|
Posted by David H. Lipman on April 29, 2008, 5:18 pm
If you were Registered and logged in, you could reply and use other advanced thread options
>> Service load:
| 0% 100%
| File: svchost(3).exe
| Status:
< snip >
| Found nothing
| Yes, the file is executed from %windir%\system32.
This is an illegitimate process...
%windir%\system32\svchost(3).exe
I am surprized that nothing was detected, even a heuristic detection.
Could you please provide me a sample.
Place svchost(3).exe in a password protected ZIP file with the password being;
infected
{ password = infected }
And send the file to DLipman~nospam~@Verizon.Net
removing ~nospam~ from trhe above address.
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
|