Svchost Process Analyzer tells you what the heck svchost.exe is doing
If you've ever taken a peek at the Windows Task Manager, odds are you've found a couple of running processes called svchost.exe. And chances are you have no idea what this process is doing or if it's safe to kill.
First, it's probably not safe to kill it from the Task Manager. But you can figure out what these processes are doing by using a free and portable (no installation required) tool called Svchost Process Analyzer. Basically, each instance of svchost.exe masks a series of Windows system services. Svchost Process Analyzer lets you figure out exactly what those processes are. If you find some running processes that you don't think you need, you can disable those services using the Windows Control Panel to free up some system resources.
You can also use the program to detect whether a worm or trojan is masking itself as a Windows service.
[via gHacks]
First, it's probably not safe to kill it from the Task Manager. But you can figure out what these processes are doing by using a free and portable (no installation required) tool called Svchost Process Analyzer. Basically, each instance of svchost.exe masks a series of Windows system services. Svchost Process Analyzer lets you figure out exactly what those processes are. If you find some running processes that you don't think you need, you can disable those services using the Windows Control Panel to free up some system resources.
You can also use the program to detect whether a worm or trojan is masking itself as a Windows service.
[via gHacks]













Comments
7
Subscribe to commentsintellerMay 22nd 2009 4:44PM
if you were using Vista you could already be doing this
SouveysMay 22nd 2009 5:29PM
What inteller is referring to (presumably) is the fact that under the Processes tab in Windows Task Manger under Vista, you can right click on an item and click "Go to Service(s)" and it will show you what service the process corresponds to in the Services tab.
AlbertMay 23rd 2009 6:50AM
Woow in Ubuntu there's a simple option for years that you click to show process dependencies. Just one click. I now, stopped wondering why i switched to Ubuntu.
EthanJMay 23rd 2009 2:56PM
I wouldn't go near this site or program. I visited the site and attempted to download and suddenly my AV went nuts.
Two generic trojans blocked by BitDefender as well as another piece of generic malware. Two definiite infections (no false positives) and both of which definatly from the download site (only the second siter I had opened today after this one).
This has severly dented my confidence in Downloadsquad. Surely this type of thing is something that should scutinised before posting a program.
AlexMay 26th 2009 9:20AM
Hi EthanJ,
I'm the developer of Svchost Process Analyzer and all the other tools from neuber.com. It is true that BitDefender report a infection on our website - but this is a false positives. We have contacted BitDefender, and they promise to fix it as soon as possible.
The problem is that some AVEngines think every program which use the WinAPI function NtQuerySystemInformation is a trojan :-(
Alex
keemanMay 24th 2009 8:30AM
Yeah, Vista and Ubuntu has this in-built function. I would stick to Process Explorer though.
JamesJun 12th 2009 11:36PM
Yeah, Process Explorer FTMFW. I've been saying for years that they should just chuck Task Manager and replace it with PE. Maybe have a "simple" (/idiot) mode by default, but ship it with Windows at least...