Home » Post Item » Identify Loaded SVCHOST.EXE in Windows Task List
bakti (bak~ti) - plain: 2001>short for bakat **** hapit, umbok, bukol.
ti - plain for ti2x

guru (gooroo) - from Hindi guru meaning teacher, mentor; attracts disciples or followers.

use it as a sentence: pare, palagi nalang bakti ha, guru lagi gagalit...


Identify Loaded SVCHOST.EXE in Windows Task List

Saturday, August 25, 2007

Credit to Reymond CC 

Many times I've been asked what is svchost or svchost.exe that's loaded in Windows?

Svchost as the name implies stands for "Service Host". Many of components of the Windows operating system are implemented as what are called "services", a fancy name for programs that run in the background and aren't necessarily associated with whomever is logged into the machine. A fair number of those services are implemented in DLLs rather than in stand-alone executables. Since DLL can't run on its own, svchost is the one that loads the DLL.

Problem with svchost.exe nowadays is the common disguise used by malware to hide its presence from the user. As you can see from the image below, the svchost.exe doesn't show up much information in Windows Task Manager. You wouldn't even know if it is loading a legitimate DLL or not…

  

Here's how to identify what's really running as Svchost.exe on Windows XP Professional.

In command prompt, type the command below and hit enter.

tasklist /svc /fi "imagename eq svchost.exe"

The service name is displayed on the right side of the tasklist result.

  

To do a final match up of the somewhat cryptic service name to something more meaningful, you'll need to go to the service browser in Windows. An easy way to get there when running XP is to right click on "My Computer", and select "Manage". This opens the "Computer Management" application. On the left side you'll see a variety of locations, but in this case, you'll need the last one, "Services and Applications". Expand that (use the +), and click on the first item, "Services".

  

Now comes the tricky part. You'll need to guess to try to match the human readable name of the service with Windows name of the service. For example, one of the named services in the list on my computer was PID 1404, Dnscache. I looked through the lists of names and the most likely service was "DNS Client". I double clicked on the entry which shows the properties for that service:

  

The "Service Name" exactly matches what I was looking for: Dnscache. Now I know that PID 1404 is the Dnscache service.

What you want to see there is that the executable that is being run is "svchost.exe". In this case, PID 1404 is the DNS Client service. If you're not using Windows XP Professional, you might not have the "tasklist.exe" to display the task list. You can download tasklist.exe from here.

If you find it too troublesome, of course there's an easier way. Use Process Explorer by Sysinternals. Just move your mouse over on top of the svchost.exe and a balloon message will tell you the service name.

 

 


Posted by baktiguru at 1:43 pm | permalink

Previous Comments

So fun article is! I agree the idea!

Posted by Coach Bags Canada at June 13, 2011, 4:34 pm

a small Nvzei step up offensive: “Brother, or the last sentence, as long as you do not take me to the police station, can you let me do?” Tears glittering, glowing crystal light. Wang Bo Pielepiezui,

Posted by Global UGGs at August 11, 2011, 11:13 am

To most of the modern world, it’s a trademark of Ugg Australia, the division of the Deckers

Posted by Ugg Boots Outlet at September 21, 2011, 9:34 am

First of all appreciate your share, like your blog, the hope can share with you more wonderful blog,and I hope you will like Canada Goose Parka too.

Posted by Canada Goose Parka at October 10, 2011, 7:01 pm

associated with lower overcoats are manufactuMoncler lower coat offers some of essential actions to create their own lower coat. The actual make up red from the following. The exterior of the lower coat is usually made from long lasting

Posted by Cheap Moncler Jackets at October 11, 2011, 10:06 am

Already been reading for a couple of days now.. I want to see more!

Posted by Cheap Uggs at October 13, 2011, 3:42 pm

Fantastic site, also it seems like you have a ton much more visitors as well, since the last time I was here. Ciao!

Posted by Burberry Sale Outlet at October 13, 2011, 3:46 pm

Great writing from brilliant and imaginetive people but still no proof their is a God.

Posted by The North Face Outlet at October 13, 2011, 3:47 pm

So nice your blog is.

Posted by moncler sale at October 13, 2011, 4:42 pm

i am very excisted once i reading your aritic .it is unique about i read many blogs.

Posted by cheap ugg boots at October 25, 2011, 8:28 am

The article is of magnificent momentum, and sophisticated statements

Posted by uggs usa at November 4, 2011, 10:13 am

Great article about this topic, I have been lately in your blog once or twice now

Posted by abercrombie clearance at November 19, 2011, 1:55 pm

Nice post.Thank you for taking the time to publish this information very useful! I’m still waiting for some interesting thoughts from your side in your next post thanks.

Posted by Atlanta Alarm Monitoring at December 25, 2011, 8:55 am

The following content needs everyone really surely after which as a result of a individual, We discovered newest factors.

Posted by Moncler Outlet at December 28, 2011, 1:31 pm

Wanna to thank you for interesting posts buddy. Keep writing.

Posted by Tory Burch Outlet at December 28, 2011, 3:16 pm

Add a comment