hidden hit counter
Welcome to WindowsForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

svchost.exe

 
Goto page Previous  1, 2
   Windows XP (Home) -> General Discussion RSS
Next:  Boot manager, XP and Xandros  
Author Message
dP

External


Since: Feb 25, 2008
Posts: 7



(Msg. 16) Posted: Mon Feb 25, 2008 9:54 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: microsoft>public>windowsxp>general (more info?)

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:uV05bLCeIHA.4396@TK2MSFTNGP02.phx.gbl...
> From: "dP" <d_powelson.RemoveThis@hotmail.com>
>
> | I am not real comfortable handling this file. I would have to turn my
> | anti-virus protection off to send the file. It is picked up with my
> virus
> | scanner since it does not load as a device on boot. Apparently when it
> is
> | loaded as a device it is locked and not able to be scanned. I am not in
> a
> | hurry to be reinfected by this file.
> |
> | Do you have any specific instructions on handling?
> | Thanks,
> | DaveP
> |
>
> It is a .SYS file so it is a Trojan and not a virus and it is not
> executable.
>
> It is safe to handle.
>
> You said...
> "It is picked up with my virus scanner..."
>
> What anti virus application and what was it identified as ?
> That is what is the name of this Trojan ?
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>

I use AVAST, apparently the file is not able to be scanned while loaded and
it was loading as a device driver on boot, normal and safe mode. It was not
detected until i got it to quit loading.

Identified as: "Trojan Horse Win32:Agent-PTJ [Trj]"


Trojan horse or virus, i dont like em.

lol

You want it?

dP

 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 17) Posted: Mon Feb 25, 2008 10:17 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "dP" <d_powelson RemoveThis @xxx.hotmail.com>


|
| I did find the files. As it was loading as a device driver, besides manually
| looking through windows folders, about the only other was would of been
| doing a bootlog and reviewing loading device drivers to find this one. Then
| cleaning registry of all entries etc etc.
| My final "hard to kill" list included:
|
| hmq26.sys loading as a driver (various registry entries)
| wlctrl32.dll that was being renamed on boot from wlctrl32.dl_ (registry
| entry)
| nkv2.sys
| chl83.sys
| rwb48.sys (device driver)
| lshvahn.(i forget)
| zllictbl.dat
|
| I used various virus and malware scanners and hijack this. nothing was
| solving my problem nor even detecting the hmq26.sys while it was loading as
| a device driver. It was only after i got it to stop loading that the virus
| scanner able to scan and detect it. "Trojan Horse Win32:Agent-PTJ [Trj]"
| This trojan horse was connecting to ip addresses at a very rapid rate. .
|
| It was also loading is safe mode which kept the file locked.
|
| this was a very heavily infected machine (not mine) that made it a challenge
| to clean, but it is now CLEAN!
|

Are you sure ?

The PC may ave a RootKit or have a file using Alternate Data Stream (ADS).
http://www.securityfocus.com/infocus/1822

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp

 >> Stay informed about: svchost.exe 
Back to top
Login to vote
dP

External


Since: Feb 25, 2008
Posts: 7



(Msg. 18) Posted: Mon Feb 25, 2008 10:17 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:OmG8cYCeIHA.4852@TK2MSFTNGP05.phx.gbl...
> From: "dP" <d_powelson DeleteThis @xxx.hotmail.com>
>
>
> |
> | I did find the files. As it was loading as a device driver, besides
> manually
> | looking through windows folders, about the only other was would of been
> | doing a bootlog and reviewing loading device drivers to find this one.
> Then
> | cleaning registry of all entries etc etc.
> | My final "hard to kill" list included:
> |
> | hmq26.sys loading as a driver (various registry entries)
> | wlctrl32.dll that was being renamed on boot from wlctrl32.dl_ (registry
> | entry)
> | nkv2.sys
> | chl83.sys
> | rwb48.sys (device driver)
> | lshvahn.(i forget)
> | zllictbl.dat
> |
> | I used various virus and malware scanners and hijack this. nothing was
> | solving my problem nor even detecting the hmq26.sys while it was loading
> as
> | a device driver. It was only after i got it to stop loading that the
> virus
> | scanner able to scan and detect it. "Trojan Horse Win32:Agent-PTJ [Trj]"
> | This trojan horse was connecting to ip addresses at a very rapid rate. .
> |
> | It was also loading is safe mode which kept the file locked.
> |
> | this was a very heavily infected machine (not mine) that made it a
> challenge
> | to clean, but it is now CLEAN!
> |
>
> Are you sure ?
>
> The PC may ave a RootKit or have a file using Alternate Data Stream (ADS).
> http://www.securityfocus.com/infocus/1822>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
I am as sure as I can be. I have ran scans that are now coming up clean.
Used different scanners.
Do you have any suggestions to be REALLY sure?

