W32.Sober in conhost.exe?

Has anyone reported this to Spybot SD support so they are made aware of it and can fix it so it doesnt come up as a worm?

Ill go ahead and do it and see what they say. You know a lot of people will just do a scan, see that and delete it because they will believe its a worm/virus because the scanner told them it was. I wouldve done it if I had not seen this post here.
 

My Computer My Computer

Computer Manufacturer/Model Number
Built
OS
Windows 7 RTM
CPU
Intel I7 920 2.67 ghz
Motherboard
EVGA X58
Memory
6GB CORSAIR DOMINATOR
Graphics Card(s)
GeForce GTX 260 Core 216 896MB 448-bit GDDR3 PCI Express 2.0
Hello BS.

Yes, quite a lot us of have sent "feedback" to MS and Spybot about it but the more the better.
















Later :shock: Ted
 

My Computer My Computer

Computer Manufacturer/Model Number
* BFK Customs *
OS
W 7 64-bit Ultimate
CPU
Intel Q9550 Yorkfield
Motherboard
ASUS P5Q Pro
Memory
8GB Dominator 8500C5D
Graphics Card(s)
ATI : XFX 5870
Sound Card
Realtek HD Audio 7-1
Monitor(s) Displays
1x 47" LCD HDMI & 3x 26" LCD HDMI
Screen Resolution
1920x1080P & 1920x1200
Hard Drives
1x 80GB Intel X25-M G2 SSD : 1x 500GB & 1x 640GB WD Caviar Black(s)
PSU
Corsair 620HX
Case
Cooler Master RC-690
Cooling
Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
Keyboard
Microsoft 500
Mouse
Razer Diamondback 3G
Internet Speed
14 Mb/s
Other Info
1x Koutech 3Gb/s SATA HDD Hot Swap Rack
Hi, I'm new here on Windows SevenForums, and so far I'm loving it!

I'm really glad I found this post!
After checking my system for spyware, Spybot reported conhost.exe as a worm. I think I got a little scared and deleted the file right away. Now some programs aren't working as they should, I receive an cmd.exe error.

Is it possible for someone to, please, upload the conhost.exe file?! If not, please, can anybody help me to restore the file so I don't have to reinstall my windows?


Thanks in advance,
 

My Computer My Computer

OS
Windows 7

My Computer My Computer

Computer Manufacturer/Model Number
Home Brew
OS
Windows 7 Ultimate Vista Ultimate x64
CPU
Core 2 Duo E8500 3.16Ghz @ 3.8Ghz
Motherboard
eVGA 750i FTW
Memory
2x2Gigs Patriot PC2-6400 LL
Graphics Card(s)
Inno3D GeForce GTX260 216 SP
Monitor(s) Displays
ASUS VW222U 22" 2ms Response time
Screen Resolution
1680x1050
Hard Drives
SATA 150GB
SATA II 250GB
USB IDE 750GB Ext.
PSU
HYTEC 600W & Thermaltake 650W Toughpower Power Exp
Case
Thermaltake Armor LCS (Liquid Cooling System)
Cooling
Liquid Cooling System
Keyboard
Logitech G15 Gaming Keyboard
Mouse
Logitech G9 Gaming Mouse
so far im sure this is just a false positive.
 

My Computer My Computer

OS
Windows 7 Build 7057 x64/7068 x86
CPU
AMD Athlon X2 64 4200+ @ 2.6GHz
Motherboard
Gigabyte GA-M55SLI-S4
Memory
4*1GB Kingston DDR2-667
Graphics Card(s)
Point of View 8800GT 512MB DDR3
Sound Card
Integrated Realtek ALC850
Monitor(s) Displays
ViewSonic VA712
PSU
CoolerMaster 430W PSU
Hi, I'm new here on Windows SevenForums, and so far I'm loving it!

I'm really glad I found this post!
After checking my system for spyware, Spybot reported conhost.exe as a worm. I think I got a little scared and deleted the file right away. Now some programs aren't working as they should, I receive an cmd.exe error.

Is it possible for someone to, please, upload the conhost.exe file?! If not, please, can anybody help me to restore the file so I don't have to reinstall my windows?


Thanks in advance,

Hello krypnik,welcome to Se7en Forums!

Sorry you found out the hard way; we already knew it's a false positive.

I had the file already to upload to you; but I'm limited by the forums upload size limit; because the file is too big to upload. I'm sorry....:o...Maybe someone with a bigger size limit will upload it for you.

As Mr Grim suggested, have you tried a System Restore to a point before you deleted the file?

Keep us informed!


