svchost infected

  • Thread starter Thread starter Neither rhyme nor reason
  • Start date Start date
N

Neither rhyme nor reason

Hi,

My issue is that the svchost is infected. My Advance Server 2000 worked
normally until I connect to the internet, then the svchost process consumes
98-100% of the cpu bringing the system to near stop.

I have tried online scans but they are are slowed to near stop. Any
anti-virus that i have been able to download from another computer will not
run on a server.

It feels like a catch 22



regards


g
 
Hi,

My issue is that the svchost is infected. My Advance Server 2000
worked normally until I connect to the internet, then the svchost
process consumes 98-100% of the cpu bringing the system to near stop.

I have tried online scans but they are are slowed to near stop. Any
anti-virus that i have been able to download from another computer
will not run on a server.

It feels like a catch 22

Svchost.exe is being used by something that has infected the machine or
Svchost.exe is a Trojan if it is not running out of the Windows/system32
directory.

The tools in the link such as Process Explorer will allow you to look
inside a running process such as svchost.exe and see what processes are
using svchost.exe.

http://tinyurl.com/klw1

Duane :)
 
1) Download the following four items...

McAfee Stinger
http://vil.nai.com/vil/stinger/

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download Sysclean.com and place it in that directory.
Dowload the Trend Pattern File by obtaining the ZIP file.
For example; lpt253.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adaware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode
5) Using Trend Sysclean, Stinger and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using the three
utilities; Trend Sysclean, Stinger and Adaware
7) If you are using WinME or WinXP, Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point

You can also try some of the below online scanners.

BitDefender:
http://www.bitdefender.com/scan/license.php

Computer Associates:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

DialogueScience:
http://www.antivir.ru/english/www_av/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

Freedom Online scanner:
http://www.freedom.net/viruscenter/index.html

Kaspersky:
http://www.kaspersky.com/de/scanforvirus

McAfee:
http://www.mcafee.com/myapps/mfs/default.asp

Panda:
http://www.pandasoftware.com/activescan/

RAV
http://www.ravantivirus.com/scan/

Symantec:
http://security.symantec.com/

Trend:
http://housecall.antivirus.com
http://housecall.trendmicro.com


* * * Please report your results ! * * *

Dave




| Hi,
|
| My issue is that the svchost is infected. My Advance Server 2000 worked
| normally until I connect to the internet, then the svchost process consumes
| 98-100% of the cpu bringing the system to near stop.
|
| I have tried online scans but they are are slowed to near stop. Any
| anti-virus that i have been able to download from another computer will not
| run on a server.
|
| It feels like a catch 22
|
|
|
| regards
|
|
| g
|
|
| ---
| Outgoing mail is certified Virus Free.
| Checked by AVG anti-virus system (http://www.grisoft.com).
| Version: 6.0.798 / Virus Database: 542 - Release Date: 18-Nov-04
|
|
 
Dave,

Thanks for the info. Sysclean was able to find about five viruses on my
system and remove them, however the one virus that is activated when on line
is still there. I can not access any of the on-line scans that your
recommended due to the scvhost hogging the system.

So better but not fixed.

regards

g
 
Stinger and Sysclean found nothing ?

