Jump to content
Tuts 4 You

svchost rootkit

jolin wong

Recommended Posts

I have ten svchost.exe process running in the computer,  process explorer shows all of them coming from c:\windows\system32 directory, so looks like no malware, but is there any chance that  rootkit can do process injection to svchost, any tool can detect it? thanks

Link to comment
Share on other sites

  • 4 weeks later...

I you can make a clean install of your operating system. you can see how many svchost.exe are running. Also what kind of rootkit are you talking about? is it Userland or Ring-0 Rootkit? 😁

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Create New...