�^Z� The version of svchost.exe could someone explain this please

Discussion in 'Malware Help (A Specialist Will Reply)' started by smith, Jul 14, 2005.

  1. smith

    smith Private E-2

    I am still trying to remove a hacker reinstall 23 has gone by. but today when I was looking up some of the people that communicate with my computer I noticed this information when I clicked a link to get more information from zone alarm.
    Program Version �B� The version of svchost.exe running on your computer.
    Program Version Px� The version of svchost.exe running on your computer.
    Program Version BlockAll2 The version of svchost.exe running on your computer.
    Program Version �9� The version of svchost.exe running on your computer.
    Program Version ��� The version of svchost.exe running on your computer.
    Program Version �^]� The version of svchost.exe running on your computer.
    Program Version �^Z� The version of svchost.exe running on your computer.

    Program Version 5.1.2600.2180 The version of svchost.exe running on your computer. This I know is the real svchost I also have besides the ones posted above a few more strange ones. Could someone explain what these other versions of svchost are. I know in my registry I have SvcHost that runs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\DComLaunch
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\HTTPFilter
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\LocalService
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\PCHealth
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\termsvcs
    but as soon as I delete these I lose complete control of my computer and have to reinstall and they are back.

    i have run every thing from your guides they do not all run properly and alot more but this thing has hidden drives copies of programs , If someone could explain if the above Scvhost versions point to anything as I am stuborn and determined to get these people out of here before I buy a new hard drive.
    Thank you for your time.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you please write your messages more clearly?

    What is a hacker reinstall?
    How do you look up people that communicate with your PC?
    In fact what does that mean?

    Are you referring to a firewall log of incoming and outgoing blocked access attempts?

    Why do you think you have non-valid svchost.exe files on your PC? Do you see any in other folders other than c:\windows\system32 ?

    Why are you deleting registry entries that you need? That is why you are having problems with your PC (whatever loosing complete control means).

    What exactly have you run from the READ ME FIRST and what do the below statements (quoted from your message) mean:
     
    Last edited: Jul 15, 2005
  3. smith

    smith Private E-2

    Thank you for your reply. I do not have alot of time to explain everything that is going on right now But I will post a full summary later tonight.I have a few programs on my computer that repeated ask for internet access to certain isp's and these same ones try to access programs on this computer these are isp's from Russia and china mainly sometimes it is as many as a few hundred times in a few hours. I have an extra internet connection that I did not create , It runs a duplicate copy of my firewall but the times I can access this and try to deny a program access it tells me my password is wrong, I get multiple copies of internet explorer open that all use different ports these i see with netstat viewer esspecially when near an e-mail account or surprising your download page. I have run every thing in your guides the ones that do not work are mainly the ones that use a vbs script. Hijack this produces errors I did contact the makers like the program told me to report these but I have never had a reply. I have files or drivers in multiple
    languages installed mainly parts of russia. There ia alot more but For now I have run out of time to post, for this I apoligise.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please punctuate sentences. And be clear in your message.

    When you say
    As written, this means programs on your computer are looking for internet access to certain ISPs and the same programs try to access programs on your computer.

    I think what you really mean is that some programs on your PC are trying to access particular IP addresses (not ISPs) and that those IP address are to gain incoming access to your PC.

    When you say
    Please be specific and tell us each program that does not work. Have you run all the programs? Did you download all of them from our site and double check that you are using the versions we have posted? What version of HijackThis do you have?

    What does the below mean?
    and
    I can understand have drivers in mutiple languages installed. But "mainly parts or Russia"?????

    What is your native language? Did you install the other drivers?
     
    Last edited: Jul 15, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds