In looking thru this forum, I found some advice on svchost.exe should not be in c:\windows only in c:\windows\system32. I have been having what appears to be a virus problem. So I have removed svchost.exe, it had a date on it that was current when I started having the problem, plus a file size of 544kb. I searched the registry and found it referenced in the image path of several registry entries, all similar, HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Service\Netlogin. NOTE that is netlogin, not netlogon. Using process explorer I saw this process running as well, with no name (the other svchost process had microsoft names). I also brought up admin tools-->services and found a netlogin service with no names set to automatic startup. I changed it do disabled. I could find not hits on netlogin, only netlogon. Is it save to remove these registry entires? Or am I messing with stuff I should not be?
Thank you
|