svchost

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by slaver, Sep 19, 2004.

  1. slaver

    slaver Private E-2

    My son is at college has something using all of his resources, called svchost he has run adaware and spybot in safe mode..............any suggestions
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Does he also get "Remote procedure call (RPC) service terminated unexpectedly. Shutdown initiated by NT AUTHORITY SYSTEM" windows? If so, he has the Blaster worm.

    He can try this removal tool:
    http://majorgeeks.com/download3967.html


    But, running our tutorial sounds like a good cleanup plan afterwards and\or if it fails:
    http://forums.majorgeeks.com/showthread.php?t=35407 because if he has Blaster that means Windows Updates is not up to date and it could have been avoided and probably has more problems he is unaware of.
     
  3. slaver

    slaver Private E-2

    Thanks i will ask him and see how it goes
     
  4. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Please do and let us know! Theres more we can do from there, but he will need to come here if it gets down to Hijack This!
     
  5. slaver

    slaver Private E-2

    My son is going to join the site, easier than me relaying to him, nickname is furb
     
  6. furb

    furb Private E-2

    Post Tutorial Stats/Report

    Trend Micro Scan - Nothing present
    Symantec Security Check - NA Explained later
    Avert Stinger - Nothing

    CCleaner Results - 1,098.9 MB removed in 52 seconds

    Adaware SE - 12 objects remove
    ---V2 Plugin (or whatever its name was) - System Clean
    Spybot - Nothing
    Spyware Blaster - I added some new protection

    CWS - My system was clean
    Kill2me - Look2me was removed if it was present
    HSRemove - Nothing
    AboutBuster - Nothing on first scan

    I was unable to do the systamantec scan because of my problem. I am unable to get certain kinds of links to work. I'm now in need of more advice. I can post hijackthis logs and screen capures of a program I have called Process Explorer.
     
  7. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    I would rather see your Hijack This log, it tells all. Please, it is important that it is in its own directory, have the newest version and that you close all running programs before running it, thats less processes we need to go through. As mentioned before the virus your describing is Blaster or a variant, the link above I gave you I saw no mention of you running. This would tell us its Blaster, allow you to remove it and notify us that your Windows Update is not current. If you can, run that as well and report back.
     
  8. furb

    furb Private E-2

    I will post the hijack this log a little later. I've got to do some of my homework - on another persons computer no less! I did make a new observation recently. When I was looking at the SVCHOST in question in process explorer I noticed that it would open up a tftp.exe. I checked my windows/system32 folder and there were generic tftp files present. I deleted them. I ran the process explorer again. SVCHOST once again started opening the tftp.exe. I went back to my system32 and more tftp files appeared. I'm not sure if this is supposed to happen or not.

    Expect the hijack this log in 3 or 4 hours.

    Thanks
     
  9. furb

    furb Private E-2

    I did my scan in normal mode. I closed everything I could without crashing the computer. I pus the Highjack This into its own folder in the program files directory.


    Edit by chaslang: inline log change to an attachment. Please post all future logs as attachments.
     

    Attached Files:

    Last edited by a moderator: Sep 20, 2004
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you installed PC Doctor Online at some point? If you did not buy this program, you should uninstall it. If you do uninstall or already did, and the below line is still there then have HijackThis fix the line:

    O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe

    You should also have HijackThis fix the following lines:
    1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/p...s/GSManager.cab
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/sof...nch/alaunch.cab
    O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab

    Let us know if this has any effect on your problem.

    By the way tftp.exe in c:\windows\system32 belongs there. It is a valid Microsoft program (Trivial File Transfer Protocol). I not sure why it would be running though unless you are running it for some reason.
     
  11. furb

    furb Private E-2

    My problem remains without any improvement.
     
  12. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Could you use the other online scanner or your own from safe mode?

    Do you get "Remote procedure call (RPC) service terminated unexpectedly. Shutdown initiated by NT AUTHORITY SYSTEM" windows error as well?

    If you did not install this, remove this also, I just noticed it:
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\ares.exe" -h
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I noticed that too MA, but so many people seem to want to use these P2P applications. I'm not sure what the general consensus is yet on Ares, but it does not seem to be anything like Kazaa. You are right though. If Furb did not install it (or does not use it), it should be fix. There may be an uninstall in Add/Remove programs for this. And it definitely could be a reason for a tftp session being initiated by a remote client via P2P using Ares.
     
  14. furb

    furb Private E-2

    I tried running the symantec scan from safemode. I was unable to get it to work. A side effect of my problem is the inability to use hyperlinks. Thus I was unable to get the thing to work. I could not even open the link in a new browser.

    Ares is there by my own doing. I use it to share files. It does not seem to add any spyware.

