| Windows 7: svchost.exe file in the /windows directory not system32 |
28 Jul 2012
|
#11 | | Windows 7 Ultimate x64 Buenos Aires |
I agree with everyone else, that the best thing is a full reformat of the system to clean up everything. Even though it's not something good, it's the best bet in the long run, generally speaking, when a Windows installation has some (severe) malfunction it's much faster to just reinstall it from scratch then try to repair it.
Make sure that before formating, you copy all your data files to another drive, CD or other place booting from a portable OS. And once you install Windows again, first of all install an antivirus and do a full scan of the backup you made, just to prevent a re-infection. | My System Specs |
| Computer type Laptop System Manufacturer/Model Number Toshiba Sattelite A665-S6092 OS Windows 7 Ultimate x64 CPU Intel Core i7-740QM Memory 8 GB DDR3 Graphics Card NVIDIA GeForce 330GT Screen Resolution 1366x768 Cooling Coolermaster Notepal U3 notebook cooling pad Hard Drives Samsung 840 SSD 500GB
1TB USB3 external HD Internet Speed 3mbps ASDL Antivirus Kaspersky Antivirus 2013 Browser Opera 12.15 x64 |
30 Jul 2012
|
#12 | | Windows 7 Home Premium 32 bit In a house with a cat trying to kill me |
Just because your scanners are showing clean doesn't necessarily mean you are free of a virus. There are different categories of viruses, some more stubborn/harder to remove then others. A rootkit is one of the harder ones to remove (in most cases) & even if you do manage clear most of it, there's always a chance that some remnant of it may cause problems down the road, or even reinstall itself at some point. Not to mention the damage that was probably caused to some of your operating system files, which will need to be repaired. Quote: Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; re-installation of the operating system may be the only available solution to the problem. Being that Microsoft recommends a reinstall when it comes to this virus, this remains your best bet.
Back up your files on the medium of your choice and make sure they are thoroughly scanned before putting them back on the system. If in doubt, you can submit files (up to 32MB) to VirusTotal, which will scan the files with multiple AV programs. https://www.virustotal.com/
Another thing you may wish to do, after you have done a reinstall ( do not do this now), is to make a system image. This can be invaluable should something like this happen down the road: Backup Complete Computer - Create an Image Backup | My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
30 Jul 2012
|
#13 | | Windows 7 Ultimate 32bit SP1 |
| My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
30 Jul 2012
|
#14 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
Borg,
I agree. Only an offline malware removal tool such as Microsoft's offline malware removal tool, WDO, will catch many problems.
Incidentally, I disagree with Jaycee's advice, but that is another topic and I'm in no mood for such discussions. | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
30 Jul 2012
|
#15 | | Windows 7 Ultimate 32bit SP1 |
My advice is to wipe the OS and do a 'clean' install. Once you have a Rootkit, your computer has been severely compromised and it will never be stable again.... unless you do what I just said.
The article above, that I linked to, tells what ZA Rootkit does and how it acts to render your computer worthless. | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
30 Jul 2012
|
#16 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
I disagree. Not all rootkits are created equal. True, there are some that do irreparable damage to your system files, however, most people would like to avoid a reinstall like the plague if at all possible. I give them a possibility that works in an amazing number of cases. | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
30 Jul 2012
|
#17 | | Windows 7 Ultimate 32bit SP1 |
Nope, not all Rootkits are created equal... this one creates it's own hidden partition that is just about impossible to find, let alone clean up.
Karl, did you read what ZA is and does? Would you allow it to be "fixed" on one of your own computers, or wipe and 'clean install' the OS? | My System Specs | | System Manufacturer/Model Number Bruce ... somewhere in his 40's OS Windows 7 Ultimate 32bit SP1 CPU Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz Motherboard INTEL/D975XBX2 Memory 4 GB Graphics Card ATI Radeon HD 2600 Pro Monitor(s) Displays Samsung SyncMaster 914v Screen Resolution 1280 x 1024 Keyboard Standard PS/2 Keyboard Mouse Microsoft PS/2 Mouse PSU Rocketfish 700 W Case G.Skill Gigabyte Chassis Hard Drives 2/500GB each ... ST3500630AS ATA Device.
One is not connected Internet Speed DSL Antivirus Avira Internet Security Browser IE 9 Other Info ATI HDMI Audio |
01 Aug 2012
|
#18 | | |
Thank you for addressing 3 & 4 in my previous message. If I get to that stage I will definitely follow the advice on that.
However, I'm the type that likes a good fight. LOL. I went ahead and skipped #1 (SUPER AntiVirus), and did #2 (ComboFix) instead. So far, combofix seems to have fixed the problem. I'm waiting for feedback on the combofix logs on another forum before I declare the issue solved, but so far, I seem to be back up and running with no issues remaining on the infected computer. Internet connection is back, updated Hitman and Malware Bytes, and all 3 (Hitman, MalwareByes, and Kapersky TDSS Killer) showing no signs of infection. Keeping my fingers crossed that ComboFix did the job!
I will review all the other information above. I was able to get all important files over to an external, so I bought myself some time and can go ahead and try to fight this battle before giving up and having to re-install 7. | My System Specs | | OS 7 Home Premium 64-bit CPU Core i7 (3rd Gen Quad Core 3.4 Ghz) Memory 12 GB Hard Drives 2 TB
256 GB SSD For startup/programs |
04 Aug 2012
|
#19 | | |
Between ComboFix and OTL, I seem to have solved all problems. I will keep you all updated with any relevant info.
I would like any input on what anti-virus, anti-malware programs you all recommend to prevent this from happening again. Things like real-time protection that don't slow things down too much (I do lots of video editing....). I will always use Malware Bytes. I've heard good things about Avast. What else? And is it advised to just stick with one or two defense programs, or is running a bunch more OK?
Thank you very much for your help, advice, and assistance. It's been interesting to say the least! | My System Specs | | OS 7 Home Premium 64-bit CPU Core i7 (3rd Gen Quad Core 3.4 Ghz) Memory 12 GB Hard Drives 2 TB
256 GB SSD For startup/programs |
04 Aug 2012
|
#20 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
I use, and use only MSE, Microsoft Security Essentials.
This will help explain why: Understanding Microsoft Anti-Malware Software 2012 ~ Security Garden | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. svchost.exe file in the /windows directory not system32 problems? All times are GMT -5. The time now is 10:55 PM. | |