... Ypager.exe is the executable for Yahoo Messenger. It is not a helper, it is the program used to launch Yahoo Messenger. The actual Ypager.exe, normally installed in the C:/Program Files/Yahoo!/Messenger/ directory is NOT being used as a tunnel into users' computers. The trojan which sometimes uses the name Ypager.exe installs itself in the Windows System directory and in the registry under a completely different key. That trojan and how to detect it is what the link you provided actually shows. The file location of the Ypager.exe file and more importantly the registry entry are the keys to recognizing the difference.


Yep I stand corrected, ypager is in fact the messenger and it should show up in the process (task_list) list as Ymsgr_tray under NT (NT4, 2000, XP and 2003 )

That is if it is not one that has been modified in some manner, which can be put on ones system from any download and installation of any application off the net if it is modified or created to do so upon installation.

Furthermore, that trojan is almost 2 years old, had a very low infection rate in an extremely limited geographical area if you research a bit more on the link you provided. Before advising someone to remove something from their computer, it might be advisable to do some simple checks to make sure of what you are advising them to remove. When you see hoofprints, don't automatically start looking for zebras.


Furthermore you totally went past my first possibility suggested that it is in fact acting as a data-miner... nice...

Adam if you think that something that is 2, 3, 5 8 years past when it comes to trojan, virus and worms is nothing to worry about then you will learn some seriously hard things over time. As far as Limited geographical are goes that is also something that is on one point something to consider and on another something totally inane. Your speaking of the interenet where Russia is only a matter of moments away from the USA. I could list over 200 sites with such black hat, script kiddy and jerk off apps on them which include that decompile/re-compile of the ypager...

As far as simple checks go and your suggestion that advising Vimal to remove the offending app, clean, reinstall and take better control of his system before advising him to do so. I did some simple checks, I traced the IP address back to the private network which his system was attempting to connect with which is outside the Yahoo network from what can be found without contacting RIPE-NET's admins. (That isn't up to me to do and it is moot when doing what was suggested is done because it should not continue was completed)

Zebra tracks have squat to do with a application attempting to use an unknown or act as it's own http (web) proxy server. If he did not configure it to do so for a specific reason ( if he had done this he would damn well know it, and if it was setup to do this he would have had to have set it up, sp it lends to the application NOT functioning in the normal manner which lends to it being MODIFIED in some manner )

Microsoft compiles information on everyone using msmsgr... I do not see why Yahoo wouldn't do it also...
Remove it, and run a tsr registry monitor such as ad-watch, or some other registry monitor so you know exactly when something is trying to change your registry and if you do not know what it is, or you are not installing anything youcan refuse to let the change happen. Then scan and clean before the fact and total infection...

from the sounds of the traffic you describe I would read this link... Link

If anything resembles the info on that link, disconnect from the net and scan/clean your system, log back on and then change your IM application passwords at least...

good luck



On Vimal's system YPager is in fact passing through as it is or is running through a HTTP:port 80, 8080, 1080 (not sure exactly which because I am not on his system to check it) proxy server. ( Hence the refereces to tunneling, which is exactly what is taking place by description and definition)

Further on in my post to him I described what to do, which was to make sure he cleaned his system of it, ran a check and then logged back into the service. I am sorry I did not hold his hand or paint a glowing green floressent line on the screen with the blow by blow steps in doing this. But I figured anyone able to log onto the net, make use of a message board and read would have be able to put it together without doing that.

Uninstall ypager.exe, clean the registry, clean any left over files off the drive, reboot, make sure that your AV aoftware is open and active, reinstall ypager from a new download off Yahoo. Log banc in and everything that possibly could be wrong should be fine.

Better?


[Message Edited]
Reply #46 Top
Yep I stand corrected, ypager is in fact the messenger and it should show up in the process (task_list) list as Ymsgr_tray under NT (NT4, 2000, XP and 2003 )


That depends on how Yahoo is configured to load. If Yahoo is not configured to load at startup, or has been exited completely and is subsequently launched from a Quicklaunch or Desktop icon, it will show in the task list as YPager.exe.

As for the rest of your latest post, I am not sure whom you are trying to impress, but you appear to be addressing your post to me. Or perhaps you're simply venting frustration. I'm not sure what the purpose is, and frankly I don't care. From your first post in this thread, you siezed upon the PWSteal.BStroj trojan based on limited information which none of us is even sure is correct. We are after all, talking about someone whom does not even know what svchost, hhsetup, and htpatch are and couldn't be bothered to update his OS with hotfixes because he's self-admittedly too lazy. I do find it interesting that he has posted twice saying that he had run stinger and Norton AV and made no comment in either case about finding either the PWSteal.BStroj trojan or any other virus/trojan/etc related to YPager.exe.

I'm not trying to engage in some type of pissing contest here. All I was trying to do was point out that given the information we had from Lord Vimal, or perhaps the lack thereof, there are numerous alternative explanations for what is/was going on with his system.

I have been impressed by your knowledge from the first few times I visited this board and saw some of your posts, IP, and nothing, including what has been posted in this thread, has altered my initial impression. If you feel I have somehow slighted you by correcting some information that was posted here, then I apologize. That was not my intent. All I was attempting to do was to correct some information which I felt was posted in error. We all have made mistakes from time to time, and often those mistakes are caused by us receiving incomplete and incorrect information from the person we are trying to help.

[Message Edited]
Reply #47 Top
I 've just been having a seriously off day/night/weekend and taking things from a defensive position. it isn't you and it isn't right that I did such. Bit my wifes head off thinks morning also without taking the time to stop and think. I stopped posting for a while because I could see things heading in this direction and had thought I had a grasp on it.

eh, no pissing contest here either, sides all it doesn't is stain the desktop and if your bad of aim there is no telling what will happen to the monitor or other hardware sittin ear it


seriously, I do apologise for it.
Reply #49 Top
thanks everyone well, i just installed a firewall. blocked internet access to few programs, now its fine.
i guess, there was a program: yupdater.exe, denied access to it.and also denied access to SVCHOST.exe (Generic process) from acting as a server. and now its fine

Thanks for all your help though. Hey, regarding the free Microsoft Update CD, how can i get it?? any links??

Thanks
-=[ Vimal ]=-
Reply #50 Top
i got the Free CD. Ordered it, will be rec. it in about a month... thanks a lot!!

Bye!