Active Topics Active Topics  Display List of Forum Members Memberlist  Invert Forum Background Colours Invert Colours  Search The Forum Search  Help Help  Register Register  Login Login
Sponsored by Beatnik Games
Hardware / Software Bits & Bobs
 |SFH| Sent From Hell :: Community Forums : Hardware / Software Bits & Bobs
Subject Topic: Unknown Publisher Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 12 April 2010 at 6:33pm | IP Logged Quote Mash-Tin_UK

Okay so i tried this link my mate sent us, it was to do with Xbox Microsoft points, i shudda known better nothing from Microsoft is free, But yer, numpty i am, decided to download a generator, then realised i shouldnt have.

Now everytime on start up, this keeps popping up...


And its starting to piss me off, By the looks of it iv downloaded some Malware or something? The annoying thing is, I can see half of its path up to \Application Data..

Is there anything i can do to stop it ?
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Darthbaz
Site Admin
Site Admin
Avatar
GW2 Leader

Joined: 17 January 2007
Location: United Kingdom
Posts: 2915
Posted: 12 April 2010 at 6:51pm | IP Logged Quote Darthbaz

Is this any help ? clicky

__________________
Back to Top View Darthbaz's Profile Search for other posts by Darthbaz Visit Darthbaz's Homepage Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 14 April 2010 at 6:19pm | IP Logged Quote Mash-Tin_UK

Right had a look at that, il save that option till last, that seems all to complicated! basically i want to know how to find the rest of the path from Jay\Application Data\.. Onwards so i can see actually where its booting from, but it never did it before i downloaded sh*tty generator so thats saying to me iv made abit of a cock up downloading something like that. Any other ideas?
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Bartaggio
Senior Community Member
Senior Community Member

Guild Member

Joined: 16 Febuary 2007
Location: Netherlands
Posts: 391
Posted: 14 April 2010 at 8:28pm | IP Logged Quote Bartaggio

You could like do a search for svchost.exe in Application Data. That would probably find it
Back to Top View Bartaggio's Profile Search for other posts by Bartaggio Send Private Message Add to Buddy List
 
Harv
Honourary Member
Honourary Member
Avatar
TF2 GOD

Joined: 24 January 2003
Location: United Kingdom
Posts: 2716
Posted: 14 April 2010 at 11:54pm | IP Logged Quote Harv

I 100% agree with Darth on this one.

The link he provided you seems to be the standard process for getting rid of the virus you seem to have installed on your machine.

I know you dismissed it as being complicated and want other ideas, but yes - viruses are often complicated and require complicated measures to get rid of them. If it were easy to get rid of viruses then the kids wouldn't bother making them, and anti-virus companies wouldn't make so much money making software to counter-act the effects.

To be honest though - there ARE other options that i could go through with you to get rid of this, but trust me - they may be FAR more complicated than what that link suggests above. One would be to download and install a virus checker (AVG is good) - but my suspision is that it may not be possible to complete this due to the virus preventing you from doing so.

My suggestion is - print out the page that Darth has linked for you and follow it word for word. If there is anything that doesn't go to plan or is not what you expect, come back to me and I will help you as much as i can.

Edited by Harv on 15 April 2010 at 12:06am
Back to Top View Harv's Profile Search for other posts by Harv Send Private Message Add to Buddy List
 
yuriclaes
Clan Member
Clan Member
Avatar
Beer Swigger

Joined: 30 August 2008
Location: Belgium
Posts: 733
Posted: 15 April 2010 at 11:56am | IP Logged Quote yuriclaes

U could always format ur PC and reinstall everything, that isnt complicated at all :p

__________________
Back to Top View yuriclaes's Profile Search for other posts by yuriclaes Visit yuriclaes's Homepage Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 15 April 2010 at 5:41pm | IP Logged Quote Mash-Tin_UK

Would doin a system restore do anything? Im not sure if its a virus, but im starting to think it is, luckily it asks to run it everytime on start up so i just cancel it
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Cock with a soc
Honourary Member
Honourary Member
Avatar

Joined: 05 December 2004
Location: United Kingdom
Posts: 957
Posted: 15 April 2010 at 9:20pm | IP Logged Quote Cock with a soc

Come on Mash its only 8 steps its not exactly an essay on Volcanoes dont do a restore it probably wont fix it.
Back to Top View Cock with a soc's Profile Search for other posts by Cock with a soc Send Private Message Add to Buddy List
 
woodster
Clan Member
Clan Member
Avatar
Guild Officer

Joined: 25 January 2009
Location: United Kingdom
Posts: 334
Posted: 15 April 2010 at 11:14pm | IP Logged Quote woodster

open ur start menu ,use the "run " function ,type "msconfig" then click startup tab . c if its listed there and unclick ,it will also show location . it might not even b a virus i got a couple programs that need to re run,but not usually on startup mind . if once unclicked it dosnt restart i wouldnt worry too much about it ,but if it re appears chances r u have got a virus :P

__________________
Back to Top View woodster's Profile Search for other posts by woodster Send Private Message Add to Buddy List
 
woodster
Clan Member
Clan Member
Avatar
Guild Officer

Joined: 25 January 2009
Location: United Kingdom
Posts: 334
Posted: 15 April 2010 at 11:16pm | IP Logged Quote woodster

hmm and just lookin at the path ,have u updated Java ? looks a java program ???

