|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
removing svchost.exe!
|
Original Message
|
Name: David
Date: December 3, 2003 at 08:06:46 Pacific
Subject: removing svchost.exe!OS: win xpCPU/Ram: not sure |
Comment: I have this file coming on to my desktop, have run adaware and spybot. Nothing I do can get rid of this... please help! "C:\Program Files\GlobalDialer\tonex00170\svchost.exe"
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: Tom41
Date: December 3, 2003 at 08:11:51 Pacific
|
Reply: (edit)Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan". When the scan is finished, click "Save Log", and copy and paste it in a reply. HijackThis!
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: David
Date: December 3, 2003 at 08:22:46 Pacific
|
Reply: (edit)Logfile of HijackThis v1.97.7 Scan saved at 11:21:41 AM, on 12/3/2003 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINNT\System32\SK9910DM.EXE C:\WINNT\GWMDMMSG.exe C:\WINNT\System32\igfxtray.exe C:\WINNT\System32\hkcmd.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\program files\GlobalDialer\tonex00170\svchost.exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINNT\System32\GEARSEC.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINNT\System32\NMSSvc.exe C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS C:\WINNT\System32\svchost.exe C:\WINNT\wanmpsvc.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O1 - Hosts: 69.56.223.196 t.rack.cc O1 - Hosts: 69.56.223.196 www.alfa-search.com O1 - Hosts: 69.56.223.196 webcoolsearch.com O1 - Hosts: 69.56.223.196 in.webcounter.cc O1 - Hosts: 69.56.223.196 i-lookup.com O1 - Hosts: 69.56.223.196 www.hand-book.com O1 - Hosts: 69.56.223.196 www.maxxxhosters.com O1 - Hosts: 69.56.223.196 allneedsearch.com O1 - Hosts: 69.56.223.196 nativehardcore.com O1 - Hosts: 69.56.223.196 teen-biz.com O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net O1 - Hosts: 69.56.223.196 best.royalsearch.net O1 - Hosts: 69.56.223.196 default-homepage-network.com O1 - Hosts: 69.56.223.196 xwebsearch.biz O1 - Hosts: 69.56.223.196 www.rightfinder.net O1 - Hosts: 69.56.223.196 www.search-1.net O1 - Hosts: 69.56.223.196 www.searchv.com O1 - Hosts: 69.56.223.196 www.websearch.com O1 - Hosts: 69.56.223.196 mysearchnow.com O1 - Hosts: 69.56.223.196 www.therealsearch.com O1 - Hosts: 69.56.223.196 www.find-itnow.com O1 - Hosts: 69.56.223.196 find.microgirls.com O1 - Hosts: 69.56.223.196 super-spider.com O1 - Hosts: 69.56.223.196 www.searching-the-net.com O1 - Hosts: 69.56.223.196 www.firstbookmark.com O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\tonex00170\svchost.exe -remove O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKLM\..\RunOnce: [OOBEDDDemise] cmd /x /c erase C:\WINNT\System32\oobe\msoobe.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O9 - Extra button: AIM (HKLM) O9 - Extra button: Real.com (HKLM) O9 - Extra button: MoneySide (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com O16 - DPF: ConferenceRoom Java Client - http://irc.ev1.net/java/cr.cab O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab O16 - DPF: {11111111-1111-1111-1111-111111111111} - http://www.spywareinfo.com/browsertest/dialer.exe O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/262884a2570b2b92b014/netzip/RdxIE601.cab O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://205.247.223.210/main/Install/CentraDownloader.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://terranova.webex.com/client/latest/webex/ieatgpc.cab
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: Tom41
Date: December 3, 2003 at 08:57:23 Pacific
|
Reply: (edit)Run HijackThis again and place a check in the box next to the following items. Doublecheck so as to be sure not to miss one. Next, close all browser Windows, and have HT 'fix checked'. You Must restart your computer when you're done. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O1 - Hosts: 69.56.223.196 t.rack.cc O1 - Hosts: 69.56.223.196 www.alfa-search.com O1 - Hosts: 69.56.223.196 webcoolsearch.com O1 - Hosts: 69.56.223.196 in.webcounter.cc O1 - Hosts: 69.56.223.196 i-lookup.com O1 - Hosts: 69.56.223.196 www.hand-book.com O1 - Hosts: 69.56.223.196 www.maxxxhosters.com O1 - Hosts: 69.56.223.196 allneedsearch.com O1 - Hosts: 69.56.223.196 nativehardcore.com O1 - Hosts: 69.56.223.196 teen-biz.com O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net O1 - Hosts: 69.56.223.196 best.royalsearch.net O1 - Hosts: 69.56.223.196 default-homepage-network.com O1 - Hosts: 69.56.223.196 xwebsearch.biz O1 - Hosts: 69.56.223.196 www.rightfinder.net O1 - Hosts: 69.56.223.196 www.search-1.net O1 - Hosts: 69.56.223.196 www.searchv.com O1 - Hosts: 69.56.223.196 www.websearch.com O1 - Hosts: 69.56.223.196 mysearchnow.com O1 - Hosts: 69.56.223.196 www.therealsearch.com O1 - Hosts: 69.56.223.196 www.find-itnow.com O1 - Hosts: 69.56.223.196 find.microgirls.com O1 - Hosts: 69.56.223.196 super-spider.com O1 - Hosts: 69.56.223.196 www.searching-the-net.com O1 - Hosts: 69.56.223.196 www.firstbookmark.com O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\tonex00170\svchost.exe -remove O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://205.247.223.210/main/Install/CentraDownloader.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://terranova.webex.com/client/latest/webex/ieatgpc.cab After restarting delete the following: C:\Program Files\GlobalDialer folder.
