What .exe`s are absolutly needed....

MudKicker

HERES MUD IN YER EYE!
Joined
Feb 24, 2005
Posts
3,967
Location
"Dynamic"
Society
THE THREAT
Avatar Name
Muddy MudKicker Helmet
....to be running in TaskManager???

I got like 33 ...dont have a pen handy so I cant write none down but I see like 10 svchost.exe. Is that right?

Got 2 AV`s running and lately seen a slowing in my comp. Scan everyday, update when needed.

Besides the running proggys that I KNOW i got goin on, what else should be in TM???

Thanx in advance.... :dunce:
 
Dunno what you have running...

...but 10 svchosts looks dangerous to me already !!! :eek:

3-4 with a normal set up win xp are ok...

What AV scanner you have ? Try to start a full system scan more often, maybe in safe mode as well.

Use "SpyBot Search&Destroy".
 
The amount of svchosts depends on your drivers and services running. First thing you should do is go to computer management and disable all services you dont need. That'll probably cut them back a bit. Some drivers use a sort of hidden services as well, which triggers an svchost running. Too bad I don't think there is a way to see by what driver or service a svchost instance is triggered.

But yes, it CAN be perfectly normal to have 10 of them.
 
@Chainfire

Even a freshly installed XP doesnt have 10 svchosts runnign the same time here. :) I dont say it HAS to be evil...

But its often trojans that got installed OR took over System32 services. (worst case)

You can look at svchosts more detailed with the "process explorer" by SysInternals. (Which is now located at microsfot) omg :(

But I would recommend doing a full system scan with your AV and try at least "SpyBot Search&Destroy".

Mc
 
marcus said:
check this out


services

gratz on the HoF & all...and the link is probably really useful, but if I don't see an in-game name on your personal page or have any idea who you are I'm skeptical.

No offence, but we build rep here ((and I know mine is basement for good reason atm))...but please identify yourself so we know who you are :)
 
McCormick said:
@Chainfire

Even a freshly installed XP doesnt have 10 svchosts runnign the same time here. :) I dont say it HAS to be evil...

But its often trojans that got installed OR took over System32 services. (worst case)

You can look at svchosts more detailed with the "process explorer" by SysInternals. (Which is now located at microsfot) omg :(

But I would recommend doing a full system scan with your AV and try at least "SpyBot Search&Destroy".

Mc

Hehe yeah SysInternals got bought up a few months ago. Indeed you can see which services are tied to a svchost (didn't know that, nice) so that gives you a good point to investigate.

And ofcourse, doing a full system scan with AV, AdAware and SpyBot is never a bad idea :)

But still, 10 svchosts, I wouldn't be alarmed. The PC I'm typing this on was built and setup about a week ago, and it has 9 of them running, and looking at Process Explorer, they're all legit. Last full scan was this morning and no weird stuff found. However, if you see them taking up a lot of resources (CPU and net), there's usually something wrong somewhere (not necessarily evil, but misconfigured maybe)

Oh and btw, running TWO virus scanners might be a part of the slowdown. AV's kind-of 'hack' to be able to scan stuff before it is executed, they might well be getting in eachothers way. But still, 33 processes might be a little overkill. Try deducting what they all are. You can disable a lot of BS processes by turning off services you don't need, and using msconfig to disable the loading of various things that really don't need to be loaded.
 
I use spybot, Ill do a scan more often, Thnax dudes... :D
 
Muddy -

If you're running Norton Internet Protection or even Norton AV, dump it... It's the biggest dog in the world... The monitoring process drastically slows system performance... I'd recommend AVG... It doesn't slow me down one bit and it's free :D
 
Here is site where you can check what each process does

Also there is something else you should seriously consider, and that is Services. Many of them are useless and can be disabled. Check Control Panel -> Administrative Tools -> Services

Each service has a brief description of what it does, but there are many other website that explain more and tell you what can and what shouldnt be disabled. This one looks ok but I didnt spend ages looking =)

One other final thing, and this is quite important. When you install some programs they add things like Services and Process that start up when you PC boots. Often you will get an icon in the bottom right. If you want to get rid of the filthy bastards then do this:

Go to Start -> Run then type in regedit and press enter. Then, navigate to HKEY_LOCAL_MACHINE -> Software -> Microsoft -> Windows -> CurrentVersion -> Run.

You will see all the filthy backdoor bastards that boot up when you PC starts up. Before you go deleting them all, I would suggest that you first of all select the Run key, and go to File -> Export and save a backup on your desktop. You can just run this file to add them all again if you change your mind. Check what each one is for before you delete it like, but if you do all this then reboot I will tell you, your pc will zoom :)

And one other thing, if you have a anti virus program installed then why dont you consider this: Keep it disabled, and only enable it to quickly check any dodgy files that you download. I hate anti virus programs with a passion. They are so wasteful. They sit there scanning every single file your PC accesses, even if its been scanned a million times already. Damn peice of shit useless :bomb:
 
Last edited:
Cool, NO NORTON!!! :wise:

ZoneAlarm PRO and like I said, SpyBot and other various passive AV scanners that arent running until I run them....

Thanx Sibbie, Ill try that stuff tonight.... :D
 
here are some that are required by windows to work with any decency.
Your set up will include these.
My setup has curently 26 process wich includes application processes like:
Mozilla, yahoo (the pager and service, 2 processes), Pe client loader, and a screenshot program.

I also run zone alarm wich takes up 2 proceses.
i also have 5 svchost instances as well.

Other programs you will have include.
explorer.exe (windows shell)
vsmon.exe (part of zone alarm)
wdfmngr.exe
spoolsv.exe (printer spooler)
lvcomsx.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
system
system idle process (you cant disable this unfortunitely)
you will also probrably have a driver for your sound card
also a driver or a control panel for you video card
(the control pannel for your vid card can be disabled)

Programs for windows loads in one of several places.
Including what ever is under the "Startup" portion of your program files list (the one you can access form the start button that you use to launch infrequently used programs)
As well as a couple of places in the windows registry
Sibuk told you where to look for one of them
In addition to run, look also for Runonce, and runonceex
In addition to looking under software>windows>currentversion under HK local machine look uinder the same path under HK current user.
and then there is the services control panel
Most of the stuff turned on under services can be disabled
MS enables all kinds of crap under services for a default installation
 
Kay-T said:
here are some that are required by windows to work with any decency.
Your set up will include these.
My setup has curently 26 process wich includes application processes like:
Mozilla, yahoo (the pager and service, 2 processes), Pe client loader, and a screenshot program.

I also run zone alarm wich takes up 2 proceses.
i also have 5 svchost instances as well.

Other programs you will have include.
explorer.exe (windows shell)
vsmon.exe (part of zone alarm)
wdfmngr.exe
spoolsv.exe (printer spooler)
lvcomsx.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
system
system idle process (you cant disable this unfortunitely)
you will also probrably have a driver for your sound card
also a driver or a control panel for you video card
(the control pannel for your vid card can be disabled)

Programs for windows loads in one of several places.
Including what ever is under the "Startup" portion of your program files list (the one you can access form the start button that you use to launch infrequently used programs)
As well as a couple of places in the windows registry
Sibuk told you where to look for one of them
In addition to run, look also for Runonce, and runonceex
In addition to looking under software>windows>currentversion under HK local machine look uinder the same path under HK current user.
and then there is the services control panel
Most of the stuff turned on under services can be disabled
MS enables all kinds of crap under services for a default installation

Thanx KT... :D
 
Back
Top