 



__________________
Back to Top View woodster's Profile Search for other posts by woodster Send Private Message Add to Buddy List
 
woodster
Clan Member
Clan Member
Avatar
Guild Officer

Joined: 25 January 2009
Location: United Kingdom
Posts: 334
Posted: 15 April 2010 at 11:21pm | IP Logged Quote woodster

and a quick browse found this bit of info

The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load. Multiple instances of Svchost.exe can run at the same time. Each Svchost.exe session can contain a grouping of services. Therefore, separate services can run, depending on how and where Svchost.exe is started. This grouping of services allows for better control and easier debugging.



__________________
Back to Top View woodster's Profile Search for other posts by woodster Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 17 April 2010 at 6:58pm | IP Logged Quote Mash-Tin_UK

Cock with a soc wrote:
Come on Mash its only 8 steps its not exactly an essay on Volcanoes dont do a restore it probably wont fix it.


I know that, i dnt have time to sit at the comp and do that atm hence why i wanted it as a last resort

Will look into it 2moro when i have a day off! cheers lads

Edited by Mash-Tin_UK on 17 April 2010 at 6:59pm
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 18 April 2010 at 1:56pm | IP Logged Quote Mash-Tin_UK

Well i ran Threat Expert and thats found nothing, and i ran the programme on start up to see what it does, Doesnt look like any unusual tasks in the process window!



Edited by Mash-Tin_UK on 18 April 2010 at 2:39pm
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
woodster
Clan Member
Clan Member
Avatar
Guild Officer

Joined: 25 January 2009
Location: United Kingdom
Posts: 334
Posted: 18 April 2010 at 3:27pm | IP Logged Quote woodster

u runnin a 32 or 64bit system ?

__________________
Back to Top View woodster's Profile Search for other posts by woodster Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 18 April 2010 at 5:07pm | IP Logged Quote Mash-Tin_UK

32bit afaik
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Darthbaz
Site Admin
Site Admin
Avatar
GW2 Leader

Joined: 17 January 2007
Location: United Kingdom
Posts: 2915
Posted: 18 April 2010 at 5:31pm | IP Logged Quote Darthbaz

Have you tried running HijackThis? see if that throws up anything

__________________
Back to Top View Darthbaz's Profile Search for other posts by Darthbaz Visit Darthbaz's Homepage Send Private Message Add to Buddy List
 
Nhumrod
Site Admin
Site Admin
Avatar
Clan Leader & GM

Joined: 09 September 2002
Location: Scotland
Posts: 13897
Posted: 03 May 2010 at 1:23am | IP Logged Quote Nhumrod

svchost.exe generally relates to system processes initiated by Windows and you can drill down to their file handles using process explorer, shich should indicate if theyre dodgy or not (though the fact theyre unsigned sounds v dodgy to me):

http://www.microsoft.com/technet/sysinternals/utilities/processexplorer.html

For future, onjly ever run anything dodgy like keygens etc, in a Sandbox:

http://www.sandboxie.com/

__________________
There is no IRL, there's just AFK.
Back to Top View Nhumrod's Profile Search for other posts by Nhumrod Visit Nhumrod's Homepage Send Private Message Add to Buddy List
 
Mash-Tin_UK
Clan Member
Clan Member
Avatar

Joined: 21 September 2005
Location: United Kingdom
Posts: 1936
Posted: 03 May 2010 at 10:26am | IP Logged Quote Mash-Tin_UK

Cheers D and everyone else!

This is the path that its at, does it look dodgy?

C:\Documents and Settings\Jay\Application Data\Microsoft\svchost.exe


Oh and on the process APP it doesnt show as a Generic Host Process for Win32 Services... Its just a Blank line

Edited by Mash-Tin_UK on 03 May 2010 at 10:27am
Back to Top View Mash-Tin_UK's Profile Search for other posts by Mash-Tin_UK Send Private Message Add to Buddy List
 
Nhumrod
Site Admin
Site Admin
Avatar
Clan Leader & GM

Joined: 09 September 2002
Location: Scotland
Posts: 13897
Posted: 03 May 2010 at 9:45pm | IP Logged Quote Nhumrod

Yes - v dodgy. Theres only ine svchost.exe on your machin that is safe and its under C:\WINDOWS\system32

__________________
There is no IRL, there's just AFK.
Back to Top View Nhumrod's Profile Search for other posts by Nhumrod Visit Nhumrod's Homepage Send Private Message Add to Buddy List
 
Lafey
Guest
Guest
Avatar
Now Pirate.Tris

Joined: 29 December 2007
Location: United Kingdom
Posts: 0
Posted: 08 May 2010 at 5:55am | IP Logged Quote Lafey

mashy, you're a nub!
love youuuuuu!
Back to Top View Lafey's Profile Search for other posts by Lafey Send Private Message Add to Buddy List
 

Page of 2
  Post ReplyPost New Topic
Printable version Printable version

Forum Jump
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot delete your posts in this forum
You cannot edit your posts in this forum
You cannot create polls in this forum
You cannot vote in polls in this forum



This page was generated in 1.1108 seconds.

Sponsored by Beatnik Games