techPowerUp! Forums

Go Back   techPowerUp! Forums > Hardware > Networking & Security

Reply
 
Thread Tools
Old Jul 11, 2010, 02:25 PM   #1
Aleksander
2000 Posts
 
Aleksander's Avatar
 
Join Date: Dec 2009
Posts: 3,028 (2.40/day)
Thanks: 648
Thanked 280 Times in 228 Posts

System Specs

Anti-Virus for 64-bit

Hello guys!
I got a month since i got hit by a "svchost.exe" terrible virus and i have tried a lot of anti viruses with all updates like:
AVG
Symantec end point
Bit defender
But all don't catch the DAMN virus. Now i am really desperate of removing this virus with winrar. The virus seems to duplicate himself, so every time i delete it from D, it reappears again. Pls help me, if anyone of you has experience this type of virus before!
Aleksander is offline  
Reply With Quote
Old Jul 11, 2010, 02:30 PM   #2
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,139 (2.59/day)
Thanks: 2,559
Thanked 1,964 Times in 1,073 Posts

System Specs

Malwarebytes or MSE would take that out in a heartbeat.
Radical_Edward is offline  
Reply With Quote
The Following User Says Thank You to Radical_Edward For This Useful Post:
Old Jul 11, 2010, 02:31 PM   #3
GENTLEMEN
75 Posts
 
Join Date: Jun 2010
Location: Philippines
Posts: 188 (0.18/day)
Thanks: 26
Thanked 23 Times in 21 Posts

System Specs

Dunno about the svchost.exe but something similar happened to me. Got it from a USB stick. ALL folders had a "shortcut" in it (name of folder) and opening it made it open the My Computer page. Deleting them made them re-appear when I open the affected folder (ALL). Dunno exactly what I did, but safemode + Avast must've done something right.
GENTLEMEN is offline  
Reply With Quote
Old Jul 11, 2010, 02:31 PM   #4
Meow9000
200 Posts
 
Join Date: Jul 2009
Location: Wales, Uk
Posts: 278 (0.20/day)
Thanks: 14
Thanked 81 Times in 63 Posts

System Specs

svchost.eve is a legitimate part of windows, Or are you saying that a virus is masquerading as it or infected it ?

probably something like Win32/Conficker possibly, as that infects and hides itself in that .exe
Meow9000 is offline  
Reply With Quote
Old Jul 11, 2010, 02:34 PM   #5
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,139 (2.59/day)
Thanks: 2,559
Thanked 1,964 Times in 1,073 Posts

System Specs

Quote:
Originally Posted by Meow9000 View Post
svchost.eve is a legitimate part of windows, Or are you saying that a virus is masquerading as it or infected it ?
I've run into quite a few nasty infections that like to "run" that about 4-8 times more than there should be in processes. (Maybe trying to hide itself as a legit exe?)
Radical_Edward is offline  
Reply With Quote
Old Jul 11, 2010, 02:39 PM   #6
Aleksander
2000 Posts
 
Aleksander's Avatar
 
Join Date: Dec 2009
Posts: 3,028 (2.40/day)
Thanks: 648
Thanked 280 Times in 228 Posts

System Specs

+1 Radical
Yeah you are totally right!
It consumes so much of processing power that i hardly open internet and there are a lot of svchost.exe in task manager, but only one changes from time to time! Like from 0% to 100% of processes T_T
Anyway, i click end process, but than the computer sound does not function as there is no sound card at all! And the windows theme changes like that old thingy of windows 2000
PLS help me as i am very desperate in removing this virus.
Aleksander is offline  
Reply With Quote
Old Jul 11, 2010, 02:43 PM   #7
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,139 (2.59/day)
Thanks: 2,559
Thanked 1,964 Times in 1,073 Posts

System Specs

Okay, you need to download and run these two anti-malware/anti virus programs.

http://www.malwarebytes.org/mbam.php

http://www.microsoft.com/security_essentials/

If your copy of windows isn't legitimate, don't bother with MSE. It WILL check if you have a legal copy before scanning your system.
Radical_Edward is offline  
Reply With Quote
The Following 2 Users Say Thank You to Radical_Edward For This Useful Post:
Old Jul 11, 2010, 02:46 PM   #8
Aleksander
2000 Posts
 
Aleksander's Avatar
 
Join Date: Dec 2009
Posts: 3,028 (2.40/day)
Thanks: 648
Thanked 280 Times in 228 Posts

System Specs

Ok! I hope this solves the problem!
Thank you!
Just for instance.... It already got 150 infected objects
Aleksander is offline  
Reply With Quote
Old Jul 11, 2010, 02:49 PM   #9
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,139 (2.59/day)
Thanks: 2,559
Thanked 1,964 Times in 1,073 Posts

System Specs

^
|

Stop watching porn.
Radical_Edward is offline  
Reply With Quote
Old Jul 11, 2010, 02:50 PM   #10
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,109 (6.94/day)
Thanks: 1,337
Thanked 6,829 Times in 3,739 Posts

System Specs

+1 to MSE. Lightest anti-virus on the market.
TheMailMan78 is offline  
Reply With Quote
Old Jul 11, 2010, 03:41 PM   #11
Steevo
Eligible for custom title
 
Steevo's Avatar
 
Join Date: Nov 2005
Posts: 5,567 (2.02/day)
Thanks: 238
Thanked 979 Times in 729 Posts

System Specs

I have been running MSE on computers at work and comparing it to AVG, Avast, Comodo, Norton, and a few others. While it lacks the seeming intelligence and finish of others, nothing escapes it, it does seem to have issues after a couple months of running with needing a reboot to clear itself and make things right where others like AVG are always on and switched on.


