 |
|
 |
|
Next: Boot manager, XP and Xandros
|
| Author |
Message |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 1) Posted: Sat Feb 23, 2008 3:09 pm
Post subject: svchost.exe Archived from groups: microsoft>public>windowsxp>general (more info?)
|
|
|
I have been cleaning a virus infected XPP machine. What i am down to I
havent seen before.
before connecting to the internet i have normal memory usage and 6 svchost
processes running.
After connecting to internet svchost processes jump to about 12.
I have used "tasklist /svc" and "process explorer" for viewing services
associated with but these extra svchost processes do not show any services
running however they are using several hundred mb's of ram. My ram usage is
escalating to the point of the computer running out of virtual memory.
A couple of these extra svchost processes are showing large amounts of TCP
activity to
216.195.56.227:2543
and
208.66.194.240:2509
earler when i thought i had this problem fixed
it was connecting to
208.72.169.19:1939
CyberPatrol was on this computer but i believe I removed it successfully.
Any ideas would be greatly appreciated. Thanks for any help.
DaveP
--
dP >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Feb 09, 2008 Posts: 146
|
(Msg. 2) Posted: Sat Feb 23, 2008 3:09 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
DaveP wrote:
> I have been cleaning a virus infected XPP machine. What i am down to I
> havent seen before.
> before connecting to the internet i have normal memory usage and 6 svchost
> processes running.
> After connecting to internet svchost processes jump to about 12.
> I have used "tasklist /svc" and "process explorer" for viewing services
> associated with but these extra svchost processes do not show any services
> running however they are using several hundred mb's of ram. My ram usage
> is escalating to the point of the computer running out of virtual memory.
>
> A couple of these extra svchost processes are showing large amounts of TCP
> activity to
> 216.195.56.227:2543
> and
> 208.66.194.240:2509
> earler when i thought i had this problem fixed
> it was connecting to
> 208.72.169.19:1939
>
> CyberPatrol was on this computer but i believe I removed it successfully.
The machine is still not clean. Review these general malware removal
procedures to see if you did something similar, including the prep work and
scanning in Safe Mode:
http://www.elephantboycomputers.com/page2.html#Removing_Malware
If you weren't that thorough, try again. If you were that thorough:
When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the first link above (not here, please).
Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic! >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 3) Posted: Sat Feb 23, 2008 8:43 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
--
dP
"Malke" <malke DeleteThis @invalid.invalid> wrote in message
news:OsobE1mdIHA.4588@TK2MSFTNGP06.phx.gbl...
> DaveP wrote:
>
>> I have been cleaning a virus infected XPP machine. What i am down to I
>> havent seen before.
>> before connecting to the internet i have normal memory usage and 6
>> svchost
>> processes running.
>> After connecting to internet svchost processes jump to about 12.
>> I have used "tasklist /svc" and "process explorer" for viewing services
>> associated with but these extra svchost processes do not show any
>> services
>> running however they are using several hundred mb's of ram. My ram usage
>> is escalating to the point of the computer running out of virtual memory.
>>
>> A couple of these extra svchost processes are showing large amounts of
>> TCP
>> activity to
>> 216.195.56.227:2543
>> and
>> 208.66.194.240:2509
>> earler when i thought i had this problem fixed
>> it was connecting to
>> 208.72.169.19:1939
>>
>> CyberPatrol was on this computer but i believe I removed it successfully.
>
> The machine is still not clean. Review these general malware removal
> procedures to see if you did something similar, including the prep work
> and
> scanning in Safe Mode:
>
> http://www.elephantboycomputers.com/page2.html#Removing_Malware
>
> If you weren't that thorough, try again. If you were that thorough:
>
> When all else fails, run HijackThis and post your log in one of the
> specialty forums listed at the first link above (not here, please).
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!
Thank you for your response. I will review the link you posted. Obviously i
am missing something.
Thanks. >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Aug 21, 2007 Posts: 145
|
(Msg. 4) Posted: Sat Feb 23, 2008 10:21 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Imported from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 5) Posted: Sat Feb 23, 2008 10:21 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
--
dP
"Thee Chicago Wolf" <.@.> wrote in message
news:1k81s31630qftb891k87imn7e7vbecdq07@4ax.com...
> >I have been cleaning a virus infected XPP machine. What i am down to I
>>havent seen before.
>>before connecting to the internet i have normal memory usage and 6 svchost
>>processes running.
>>After connecting to internet svchost processes jump to about 12.
>>I have used "tasklist /svc" and "process explorer" for viewing services
>>associated with but these extra svchost processes do not show any services
>>running however they are using several hundred mb's of ram. My ram usage
>>is
>>escalating to the point of the computer running out of virtual memory.
>>
>>A couple of these extra svchost processes are showing large amounts of TCP
>>activity to
>>216.195.56.227:2543
>>and
>>208.66.194.240:2509
>>earler when i thought i had this problem fixed
>>it was connecting to
>>208.72.169.19:1939
>>
>>CyberPatrol was on this computer but i believe I removed it successfully.
>>
>>Any ideas would be greatly appreciated. Thanks for any help.
