Windows 10 svchost virus

Page 2 of 4 FirstFirst 1234 LastLast

  1. Posts : 579
    Windows 10 Home
       #11

    victor122,

    The hosts file is OK.

    Let's do the following:

    Download Zemana AntiMalware:
    Zemana AntiMalware Download
    Save to the Desktop.

    Double-click on the file Zemana.AntiMalware.Setup.exe to install.

    When the program starts you are presented with a Setup screen, click: Next
    Follow the prompts to install.

    Once Zemana AntiMalware starts, click: Scan

    When finished, it displays a list of all the malware found. Click on Next to remove any malicious files from your computer.

    A reboot may be required to remove malware.

    When done, click the Graph icon (far upper right), highlight the applicable log file, and click: Open Report

    Please post the notepad text report for review.
      My Computer


  2. Posts : 15
    Windows 10
    Thread Starter
       #12

    cottonball said:
    victor122,

    The hosts file is OK.

    Let's do the following:

    Download Zemana AntiMalware:
    Zemana AntiMalware Download
    Save to the Desktop.

    Double-click on the file Zemana.AntiMalware.Setup.exe to install.

    When the program starts you are presented with a Setup screen, click: Next
    Follow the prompts to install.

    Once Zemana AntiMalware starts, click: Scan

    When finished, it displays a list of all the malware found. Click on Next to remove any malicious files from your computer.

    A reboot may be required to remove malware.

    When done, click the Graph icon (far upper right), highlight the applicable log file, and click: Open Report

    Please post the notepad text report for review.
    That didn't help but thanks. The trojan seems to be operating from a different program/file now called tor. Happened after i blocked its IP.
    Windows 10 svchost virus-2017-01-22.png
      My Computer


  3. Posts : 579
    Windows 10 Home
       #13

    victor122,

    Please use the Farbar Recovery Scan Tool Download
    Save FRST to your Desktop.

    [Note: You need to run the version compatible with your system: 32 bit or 64 bit]


    Double-click FRST to run it.
    When the tool opens click Yes to the disclaimer.

    Next, press the Scan button.


    When done, the tool makes a log (FRST.txt) on the Desktop.
    The first time the tool is run, it makes another log: (Addition.txt).

    Please provide the results of both reports in your reply. (Attach if you can, if not, then post.)
      My Computer


  4. Posts : 15
    Windows 10
    Thread Starter
       #14

    FRST.txtAddition.txt
    Here are both txt files
      My Computer


  5. Posts : 579
    Windows 10 Home
       #15

    victor122,

    Thanks for the reports.


    Please try the following:

    Press the Windows and R keys at the same time. This opens the Run box.
    Type Notepad and click OK.
    Next, please copy the entire contents inside the code box below to Notepad.

    Code:
    Start
    CreateRestorePoint:
    EmptyTemp:
    CloseProcesses:
    
    GroupPolicy: Restriction - Windows Defender <======= ATTENTION
    C:\Users\Admin\AppData\Roaming\{59408139-9EFE-349B-1691-101637D4F461}
    C:\Users\Admin\AppData\Roaming\tor.exe
    Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File
    S1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [X]
    Shortcut: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G?ogl? ?hr?me.lnk -> C:\Users\Admin\AppData\Roaming\Browsers\exe.emorhc.bat (No File) 
    Task: {6C4DAD07-8BDC-4C35-A0ED-C91CBAE0BC26} - System32\Tasks\{034BCED7-1B5D-90E9-5A06-A9A295CA4F99} => C:\Users\Admin\AppData\Roaming\{59408139-9EFE-349B-1691-101637D4F461}\aitdgvten.exe [2017-01-03] (TechSmith Corporation) 
    Task: {CD6DF866-8AC9-4D6C-A904-9975E75B6872} - System32\Tasks\Microsoft\Windows\SystemRestore\FreeVPN => C:\Users\Admin\AppData\Roaming\FreeVPN\FreeVPN.exe
    
    Reboot:
    End
    Save the file as fixlist.txt in the same folder where the FRST is running from. It appears to be in the Downloads folder (Running from C:\Users\Admin\Downloads) vs. the Desktop. They both need to be in the same place, preferably the Desktop.



    Next, run FRST and click Fix only once, and wait.


    The tool creates a log: (Fixlog.txt)

    Please attach it to your reply.
    Last edited by cottonball; 23 Jan 2017 at 18:04.
      My Computer


  6. Posts : 42,961
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #16

    FYI: QQ is a Chinese chat program - I've used it myself quite extensively.
      My Computers


  7. Posts : 579
    Windows 10 Home
       #17

    @dalchina,


    When there is an [X] at the end of a listed service, that indicates that FRST could not find the files associated with the particular Service or Driver and has listed the ImagePath as it is in the Registry.
      My Computer


  8. Posts : 579
    Windows 10 Home
       #18

    @victor122,

    Please note, post number 15 was modified.
      My Computer


  9. Posts : 15
    Windows 10
    Thread Starter
       #19

    cottonball said:
    victor122,

    Thanks for the reports.


    Please try the following:

    Press the Windows and R keys at the same time. This opens the Run box.
    Type Notepad and click OK.
    Next, please copy the entire contents inside the code box below to Notepad.

    Code:
    Start
    CreateRestorePoint:
    EmptyTemp:
    CloseProcesses:
    
    GroupPolicy: Restriction - Windows Defender <======= ATTENTION
    C:\Users\Admin\AppData\Roaming\{59408139-9EFE-349B-1691-101637D4F461}
    C:\Users\Admin\AppData\Roaming\tor.exe
    Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File
    S1 SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [X]
    Shortcut: C:\Users\Admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\G?ogl? ?hr?me.lnk -> C:\Users\Admin\AppData\Roaming\Browsers\exe.emorhc.bat (No File) 
    Task: {6C4DAD07-8BDC-4C35-A0ED-C91CBAE0BC26} - System32\Tasks\{034BCED7-1B5D-90E9-5A06-A9A295CA4F99} => C:\Users\Admin\AppData\Roaming\{59408139-9EFE-349B-1691-101637D4F461}\aitdgvten.exe [2017-01-03] (TechSmith Corporation) 
    Task: {CD6DF866-8AC9-4D6C-A904-9975E75B6872} - System32\Tasks\Microsoft\Windows\SystemRestore\FreeVPN => C:\Users\Admin\AppData\Roaming\FreeVPN\FreeVPN.exe
    
    Reboot:
    End
    Save the file as fixlist.txt in the same folder where the FRST is running from. It appears to be in the Downloads folder (Running from C:\Users\Admin\Downloads) vs. the Desktop. They both need to be in the same place, preferably the Desktop.



    Next, run FRST and click Fix only once, and wait.


    The tool creates a log: (Fixlog.txt)

    Please attach it to your reply.
    Here is the logFixlog.txt
      My Computer


  10. Posts : 579
    Windows 10 Home
       #20

    victor122,

    Please update, any progress?
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 11:33.
Find Us




Windows 10 Forums