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: kevin
Date: December 3, 2003 at 21:26:22 Pacific
|
Reply: (edit)I have XP home and about six (all caps) SVCHOST.EXE on my C drive. I was told that it is a virus that Norton does not detect because of the all caps (vs the legit all lower case version). Does anyone know how I can remove the six? P.S. I don't know if this is related but when I first get up the desktop page, I get a sound and a box shows up in the middle of the page that says "access to drive C denied" and then an "ok" box right below it. Thanks a ton to anyone who has an answer to my question!! Kevin.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: Steven33
Date: December 7, 2003 at 09:24:56 Pacific
|
Reply: (edit)Well,I did run Hijack This and fixed all the R1's and R0's that had bad url's in them (allneedsearch, etc.); You could check all the other things Tom41 said, but I had none of those. Then I restarted my computer and I could just search it and remove it. One problem left: after I start up my PC I always get this message: "RUNDLL: problems opening svchost: can't find item" or something like that. Does anybody know what to do about it?
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: Steven33
Date: December 7, 2003 at 10:27:31 Pacific
|
Reply: (edit)On the other hand... http://www.grtg.org/stuff/computers/windows/svchost_exe.php Read this first; it seems the svchost.exe is nothing to worry about? Anyway; I deleted it and I thus far haven't got any problems with the system; and all popups and starting pages and the like are gone... Thanks for any info; Steven
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: Tristan
Date: December 8, 2003 at 12:06:16 Pacific
|
Reply: (edit)That Global dialer is causing me problems too and it usually happens once a day when i first connect to the net it downloads it and creates a new internet connection and then bumps me off the my current connection , at this point I unplug my phone line and delete the first svchost and then I can delete all the files (in folder c:\program files\global dialer\tonex00170) or global dialer\wordxxxx) in the mean time it won't let me delete the new internet connection it creates (live content) So I have to restart and then delete it after that im fine to use it for the rest of the day
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: Sean Whiting
Date: December 29, 2003 at 14:37:42 Pacific
|
Reply: (edit)I also have a problem with svchost.exe, i downloaded a program from winmx it said it was a zip file so i double clicked on it. but did nothing, i thought nothing of it. then i started to encounter problems like i couldn't run my BCWipe program or my evidence eliminator program. and i noticed that it had 2 svchost.exe programs in the applications tab of the task manager. at the time one was running and the other was not responding. i thought this was the problem so i went into regedit and searched for svchost.exe and it brought up many results had names that related to my songs i downloaded e.g. back in the USSR. so i decided to open that beatles song and it brought a blue screen reporting some serious error, then restarted. nothing bad happened but the 2 files were still there. so i went into regedit and deleted all the results of 'svchost' i restarted my computer and then to my surprise only one svchost.exe file was there in the applications tab. (the other funny thing is that the little icon near svchost.exe in the applications tab was an icon for a zip file) and i tried to listen to the song again it worked but media player brought an error message saying it had to be closed down. i then downloaded hijackthis and here is the log. Logfile of HijackThis v1.97.7 Scan saved at 22:24:50, on 29/12/2003 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\KMaestro\KMaestro.exe C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe C:\WINDOWS\Mixer.exe C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Program Files\AOL 8.0\aoltray.exe C:\Program Files\AOL Companion\companion.exe C:\KMaestro\WTS_KEY.EXE C:\Program Files\AOL 8.0\waol.exe C:\Program Files\AOL 8.0\shellmon.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Sean\LOCALS~1\Temp\Rar$EX01.140\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://wer-mit-wem.webhop.net/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wer-mit-wem.webhop.net/ R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe O4 - HKLM\..\Run: [KeyMaestro] C:\KMaestro\KMaestro.exe O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [BCWipeTM Startup] "C:\Program Files\Jetico\BCWipe\BCWipeTM.exe" startup O4 - HKLM\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor O4 - HKCU\..