>>
>>DaveP
>
> Couple of tools to use to see if something is posing as svchost.exe
> and / or if it's hiding in some other directory.
>
> 1. Process Explorer: Let's you see the programs associated with the
> svchost.exe session.
>
> 2. tcpview: Let's you see the connections and ports associated with
> the exe's.
>
> - Thee Chicago Wolf
Thanks for your response, but as you can see from my post I did use process
explorer. There are no services associated with the svchost processes in
question.
Again thanks for your time. >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 6) Posted: Sun Feb 24, 2008 6:12 am
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
--
dP
"Malke" <malke DeleteThis @invalid.invalid> wrote in message
news:OsobE1mdIHA.4588@TK2MSFTNGP06.phx.gbl...
> DaveP wrote:
>
>> I have been cleaning a virus infected XPP machine. What i am down to I
>> havent seen before.
>> before connecting to the internet i have normal memory usage and 6
>> svchost
>> processes running.
>> After connecting to internet svchost processes jump to about 12.
>> I have used "tasklist /svc" and "process explorer" for viewing services
>> associated with but these extra svchost processes do not show any
>> services
>> running however they are using several hundred mb's of ram. My ram usage
>> is escalating to the point of the computer running out of virtual memory.
>>
>> A couple of these extra svchost processes are showing large amounts of
>> TCP
>> activity to
>> 216.195.56.227:2543
>> and
>> 208.66.194.240:2509
>> earler when i thought i had this problem fixed
>> it was connecting to
>> 208.72.169.19:1939
>>
>> CyberPatrol was on this computer but i believe I removed it successfully.
>
> The machine is still not clean. Review these general malware removal
> procedures to see if you did something similar, including the prep work
> and
> scanning in Safe Mode:
>
> http://www.elephantboycomputers.com/page2.html#Removing_Malware
>
> If you weren't that thorough, try again. If you were that thorough:
>
> When all else fails, run HijackThis and post your log in one of the
> specialty forums listed at the first link above (not here, please).
>
> Malke
> --
> MS-MVP
> Elephant Boy Computers
> www.elephantboycomputers.com
> Don't Panic!
It took another closer manual file search to find 3 files that were causing
my problems.. Had to use my "magic cd" to get rid of them.
in windows\system32\
"WLCtrl32.dll"
"Zllictbl.dat"
in windows\system32\drivers\
"rwb48.sys"
Thanks again,
daveP >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 7) Posted: Sun Feb 24, 2008 4:10 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
--
dP
"DaveP" <d_powelson RemoveThis @xxxhotmail.com> wrote in message
news:%23fjUE6tdIHA.4712@TK2MSFTNGP04.phx.gbl...
>
>
> --
> dP
> "Malke" <malke RemoveThis @invalid.invalid> wrote in message
> news:OsobE1mdIHA.4588@TK2MSFTNGP06.phx.gbl...
>> DaveP wrote:
>>
>>> I have been cleaning a virus infected XPP machine. What i am down to I
>>> havent seen before.
>>> before connecting to the internet i have normal memory usage and 6
>>> svchost
>>> processes running.
>>> After connecting to internet svchost processes jump to about 12.
>>> I have used "tasklist /svc" and "process explorer" for viewing services
>>> associated with but these extra svchost processes do not show any
>>> services
>>> running however they are using several hundred mb's of ram. My ram
>>> usage
>>> is escalating to the point of the computer running out of virtual
>>> memory.
>>>
>>> A couple of these extra svchost processes are showing large amounts of
>>> TCP
>>> activity to
>>> 216.195.56.227:2543
>>> and
>>> 208.66.194.240:2509
>>> earler when i thought i had this problem fixed
>>> it was connecting to
>>> 208.72.169.19:1939
>>>
>>> CyberPatrol was on this computer but i believe I removed it
>>> successfully.
>>
>> The machine is still not clean. Review these general malware removal
>> procedures to see if you did something similar, including the prep work
>> and
>> scanning in Safe Mode:
>>
>> http://www.elephantboycomputers.com/page2.html#Removing_Malware
>>
>> If you weren't that thorough, try again. If you were that thorough:
>>
>> When all else fails, run HijackThis and post your log in one of the
>> specialty forums listed at the first link above (not here, please).
>>
>> Malke
>> --
>> MS-MVP
>> Elephant Boy Computers
>> www.elephantboycomputers.com
>> Don't Panic!
>
> It took another closer manual file search to find 3 files that were
> causing my problems.. Had to use my "magic cd" to get rid of them.
>
> in windows\system32\
> "WLCtrl32.dll"
> "Zllictbl.dat"
> in windows\system32\drivers\
> "rwb48.sys"
>
> Thanks again,
> daveP
>
I spoke too soon.ARGH! >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Feb 09, 2008 Posts: 146
|
(Msg. 8) Posted: Sun Feb 24, 2008 4:10 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Aug 21, 2007 Posts: 145
|
(Msg. 9) Posted: Mon Feb 25, 2008 8:40 am
Post subject: Re: svchost.exe [Login to view extended thread Info.] Imported from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Oct 08, 2005 Posts: 16
|
(Msg. 10) Posted: Mon Feb 25, 2008 5:16 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
--
dP
"Thee Chicago Wolf" <.@.> wrote in message
news:knk5s319giouiecrr4jjltulaodtphf1h3@4ax.com...
