W32.Sober in conhost.exe?

Page 1 of 5 123 ... LastLast

  1. Posts : 17
    Windows 7 build 7057
       #1

    W32.Sober in conhost.exe?


    SpyBot discovered W32.Sober in file Windows\System32\conhost.exe (build 6956). Can somebody confirm it? Or it's fake alert?
      My Computer


  2. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #2

    can you do a sfc /scannow???

    or if you dont want to go thorough that process can you give us the MD5 hash
    go here
    http://www.whitsoftdev.com/md5/
    download the unicode and open it point to the file itself and post the hash here..
      My Computer


  3. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #3

    i got this
    05f88bf36b0cdd276cc0b6ad9554b397 md5 hash
    whats yours???
      My Computer


  4. Posts : 17
    Windows 7 build 7057
    Thread Starter
       #4

    darkassain said:
    i got this
    05f88bf36b0cdd276cc0b6ad9554b397 md5 hash
    whats yours???
    It's same as I have, there are 2 options now:

    1) Worm is in instalation files
    2) SpyBot doing false alarm
      My Computer


  5. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #5

    yes this is a false alarm...
    have 6956 in vm...
    clean install
    there are no connections bypassing the firewall (got ms network monitor to check for that)
    and frankly avast would have picked it up (on my real machine have 6956...)
      My Computer


  6. Posts : 72,050
    64-bit Windows 11 Pro for Workstations
       #6

    Hello Shawn,

    Yes, I can confirm the same thing.

    W32.Sober in conhost.exe?-s-d.jpg

    Shawn
      My Computer


  7. Posts : 2,899
    Windows 7 Ult x64(x2), HomePrem x32(x4), Server 08 (+VM), 08 R2 (VM) , SuSe 11.2 (VM), XP 32 (VM)
       #7

    you can also check in processxp
    its strings
    if you know how...
    here is conhost.exe strings...
    i see nothing out of the ordinary in the strings....

    edit: two shawns ...lol
      My Computer


  8. Posts : 72,050
    64-bit Windows 11 Pro for Workstations
       #8

    I agree, but I just do not feel comfortable with it considering the source of the OS.
      My Computer


  9. Posts : 47
    Windows 7 Build 7057 x64/7068 x86
       #9

    this file was running when i was playing GTA IV.

    but then after a few runs, it's gone.
      My Computer


  10. Posts : 31,249
    Windows 11 Pro x64 [Latest Release and Release Preview]
       #10

    Thanks for the info Shawn,

    Was thinking of replacing my 6801 x86 with 6956 but think I'll wait till the public beta
      My Computers


 
Page 1 of 5 123 ... LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 14:10.
Find Us