Dave




| Dave,
|
| Thanks for the info. Sysclean was able to find about five viruses on my
| system and remove them, however the one virus that is activated when on line
| is still there. I can not access any of the on-line scans that your
| recommended due to the scvhost hogging the system.
|
| So better but not fixed.
|
| regards
|
| g
|
|
| | > 1) Download the following four items...
| >
| > McAfee Stinger
| > http://vil.nai.com/vil/stinger/
| >
| > Trend Sysclean Package
| > http://www.trendmicro.com/download/dcs.asp
| >
| > Latest Trend Pattern File.
| > http://www.trendmicro.com/download/pattern.asp
| >
| > Adaware SE (free personal version v1.05)
| > http://www.lavasoftusa.com/
| >
| > Create a directory.
| > On drive "C:\"
| > (e.g., "c:\New Folder")
| > or the desktop
| > (e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")
| >
| > Download Sysclean.com and place it in that directory.
| > Dowload the Trend Pattern File by obtaining the ZIP file.
| > For example; lpt253.zip
| >
| > Extract the contents of the ZIP file and place the contents in the same
| directory as
| > sysclean.com.
| >
| > 2) Update Adaware with the latest definitions.
| > 3) If you are using WinME or WinXP, disable System Restore
| > http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
| > 4) Reboot your PC into Safe Mode
| > 5) Using Trend Sysclean, Stinger and Adaware, perform a Full Scan of
| your
| > platform and clean/delete any infectors/parasites found.
| > (a few cycles may be needed)
| > 6) Restart your PC and perform a "final" Full Scan of your platform
| using the three
| > utilities; Trend Sysclean, Stinger and Adaware
| > 7) If you are using WinME or WinXP, Re-enable System Restore and
| re-apply any
| > System Restore preferences, (e.g. HD space to use suggested 400 ~
| 600MB),
| > 8) Reboot your PC.
| > 9) If you are using WinME or WinXP, create a new Restore point
| >
| > You can also try some of the below online scanners.
| >
| > BitDefender:
| > http://www.bitdefender.com/scan/license.php
| >
| > Computer Associates:
| > http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
| >
| > DialogueScience:
| > http://www.antivir.ru/english/www_av/
| >
| > F-Secure:
| > http://support.f-secure.com/enu/home/ols.shtml
| >
| > Freedom Online scanner:
| > http://www.freedom.net/viruscenter/index.html
| >
| > Kaspersky:
| > http://www.kaspersky.com/de/scanforvirus
| >
| > McAfee:
| > http://www.mcafee.com/myapps/mfs/default.asp
| >
| > Panda:
| > http://www.pandasoftware.com/activescan/
| >
| > RAV
| > http://www.ravantivirus.com/scan/
| >
| > Symantec:
| > http://security.symantec.com/
| >
| > Trend:
| > http://housecall.antivirus.com
| > http://housecall.trendmicro.com
| >
| >
| > * * * Please report your results ! * * *
| >
| > Dave
| >
| >
| >
| >
| > | > | Hi,
| > |
| > | My issue is that the svchost is infected. My Advance Server 2000 worked
| > | normally until I connect to the internet, then the svchost process
| consumes
| > | 98-100% of the cpu bringing the system to near stop.
| > |
| > | I have tried online scans but they are are slowed to near stop. Any
| > | anti-virus that i have been able to download from another computer will
| not
| > | run on a server.
| > |
| > | It feels like a catch 22
| > |
| > |
| > |
| > | regards
| > |
| > |
| > | g
| > |
| > |
| > | ---
| > | Outgoing mail is certified Virus Free.
| > | Checked by AVG anti-virus system (http://www.grisoft.com).
| > | Version: 6.0.798 / Virus Database: 542 - Release Date: 18-Nov-04
| > |
| > |
| >
| >
|
|
| ---
| Outgoing mail is certified Virus Free.
| Checked by AVG anti-virus system (http://www.grisoft.com).
| Version: 6.0.798 / Virus Database: 542 - Release Date: 18-Nov-04
|
|
 
They did find about five infections, and deleted them, but there appears to
be one somewhere that they do not find.


r,
gilbert
 
Gilbert:

Send me an email and I will send you some information on a Command Line Scanner that I can't
post publicly due to licensing issues.

Dave



| They did find about five infections, and deleted them, but there appears to
| be one somewhere that they do not find.
|
|
| r,
| gilbert
 
Dave,

Thanks for the info. Sysclean was able to find about five viruses on
my system and remove them, however the one virus that is activated
when on line is still there. I can not access any of the on-line scans
that your recommended due to the scvhost hogging the system.

So better but not fixed.

Yeah, you can throw all the virus and malware detection software in the
world at the problem and you may never find it, because such software is
always a dime short and a dollar late in the detection. Svchost.exe is not
hogging the system and something is using svchost.exe on its behalf forcing
svchost.exe to hog the system. You need to look inside the running
svchost.exe with Process Explorer (free) or other such tools and see what
process/program is hogging svchost.exe and pinpoint/locate the
program/malware on the machine that's doing it. Sometimes, you have to go
look for yourself.

Duane :)
 
Neither rhyme nor reason said:
They did find about five infections, and deleted them, but there appears to
be one somewhere that they do not find.

You are on a false track. Pay attention to what Duane Arnold is telling you.

Regards
 
Zvi:

As of right now he has cleaned a varaiant of sdbot.which McAfee's Command Line Scanner
detected as "W32/sdbot.worm.gen.j".
Also, detected/cleaned are two Adware objects and two Trojans; "Downloader-PR" and
"QLowZones-2.gen"

So, how is this a "false track" ?

Dave




|
| > They did find about five infections, and deleted them, but there appears to
| > be one somewhere that they do not find.
|
| You are on a false track. Pay attention to what Duane Arnold is telling you.
|
| Regards
| --
| NetZ Computing Ltd. ISRAEL www.invircible.com www.ivi.co.il (Hebrew)
| InVircible Virus Defense Solutions, ResQ and Data Recovery Utilities
 
Back
Top