Author Topic: help with c:\\windows\system32\svchost.exe Virus  (Read 29958 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #30 on: February 25, 2015, 06:41:41 PM »
here we go

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #31 on: February 25, 2015, 06:59:18 PM »
OK a new programme has been released that makes investigating what is using svchost easy

Download the Technical toolbox (portable)   to your desktop
Run the programme and on the left select Svchost.exe lookup

Right click any where on the right and select Copy list
Open notepad and select paste
Save that as svchost
And attach to your next post


REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #32 on: February 25, 2015, 07:36:01 PM »
wow, that's awesome! thanx for the tip, I'm running it right now

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #33 on: February 25, 2015, 07:37:05 PM »
here's the list

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #34 on: February 25, 2015, 07:43:23 PM »
OK ta, it will take me a while to run a compare on this

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #35 on: February 28, 2015, 05:49:27 PM »
okay. well thank you very much for all the help already. and if there's anything I can / should do, let me know...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #36 on: February 28, 2015, 06:02:15 PM »
OK I have run a compare and for the life of me cannot see where it is coming from

This programme will generate a zip file, if you could upload it to a file sharing site for me to collect

 Download AVZ tool from here to your desktop
Unzip all files to a folder on your desktop
Open the folder and double click the AVZ icon
When the tool opens select "File" > "Standards scripts"


Place a tick in :

 
5. Update signature database


Then press "Execute selected scripts"


Once that has execute then
select "File" > "Standards scripts"
Place a tick in :

3.   Advanced  System Analysis with malware removal mode enabled


When finished look in the folder AVZ4 on your desktop
Open the LOG folder
Attach KL_syscure.zip to your next post


REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #37 on: March 01, 2015, 01:57:58 PM »
okay. what a crafty little virus... grrrr...

I ran the scan three times because for some reason, it never created the zip-folder you asked me to share with you. maybe I have a different version? or maybe I made a mistake?

whenever I run the scans, it creates two zip-folders in the LOG folder: one is called virusinfo_autoquarantine (this one is empty). the other one is called virusinfo_syscure. I uploaded the second one to dropbox so you can have a look:

https://www.dropbox.com/s/x1zqncmhc8qw1p8/virusinfo_syscure.zip?dl=0

I also attached three pictures of the different avz-tabs, in case I made a mistake and have to run a different scan.

thanx again. let me know what to do next!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #38 on: March 01, 2015, 03:16:10 PM »
That's the one, I need to change my instructions

C:\Program Files (x86)\Tinn-R did you install this programme ?

Also could you temporarily disable Spotify and Skype from running at start


REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #39 on: March 01, 2015, 06:42:28 PM »
okay, great!

Tinn-R is a code editor that I installed to work with the open source statistical software R (http://www.r-project.org).
I installed it maybe one or two years ago and it seems unlikely that it would cause problems now all of a sudden, no?

I deactivated spotify autorun. skype wasn't in my autorun list and it actually never does run when I start my computer. I always have to start it manually. so if your list says otherwise, that's weird.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #40 on: March 01, 2015, 10:55:39 PM »
Checking through the active and waiting connection shows nothing that should not be running.  I will ask some network gurus for assistance 

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #41 on: March 02, 2015, 12:17:11 AM »
thank you lots.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #42 on: March 02, 2015, 01:59:31 PM »
OK I have a few options, one is a programme which I have never used before so I am testing that out

The other is sysinternals

Download to your desktop process explorer from here http://technet.microsoft.com/en-gb/sysinternals/bb896653.aspx
Open process explorer and from the menu bar select View > Lower Pane
A Lower window will open
Select svchost.exe
 As soon as an Alert appears do the following :
Then on the menu bar go to File > Save as..
Then select the desktop and click save
On the desktop will then be a text file called svchost please attach that
You may need to edit the file name from svchost.exe.txt  to svchost.txt  to allow it to be attached

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #43 on: March 02, 2015, 06:14:41 PM »
oookeydokey.

so, I did what you asked. I'm not sure I did it right but well...

cuz svchost.exe shows up in the process list eleven times. sometimes it has a tree of sub-processes, sometimes it doesn't.

however, I "selected" the first one in the list and right when the alarm popped up, I saved a report.

the svchost.exe.txt and a screenshot are attached.

REDACTED

  • Guest
Re: help with c:\\windows\system32\svchost.exe Virus
« Reply #44 on: March 02, 2015, 06:15:47 PM »
hmmm... why didn't it attach the file... I'll try again