Virus Detected in Windows Files!, Please help fast!!!

demetroman

New member
Local time
7:39 AM
Messages
23
Hi,
I detected these viruses on open with the task manager (process tab),I am 100% sure that these files are infected with viruses , when these are running, my pc slows down and sometimes freezes the program i am into. The Infected files I found till now are:

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\SearchProtocolHost.exe

C:\Windows\System32\dllhost.exe

C:\Windows\splwow64.exe

Please Help, My anti-virus(ESET NOD32 Antivirus 5) doesn't detect these infected files. Neither Windows defender or Microsoft Windows Malicious Software Removal Tool do. What should I do??? Any helpful answers will be appriciated.

Thanks for reading and sorry for too long. If you know how to fix this pls tell me fast.

Demetroman
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64-bit
OS
Windows 7 Ultimate 64-bit

My Computer My Computer

At a glance

Windows 7 Home Premium Service Pack 1 x64Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz3GBNVIDIA GeForce G 103M; Codename: G98
Computer Manufacturer/Model Number
Compaq Presario CQ61
OS
Windows 7 Home Premium Service Pack 1 x64
CPU
Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
Memory
3GB
Graphics Card(s)
NVIDIA GeForce G 103M; Codename: G98
Screen Resolution
1366x768
Try Malwarebytes or ESET's Online Scanner.
 

My Computer My Computer

At a glance

Windows 7 Ultimate SP1 - 64 BitIntel Core i5 2500k2x4GB DDR3 1333HzAti Radeon 6770
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Novatech iRush Pro
OS
Windows 7 Ultimate SP1 - 64 Bit
CPU
Intel Core i5 2500k
Motherboard
Foxconn H67M-S/H67M-V/H67
Memory
2x4GB DDR3 1333Hz
Graphics Card(s)
Ati Radeon 6770
Sound Card
None
Monitor(s) Displays
Samsung S22B150
Screen Resolution
1920x1080
Hard Drives
2x500GB
PSU
500W
Cooling
Fan
Keyboard
HP KU0316
Mouse
Wireless Logitech M185
Internet Speed
20MB/s
Antivirus
Avast Free
Browser
Google Chrome
Other Info
Logitech M185 Mouse
KU-M316 Keyboard

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

Hey, Thanks a lot. I have done the second option. It says it didn't find any integrity violations :))
I hope this is true. But I almost always find in task manager process splwow64.exe, (Printer Host 32-bit which is splwow64.exe) Its is open while i am not printing, i end this process and every 3-5 minutes it comes up again :sarc:, is there something where i can stop this thing or block it through services or something? Please reply and thnnxx for ur help till now.

Best Regards,I'll be waiting for a reply.
Demetroman
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64-bit
OS
Windows 7 Ultimate 64-bit
If you do not have a Printer go to services.msc, locate to Print Spooler, then stop and disable the service.
 

My Computer My Computer

At a glance

Windows 7 Ultimate SP1 - 64 BitIntel Core i5 2500k2x4GB DDR3 1333HzAti Radeon 6770
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Novatech iRush Pro
OS
Windows 7 Ultimate SP1 - 64 Bit
CPU
Intel Core i5 2500k
Motherboard
Foxconn H67M-S/H67M-V/H67
Memory
2x4GB DDR3 1333Hz
Graphics Card(s)
Ati Radeon 6770
Sound Card
None
Monitor(s) Displays
Samsung S22B150
Screen Resolution
1920x1080
Hard Drives
2x500GB
PSU
500W
Cooling
Fan
Keyboard
HP KU0316
Mouse
Wireless Logitech M185
Internet Speed
20MB/s
Antivirus
Avast Free
Browser
Google Chrome
Other Info
Logitech M185 Mouse
KU-M316 Keyboard
Upload the individual files to Virus Total. As Jacee said, they are all names of legitimate windows files. Confirm their locations, and see if VT finds their hash and/or scans them as safe. A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
NO, it is a virus, always hen it's open wndows explorer stops responding!
This cant be a legit file!!! please help , how can i stop this? or replace splwow64.exe???? (print driver host for 32-bit applications)
 

My Computer My Computer

At a glance

Windows 7 Ultimate 64-bit
OS
Windows 7 Ultimate 64-bit
I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi there!

I hate to sound harsh here, but just because they have legitimate names, doesn't mean their not infected. The original files could have been replaced with he infected ones. Upload the files to Virus Total, do a Malwarebytes scan, do an ESET scan, and then we'll talk about disabling the service IMHO.

Let us know what happens!
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel i5 430m4 GB DDR3nvidia Geforce GTS 360M Cuda 1GB
Computer Manufacturer/Model Number
ASUS G60JX Republic of Gamers
OS
Windows 7 Professional 64-bit
CPU
Intel i5 430m
Memory
4 GB DDR3
Graphics Card(s)
nvidia Geforce GTS 360M Cuda 1GB
Sound Card
EAX Advanced HD 4.0
Screen Resolution
1366 x 768
Hard Drives
460 GB 7200 RPM built in
Internet Speed
Too slow :-( 160kbs
Yes, a virus or malware will hide using a legit file name, that's why I asked for an ESET scan.
 

My Computer My Computer

At a glance

Windows 7 Ultimate 32bit SP1Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz4 GBATI Radeon HD 2600 Pro
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Good call. I had the thread open for a while, so your reply popped up unbeknownst to me. :)
 

My Computer My Computer

At a glance

Windows 7 Professional 64-bitIntel i5 430m4 GB DDR3nvidia Geforce GTS 360M Cuda 1GB
Computer Manufacturer/Model Number
ASUS G60JX Republic of Gamers
OS
Windows 7 Professional 64-bit
CPU
Intel i5 430m
Memory
4 GB DDR3
Graphics Card(s)
nvidia Geforce GTS 360M Cuda 1GB
Sound Card
EAX Advanced HD 4.0
Screen Resolution
1366 x 768
Hard Drives
460 GB 7200 RPM built in
Internet Speed
Too slow :-( 160kbs
Yes, we are aware, we were just stating that they are the names of legit files :) A Guy
 

My Computer My Computer

At a glance

Windows 10 Home x64INTEL Core i5-750 Quad-Core 3.37GHzHyperX Fury Black Series 8GB (2 x 4GB) 1866MhzEVGA GeForce GTX 750 Superclocked 1GB 128-Bit...
Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Back
Top