Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

Security Issue? with Windows Audio Endpoint Builder

microsoft.public.windows.vista.security



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 08-29-2008
Nobias Nobias is offline
 

Join Date: Aug 2008
Posts: 3
Nobias is on a distinguished road
Thanks: 0
Thanked 0 Times in 0 Posts
Security Issue? with Windows Audio Endpoint Builder
Security Issue? with Windows Audio Endpoint Builder Hello. I was tracking down why my svhost.exe (used for internet & network Connections) was being used to access a whole bunch of Picture files in one of my folders. Files that were not being used by any other program or service at the time (not even the File Manager). It was running under LocalSystemNetworkRestricted mode and i tracked the PID to the "Windows Audio Endpoint builder" Service. I used the resource monitor to see that the WAEB was accessing numerous files in various folders. What stood out was my personal pictures it was accessing.

I looked the service up and in no way is it dependant on or is depended on by any system except AUDIO on the computer. However according to a company that deals in computer security (and Microsoft) it is a service launched by the legitimate 'C:\Windows\System32\svchost.exe' program.

The actual executable file for the Windows Audio Endpoint Builder service is 'C:\Windows\System32\audiosrv.dll'.

Now this 'service' was reading my picture (JPG) files in the Public folder that has no system files in it. Can anyone explain why an Audio Support DLL is interested in my Pictures? As well as other files.

I saw mention of this service having something to do with the System Indexing Serice as well in my search results when trying to find information. If it is related to indexing then why is it interested in NON-AUDIO files at all? if the indexer uses 'Associated With' executables to 'read' files for indexing then it should be using an audio processor to deal with audio files and an image processor for pictures, etc -- right?

My concern is that it is being used as a backdoor or such to grab files for a third party. Though I cannot find that this file sends data beyond my machine, it may process it for another program which would. As yet i cannot find anything suspicious on the outgoing side.

I realize that Microsoft is trying to use internet protocols for program interactions (even within the same machine) in support of its ditributed processing theme (BAD idea), but allowing such DLLs to be connected to much less - Launched By - the same service that talks to the internet seems risky, if not downright stupid (Thats a seperate subject alone).

Any Thoughts or comments would be appreciated.

THANK YOU
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Issue? with Windows Audio Endpoint Builder Nobias Security News 0 08-29-2008 05:26
Security Issue with Vista's 'Audio Endpoint builder' Nobias microsoft.public.windows.vista.general 0 08-29-2008 05:19
Windows Audio Endpoint Builder Service fails to start Kghareus microsoft.public.windows.vista.installation setup 0 02-14-2008 19:32
Symantec Endpoint Protection - A Unified, proactive approach to endpoint security Steve Security News 0 08-21-2007 22:12
Windows Audio Endpoint builder: high cpu usage =?Utf-8?B?ZWRzYWdlcg==?= microsoft.public.windows.vista.performance maintenance 0 04-15-2007 09:38


All times are GMT +1. The time now is 10:22.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119