However for a lightweight laptop anti-virus or for machines with lacking specs it is great.


I give it 7/10 mushroom stamps.
__________________

“it would have been perfect....its got trains and the line"tech your kids not to do what iv done"(or similar) because i had obviously done something to warrent 2 e-thugs to come 4000miles out of their way and kill me.” -Solaris17
“yeah i failed. i noticed the "coming soon" part after i posted.” -Mussels
“people are just stupid.” -W1zzard
Yes I am evil, yes you can have some.
Steevo is offline  
Reply With Quote
Old Jul 11, 2010, 03:45 PM   #12
Mussels
Doctor Moderator
 
Mussels's Avatar
 
Join Date: Oct 2004
Location: Bendigo, Australia (NOT THE USA)
Posts: 34,545 (10.98/day)
Thanks: 3,699
Thanked 8,686 Times in 6,387 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
+1 to MSE. Lightest anti-virus on the market.
MSE is my free choice as well, with kaspersky being the paid alternative i reccomend.


MSE plays nice, for example it detects some IP scanners i have as 'legal' but 'potentially dangerous' - it doesnt go and scream "OMG GENERIC.WIN32.NOTAVIRUS HAS BEEN DETECTED"
Mussels is offline  
Reply With Quote
Old Jul 11, 2010, 04:09 PM   #13
kid41212003
2000 Posts
 
kid41212003's Avatar
 
Join Date: Jul 2008
Location: California
Posts: 2,557 (1.43/day)
Thanks: 312
Thanked 533 Times in 435 Posts

System Specs

SO MSE is a better choice compare to AVG?
__________________
kid41212003 is offline  
Reply With Quote
Old Jul 11, 2010, 04:12 PM   #14
Kreij
Hardcore Monkey Moderator
 
Kreij's Avatar
 
Join Date: Feb 2007
Location: Cheeseland (Wisconsin, USA)
Posts: 12,110 (5.28/day)
Thanks: 591
Thanked 5,488 Times in 2,932 Posts

System Specs

I like MSE better than AVG. Just my opinion though.
__________________

Cloud (noun, singular): A dynamic arrangement of multiple potential single points of failure, with a user at one end and their data at the other.


Get more tech news on a wide variety of topics at NextPowerUp
Kreij is online now  
Reply With Quote
Old Jul 11, 2010, 04:33 PM   #15
_JP_
2000 Posts
 
_JP_'s Avatar
 
Join Date: Apr 2010
Location: Portugal
Posts: 2,112 (1.87/day)
Thanks: 1,952
Thanked 644 Times in 466 Posts

System Specs

I prefer any Anti-virus to AVG, just from personal experience, but then again this is just an opinion.

Alek, I'm currently using ESET Smart Security. It's pretty good IMHO, low memory footprint, fast, also comes in 64-bit, so it's another option for you.

Using NOD32 doesn't cover all threats, as such Malwarebytes and/or other anti-adware is recommendable to install as well.
_JP_ is offline  
Reply With Quote
Old Jul 11, 2010, 05:19 PM   #16
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,509 (4.21/day)
Thanks: 2,297
Thanked 1,308 Times in 895 Posts
Send a message via Skype™ to de.das.dude

System Specs

I'm using ESSET nod32 for the x64.

i got hit by a similiar svchost.exe virus, but i deleted by hand(anti vir sucked).
heres what i did.


* i ran "msconfig" from RUN.
*in that i checked that all the startup and services were the ones i installed. and lucky enough, i found a "AviraAnti Desktop bla bla" thing under startup. i unchecked it immediately. also noted its path. it was in system32 under a self created folder with giberish name.

*next i opened my windows in safe mode. opened winrar, and taskmanager.
*in the winrar, i went to the path of that thing and tried deleting it, it didnt let me.
*then i went to process tab of taskmanager and ended a suspicious looking svchost(luckily that was the one, or else i would have to do trial and error). immediately i deleted that virus from system32. and it happened. did a direct power off and restarted.

