• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

The importance of updates on a post-virus install

T

twilyth

Guest
I'm not sure I had a virus, but at this point, I would have to say that the odds are in favor of it.

I noticed that of 3 machines, only one had a dozen or more instances of svchost.exe. In fact, on the other 2, there were no instances at all. So I formatted the drive and reinstalled W7.

But before the updates were done, i used IE to dl firefox. A couple hours later I happen to look at taskmanger and there are those svchost pgms again.

So I format and reinstall again, but this time do all the updates first before even enabling the ethernet card (i turned it on to dl the updates and off while they were being installed).

Now when I check, not a single svchost is running.

I should also mention that after the first install, FF was acting weird, telling me that it was running in "safe mode" - whatever that is.

the only way I could have gotten infected again was through a hole in IE. But even that blows my mind because that means that these guys must be sitting on every IP address out there like hungry dogs.

I still have some more software to install before the 2 installs are exactly comparable, but I don't think anything I have left will be needing a dozen instances of svchost.

edit: oh, the reason I was in taskmanager was because MSE found a virus in a file on the drive I just formated and it was in an IE directory and related to FF. That together with the litter of svchost pgms made think something was definitely amiss.
 

brandonwh64

Addicted to Bacon and StarCrunches!!!
Joined
Sep 6, 2009
Messages
19,542 (3.66/day)
I wouldnt worry about svchost.exe, it is not a virus.



svchost.exe is a process and its associated image (executable file) for hosting services. These services are contained within dynamically-linked libraries (DLLs).
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
the reason you couldnt see them after the format was cause you forgot the 'show process from all users' button...
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
its not a virus.... USUALY :p

its just random ms software running as far as i know... 11 instances of it running on my pc atm, with avast installed and not even the slightest hint of a virus / malware worm or anything anywhere near my pc.
 
T

twilyth

Guest
its not a virus.... USUALY :p

its just random ms software running as far as i know... 11 instances of it running on my pc atm, with avast installed and not even the slightest hint of a virus / malware worm or anything anywhere near my pc.

I was running malwarebytes and avira and no hints from them either. But now they're gone, so . . .

edit - and like I said - the other 2 machines didn't have a single instance of the pgm - all with W7 64-bit
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
I was running malwarebytes and avira and no hints from them either. But now they're gone, so . . .

you forgot the button to show all processes.
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
click the show all processes and double check there arnt any running on all 3 pc's? i find it very hard to belive not 1 is running... if not imposible... im sure your network needs 1 to be running to work.
 
T

twilyth

Guest
the reason you couldnt see them after the format was cause you forgot the 'show process from all users' button...

Yup. You're right. I guess I never thought to check that off on any of the rigs after the last install.

Think I should delete this then? Your call. I'm used to looking stupid.
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
lol, naa its always good to leave threads up incase someone googles Svchost.exe... they might find this and workout its ment to be running 11 or so times :D

hopfully it will stop the "i saw Svchost.exe open 10 times so i ended all there process trees and now my pc dosnt work" thead :p


Edit,

it seems somewhere between 5 and 14 its the average users amount open, my laptop has 9, pc has 11 dads pc has 14. (his if full of crap -.-)




just make sure there not using a TON of ram / cpu usage.... like over 800mb ect.... if they are then somthing is wrong ^^
 

Mussels

Freshwater Moderator
Staff member
Joined
Oct 6, 2004
Messages
58,413 (8.18/day)
Location
Oystralia
System Name Rainbow Sparkles (Power efficient, <350W gaming load)
Processor Ryzen R7 5800x3D (Undervolted, 4.45GHz all core)
Motherboard Asus x570-F (BIOS Modded)
Cooling Alphacool Apex UV - Alphacool Eisblock XPX Aurora + EK Quantum ARGB 3090 w/ active backplate
Memory 2x32GB DDR4 3600 Corsair Vengeance RGB @3866 C18-22-22-22-42 TRFC704 (1.4V Hynix MJR - SoC 1.15V)
Video Card(s) Galax RTX 3090 SG 24GB: Underclocked to 1700Mhz 0.750v (375W down to 250W))
Storage 2TB WD SN850 NVME + 1TB Sasmsung 970 Pro NVME + 1TB Intel 6000P NVME USB 3.2
Display(s) Phillips 32 32M1N5800A (4k144), LG 32" (4K60) | Gigabyte G32QC (2k165) | Phillips 328m6fjrmb (2K144)
Case Fractal Design R6
Audio Device(s) Logitech G560 | Corsair Void pro RGB |Blue Yeti mic
Power Supply Fractal Ion+ 2 860W (Platinum) (This thing is God-tier. Silent and TINY)
Mouse Logitech G Pro wireless + Steelseries Prisma XL
Keyboard Razer Huntsman TE ( Sexy white keycaps)
VR HMD Oculus Rift S + Quest 2
Software Windows 11 pro x64 (Yes, it's genuinely a good OS) OpenRGB - ditch the branded bloatware!
Benchmark Scores Nyooom.
i've got 12 of em, so yeah.. its fairly normal.
 

