Skip to main content

Geek Question - Ren? Reggie?

25 replies [Last post]
tailz
Offline
Joined: 19/09/2003

Didn't know where else to post this.

Ok, so it seems I have a nasty little trojan worming it's way around my computer...

I have checked my task manager and I have about 6 svchost.exe processes running.  SOme of which are using up MASSES of my CPU memory.

After doing some homework, I hacve found that the process is a necessary windows file that runs code, but is also vulnerable to trojans and spyware. From what I've read - the REAL svchost.exe is in the C:\Windows\System32 folder (which makes sense).  

I've identified these files on my PC:

C:\WINDOWS\system32
C:\WINDOWS\ServicePackFiles\i386
C:\WINDOWS\$NtServicePackUninstall$
C:\WINDOWS\Prefetch

I know the top on (system32) is the REAL real one. But I'm reluctant to delete or stop any of the processes cause I could fuck Windows right up if I get it wrong.

My computer is showing all the symptoms of some form of trojan running in the background (is trojan the right word?).  Anyhoo, what I wnt to ask is:
Is a registry scan thing like  UniBlue  Registry Booster (Free Registry Scan) reliable? it says it can identify and fix the problem caused by trojans hiding as svchost.exe... (but I'm reluctant to download anything new I don't know about)....

AVG hasn't picked up any virus - Am currently downloading and running Norton as well (forums suggest onluy Norton is catching onto it, strangely)...
I've cleaned up my PC using Spybot (are there better spyware programs?) and restricted a bunch of cookies from being dumped on my PC.

Would a registry scan be advised (rather than deleting teh files manually)?

is there anything else I can do? You think it's okay ot delete the file and end the process for:

C:\WINDOWS\ServicePackFiles\i386
C:\WINDOWS\$NtServicePackUninstall$
C:\WINDOWS\Prefetch - this one in particular, I have read that it should be left as it is a back up file, but the file names is suss
(SVCHOST.EXE-3530F672.pf) and it's the most recently modified file. I wonder if that post about leaving it there was a dodgy person trying to discourage people getting rid of the file???

Most responses say to delete ANYTHING that's not in C:\WINDOWS\SYSTEM32

Am I paranoid?

Could I be infecting others by being online?
To ease concerns, I'm pretty sure this won't be infecting other's PCs - it's not an email worm or anything, as far as I can tell. I beleive it's jsut allowing spyware onto my PC and it's slowing my PC right down. Computer shits itself everytime I close a program and bumps me off teh net every now and again...

Cheers

Wrong. Most of the time.

riding the obnox train

Mr. Nodding Puppet
Offline
Joined: 25/08/2004
Re: Geek Question - Ren? Reggie?

rita

you're a nerd

rock the fucken fuck or stfu

Mr. Nodding Puppet
Offline
Joined: 25/08/2004
Re: Geek Question - Ren? Reggie?

yes you are paranoid

rock the fucken fuck or stfu

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Yes

but I have identified a fucking wickid little worm all by myself without the use of a virus scanner (GO ME!)!!!

Geeks will inherit the Earth, my friends - just you wait!

Wrong. Most of the time.

riding the obnox train

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Wrong. Most of the time.

riding the obnox train

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

ay rita, have ya got spybot?

it's good

check

http://www.spybot.info/en/index.html

i am a naughty cheesecake

Luka
Luka's picture
Offline
Joined: 04/02/2004
Re: Geek Question - Ren? Reggie?

spy bot works well

problemchild

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Yep.

But it only detects adware and stuff. I can (and have) delete the programs, no worries. The problem with this is it's a hidden vulnerability that runs code to allow new adware and more malciious spyware (or so I've read).  

It's a vulnerability in the system files that aparrently keeps popping up when you end processes.

It's not the adware that's eating up my PC - it's background other stuff that I can't detect.

I wanna delete the dodgy process files - but if i delete the wrong one, I'll fuck Windows up and it won't run at all! The problem is this important file also allows trojans to run processes that look, l;ike the real deal, but aren't.
>:(

Wrong. Most of the time.

riding the obnox train

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Yeah geek forums say nothing detects it yet - except maybe norton - and I ain't paying for that shit!

AVG has done wel, to date. it's shit - myPC is running SO SLOWLY and Word is fucked (thank god I finished my assignment). Furthermore, it's corrupting MS OUtlook  >:(

Also - there's a Windows Security patch that apparently helps, but I can't download it- keeps telling me that I ahve a newer Service pack than the patch version and I can't patch a version that is newer than the update (even more reason to think that this newer version is the trojan blocknig me from repairing it!)

Wrong. Most of the time.

riding the obnox train

Luka
Luka's picture
Offline
Joined: 04/02/2004
Re: Geek Question - Ren? Reggie?

spybot + virus software should do the trick
dont delete anything reets untill you find it neccessary (ie dont)

problemchild

Luka
Luka's picture
Offline
Joined: 04/02/2004
Re: Geek Question - Ren? Reggie?

we have norton. ill copy it for you next time jon come around with his discs

problemchild

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

hmm, bugger

delete the ones except the one you need

sounds like you won't fuck it anymore than it is

also get zone alarm and install that if you don't have it

also - anyone else got this problem

rember the wierdo stuff here a couple of weeks ago?

i am a naughty cheesecake

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

opps, maybe wot he said....

i am a naughty cheesecake

spazmAt
Offline
Joined: 09/04/2005
Re: Geek Question - Ren? Reggie?

