Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 01-16-2008, 02:10 PM   #11 (permalink)
Redmo0n's Avatar
 
Techalicious

Join Date: Aug 2007

Location: Perth, Australia

Posts: 1,573

Redmo0n is on a distinguished road

Send a message via MSN to Redmo0n
Default Re: Svchost.exe?

Quote:
wasn't bad as I thought
I'm still waiting for you to find a really infected log for me

Please message me if you do, i would love to read it
__________________
Back to stay?
Redmo0n is offline  
Old 01-16-2008, 02:23 PM   #12 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,120

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Svchost.exe?

Find one for you?
__________________
Osiris is online now  
Old 01-16-2008, 03:14 PM   #13 (permalink)
Redmo0n's Avatar
 
Techalicious

Join Date: Aug 2007

Location: Perth, Australia

Posts: 1,573

Redmo0n is on a distinguished road

Send a message via MSN to Redmo0n
Default Re: Svchost.exe?

Ages ago i asked what was the most infected log you have seen and could you find it for me.

I still expect you to find me one
__________________
Back to stay?
Redmo0n is offline  
Old 01-16-2008, 03:22 PM   #14 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,120

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Svchost.exe?

Oh, well I will let you know when I come across one
__________________
Osiris is online now  
Old 01-16-2008, 07:47 PM   #15 (permalink)
 
Newb Techie

Join Date: May 2007

Posts: 19

StriderZ is on a distinguished road

Default Re: Svchost.exe?

Hi,

i tried the delete file on reboot, but it doesn't work..
i downloaded filemon and put in SVCHOST.EXE..

and i enter the D:\ drive and it shows up like D:\WINDOWS\MDM.exe
C:\RavMon.exe D:\RavMon.exe D:\AutoRun.inf C:\AutoRun.inf and D:\WINDOWS\SVCHOST.ini.

and i think i know how i got this..yesterday my friend came over with his usb..and i took something out of the usb, my friend has this also.
StriderZ is offline  
Old 01-16-2008, 08:04 PM   #16 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,120

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Svchost.exe?

Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion
\ Run\SVCHOST: “C:\WINDOWS\MDM.EXE”

Do you have that? If so, delete it, and then reboot.
__________________
Osiris is online now  
Old 01-24-2008, 10:31 PM   #17 (permalink)
 
Newb Techie

Join Date: May 2007

Posts: 19

StriderZ is on a distinguished road

Default Re: Svchost.exe?

Hi,

sorry for the late reply..anyway, i did that but it still comes up..every time i go to any drives.

i then did some more searching with filemon to see what happens, and theres a file called "RavMon.exe" that is in both of my drives(C: D, everytime i open C: or D:, it will execute RavMon.exe..i used HiJackThis to change the SVCHOST.EXE to NOT read-only so i can delete it with AUTOIT(www.autoitscript.com), but RavMon.exe makes a new SVCHOST.EXE everytime i open up C: or D:, so then i used AVG to delete RavMon.exe in the D: drive, but then i can't open my D: drive? it will say, "What program would you like to open D: with", but when i restore RavMon.exe to the D: drive it can open again..same thing happens with C:...
StriderZ is offline  
Old 01-25-2008, 12:37 AM   #18 (permalink)
Redmo0n's Avatar
 
Techalicious

Join Date: Aug 2007

Location: Perth, Australia

Posts: 1,573

Redmo0n is on a distinguished road

Send a message via MSN to Redmo0n
Default Re: Svchost.exe?

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Run combo fix and post a new log
__________________
Back to stay?
Redmo0n is offline  
Old 01-25-2008, 06:32 AM   #19 (permalink)
 
Newb Techie

Join Date: May 2007

Posts: 19

StriderZ is on a distinguished road

Default Re: Svchost.exe?

Hi,

thank you! that got rid of it ..thanks all who helped.

:happy:
StriderZ is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
svchost.exe takes up 100% of CPU on start up. johnc123 Windows Operating Systems and Software 29 06-04-2007 09:20 PM
CPU Usage And Crashing, svchost.exe sucking up CPU Usage Bahamut Other Computer HW Topics 10 05-30-2007 06:01 PM
Photoshop Cs3 installation problems mssssee2 Windows Operating Systems and Software 5 05-30-2007 03:22 AM
svchost.exe virus mlucool Virus - Spyware Protection / Detection 12 05-24-2007 07:09 PM
svchost.exe causing all kinds of problems. Disillusion Windows Operating Systems and Software 6 05-24-2007 03:11 AM