|
-
August 26th, 2005, 09:42 AM
#1
system vulnerability
Hi,
My firewall is blocking a couple of
processes from accessing the internet.
One is an application named 'ntoskrnl.exe'
and the other is 'svchost.exe' ...
Ideally I'd like to locate where in the
registry the lines kickstarting these
scripts exists and interrogate further.
I'm aware that svchost.exe serves a
multitude of tasks but I expect only a
few have scripts enabled to access the
internet.
Although no harm is being caused I'd like
to remove them from my system if possible.
Any suggestions on the best way to proceed
is appreciated.
Thanks,
TF.
-
August 26th, 2005, 09:52 AM
#2
Download TCPView http://www.sysinternals.com/Utilities/TcpView.html By default, TCPView updates every second, but you can use the Options|Refresh Rate menu item to change the rate. Endpoints that change state from one update to the next are highlighted in yellow; those that are deleted are shown in red, and new endpoints are shown in green.
Double click the process and check the command line, post back with what you find if you're unsure of what to do next.
Liam
Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse 
-
August 28th, 2005, 06:34 AM
#3
according to my firewall (mcafee v.6), svchost is a windows application that never needs access to the internet. the only time it will ask for permission to access the internet is when it has been highjacked by a trojan.
SANITY IS JUST A STATE OF MIND
-
August 28th, 2005, 10:48 AM
#4
It will usually have a system process go through it to access the internet, and the way that virus/trojan writers have played it now is to use a windows system file as a trojan so that is it is accessing the internet through another standard file the user won't pick it up, and won't deny the access.
Liam
Desktop:I5 2500K|Asus P8Z68-V|8GB Corsair Vengeance|1280MB Nvidia 560 TI PE|1TB Seagate/60GB OCZ SSD|LG Blu-ray Writer|Corsair 750W
27" iMac:I5 2500S|12GB Crucial DDR3|ATI 1GB 6970|1TB|Superdrive|Mighty Mouse 
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|