Later :confused: Ted
 

My Computer My Computer

Computer Manufacturer/Model Number
* BFK Customs *
OS
W 7 64-bit Ultimate
CPU
Intel Q9550 Yorkfield
Motherboard
ASUS P5Q Pro
Memory
8GB Dominator 8500C5D
Graphics Card(s)
ATI : XFX 5870
Sound Card
Realtek HD Audio 7-1
Monitor(s) Displays
1x 47" LCD HDMI & 3x 26" LCD HDMI
Screen Resolution
1920x1080P & 1920x1200
Hard Drives
1x 80GB Intel X25-M G2 SSD : 1x 500GB & 1x 640GB WD Caviar Black(s)
PSU
Corsair 620HX
Case
Cooler Master RC-690
Cooling
Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
Keyboard
Microsoft 500
Mouse
Razer Diamondback 3G
Internet Speed
14 Mb/s
Other Info
1x Koutech 3Gb/s SATA HDD Hot Swap Rack
I don't think you can transfer system32 files, can you?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5

My Computer My Computer

Computer Manufacturer/Model Number
* BFK Customs *
OS
W 7 64-bit Ultimate
CPU
Intel Q9550 Yorkfield
Motherboard
ASUS P5Q Pro
Memory
8GB Dominator 8500C5D
Graphics Card(s)
ATI : XFX 5870
Sound Card
Realtek HD Audio 7-1
Monitor(s) Displays
1x 47" LCD HDMI & 3x 26" LCD HDMI
Screen Resolution
1920x1080P & 1920x1200
Hard Drives
1x 80GB Intel X25-M G2 SSD : 1x 500GB & 1x 640GB WD Caviar Black(s)
PSU
Corsair 620HX
Case
Cooler Master RC-690
Cooling
Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
Keyboard
Microsoft 500
Mouse
Razer Diamondback 3G
Internet Speed
14 Mb/s
Other Info
1x Koutech 3Gb/s SATA HDD Hot Swap Rack
Hi BFK..How ya doin?

No, I mean I believe it's a prohibited thing to do, according to dmex, I saw him say it in a post a few days ago. :eek: I could be wrong though.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Howdy, so far so good.

I thought that's what you were asking/saying; believe me if anyone knows, it would be dmex.

















Later :shock: Ted
 

My Computer My Computer

Computer Manufacturer/Model Number
* BFK Customs *
OS
W 7 64-bit Ultimate
CPU
Intel Q9550 Yorkfield
Motherboard
ASUS P5Q Pro
Memory
8GB Dominator 8500C5D
Graphics Card(s)
ATI : XFX 5870
Sound Card
Realtek HD Audio 7-1
Monitor(s) Displays
1x 47" LCD HDMI & 3x 26" LCD HDMI
Screen Resolution
1920x1080P & 1920x1200
Hard Drives
1x 80GB Intel X25-M G2 SSD : 1x 500GB & 1x 640GB WD Caviar Black(s)
PSU
Corsair 620HX
Case
Cooler Master RC-690
Cooling
Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
Keyboard
Microsoft 500
Mouse
Razer Diamondback 3G
Internet Speed
14 Mb/s
Other Info
1x Koutech 3Gb/s SATA HDD Hot Swap Rack
Thank you very much for your quick answers.

I have successfully recovered the file, following Ted's and Mr Grim's suggestion on doing a system restore.


Thank very much, once again!
 

My Computer My Computer

OS
Windows 7
Hello again krypnik.

I'm pleased to see you've found a solution that worked for you!

















Later :) Ted
 

My Computer My Computer

Computer Manufacturer/Model Number
* BFK Customs *
OS
W 7 64-bit Ultimate
CPU
Intel Q9550 Yorkfield
Motherboard
ASUS P5Q Pro
Memory
8GB Dominator 8500C5D
Graphics Card(s)
ATI : XFX 5870
Sound Card
Realtek HD Audio 7-1
Monitor(s) Displays
1x 47" LCD HDMI & 3x 26" LCD HDMI
Screen Resolution
1920x1080P & 1920x1200
Hard Drives
1x 80GB Intel X25-M G2 SSD : 1x 500GB & 1x 640GB WD Caviar Black(s)
PSU
Corsair 620HX
Case
Cooler Master RC-690
Cooling
Tuniq Tower 120, 2x 140mm and 3x 120mm case fans
Keyboard
Microsoft 500
Mouse
Razer Diamondback 3G
Internet Speed
14 Mb/s
Other Info
1x Koutech 3Gb/s SATA HDD Hot Swap Rack
Glad you got it back krypnik.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
is this a false postive? i know its been while since this thread has had anything added to the topic, but i just got home and when my computer came back up from idling for about 3 hours i had about 20-25 conhost.exe's running the back ground. and then one by one they disappeared. im running build 7048 64-bit. just was unclear if it was or not.


im probably going to to a clean install within the next few days, so any kind of infection at this point will get erased then.



spook
 

My Computer My Computer

OS
Win 7 x64
conhost.exe (Sober Trojan)

If everybody is so sure this is a False Positive, tell me how you deleted it! It has it's own Administrator rights and Says can only be deleted or changed by "Trusted Installer"! As Administrator, I should be able to delete or change any file I wish!
It claims to be a Microsoft file. Why will Microsoft not come out and say it is?
I wonder how many computers are infected, and when will Conhost suddenly come alive! I do believe this is a Trojan!
 

My Computer My Computer

OS
windows 7
If everybody is so sure this is a False Positive, tell me how you deleted it! It has it's own Administrator rights and Says can only be deleted or changed by "Trusted Installer"! As Administrator, I should be able to delete or change any file I wish!
It claims to be a Microsoft file. Why will Microsoft not come out and say it is?
I wonder how many computers are infected, and when will Conhost suddenly come alive! I do believe this is a Trojan!