System resources are no longer being taken over. All firewall logs are now
quiet. No unexplained activity. I am open to any suggestions you may have
to make sure it is clean.

DaveP
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 19) Posted: Mon Feb 25, 2008 10:20 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "dP" <d_powelson RemoveThis @xxx.hotmail.com>

| I use AVAST, apparently the file is not able to be scanned while loaded and
| it was loading as a device driver on boot, normal and safe mode. It was not
| detected until i got it to quit loading.
|
| Identified as: "Trojan Horse Win32:Agent-PTJ [Trj]"
|
| Trojan horse or virus, i dont like em.
|
| lol
|
| You want it?
|
| dP
|

Yes to make sure all AV vendors can recognize this Trojan.
Just remove ~nospam~ from my posting address.

Place it a password protected ZIP file with the password being; infected
{ password = infected }

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 20) Posted: Mon Feb 25, 2008 10:32 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "dP" <d_powelson.TakeThisOut@xxx.hotmail.com>


| I uploaded the file. It was previously reported on 11 Feb08. The whole
| problem with this file is where it loads. It doesnt appear to be detectable
| when loaded as a device driver. I am no expert but that does make it harder
| to locate and deal with.
|

If when the file is loaded and its File Handle is held open by the OS then it is in effect
protecting itself from being scanned.

Malware uses many forms of self preservation techniques to keep itself running on the PC,
and delivering its payload, and keep the unitiated from removing it.

The Recovery Console is an effective way to deal with such a file. Load the Recovery
Console. Rename the file and it will no longer be able to be loaded and you can then go
about cleaing the PC as well as submitting it to places like Virus Total to understand what
it is and what it does.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
dP

External


Since: Feb 25, 2008
Posts: 7



(Msg. 21) Posted: Mon Feb 25, 2008 10:32 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

> The Recovery Console is an effective way to deal with such a file. Load
> the Recovery
> Console. Rename the file and it will no longer be able to be loaded and
> you can then go
> about cleaing the PC as well as submitting it to places like Virus Total
> to understand what
> it is and what it does.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>

I can get them killed if I can find them. Its the finding part that is a
challenge at times.
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 22) Posted: Mon Feb 25, 2008 10:33 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "dP" <d_powelson.RemoveThis@xxx.hotmail.com>


| I am as sure as I can be. I have ran scans that are now coming up clean.
| Used different scanners.
| Do you have any suggestions to be REALLY sure?
|
| System resources are no longer being taken over. All firewall logs are now
| quiet. No unexplained activity. I am open to any suggestions you may have
| to make sure it is clean.
|
| DaveP
|

Have you used programs such as AutoRuns and ProcessExplorer ?

Have you used an Anti RootKit utility such as Gmer ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
dP

External


Since: Feb 25, 2008
Posts: 7



(Msg. 23) Posted: Mon Feb 25, 2008 10:33 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:OvdEghCeIHA.5164@TK2MSFTNGP03.phx.gbl...
> From: "dP" <d_powelson DeleteThis @xxx.hotmail.com>
>
>
> | I am as sure as I can be. I have ran scans that are now coming up
> clean.
> | Used different scanners.
> | Do you have any suggestions to be REALLY sure?
> |
> | System resources are no longer being taken over. All firewall logs are
> now
> | quiet. No unexplained activity. I am open to any suggestions you may
> have
> | to make sure it is clean.
> |
> | DaveP
> |
>
> Have you used programs such as AutoRuns and ProcessExplorer ?
>
> Have you used an Anti RootKit utility such as Gmer ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>

I have and did use process explorer. I did not find this file using process
explorer. I do not see any unidentifiable processes using process explorer.
Unfamiliar with the others.

