svchost virus

Page 2 of 2 FirstFirst 12

  1. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #11

    oops, my bad! But, yes, clean out C:\windows\temp folder. If it gives you a permissions warning, take ownership.

    Take Ownership Shortcut
      My Computer


  2. Posts : 22
    Windows 7 Home Premium 32bit
    Thread Starter
       #12

    Have deleted the C:\Windows\Temp file and I guess I'll have to wait and see if any further problems arise (as scans aren't showing anything).
      My Computer


  3. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #13

    Can you describe the annoying behaviour you mentioned in your first post? While svchost.exe is a valid windows generic host process, there is also a virus/worm that takes on that name. It is detected as W32/YahLover.Worm.gen by McAfee and Win32/Autorun.R.worm by NOD32. IDK what other AVs read it as.

    The symptoms can be failure of the Task Manager and Registry editor to launch, or CMD restarting windows.
      My Computer


  4. Posts : 22
    Windows 7 Home Premium 32bit
    Thread Starter
       #14

    BitDefender would pop up a message saying Trojan.Generic.4129231 (I think that number is right) with the file being svchost.exe. It would usually appear when I click on the start button and when I tried to access Windows Live Messenger, but also popped up frequently while simply going about my day-to-day business.
      My Computer


  5. Posts : 5,056
    Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
       #15

    Google didnt turn up anything for that particular number. But it could be a false positive. OTOH, it may not be. If you have Bitdefender still running, next time it throws up that message, try submitting it for analysis. That'll help establish what exactly it is.
      My Computer


  6. Posts : 186
    Windows Seven, Ubuntu
       #16

    From what I understand the SVCHOST.EXE is a virus if it is capitalized.

    svchost.exe Windows process - What is it?
      My Computer


  7. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #17

    The "Application" svchost *random number*. tmp files are malware ...

    Don't try to delete all, you could get a legit file!
    Run Malwarebytes' Anti-malware as suggested above:
    http://majorgeeks.com/download5756.html


    C:\Windows\System32\ svchost.exe is the legitimate location and is the Host Process for Services
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 03:06.
Find Us