Windows 7 Forums Search
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7 - W32.Sober in conhost.exe?



 
12-16-2008   #1


Windows 7 build 7057
 
 

W32.Sober in conhost.exe?

SpyBot discovered W32.Sober in file Windows\System32\conhost.exe (build 6956). Can somebody confirm it? Or it's fake alert?

My System SpecsSystem Spec
12-16-2008   #2


Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
 
 


can you do a sfc /scannow???

or if you dont want to go thorough that process can you give us the MD5 hash
go here
http://www.whitsoftdev.com/md5/
download the unicode and open it point to the file itself and post the hash here..
My System SpecsSystem Spec
12-16-2008   #3


Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
 
 


i got this
05f88bf36b0cdd276cc0b6ad9554b397 md5 hash
whats yours???
My System SpecsSystem Spec
.


12-16-2008   #4


Windows 7 build 7057
 
 


Quote   Quote: Originally Posted by darkassain View Post
i got this
05f88bf36b0cdd276cc0b6ad9554b397 md5 hash
whats yours???
It's same as I have, there are 2 options now:

1) Worm is in instalation files
2) SpyBot doing false alarm
My System SpecsSystem Spec
12-16-2008   #5


Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
 
 


yes this is a false alarm...
have 6956 in vm...
clean install
there are no connections bypassing the firewall (got ms network monitor to check for that)
and frankly avast would have picked it up (on my real machine have 6956...)
My System SpecsSystem Spec
12-16-2008   #6


Windows 7 Ultimate x64 SP1
 
 


Hello Shawn,

Yes, I can confirm the same thing.

W32.Sober in conhost.exe?-s-d.jpg

Shawn
My System SpecsSystem Spec
12-16-2008   #7


Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
 
 


you can also check in processxp
its strings
if you know how...
here is conhost.exe strings...
i see nothing out of the ordinary in the strings....

edit: two shawns ...lol
Attached Files
File Type: zip conhost.exe.zip (9.7 KB, 569 views)
My System SpecsSystem Spec
12-16-2008   #8


Windows 7 Ultimate x64 SP1
 
 


I agree, but I just do not feel comfortable with it considering the source of the OS.
My System SpecsSystem Spec
12-16-2008   #9


Windows 7 Build 7057 x64/7068 x86
 
 


this file was running when i was playing GTA IV.

but then after a few runs, it's gone.
My System SpecsSystem Spec
12-16-2008   #10


Windows 7 Ultimate x64 + x86 + Windows 8 x64
 
 


Thanks for the info Shawn,

Was thinking of replacing my 6801 x86 with 6956 but think I'll wait till the public beta
My System SpecsSystem Spec
Reply

W32.Sober in conhost.exe? problems?



Thread Tools



Similar Threads for: W32.Sober in conhost.exe?
Thread Forum
Conhost exe General Discussion
conhost.exe infected. (backdoored) System Security
Conhost.exe terminated on "Black List" Crashes and Debugging
conhost.exe General Discussion


All times are GMT -5. The time now is 09:07 PM.



Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30