DaveP
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
dP

External


Since: Feb 25, 2008
Posts: 7



(Msg. 24) Posted: Mon Feb 25, 2008 10:33 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

>> Have you used an Anti RootKit utility such as Gmer ?


Thanks for the heads up on Gmer. I have downloaded it and added it to my
collection of tools.

daveP
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
Thee Chicago Wolf

External


Since: Aug 21, 2007
Posts: 145



(Msg. 25) Posted: Tue Feb 26, 2008 12:56 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
Thee Chicago Wolf

External


Since: Aug 21, 2007
Posts: 145



(Msg. 26) Posted: Tue Feb 26, 2008 12:56 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

This message is not archived
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
DaveP

External


Since: Oct 08, 2005
Posts: 16



(Msg. 27) Posted: Tue Feb 26, 2008 5:42 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I have run Gmer, CatchMe, SDfix, Ad-Aware 2007 and Avast.
SDfix found one small thing. Looks great.
Thanks for all your input.

DaveP


--
dP
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:OvdEghCeIHA.5164@TK2MSFTNGP03.phx.gbl...
> From: "dP" <d_powelson DeleteThis @xxx.hotmail.com>
>
>
> | I am as sure as I can be. I have ran scans that are now coming up
> clean.
> | Used different scanners.
> | Do you have any suggestions to be REALLY sure?
> |
> | System resources are no longer being taken over. All firewall logs are
> now
> | quiet. No unexplained activity. I am open to any suggestions you may
> have
> | to make sure it is clean.
> |
> | DaveP
> |
>
> Have you used programs such as AutoRuns and ProcessExplorer ?
>
> Have you used an Anti RootKit utility such as Gmer ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 28) Posted: Tue Feb 26, 2008 6:53 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "DaveP" <d_powelson.DeleteThis@xxxhotmail.com>

| I have run Gmer, CatchMe, SDfix, Ad-Aware 2007 and Avast.
| SDfix found one small thing. Looks great.
| Thanks for all your input.
|
| DaveP
|

No sweat. I would still like that file or files Smile

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
DaveP

External


Since: Oct 08, 2005
Posts: 16



(Msg. 29) Posted: Tue Feb 26, 2008 6:53 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

>
> No sweat. I would still like that file or files Smile
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>

sent
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
David H. Lipman

External


Since: Mar 14, 2004
Posts: 1767



(Msg. 30) Posted: Tue Feb 26, 2008 8:16 pm
Post subject: Re: svchost.exe [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "DaveP" <d_powelson.RemoveThis@xxxhotmail.com>


| sent
|

Received and provided to researchers.

BTW: The files received were for a spambot using RootKit techniques.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: svchost.exe 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
svchost x7 - I'm sure this question has been asked before, but i'm gonna ask it again. Why is there 7 instances of svchost.exe running in the processes tab? 4 of them are system run, 2 of them are local services, and the last one is a local service thanks -- ..

SVCHOST.EXE ??????????? - what is svchost.exe?? and why does it use so much memory???

SVCHost @ ~95% CPU - I'm helping a friend diagose an odd problem on his rather old AMD system running XP with current updates. At times, usually a minute or two after booting the computer, something kicks in and takes up ~95% of the CPU and is shown as SVCHost in Taskmgr. ....

Svchost - Hello, I have a computer that had a bad case of virus infection. Norton did not help, had to do Smithfraud. Then I started to get the svchost error on startup. I did not know what else to do so I did a repair install of windows, then downloaded all th...

svchost using near 100% CPU usage - My computer is screwing up badly. The task manager says svchost is using near 100 % of my CPU. The machine is sluggish. I've run McAfee antivirus and adaware with no luck so far. The fan in my laptop is running constantly to try to cool the machine...
   Windows XP (Home) -> General Discussion All times are: Eastern Time (US & Canada) (change)
Goto page Previous  1, 2
Page 2 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You can edit your posts in this forum
You can delete your posts in this forum
You can vote in polls in this forum

Categories:
  Windows XP
 Win 2000/NT/98/ME
 Windows Vista!


[ Contact us | Terms of Service/Privacy Policy ]