Things I learnt this week: SVCHOST

2008-10-25 12:23:02 +0000

SVCHOST services are configured by having ImagePath set to “%windir%\system32\svchost.exe -k name-of-service”, and a Parameters key containing ServiceDll (REG_EXPAND_SZ), which names a DLL with a ServiceMain entry point. ServiceMain has argc and argv.