How to find spyware dll launched using svchost.exe

Posted by Sheen on Super User See other posts from Super User or by Sheen
Published on 2010-11-22T09:54:25Z Indexed on 2011/03/11 16:12 UTC
Read the original article Hit count: 251

Filed under:
|
|

This weekend I found my PC was possibly infected by some virus or spyware. There is one "svchost.exe -k netsvcs" in my task manager, and it is running under my user name, rather than SYSTEM accounts. There is already another same process with same command line options under SYSTEM account.

This user account svchost.exe consistently consumes 50% CPU (1 of 2 cores of my CPU). In Process Explorer, I can see it is started by explorer.exe, instead of services.exe. However, I failed to find its real service dll place in registry or disk. Does anyone know how to find this malicious program?

© Super User or respective owner

Related posts about windows-7

Related posts about malicious