Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 20-04-2007, 09:47 PM   #1 (permalink)
Apprentice
 
Join Date: Sep 2006
Posts: 60
Default core.sys malware infection issue & resolution.


Hi all,

I have recently started noticing multiple instances of svchost.exe in my task mgr.

also... for a period of a month i ran my net conn without any firewall.. now ie seems to be popping up for no reason and redirects me to an unknown web page... is my browser hijacked???

i have scanned my system with avg 7.5 pro, ad aware and spybot search n destroy.. (latest updates installed).. however i have been unable to solve this problem..


I read the following on webpage...



Process File: svchost.exe or svchost
Process Name: Microsoft Service Host Process

Description:
svchost.exe is a system process belonging to the Microsoft Windows Operating System which handles processes executed from DLLs. This program is important for the stable and secure running of your computer and should not be terminated.

Note:

svchost.exe is a process registered as a backdoor vulnerability which may be installed for malicious purposes by an attacker allowing access to your computer from remote locations, stealing passwords, Internet banking and personal data. If unaccounted for, this process should be removed immediately.

Note:
svchost.exe is a process which is registered as a trojan. This Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. This process is a security risk and should be removed from your system.

Note: svchost.exe is a process belonging to Microsoft Service Host Process. This could also be a stealth monitoring software that sits in the background and tracks all activities such as keyboard input (including websites visited, passwords etc.) This information can be sent to third parties through email or ftp uploads. If you did not intentionally install this program make sure you remove it to protect your privacy.


I think svchost has been registered as a trojan on my system...


please help me out with this..


any help will be greatly appreciated...

thnx in advance..
rakesh14021983 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 20-04-2007, 10:37 PM   #2 (permalink)
-- No Easter Eggs here --
 
hemant_mathur's Avatar
 
Join Date: Apr 2006
Location: Front of my pc
Posts: 949
Default Re: SVCHOST.EXE Issues

Is it named svchost.exe or scvhost.exe ??

svchost.exe is a system process and usually runs in multiple instances. For more info on it check this link http://www.thinkdigit.com/forum/technology-news/38157-unlocking-mysteries-svchost-exe.html#post319520

scvhost.exe is a trojan.
__________________
E6850 3.0 Ghz, 4gb 667 Mhz RAM, Asus p5n Esli Mobo, Nvidia 8600GT 512mb, 400gb WD HDD, Samsung Syncmaster 920NW, Vista x64
hemant_mathur is offline  
Old 20-04-2007, 10:48 PM   #3 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: SVCHOST.EXE Issues

svchost.exe situated in the system32 folder is the legit ms process. situated anywhere else or scvhost.exe is malware. check exactly what ur suspects r named/spelled and their locations. if required u can get the suspect scanned with multiple scan engines at http://www.virustotal.com/en/virustotalf.html

i think scanning with avg anti-spyware or a-squared anti-malware shud take care of ur problem.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 21-04-2007, 10:18 AM   #4 (permalink)
Apprentice
 
Join Date: Sep 2006
Posts: 60
Default Re: SVCHOST.EXE Issues

hey anand n hemant...

the file is svchost.exe itself..not scvhost.exe (i knew that !!

n there is only one instance of the file in c:\windows\system32.. thus i presume it is a legit file..

any other ideas??
rakesh14021983 is offline  
Old 21-04-2007, 03:45 PM   #5 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: SVCHOST.EXE Issues

nope ! but maybe u'd like to get ur browser checkd for hijackers ! just clicking on this http://www.doxdesk.com/parasite/ might giv u an idea if ur browser has been hijacked. or else ur host file cud v been hijacked get ur hjt logfile auto-analysed at www.hijackthis.de in case ur host file has been hijacked, u might wanna replace it with a good host file from http://www.mvps.org/winhelp2002/hosts.htm
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 21-04-2007, 05:56 PM   #6 (permalink)
Apprentice
 
Join Date: Sep 2006
Posts: 60
Default Re: SVCHOST.EXE Issues

Hey anand,

okie... HijackThis dint solve the problem.. but it did help me remove a lot of other crap.. so thanks anyways..

actually i discovered the solution....

now as i had said ie used to pop up randomly.. it always used to redirect me to url.cpvfeed.com.. now i dunno hw many know this but this is the problem.

Its malware.. no point scanning ur system with avg / norton / mcafee with latest updates.. does not solve anything.. Ad Aware and Spybot dont solve anything either..

go to c:\windows\system32\drivers

you will find a file called core.sys.. the trick is to delete this.. in normal windows mode you cant.. also if you try to upload the same to www.virustotal.com, it does not work, cuz the malware prevents the upload...

the error msg is "Upload file length is 0 bytes"...

only soln that i found is this..

1) Restart windows in safe mode
2) Delete the core.sys file. You might also find a cache file for core.sys. delete this too.
3) Restart the system in normal mode.
4) Voila!! Problem gone.....


Just thought i would post this.. I dunno how many ppl have the same prob n in case they do, they can use this soln..

anand since u r pretty well knwn in these circles i would definitely suggest you start a new thread n propogate this...

ppl are more likely to listen to you than me brother..

and yeah... thanks a lot for your help n suggestions too!!!

Ciao!!!
rakesh14021983 is offline  
Old 21-04-2007, 06:52 PM   #7 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: SVCHOST.EXE Issues

hey thanx 4 posting the soln buddy ! one must always do so ! learnt something new bcoz of u - THANX !

ya, "CORE.SYS is a file recently detected by the Prevx database. This file is yet to be determined globally as Good or Bad, therefore it is currently classified as Unknown" prevx

it gives popups from the foll crapsites :
xads.zedo.com
upspiral.com
searchlocal.ws
aavalue.com
url.cpvfeed.com
its detailed removal instructions are given at pchell.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 21-04-2007, 10:08 PM   #8 (permalink)
-- No Easter Eggs here --
 
hemant_mathur's Avatar
 
Join Date: Apr 2006
Location: Front of my pc
Posts: 949
Default Re: SVCHOST.EXE Issues

^^ Reported.
@rakesh14021983 : Great info. thanx
__________________
E6850 3.0 Ghz, 4gb 667 Mhz RAM, Asus p5n Esli Mobo, Nvidia 8600GT 512mb, 400gb WD HDD, Samsung Syncmaster 920NW, Vista x64
hemant_mathur is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan infection aneesh kalra Software Q&A 7 24-04-2007 09:32 PM
Trojano-g. Infection nooob QnA (read only) 3 14-12-2006 04:01 PM
spyware infection...please help ace1 Software Q&A 3 25-11-2005 07:24 PM

 
Latest Threads
- by Tenida
- by Charan
- by abhidev

Advertisement




All times are GMT +5.5. The time now is 10:01 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2