Computing.Net > Forums > Security and Virus > Help - SVCHOST99% And SPYware

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Help - SVCHOST99% And SPYware

Reply to Message Icon

Name: italianjob17
Date: May 25, 2005 at 08:55:18 Pacific
OS: WinXpPro2002Sp1
CPU/Ram: PentiumIV 1.7GB - RAM 76
Comment:

I didn't.... but now i got this crappy svchost.exe 99% cpu problem,

i know i've been infected by some malware, i got a Pentium IV with winxpprosp1, patched and fully

protected against blaster, sasser etc... I use Mozilla Firefox, Recently I installed a piece of junk

(msn emoticon installer...) that came with 180search assistant...and god only knows what else...

crap!
So i removed everything: the host application, all the specific registry keys, i scanned everything

with fully updated nod32 antovirus, blocked every malicious application with look'n stop firewall,

removed and cleaned everything with every kind of malware/spyware tool: ad aware, giant antispyware,

panda online virus scan, cwssherdder, secure guard, ccleaner, housecall trendmicro, stinger, spybot

sd, activescan, pest patrol, regscrub, and every other antispy app you can think about.
Now they all say i'm clean, but still have 99% of cpu sucked by that damn svchost.exe, this happens

after 10 mins i start my pc.
If i shut svchost.exe down i solve my problem, but got no more audio!

the svchost affected contains these running tasks (found with start/execute/CMD.exe tasklist/svc)

AudioSrv,
Browser,
CryptSvc,
Dhcp,
dmserver,
EventSystem,
helpsvc,
lanmanserver,
lanmanworkstation,
Netman,
Nla,
RasMan,
seclogon,
SENS,
ShellHWDetection,
TapiSrv,
TermService,
Themes,
TrkWks,
uploadmgr,
winmgmt,
WmdmPmSp,
WZCSVC

Do you know wich one of these i have to remove??

Do you need an Hijackthis log??

PLEASE SOMEBODY HELP ME!!! i really need this!



Sponsored Link
Ads by Google

Response Number 1
Name: PDB
Date: May 25, 2005 at 09:11:49 Pacific
Reply:

Have you tried Bitdefender, SpyWareNuker or Xoftspy - I found these guys took out some weird stuff that the other main line guys missed.


0

Response Number 2
Name: italianjob17
Date: May 25, 2005 at 09:23:10 Pacific
Reply:

I'm downloading them right now, i'll let you know whant they found.... keeping my fingers crossed!


0

Response Number 3
Name: italianjob17
Date: May 25, 2005 at 09:52:53 Pacific
Reply:

Xoftspy found 3 threats... 2 reg keys trojan and a unharmful cookie. great app! no other app found that! now i hope my svchost will be healthy again.....


0

Response Number 4
Name: italianjob17
Date: May 25, 2005 at 10:41:11 Pacific
Reply:

i restarted and still got this svchost problem.... any other idea???


0

Response Number 5
Name: Lionheart
Date: May 25, 2005 at 15:37:01 Pacific
Reply:

First off-Xoftspy,and Spwarenuker are suspected rogue antispyware,and you can read up on it from here- Rogue.So i suggest you remove those antispyware apps before you add to your problems.

Secondly-Scan the suspected file from this site that has 10+ of the top antivirus companies outthere from here- Virus Scanners.

Thirdly-Write down the name of the ofending infection file(Virus,Trojan,worm, ect name) so we know what you are up against so that we can offer a proper cleaning of the infection.

Lastly-if all else fails???just post a hijack this log so that we can determine whats in your system.


0

Related Posts

See More



Response Number 6
Name: italianjob17
Date: May 25, 2005 at 17:14:22 Pacific
Reply:

ok, thanks i'll try that and let you know asap!


0

Response Number 7
Name: italianjob17
Date: May 26, 2005 at 08:16:13 Pacific
Reply:


WORM_MYTOB.X this is the PEST!!!! i con't remove it with nod32.... i discovered that because i received a mail server message that said i was attempting to send this message automatically.... please help me remove this!!! thanks a lot


0

Response Number 8
Name: Lionheart
Date: May 26, 2005 at 11:03:33 Pacific
Reply:

To start=Fully update nod32,and then turn system restore off,then reboot your pc,and start tapping the (F8) upon boot to enter into (SAFEMODE).

Step 2- Fully scan your pc with nod32 with system restore turned off,and while in safe mode,and see if it can remove the worm.

To turn system restore off,and on,follow these instructions.(Dont forget to turn system restore on after the pc is clean.)

For Windows XP:

1. Log on as Administrator.
2. Right-click the My Computer icon on the desktop and click Properties.
3. Click the System Restore tab.
4. Select Turn off System Restore.
5. Click Apply > Yes > OK.
6. Continue with the scan/clean process. Files under the _Restore folder can now be deleted.
7. Re-enable System Restore by clearing Turn off System Restore.

If this fails???here is a link with a removal tool,and manual removal instructions.You cann also submitt a hijack this lof after you have completed all these steps.

Worm removal


0

Response Number 9
Name: PDB
Date: May 26, 2005 at 13:18:06 Pacific
Reply:

Some of the programs that got labeled Rogue where the result of older versions. Like I explained above, some of these programs are finding stuff the main channal guys are not finding. If uncomfortable with the idea they might be malicious, uninstall after using. XoftSpy found 2 Trojans in my computer that the others didn't. Fixed my computer problems great. Alot of the times, scanning in Safe Mode is a better way to find problems that hide on Normal bootup. I have found 1 item relating to SpyNuker, none for XoftSpy when scanning afterwards with SpySubtract, AdAware SE, SpySweeper, BulletProof (SpyBot doesn't like this one), SpyBot, Counterspy, Bazooka etc. My motto is, if it fixes something the others won't or can't, I think the benefits outway the problems. Usually, if the other scanners find problems with the programs, I eliminate the problem found and continue to use the program with the problem eliminated.


0

Response Number 10
Name: dj_gie
Date: May 31, 2005 at 04:51:57 Pacific
Reply:

I find that Spyware Eliminator 4.0 and Spy Sweeper 3.5 are the best spyware removal products about.

Spyware Eliminator 4.0 shines when it comes to rooting out extra-sneaky spyware and adware. Spyware Eliminator 4.0 identifies stubborn, self-regenerating adware and spyware cleverly hidden deep inside program files—including a nasty, sex-dialer program and a pair of redundant adware files, especially skilled at regenerating themselves once deleted.


0

Response Number 11
Name: larockman
Date: June 19, 2005 at 01:12:22 Pacific
Reply:

I don't really use much other than hijackthis, spybot, adaware, and MS antispy. I also have a strong preference for Avast as a virus scanner.
Spyware Removal I would try www.sarc.com and see if norton has a removal tool for mytob. I'm sure they do.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Help - SVCHOST99% And SPYware

help adware and spyware www.computing.net/answers/security/help-adware-and-spyware-/17032.html

Help think its spyware www.computing.net/answers/security/help-think-its-spyware/17954.html

Help! Virus Alert & Spyware prob ++ www.computing.net/answers/security/help-virus-alert-spyware-prob-/23052.html