Tuesday, April 14, 2009

Determine what application is using svchost to connect to Internet

Google keyword (not too useful):
discover|determine|check program|application|software
using svchost connect|download internet

Own experience:
Run TCPView to discover PID of svchost instance connecting to Internet.
Use Process Explorer to see properties of svchost in question.
Check TCP/IP tab for established connection and the destination.
Check Services tab for service(s) with suspicious path.

Related
--------
10 Tools to Easily Determine If a Specific Process is Secretly Accessing the Internet

No comments:

Post a Comment