svchost virus

BreakGuy

New member
Local time
11:59 AM
Messages
22
From what I can understand the only svchost.exe should be found in the system32 folder. However, I completed a search and I've discovered it's in a lot more folders than system32.

I need to get rid of these files as I believe they are the cause of my recent problems and annoyances. How do I go about doing this?
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
svchost.exe can be in several folders and you may have 2 different versions. One in system32 (x64) and one in SysWOW64 (x86).
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg
I've done numerous scans over the past week using my paid for BitDefender and it's failed to pick up on anything. However Prevx picked up on it, but I need to purchase their program in order for it to remove it.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
I've done numerous scans over the past week using my paid for BitDefender and it's failed to pick up on anything. However Prevx picked up on it, but I need to purchase their program in order for it to remove it.

Try: Malwarebytes it is free
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg
After waiting two and a half hours for the scan to complete.... nothing. MalwareBytes also failed to pick up on it.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
Why dont you just clean out the temp folder? Please do the following to access the Temp folder:

1. Click Start.
2. Type:
%tmp%
3. Press Enter.

This will open the temp folder. Delete everything in it.

Alternatively, you can use CCleaner.
 

My Computer

Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
There is no svchost in C:\Users\<username>\AppData\Local\Temp. My problem is within the C:\Windows\Temp folder. Should I continue with the deletion?
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
Have deleted the C:\Windows\Temp file and I guess I'll have to wait and see if any further problems arise (as scans aren't showing anything).
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
Can you describe the annoying behaviour you mentioned in your first post? While svchost.exe is a valid windows generic host process, there is also a virus/worm that takes on that name. It is detected as W32/YahLover.Worm.gen by McAfee and Win32/Autorun.R.worm by NOD32. IDK what other AVs read it as.

The symptoms can be failure of the Task Manager and Registry editor to launch, or CMD restarting windows.
 

My Computer

Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
BitDefender would pop up a message saying Trojan.Generic.4129231 (I think that number is right) with the file being svchost.exe. It would usually appear when I click on the start button and when I tried to access Windows Live Messenger, but also popped up frequently while simply going about my day-to-day business.
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion dv6
OS
Windows 7 Home Premium 32bit
CPU
AMD Athlon(tm) II Dual-Core M320
Memory
4GB
Graphics Card(s)
ATI Mobility Radeon HD 4530 Series
Google didnt turn up anything for that particular number. But it could be a false positive. OTOH, it may not be. If you have Bitdefender still running, next time it throws up that message, try submitting it for analysis. That'll help establish what exactly it is.
 

My Computer

Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
The "Application" svchost *random number*. tmp files are malware ...

Don't try to delete all, you could get a legit file!
Run Malwarebytes' Anti-malware as suggested above:
http://majorgeeks.com/download5756.html


C:\Windows\System32\ svchost.exe is the legitimate location and is the Host Process for Services
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Back
Top