Hi john d ross & welcome :)
The whole point is, is that MS don't want you to delete that file as it's needed by the system.
Even with admin privileges, you don't have access/control over a lot of files.
If you really did want to delete it, you'd make sure that you have ownership and full control permissions before doing so (NOT RECOMMENDED).
This might be of interest to you.
What is conhost.exe and Why Is It Running? :: the How-To Geek
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Touchsmart IQ771.uk
OS
Windows 7 Ultimate x64
CPU
AMD Turion(tm) 64 X2 Mobile Technology TL-56
Motherboard
ASUS Pheonix
Memory
3GB Nanya PC2-6400 DDR2-SDRAM SO-DIM (400MHz)
Graphics Card(s)
NVIDIA GeForce Go 7600 256MB GDDR3 SDRAM
Sound Card
High Definition Intergrated NVIDIA MCP51
Monitor(s) Displays
46" Sony Bravia HDTV
Screen Resolution
1600x1200
Hard Drives
1.5TB Samsug
320GB Seagate ST3320820AS - SATA 3Gb/s 8MB
500GB Maxtor Basics STM305003EHD301-RK
Internet Speed
↓6.32 Mb/s ↑0.35 Mb/s ↔26ms
Other Info
BIOS - American Megatrends Inc. 5.07
Ethernet Port - NVIDIA nForce 10/100/1000 Mbps
DVD Drive - TSSTcorp DVDR/RW TS-T632L
conhost sober trojan

icon1.gif
conhost.exe (Sober Trojan)
thanks rsvr85
APPRECIATE YOUR QUICK REPLY. jUST WONDERED ARE THERE ANY OTHER FILES IN THE O.S, WHICH ARE UNDER THE CONTROL OF "' tRUSTED iNSTALLER"' AND WON'T ALLOW EVEN ADMINISTRATOR ACCESS? AND WHY DOES CONHOST.EXE CHANGE TO CMD.EXE AND BACK AGIN, BY ITSELF, AFTER I OPEN THE SYSTEM32 FILES.
REGARDS
 

My Computer My Computer

OS
windows 7
A lot of the files in %windir% & %windir%\system32 are under the control of trusted installer. It's much safer that way ;)
conhost doesn't have a GUI i believe and as such will probably just flash when you try and execute it in Explorer, much the same as ipconfig.exe does.
See the How-To-Geek link above for a full explanation of conhost.exe
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Touchsmart IQ771.uk
OS
Windows 7 Ultimate x64
CPU
AMD Turion(tm) 64 X2 Mobile Technology TL-56
Motherboard
ASUS Pheonix
Memory
3GB Nanya PC2-6400 DDR2-SDRAM SO-DIM (400MHz)
Graphics Card(s)
NVIDIA GeForce Go 7600 256MB GDDR3 SDRAM
Sound Card
High Definition Intergrated NVIDIA MCP51
Monitor(s) Displays
46" Sony Bravia HDTV
Screen Resolution
1600x1200
Hard Drives
1.5TB Samsug
320GB Seagate ST3320820AS - SATA 3Gb/s 8MB
500GB Maxtor Basics STM305003EHD301-RK
Internet Speed
↓6.32 Mb/s ↑0.35 Mb/s ↔26ms
Other Info
BIOS - American Megatrends Inc. 5.07
Ethernet Port - NVIDIA nForce 10/100/1000 Mbps
DVD Drive - TSSTcorp DVDR/RW TS-T632L
conhost sober trojan

One more concern.
My Virus protection provider asked me to Password Protect Archive and send to their investigators. The system will not allow me to Archive and send. Message says Access not allowed! I am not deleting, or changing the file, but access is denied!
Why is Microsoft not speaking about all these concerns?
 

My Computer My Computer

OS
windows 7
What concerns?

As the file is system protected, it won't allow access by anything other that itself. Also this is possible to happen if the file is in use (which conhost.exe probably will be)
Please, unless you are 100% sure it's malicious, do not delete conhost.exe
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Touchsmart IQ771.uk
OS
Windows 7 Ultimate x64
CPU
AMD Turion(tm) 64 X2 Mobile Technology TL-56
Motherboard
ASUS Pheonix
Memory
3GB Nanya PC2-6400 DDR2-SDRAM SO-DIM (400MHz)
Graphics Card(s)
NVIDIA GeForce Go 7600 256MB GDDR3 SDRAM
Sound Card
High Definition Intergrated NVIDIA MCP51
Monitor(s) Displays
46" Sony Bravia HDTV
Screen Resolution
1600x1200
Hard Drives
1.5TB Samsug
320GB Seagate ST3320820AS - SATA 3Gb/s 8MB
500GB Maxtor Basics STM305003EHD301-RK
Internet Speed
↓6.32 Mb/s ↑0.35 Mb/s ↔26ms
Other Info
BIOS - American Megatrends Inc. 5.07
Ethernet Port - NVIDIA nForce 10/100/1000 Mbps
DVD Drive - TSSTcorp DVDR/RW TS-T632L
Back
Top