<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tip: Tracking Down That Wiley Svchost Process</title>
	<atom:link href="http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/</link>
	<description>A Technology Crow in search of Bright Shiny Objects</description>
	<lastBuildDate>Sat, 11 Feb 2012 03:40:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Chris</title>
		<link>http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11765</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sun, 02 Sep 2007 13:42:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11765</guid>
		<description>@Sephyroth - It&#039;s built-in with winxp &amp; up.  I just tried it again on a couple XP SP2 machines and they all ran it just fine.

On my machine, tasklist.exe is located in c:\windows\system32.  Dated 8/4/2004 and is 71KB.

My win2k machine gave the same error you mention though.</description>
		<content:encoded><![CDATA[<p>@Sephyroth &#8211; It&#8217;s built-in with winxp &#038; up.  I just tried it again on a couple XP SP2 machines and they all ran it just fine.</p>
<p>On my machine, tasklist.exe is located in c:\windows\system32.  Dated 8/4/2004 and is 71KB.</p>
<p>My win2k machine gave the same error you mention though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sephyroth</title>
		<link>http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11745</link>
		<dc:creator>Sephyroth</dc:creator>
		<pubDate>Sun, 02 Sep 2007 05:01:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11745</guid>
		<description>I&#039;m using XP SP2, and tried to do that tasklist /svc command, but all I got was that &#039;tasklist&#039; is not recognized as a command or program, etc.

Is this a separately downloaded program, or is it something built into another version of Windows?

Sephyroth</description>
		<content:encoded><![CDATA[<p>I&#8217;m using XP SP2, and tried to do that tasklist /svc command, but all I got was that &#8216;tasklist&#8217; is not recognized as a command or program, etc.</p>
<p>Is this a separately downloaded program, or is it something built into another version of Windows?</p>
<p>Sephyroth</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11540</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 29 Aug 2007 15:36:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11540</guid>
		<description>Great tale, Michael!  And a good example of where runnning as LPU can be so very helpful -- and how much sysinternals tools rock.  :-)</description>
		<content:encoded><![CDATA[<p>Great tale, Michael!  And a good example of where runnning as LPU can be so very helpful &#8212; and how much sysinternals tools rock.  <img src='http://www.solo-technology.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11533</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 29 Aug 2007 13:38:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.solo-technology.com/blog/2007/08/28/tip-tracking-down-that-wiley-svchost-process/#comment-11533</guid>
		<description>I got hiyt by the mljjh.dll adware last week, but it was hard to detect since it was running behind an rundll.exe process. The malware was constantly accessing the disk, so I knew something was wrong.

Using FileMon, I looked at what was making all the disk pings (rundll.exe), and then using Process Explorer, I identified the file behind the operation (mljjh.dll). Only problem was that ending rundll.exe wouldn&#039;t help; it would just relaunch itself.

Since I run as an LPU (least priveleged user), Iw as able to switch to an admin user, and delete the DLL from there (since it wasn&#039;t running on that user).</description>
		<content:encoded><![CDATA[<p>I got hiyt by the mljjh.dll adware last week, but it was hard to detect since it was running behind an rundll.exe process. The malware was constantly accessing the disk, so I knew something was wrong.</p>
<p>Using FileMon, I looked at what was making all the disk pings (rundll.exe), and then using Process Explorer, I identified the file behind the operation (mljjh.dll). Only problem was that ending rundll.exe wouldn&#8217;t help; it would just relaunch itself.</p>
<p>Since I run as an LPU (least priveleged user), Iw as able to switch to an admin user, and delete the DLL from there (since it wasn&#8217;t running on that user).</p>
]]></content:encoded>
	</item>
</channel>
</rss>