\Run: [Winstart] C:\windows\winstart32.exe O4 - HKCU\..\Run: [Ahead] C:\windows\Ahead.exe O4 - HKCU\..\RunServices: [Winstart] C:\windows\winstart32.exe O4 - HKCU\..\RunServices: [cmuninst32] C:\windows\cmuninst32.com O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.exe O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: PSPSetup.lnk = C:\WINDOWS\regedit.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Researcher (HKLM) O9 - Extra button: Real.com (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{50D60893-9619-4269-94E8-0E2C6E0F5121}: NameServer = 195.93.32.134 I also have used mcafee virus scanner, and it brought up no results. Sorry for my long winded problem report, but could someone please help me. Many thanks Sean
Report Offensive Follow Up For Removal
|
|
Response Number 9
|
Name: JasonBenoit
Date: January 6, 2004 at 11:15:13 Pacific
|
Reply: (edit)I have gotten rid of uneeded scvhost.exe's b4 I read this because of past problems...and i have heard if it's not broke don't fix it..but I want to get rid of anything that I don't need on my computer. Because it is starting to get a little glogged up with needless crap, and I know it makes my system just strain. so here is my hijack this log...please let me know what I need to delete..what I may want to keep...thank you.. Jason Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\tppaldr.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe C:\Program Files\AVPersonal\AVGNT.EXE C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\MYIE2\MYIE.exe C:\Documents and Settings\TIMOTHY RA Y BENOIT\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Surfin the world! R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O1 - Hosts: 66.250.107.101 google.co.in O1 - Hosts: 66.250.107.101 google.com.au O1 - Hosts: 66.250.107.101 google.co.uk O1 - Hosts: 66.250.107.101 google.com.ar O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file) O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\WINDOWS\Downloaded Program Files\ycomp5_1_6_0.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: PowerSearch - {4E7BD74F-2B8D-469E-D1F0-E56FA787AD2D} - C:\PROGRA~1\POWERS~1\Toolbar\pwrscznc.dll O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\Keenware\wupdater.exe O4 - Startup: PowerReg SchedulerV2.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Add to Ad Hunter - C:\Program Files\MYIE2\config/blacklist.htm O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: MoneySide (HKLM) O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1066585473546 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab O16 - DPF: {36C417C6-13C6-448B-9784-DD73A93B0582} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,56/mcinsctl.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,74/mcinsctl.cab O16 - DPF: {5D8488E6-071F-4694-B3E4-BCD1976770B4} - http://media.euniverse.com/cursorzone/files/ACF11EE.cab O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs7b.instantservice.com/jars/customerxsigned35.cab O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37881.4614351852 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4302/mcfscan.cab O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Companion) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
Report Offensive Follow Up For Removal
|
|
Response Number 10
|
Name: needshelp
Date: January 15, 2004 at 17:57:20 Pacific
|
Reply: (edit)does anyone know how to remove svchost.exe? i know its been a long time since someone posted here, but this site is all i can find
Report Offensive Follow Up For Removal
|
|
Response Number 11
|
Name: gmoney
Date: January 18, 2004 at 19:10:22 Pacific
|
Reply: (edit)In general, do NOT remove the "svchost.exe" file itself! It is a critical part of your system (at least the one in C:\WINDOWS\System32 or C:\WINNT\System32 is critical)! Unfortunately it is sometimes used or imitated by malicious programs too. What you want to do is look for traces of a malicious program, if any by running antivirus, anti-spyware, and a firewall - also check your "startup" config and search your hard drives for 'svchost.exe' that are not in the System32 directory - if none of that search finds anything, then odds are you're clean. Did you read the article Steve33 posted above: http://www.grtg.org/stuff/computers/windows/svchost_exe.php Disabling unnecessary services in Windows 2000/XP/2003 may reduce the number of svchost.exe processes you have running. Check out Black Viper's info on Windows XP and Windows 2000 for more information
Report Offensive Follow Up For Removal
|
|
Response Number 12
|
Name: Special Effect
Date: January 28, 2004 at 07:21:53 Pacific
|
Reply: (edit)I think i am having the same problem. I currently have 4 scvhost.exe running. But in addition to that i have no start menu at the bottom of my desktop and it takes forever to load up windows. "Windows is starting up...". is there for what seems like forever. Can someone please help?