Ok this is a tricky one, i have this too i think on a PC at home, and if you google you'll find a lot of people just going "LEAVE IT ALONE !! 1" but of course we know one can't do that when it's consuming 100% of processor etc.

Ok so what do we do? We need svchost of course because it's a vital windows service. The PreFetch folder is a kind of temporary folder that windows uses... you can delete svchost from there if you want, windows will just pop a new file in there for next time it wants access.

i recommend searching the entire harddrive, particularly in the program files folders, as a malignant svchost.exe may be hiding somewhere outside of the windows system folders.

also there a trojans that are known to hide themselves as "C:\windows\system\ svchost.exe"     <- notice the space after system\, making the filename
" svchost.exe" so have a look for that too.

exact method of removal depends on the exact kind of trojan.

An automated registry scan / removal could be a good idea as you certainly don't want to be editing it yourself if you don't know what you're doing

ok well i have to go to lunch at the moment - it's a family thing - but when i get back i'll continue this, i think i've narrowed it down to a group of three trojans/virii and have found maybe a tool or two to remove it, depending on which/what you have.. so if you can wait that long (an hour or so) i'll be bach

da da da dum!

link that shit up!

http://www.myspace.com/evansparks
http://www.myspace.com/bubbleandsqueakmusic

want hot msn sexy chats now now now email felchstick@hotmail.com

all your face belong to us.

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

there is a registry inconsistency thing in spybot, run it anyway....

it works well, i can't remember how to run it though....

good luck tails

i am a naughty cheesecake

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Quote:
spybot + virus software should do the trick
dont delete anything reets untill you find it neccessary (ie dont)

Nope - that's the prob - no anti-virus picks it up (many people have said they have run several to check)...

Thanks Spaz. That's pretty much what I thought. And what i hacve done - I have identified the ones I think are suss. Justwasn't ure if I could delete the Preftch one.

Yep, a lot of people say leave it alone - but they mean the system registry (REAL) file, I'm sure...

Thanks for the help! Apparently, it can also hide as svChost and stuff like that - which gives it away. What's interesting when I do a file search the file in C:\WINDOWS\$NtServicePackUninstall$ is highlighted in blue text - does that mean anything special?

What I really wanted to know was whether UniBlue is a good system registry scan. Sounds like that might be the goer.

Will let you know how I go!

cheers :^)

And Luka - thanks - that might be handy!

Taxi - It might be from the dodgy links from dodgy users, but I don't think so - It's only been happening since I started using Limewire. more specifically since I d/loaded a game that dumped a shit load of spywaare n my PC.

I've really noticed it though, since I opened a Word.doc from a friend that seemed a bit dodgy - and she's having similar probmels on her PC! So I think that it's not Messy related!

Wrong. Most of the time.

riding the obnox train

becy
Offline
Joined: 24/03/2006
Re: Geek Question - Ren? Reggie?

download hijackthis and run it mate

In safemode of course.

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

yeah well, it's pretty easy to activate something from a script in word

in fact we used to send eject commands to people's cd players once for a laugh

but that shit just causes unrest so no more hacking for pete, not that that really qualifies

i am a naughty cheesecake

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

BAH! The registry scanner I'm using has detected 93 anomalies - but OF COURSE you have to BUY the full version to repair all of them (78 remain unrepaired)

grrr

'hijackthis' you say - I'll give it a go!

*****
HE HE! I've been 'ejected' before! Cute. my ex used to hack into my work PC when he knew I was on lunch and rearrange all my desktop icons so when I got back I'd be all like "hey, what's happened here"...

Cheeky bastard.

Wrong. Most of the time.

riding the obnox train

becy
Offline
Joined: 24/03/2006
Re: Geek Question - Ren? Reggie?

ahhh fuck i meant don't run it in safe mode LOL oops.  

however DO turn off system restore, then run your antivirus software in safe mode first.
You should be able to pick up and delete stuff easier.  But yeah no need to run hijackthis in safemode. no point really...

Sm1clatxi
Offline
Joined: 25/09/2005
Re: Geek Question - Ren? Reggie?

maybe use the spybot one then, it's fully free and easy

kinda like me but i'm cheap and easy is all

i am a naughty cheesecake

Mbug
Mbug's picture
Offline
Joined: 10/02/2010
Re: Geek Question - Ren? Reggie?
reGGie
Offline
Joined: 13/12/2004
Re: Geek Question - Ren? Reggie?

I'll have a gander at this later this arvo when i get a chance for ya, hit me up on msn if you like and we can work through it.  Another Virus proggy to try is Kaspersky which i use at home after learning that Norton and AVG were both shit Sad

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

Cheers Reggie - Actually my pooter seeems to be running better (if I'm not using too many word docs at the one time - my Outlook is still shitting itself but not nearly as regularly).

Strangely, that Norton checker did not pick up the Wlchia worm, REn. That's good, I guess - mustn't be there.

Will try the new Virus checker you mentioned. Although, is a free downloaded version gioig to suffice?

Wrong. Most of the time.

riding the obnox train

tailz
Offline
Joined: 19/09/2003
Re: Geek Question - Ren? Reggie?

he he - "proggy" you'are a REAL geek aren't you. Endearing terms for programs - I think that's cool Wink

Wrong. Most of the time.

riding the obnox train

reGGie
Offline
Joined: 13/12/2004
Re: Geek Question - Ren? Reggie?

its worth a shot Wink

free trial version
http://www.kaspersky.com/trials