Perseid

New Member
Joined
Jul 4, 2010
Messages
154 (0.03/day)
Location
Wisconsin, USA
Processor i7-870
Motherboard ASUS P7P55D-E Pro
Cooling Coolermaster Hyper 212
Memory 2x OCZ Special Ops 2GB DDR3 1600 (PC3 12800) 8-8-8-24
Video Card(s) Palit GTX 470
Storage Numerous 1.5 and 2 TB
Display(s) HP w2338h
Case NZXT Lexa S
Power Supply CORSAIR TX Series 950W
Software Windows 7
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
If you use a program called Process Explorer it will let you see what each svchost is actually running.

http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

Hmmmm somthing wrong with just right clicking the SvcHost.exe and click Goto Services to see exacly what its running?



Windows Firewal, DHCP, Audio, security center, Homegroup, Event log, RPC, plug and play, windows defender......

these are all things that SvcHost.exe helps to run.
 

Perseid

New Member
Joined
Jul 4, 2010
Messages
154 (0.03/day)
Location
Wisconsin, USA
Processor i7-870
Motherboard ASUS P7P55D-E Pro
Cooling Coolermaster Hyper 212
Memory 2x OCZ Special Ops 2GB DDR3 1600 (PC3 12800) 8-8-8-24
Video Card(s) Palit GTX 470
Storage Numerous 1.5 and 2 TB
Display(s) HP w2338h
Case NZXT Lexa S
Power Supply CORSAIR TX Series 950W
Software Windows 7
Hmmmm somthing wrong with just right clicking the SvcHost.exe and click Goto Services to see exacly what its running?

Maybe that's a Windows 7 thing. I'm still on XP. Disregard, then. :) It is still a nifty program, though.
 

95Viper

Super Moderator
Staff member
Joined
Oct 12, 2008
Messages
12,679 (2.23/day)
Hmmmm somthing wrong with just right clicking the SvcHost.exe and click Goto Services to see exacly what its running?



Windows Firewal, DHCP, Audio, security center, Homegroup, Event log, RPC, plug and play, windows defender......

these are all things that SvcHost.exe helps to run.

Process Explorer is a very useful program, makes things easy... less clicking and more info.

pe.jpg

I like easy and available.:)
 
Last edited:
T

twilyth

Guest
You know, I just realized something though. Where did the infection that MSE picked up come from then? All I did was dl Firefox. From there I installed my normal addons but using FF and the infection was listed mainly in IE directories. There's no way that should have happened.

Also, after the first install I hadn't checked off the view processes from all users option either but i was still seeing the svchosts. I definitely reformatted before both installs. That's a little weird.
 
Joined
Jan 14, 2009
Messages
2,644 (0.47/day)
Location
...
System Name MRCOMP!
Processor 5800X3D
Motherboard MSI Gaming Plus
Cooling Corsair 280 AIO
Memory 64GB 3600mhz
Video Card(s) GTX3060
Storage 1TB SSD
Display(s) Samsung Neo
Case No Case... just sitting on cardboard :D
Power Supply Antec 650w
maybe it was a mis diagnosis? or maybe it just blocked an ad?



yeah its only for 7 and vista(i think).
 
Joined
Feb 10, 2007
Messages
2,582 (0.41/day)
Location
Oulu, Finland
System Name Enslaver :)
Processor Ryzen 7 7800X3D
Motherboard ASUS TUF Gaming B650-Plus
Cooling CPU: Noctua NH-D14 with LED fans, Case: 2 front in - 1 rear out
Memory 2x16GB Kingston Fury Beast RGB 6000MHz
Video Card(s) ASUS TUF RTX 4070Ti OC
Storage Samsung Evo Plus 1TB NVMe , internal WD Red 4TB for storage, WD Book 8TB
Display(s) LG CX OLED 65"
Case Lian Li LANCOOL II Mesh C Performance
Audio Device(s) HDMI audio powering Dolby Digital audio on 5.1 Z960 speaker system
Power Supply Corsair RM850x
Mouse Logitech G700
Keyboard ASUS Strix Tactic Pro
Software Windows 11 Pro x64
Since WinXP SP2 I have had 0 problem with being connected to the internet before all updates were in place and a anti-virus installed.
 

user09

New Member
Joined
Jul 27, 2010
Messages
1 (0.00/day)
Hi.If you had for the first time installed a good antivirus you woud not have to format your systems.I advise tou to pick up another antivirus from top ten best antiviruses http://www.best-antivirus.co/ good luck
:):)
 
Top