> On Sat, 23 Feb 2008 20:39:01 -0600, "DaveP"
> <d_powelson DeleteThis @xxxhotmail.com> wrote:
>
>>Thanks for your response, but as you can see from my post I did use
>>process
>>explorer. There are no services associated with the svchost processes in
>>question.
>>
>>
>>Again thanks for your time.
>
> Sorry about that, must have jumped the gun a bit. It does seem like
> something else must be still on the PC. Other than SpyBot or Adaware,
> have you tried running the Malicious Software Removal Tool? Start >
> Run > mrt.exe and click ok.
>
> - Thee Chicago Wolf
No problem, I finally found a file "hmq26.sys" that was loading as a device.
It did take some time to do a file by file search to find this culprit.
Then a major manual registry cleaning to follow. At this time i do believe
that I am clean.
I appreciate your input.
DaveP >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Mar 14, 2004 Posts: 1767
|
(Msg. 11) Posted: Mon Feb 25, 2008 6:22 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Feb 25, 2008 Posts: 1
|
(Msg. 12) Posted: Mon Feb 25, 2008 8:42 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
I am not real comfortable handling this file. I would have to turn my
anti-virus protection off to send the file. It is picked up with my virus
scanner since it does not load as a device on boot. Apparently when it is
loaded as a device it is locked and not able to be scanned. I am not in a
hurry to be reinfected by this file.
Do you have any specific instructions on handling?
Thanks,
DaveP
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%23Ad3SVAeIHA.4704@TK2MSFTNGP03.phx.gbl...
> From: "DaveP" <d_powelson RemoveThis @xxxhotmail.com>
>
> |
>
> Please submit a sample of "hmq26.sys" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition,
> unless told
> otherwise, Virus Total will provide the sample to all participating
> vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
> >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Feb 25, 2008 Posts: 7
|
(Msg. 13) Posted: Mon Feb 25, 2008 9:10 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
|
|
| Back to top |
|
 |  |
External

Since: Feb 25, 2008 Posts: 7
|
(Msg. 14) Posted: Mon Feb 25, 2008 9:24 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:%23Ad3SVAeIHA.4704@TK2MSFTNGP03.phx.gbl...
> From: "DaveP" <d_powelson.DeleteThis@xxxhotmail.com>
>
> |
>
> Please submit a sample of "hmq26.sys" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition,
> unless told
> otherwise, Virus Total will provide the sample to all participating
> vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
I uploaded the file. It was previously reported on 11 Feb08. The whole
problem with this file is where it loads. It doesnt appear to be detectable
when loaded as a device driver. I am no expert but that does make it harder
to locate and deal with. >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
External

Since: Mar 14, 2004 Posts: 1767
|
(Msg. 15) Posted: Mon Feb 25, 2008 9:54 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
From: "dP" <d_powelson.TakeThisOut@hotmail.com>
| I am not real comfortable handling this file. I would have to turn my
| anti-virus protection off to send the file. It is picked up with my virus
| scanner since it does not load as a device on boot. Apparently when it is
| loaded as a device it is locked and not able to be scanned. I am not in a
| hurry to be reinfected by this file.
|
| Do you have any specific instructions on handling?
| Thanks,
| DaveP
|
It is a .SYS file so it is a Trojan and not a virus and it is not executable.
It is safe to handle.
You said...
"It is picked up with my virus scanner..."
What anti virus application and what was it identified as ?
That is what is the name of this Trojan ?
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp >> Stay informed about: svchost.exe |
|
| Back to top |
|
 |  |
| Related Topics: | svchost x7 - I'm sure this question has been asked before, but i'm gonna ask it again. Why is there 7 instances of svchost.exe running in the processes tab? 4 of them are system run, 2 of them are local services, and the last one is a local service thanks -- ..
SVCHOST.EXE ??????????? - what is svchost.exe?? and why does it use so much memory???
SVCHost @ ~95% CPU - I'm helping a friend diagose an odd problem on his rather old AMD system running XP with current updates. At times, usually a minute or two after booting the computer, something kicks in and takes up ~95% of the CPU and is shown as SVCHost in Taskmgr. ....
Svchost - Hello, I have a computer that had a bad case of virus infection. Norton did not help, had to do Smithfraud. Then I started to get the svchost error on startup. I did not know what else to do so I did a repair install of windows, then downloaded all th...
svchost using near 100% CPU usage - My computer is screwing up badly. The task manager says svchost is using near 100 % of my CPU. The machine is sluggish. I've run McAfee antivirus and adaware with no luck so far. The fan in my laptop is running constantly to try to cool the machine... |
|
You can post new topics in this forum You can reply to topics in this forum You can edit your posts in this forum You can delete your posts in this forum You can vote in polls in this forum
|
|
|
|
 |
|
|