svchost.exe is not a trojan virus?
Users questions: QQ show the doctor suspicious Trojan program svchost.exe, I use 360, AVG_Anti-Spyware kill me after this but not the virus. LuckyStar is my computer user name. I forgot the map. . .
Experts answer:Svchost. exe file exists in "% systemroot% * system32" (for example, C: * Windows * system32) directory, which is the core of the important process of WindowsNT (Windows9X not the process), specifically for the system starts Various services. For example, call rpcss.dll Svchost.exe file, it will start rpcss Service (remoteprocedurecall). Svchost.exe is actually a service host, it did not in itself provide any Any services, but can be used to run the dynamic link library DLL files to start the corresponding service. Svchost.exe process can also start multiple services. Normal Svchost files should exist in the "c: * Windows * system32" directory, such as Fruit you find the path of its implementation in other directory, there is the possibility of contracting a virus or trojan, and should be immediately detected and addressed. Svchost process of how to kill can not afford to do? If some Svchost process in Task Manager you can not turn off of, you can use the ntsd command to kill it , As follows: first need to understand the Yusha the Svchost process, its PID is the number? In WindowsXP, press Ctrl + Alt + Del to open Task Manager, click the "processes tab" "View" "select out" in the pop-up window (Figure 4), check " PID (Process Identifier) "and then back to Task Manager, you can see the PID of the (for example, to kill the Svchost process, its PID is 844). Then shut down the process. Click" Start "" Programs "" Accessories "" Command Prompt "in the command prompt, enter the command ntsd-cq-p844 can kill the Svchost process (PID is 844). Tip: In addition to System, SMSS.EXE and CSRSS.EXE the three processes, ntsd command can kill any system process. From Windows2 000, the company has provided ntsd tool, the command post, allowing you access to debug the system right, it can be used to shut down most of the system process, if you encounter can not close the process, you can use this command, The kill process command format: ntsd-cq-p XXX XXX above process for the Yusha PID; ntsd-pXXX open in the debugger that a process (PID for the XXX); The-cq argument is that out of the debugger. Since the closure of the debugger, it opens the process will exit together with the debugger, so ntsd command to Closing process. This is killing on the network: process: C: * windows * svchost.exeO2-BHO: Webacc-(CAC068F3-A608-406B-8581-458788A67694)-C: * win dows * system32 * HKLM svchost.dllO4-*..* Run: [svc] C: * Windows * svchost.exeO4-HKCU *..* Run: [svc] C: * Windows * sv chost.exe killing method: 1, prohibits line with IceSword * process creation, end explorer.exe and svchost.exe process (be careful not to mistake) 2, delete the C: * windows * system32 * svcho st.dll and C: * windows * svchost.exe3, use HijackTHis repair the above-mentioned three note: must end explorer.exe explorer.exe or removal of the insertion of svchost.dl l (baohe Moderator posts 8th floor), because I do not want the end result, the test found that the use IceSword delete this svchost.exe, then explorer.exe will create it. Till I trouble ah well. Reference: Network screen. width*0.35)this.width=screen.width*0.40 *