»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 11-12-2003, 08:34 AM   #1 (permalink)
Registered User
 
ben-the-slacker's Avatar
 
Join Date: Nov 2001
Location: MSU
Posts: 1,076
ben-the-slacker is on a distinguished road
svchost.exe

I just reformatted my computer an hour ago and put Adaware free on it. Updated the prog and did a scan. Came up with

c:\windows\system32\wins\svchost.exe

Adaware lists this as Malware, but it's not deletable. How do I get rid of this? Does anyone else have this problem?

ben-the-slacker is offline   Reply With Quote
Old 11-12-2003, 08:45 AM   #2 (permalink)
Registered User
 
Droppyale's Avatar
 
Join Date: Dec 2002
Location: -----------
Posts: 1,798
Droppyale is on a distinguished road
Send a message via AIM to Droppyale Send a message via Yahoo to Droppyale
boy that's weird.. I thought that was a system file.



Did you installl anything after you did the format?
Droppyale is offline   Reply With Quote
Old 11-12-2003, 08:45 AM   #3 (permalink)
Registered User
 
e980238's Avatar
 
Join Date: Jan 2002
Posts: 1,777
e980238 is on a distinguished road
When I have installed zone alarm in the past, svchost.exe has always poped up but all I know is that it is part of windows. I usually allow it but really am not sure about it.
__________________
Got root?
e980238 is offline   Reply With Quote
Old 11-12-2003, 08:52 AM   #4 (permalink)
Registered User
 
ben-the-slacker's Avatar
 
Join Date: Nov 2001
Location: MSU
Posts: 1,076
ben-the-slacker is on a distinguished road
All I have installed right now is Pop-Up Stopper, Ad Aware 6, Spybot, and AIM.
ben-the-slacker is offline   Reply With Quote
Old 11-12-2003, 08:55 AM   #5 (permalink)
Registered User
 
Droppyale's Avatar
 
Join Date: Dec 2002
Location: -----------
Posts: 1,798
Droppyale is on a distinguished road
Send a message via AIM to Droppyale Send a message via Yahoo to Droppyale
does spybot detect it as malware?

what does adaware give you as a description?
Droppyale is offline   Reply With Quote
Old 11-12-2003, 08:55 AM   #6 (permalink)
Registered User
 
e980238's Avatar
 
Join Date: Jan 2002
Posts: 1,777
e980238 is on a distinguished road
well even if you didnt install any of those you would still have svchost.exe. Its a windows system file.
__________________
Got root?
e980238 is offline   Reply With Quote
Old 11-12-2003, 08:57 AM   #7 (permalink)
Registered User
 
Droppyale's Avatar
 
Join Date: Dec 2002
Location: -----------
Posts: 1,798
Droppyale is on a distinguished road
Send a message via AIM to Droppyale Send a message via Yahoo to Droppyale
have you done your windows updates?
Droppyale is offline   Reply With Quote
Old 11-12-2003, 09:03 AM   #8 (permalink)
Registered User
 
Droppyale's Avatar
 
Join Date: Dec 2002
Location: -----------
Posts: 1,798
Droppyale is on a distinguished road
Send a message via AIM to Droppyale Send a message via Yahoo to Droppyale
Here's some good info

http://support.microsoft.com/?kbid=314056
Droppyale is offline   Reply With Quote
Old 11-12-2003, 09:11 AM   #9 (permalink)
Registered User
 
ben-the-slacker's Avatar
 
Join Date: Nov 2001
Location: MSU
Posts: 1,076
ben-the-slacker is on a distinguished road
I haven't done WinUpdate yet. No time right now.

Spybot didn't detect it as malware. Maybe Adaware is just being retarded...

wtf, adaware just detected c:\windows\system32\wins\dllhost.exe as malware...
ben-the-slacker is offline   Reply With Quote
Old 11-12-2003, 09:36 AM   #10 (permalink)
Registered User
 
davidamarkley's Avatar
 
Join Date: May 2002
Location: Joplin, MO
Posts: 2,208
davidamarkley is on a distinguished road
Send a message via ICQ to davidamarkley Send a message via AIM to davidamarkley
I got hit with this virus just about a week ago...

It's a "Backdoor.Litmus" variant...

Here's info on how to get rid of it...

Also, for future reference, the file "svchost.exe" is a system file, but unless it's located in "C:/WINDOWS/system32/" or "%SYSTEMROOT%/system32/" it's not the legit file.

Also, after you follow the directions, scan with the HouseCall program by going HERE.

Also, if you have an Anti-Virus installed, make sure to keep the definitions up to date.

HTH,

David
__________________
-David

Last edited by davidamarkley; 11-12-2003 at 09:39 AM.
davidamarkley is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 04:21 PM.