Report Offensive Follow Up For Removal
|
|
Response Number 13
|
Name: Special Effect
Date: January 28, 2004 at 08:53:48 Pacific
|
Reply: (edit)My log file of hijack this Logfile of HijackThis v1.97.7 Scan saved at 11:52:45 AM, on 1/28/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS C:\WINNT\wanmpsvc.exe C:\WINNT\System32\SK9910DM.EXE C:\WINNT\GWMDMMSG.exe C:\WINNT\System32\igfxtray.exe C:\WINNT\System32\hkcmd.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\DownloadWare\dw.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Common Files\CMEII\CMESys.exe C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE C:\Program Files\DelFin\PromulGate\PgMonitr.exe C:\WINNT\System32\SahAgent.exe C:\WINNT\wt\updater\wcmdmgr.exe C:\Program Files\Date Manager\DateManager.exe C:\Program Files\PrecisionTime\PrecisionTime.exe C:\Program Files\Webshots\WebshotsTray.exe C:\WINNT\explorer.exe C:\WINNT\System32\rsvp.exe C:\Program Files\America Online 8.0\aol.exe C:\Program Files\America Online 8.0\waol.exe C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-search.cgi?tcode=exesrch&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.search-exe.com/nph-search.cgi?tcode=exesrch&fw= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-search.cgi?tcode=exesrch&fw= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-search.cgi?tcode=exesrch&fw= R3 - URLSearchHook: WebSearch Class - {9368D063-44BE-49B9-BD14-BB9663FD38FC} - C:\Program Files\se\v2\se.DLL O2 - BHO: (no name) - {00041A26-7033-432C-94C7-6371DE343822} - C:\Program Files\se\v2\se.DLL O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet5_48.dll (file missing) O2 - BHO: (no name) - {65C8C1F5-230E-4DC9-9A0D-F3159A5E7778} - C:\Program Files\POP\pop167.dll (file missing) O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &POP - {645FD3BC-C314-4F7A-9D2E-64D62A0FDD78} - C:\Program Files\POP\pop167.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [MediaLoads Installer] "C:\Program Files\DownloadWare\dw.exe" /H O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" O4 - HKLM\..\Run: [POP] C:\Program Files\POP\PopSrv146.exe O4 - HKLM\..\Run: [AutoUpdater] C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE O4 - HKLM\..\Run: [wcmdmgr] C:\WINNT\wt\updater\wcmdmgrl.exe -launch O4 - HKLM\..\Run: [Search-Exe] "C:\Program Files\se\v2\se.EXE" /U O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe" O4 - HKLM\..\Run: [SAHAgent] C:\WINNT\System32\SahAgent.exe O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe" O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe O9 - Extra button: ATI TV (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Real.com (HKLM) O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet5_48.dll' missing O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - hcp://system/TechTools.CAB O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/shockwave/virtualwarfare/install.cab O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{09C02537-FB35-41BB-A8DD-CD8C4540893E}: NameServer = 205.188.146.146 O17 - HKLM\System\CS1\Services\Tcpip\..\{09C02537-FB35-41BB-A8DD-CD8C4540893E}: NameServer = 205.188.146.146
Report Offensive Follow Up For Removal
|

|

|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
|
|
|