* that thing was dead

the really hard part was that thevirus was in the system32 and though it was an .exe it appeared as a folder.
also it wasnt letting any of the anti viruses i tried from scanning the system32!!


sorry for the lecture but this is a dire situation solver.
__________________
Cheers!
de.das.dude is online now  
Reply With Quote
Old Jul 11, 2010, 06:36 PM   #17
Aleksander
2000 Posts
 
Aleksander's Avatar
 
Join Date: Dec 2009
Posts: 3,028 (2.40/day)
Thanks: 648
Thanked 280 Times in 228 Posts

System Specs

I know that method, but i didnt use it, cuz the virus is still in your computer and there are some viruses who are "active" of which after dead they never appear again, like humans.
But there are some ADVANCEMENTS in "viruso-technology" that after killing them, they have left the babies to other files... So better not to risk it. Who makes the viruses knows for sure this method
When i worked as an operator an informatics engineer told me that :P
And still i am having ANOTHER PROBLEM with the thumbnails!!!
The names of the photos do not appear T_T
I know this is another kind of virus
Aleksander is offline  
Reply With Quote
Old Jul 11, 2010, 06:56 PM   #18
qubit
Overclocked quantum bit
 
qubit's Avatar
 
Join Date: Dec 2007
Location: Quantumville UK
Posts: 8,640 (4.34/day)
Thanks: 4,169
Thanked 3,301 Times in 1,941 Posts

System Specs

Reformat and reinstall to remove it. Don't waste time with anything else.

Then put Kaspersky Internet Security on and you'll be alright.
__________________
Siggie in the post.
qubit is offline  
Reply With Quote
Old Jul 11, 2010, 06:59 PM   #19
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,139 (2.59/day)
Thanks: 2,559
Thanked 1,964 Times in 1,073 Posts

System Specs

Sounds like fresh install time to me.
Radical_Edward is offline  
Reply With Quote
Old Jul 11, 2010, 07:15 PM   #20
twicksisted
2000 Posts
 
twicksisted's Avatar
 
Join Date: Oct 2007
Location: London, UK
Posts: 2,231 (1.09/day)
Thanks: 390
Thanked 358 Times in 285 Posts

System Specs

Quote:
Originally Posted by Radical_Edward View Post
^
|

Stop watching porn.
No way dude!!! porn FTW!!!
__________________
twicksisted is offline  
Reply With Quote
Old Jul 11, 2010, 07:18 PM   #21
LittleLizard
2000 Posts
 
LittleLizard's Avatar
 
Join Date: Nov 2008
Location: Latin America, Uruguay
Posts: 3,380 (2.06/day)
Thanks: 339
Thanked 584 Times in 516 Posts

System Specs

Avast. Period.
__________________


"oh no, i make a very good person. I eat poop and sleep just like everyone else.
My sense of humour just happens to fall under the DnD category of Chaotic Evil." - Mussels
"I was expecting a line of EVGA FTW condoms or something like that." - DrPepper
"I like my sex like my basketball, one on one, and with as little dribbling as possible" - Robert-The-Rambler
LittleLizard is offline  
Reply With Quote
Old Jul 11, 2010, 07:31 PM   #22
_JP_
2000 Posts
 
_JP_'s Avatar
 
Join Date: Apr 2010
Location: Portugal
Posts: 2,112 (1.87/day)
Thanks: 1,952
Thanked 644 Times in 466 Posts

System Specs

If you're going for free, try the Comodo.
If you want payed stuff, try the ESET.

/My 2 cents
_JP_ is offline  
Reply With Quote
Old Jul 11, 2010, 07:33 PM   #23
Baam
75 Posts
 
Baam's Avatar
 
Join Date: Aug 2008
Location: Trucker..so all over
Posts: 93 (0.05/day)
Thanks: 8
Thanked 18 Times in 18 Posts

System Specs

I am using SUPERAntiSpyware free version. It does a nice job.

http://www.superantispyware.com/
Baam is offline  
Reply With Quote
Old Jul 11, 2010, 07:38 PM   #24
Graogrim
200 Posts
 
Join Date: Jan 2008
Location: East Coast US
Posts: 301 (0.15/day)
Thanks: 19
Thanked 31 Times in 29 Posts

System Specs

I'll toss my hat in for Microsoft Security Essentials. Easily it's the lowest impact product I've ever used, and by all reports it is among the leaders in effectiveness.
Graogrim is offline  
Reply With Quote
Old Jul 11, 2010, 08:17 PM   #25
{JNT}Raptor
500 Posts
 
{JNT}Raptor's Avatar
 
Join Date: Jul 2005
Location: NY
Posts: 724 (0.25/day)
Thanks: 131
Thanked 88 Times in 84 Posts

System Specs

Quote:
Originally Posted by Baam View Post
I am using SUPERAntiSpyware free version. It does a nice job.

http://www.superantispyware.com/

+1 to that....I bought it with lifetime updates.....very nice app.

Nod32 64bit SS for me on the AV/Firewall side of things.
__________________
<----- Specs
{JNT}Raptor is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
1 reason why Norton Anti-Virus is the best Anti-Virus out there. Mega-Japan General Software 48 Jun 15, 2009 12:48 PM
anti virus for windows server Hayder_Master General Software 5 Sep 18, 2008 05:32 PM
Anti-Virus Software for Server 2008? beyond_amusia General Software 11 Apr 29, 2008 10:22 AM
Vote for best anti-virus freebird_9924 General Software 47 Jul 14, 2007 08:32 PM


All times are GMT. The time now is 06:02 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts