Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Dec 1st, 2008, 8:53pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   ???C:\I386\SVCHOST.EXE?? -Help
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: ???C:\I386\SVCHOST.EXE?? -Help  (Read 1515 times)
dsteve54
Newbie
*





   


Posts: 9
???C:\I386\SVCHOST.EXE?? -Help
« on: Mar 12th, 2003, 4:46am »
Quote Quote  Modify Modify

I have been using Trojanhunter 3.0 with updated rulesets for awhile, with a persistant
Port 5180/TCP is open (matches Peeper.120)
in the Port Scan section.  However, I have figured this to be benign because when I shut down AOL IM, the port closes.
 
Heretofore I have had no other problems reported...I do have a 3 computer LAN in my home in a peer-to-peer topology behind a router.  Each computer has Norton IS 2003, SpyWareBlaster, TrojanHunter, IE-SPYAD, AnalogX Cookie Wall, Paniware Pop Up Stopper.
 
Ok, everything has been fine....last night I downloaded TrojanHunter 3.5 and implemented and copied my license.dat back to the new dir, then deleted old 3.0 directory.  I updated the ruleset.
 
Now, on one of my computers, an XP Pro node, I am getting the same message as above under the Port Scan.  
 
But now I am getting a suspect file, like so:
 
Found possible trojan file: C:\I386\SVCHOST.EXE (LanFiltrator)
 
 
This is the first time this has happened.  Could this file have been there all along and only 3.5 version has detected it?
Do I simply just delete this file?  Could this be harmless..a false trojan message...it does say "possible"...is there a valid reason this file should be here?  If it is a trojan, could something have proliferated?  After deleting (if I should) do I quarantine anything else?  Can I stop any other spread or usage?   My Norton Antivirus with LiveUpdate current shows no virus files.  I have run www.hackerwhacker.com self test recently.
 
When I was downloading 3.5, I experienced irregularities...I reported to Magnus.  I got to www.misec.net fine and started downloading TrojanHunter 3.5 executable install.  The installation hung and I got "Invalid IP CheckSum" from Norton.
Magnus said he would appraise the situation but for now said there had been heavy hits on that server.  When I tried to go back to www.misec.net I got Bage Not Found..  I finally turned off NIS 2003 and got to the site and the download worked.  But it seemed funny, almost like there was a tainted file or process going on in the act of trying to download this new version.  I did a file disk virus scan and a full TrojanHunter 3.0 scan of C: drive before I deployed the new 3.5...all was ok.  Now I get this error.
 
Please advise on my next move.  So far this has just been reported on one machine.
 
Helppppppp....thx Sad
IP Logged
Joel
Newbie
*






   


Gender: male
Posts: 34
Re:  ???C:\I386\SVCHOST.EXE?? -Help
« Reply #1 on: Mar 12th, 2003, 7:29am »
Quote Quote  Modify Modify

The svchost.exe in i386 is a false positive that has been explained in another thread on the board here somewhere.  You can tell TH to ignore that file or you can just ignore the message when you see it.  I think this false positive may be eliminated in a future release.
IP Logged
Jamming
Stole All the Forum Stars
********




Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2039
Re:  ???C:\I386\SVCHOST.EXE?? -Help
« Reply #2 on: Mar 14th, 2003, 8:02am »
Quote Quote  Modify Modify

Good Job! Joel!  That's the kind of participation that keeps this board helpful and to the point, never be afraid to try and help because what mistakes are made will not usually make the problem worse.  If you say something that you know for sure say that if your not sure then say "this might help'.  No one is keeping score, but what you can do is only provide advice you feel comfortable with.  Never volunteer information that you feel uncomfortable saying, someone here with a different level of experience will help you out.  Regardless of what people believe there are not stars here, just a group of people with different talents, willing to help people out.
 
Thanks for being one of us,
IP Logged

Team Z Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca
I was born an American; I live an American; I shall die an American!
- Daniel Webster
dsteve54
Newbie
*





   


Posts: 9
Re:  ???C:\I386\SVCHOST.EXE?? -Help
« Reply #3 on: Mar 14th, 2003, 8:29am »
Quote Quote  Modify Modify

To Joel and Jamming:
Yes, *THANKS* to Joel for being succinct and indicating other references were on this site, rather than creating a whole new writeup.
 
I apologize Embarassed for creating an unnecessary post...if I had kept my head and *not* panicked instead, I would have thought to use SEARCH first and found in Trojanhunter forum the topic
http://www.misec.net/forum/?board=TrojanHunter;action=display;num=104698 2539;start=7
 
which TOTALLY answers my question (I just got a Dell machine also).
 
If a moderator or forum administrator sees this thread and wants to delete it, that would be ok with me.
 
From now on, I will use the SEARCH function FIRST Embarassed.
 
 
IP Logged
Jamming
Stole All the Forum Stars
********




Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2039
Re:  ???C:\I386\SVCHOST.EXE?? -Help
« Reply #4 on: Mar 15th, 2003, 9:32am »
Quote Quote  Modify Modify

Naw Steve, sometimes it is useful to have a reminder to others about the fact that other threads might be around that explains their problem.  You have set an example not to be ashamed of but to show others two important issues, one that there is a search function and you allowed Joel to show people how to be helpful in a positive way.  All in all not a wasted post even if it might appear to be a little embarrassing to you (which is not my belief).  Don't sell yourself short. Cool
IP Logged

Team Z Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca
I was born an American; I live an American; I shall die an American!
- Daniel Webster
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register