    Here is some back information on the problem. It all began last Thursday during a late night power outage. I woke up, and my computer was off. I noticed that it booted slow, but I did not think much of it. I went on to do my normal actions on the computer. I noticed how minimized windows did not go to the system tray. I also noted the slow speed my computer was running. I saw a new SVCHOST under my task manager. I usually had 3, but I had a fourth using all my CPU. I went to safe mode and ran a spyware scan thinking it would fix it. It did not. I did some research afterwards. I thought I had a viral SVCHOST. I deleted it. Bad move. This crippled my computer. I had to go into safemode and use a command prompt to copy SVCHOST out of my dll cache. It worked. The same old problems consisted. The system tray was malfunctioning. It took forever to boot the computer. I could copy but not paste in IE. I could not use hyperlinks. The CPU was still being hogged by SVCHOST. I did manage to pluge the CPU leak with Zone Alarm. My cpu usage is now low again, but the other problems persist.

    I hope this information can lead some of you to more advice.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to find out where the svchost.exe process is running from. The one's in c:\windows\system32 are ok. Anyplace else is normally bad. In addition, many bad applications name thinks very similar to svchost.exe to hide themselves. Names like: svhost.exe, svcdhost.exe, svchostx.exe (where x can be anything). You should be able to determine from a process list in HijackThis where the process is running from.
     
  16. furb

    furb Private E-2

    Alright.

    I'll what I can do then.
     
  17. furb

    furb Private E-2

    I could figure out how to find the information I needed with Hijack This. I used a program called AnVir Task Manager instead. This is some of the information I learned.

    Program Name - svchost.exe
    PID - 844
    CPU - 80%
    Executable file - C:\Window\System32\svchost.exe
    Discription - Generic Host Process for WIN 32 services

    9/22 1:38 A.M. svchost.exe 844 started by services.exe
    Data - C:\Windows\system32\svchost.exe -k rpcss

    I can also list all the Files, Handels, DLL's, Threads, and Drives that this particular svchost is using.

    Also is Softex Omnipass spyware?
     
  18. Adrynalyne

    Adrynalyne Guest

    Define using all his resources?

    svchost.exe can easily reach over 20mb of memory useage.

    Is this Windows XP Home, or Pro?
     
  19. furb

    furb Private E-2

    I'm using XP Home.
     
  20. Adrynalyne

    Adrynalyne Guest

    Ok, well, that makes it a little harder to narrow down without third party software.

    Get Process Explorer from www.sysinternals.com

    Locate the Process PID (It may have changed, so check it again.

    Locate it in the list, right click on the svchost.exe and choose properties.

    Click on the services tab.

    This will tell you what services are using that process, and possibly locate your culprit.

    You could then go through the tweaks at www.blackviper.com
     
  21. furb

    furb Private E-2

    The service the SVCHOST in question using is RpcSs or the remote procedure call. I observed something very interesting just now too. I mention that the SVCHOST would open up the tftp.exe. Under the image tab in process explorer I noticed something weird about the tftp.exe It's command line is the following - tftp.exe -i 10.102.133.137 get msnmsg.exe. I did some quick reading and it seems msnmsg.exe is some sort of virus. I could not locate it on my machine though.
     
  22. Adrynalyne

    Adrynalyne Guest

  23. furb

    furb Private E-2

    I did a brief search of my registry for "msnmsg". It didn't turn up any results. I did not check all of the registry addressed manually though.
     
  24. Adrynalyne

    Adrynalyne Guest

    Look for the file on your system, first.
     
  25. furb

    furb Private E-2

    I haven't had a chance to manually look through my folders. I'm going to be away fro the next three days too. I just don't want to let this tread die yet.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to do it manually. Let Windows Search do it. But configure it first.

    How to use windows XP search mechanism to look for hidden files:
    If you use Search, you need to do the following:
    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box, so enter msnmsg.exe
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.
     
  27. furb

    furb Private E-2

    I can't do searches. Whenever I click the search icon under start is does not respond. I have no idea why, but it started when my problem started.
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Then start by using Windows Explorer and look in these directories first:
    C:\WINDOWS\System32
    C:\WINDOWS\System
    C:\WINDOWS
     
  29. furb

    furb Private E-2

    I didn't find it there.

    However, I got a new virus scanner that some of said elsewhere may find my problem. I am going to run the scan later tonight.
     
  30. furb

    furb Private E-2

    I've fixed the problem. I apparently had a virus on my computer called Win32.Lemmy.u. I used a virus scan called Kaspersky to find it. The scan took like 9 hours, but it did fix the problem.

    I do apperciate all the advice I got here. Thanks for the help!
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds