My computer was compromised- virus svchost.exe?

Anonymous
2016-08-30T07:08:19+00:00

Few today my computer strange phenomenon

I'm opening the web page , suddenly shows up table Command Prompt (Admin) and then turn off the ejector

and many other phenomena also itself turned up and turned off the ejector, I do not turn on them up ?

I used UnHacMe, Avira, HitmanPro, Malwarebytes Anti ESET Smart Installer to scan but do not have the virus?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

50 answers

Sort by: Newest
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2016-10-13T14:01:19+00:00

    I use Virustotal scan files svchost,exe ??

    × Cookies are disabled! This site requires cookies to be enabled to work properly

    × Ciphered bundle

    The submitted file is a compressed bundle ciphered with password infected, do you want to display the report for the contained inner file?

    Compressed file Inner file

    SHA256: 438b6ccd84f4dd32d9684ed7d58fd7d1e5a75fe3f3d12ab6c788e6bb0ffad5e7
    File name: svchost.exe
    Detection ratio: 0 / 56
    Analysis date: 2016-10-13 09:44:04 UTC ( 3 hours, 22 minutes ago )

    2

    1

    Probably harmless! There are strong indicators suggesting that this file is safe to use.

    ALYac 20161013
    AVG 20161013
    AVware 20161013
    Ad-Aware 20161013
    AegisLab 20161013
    AhnLab-V3 20161012
    Alibaba 20161013
    Antiy-AVL 20161013
    Arcabit 20161013
    Avast 20161013
    Avira (no cloud) 20161013
    Baidu 20161012
    BitDefender 20161013
    Bkav 20161012
    CAT-QuickHeal 20161013
    CMC 20161013
    ClamAV 20161013
    Comodo 20161013
    CrowdStrike Falcon (ML) 20160725
    Cyren 20161013
    DrWeb 20161013
    ESET-NOD32 20161013
    Emsisoft 20161013
    F-Prot 20161013
    F-Secure 20161013
    Fortinet 20161013
    GData 20161013
    Ikarus 20161013
    Invincea 20160928
    Jiangmin 20161013
    K7AntiVirus 20161013
    K7GW 20161013
    Kaspersky 20161013
    Kingsoft 20161013
    Malwarebytes 20161013
    McAfee 20161013
    McAfee-GW-Edition 20161013
    eScan 20161013
    Microsoft 20161013
    NANO-Antivirus 20161013
    Panda 20161012
    Qihoo-360 20161013
    Rising 20161013
    SUPERAntiSpyware 20161013
    Sophos 20161013
    Symantec 20161013
    Tencent 20161013
    TheHacker 20161011
    TrendMicro 20161013
    TrendMicro-HouseCall 20161013
    VBA32 20161012
    VIPRE 20161013
    ViRobot 20161013
    Yandex 20161011
    Zillya 20161012
    Zoner 20161013
    nProtect 20161013

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-10-13T13:41:40+00:00

    I new reinstall Windows yesterday

    Today I use Hitmanpro scan it out files Suspicious svchost.exe, I do not understand?

    Why is that ?

    [code]

    HitmanPro 3.7.14.280

    www.hitmanpro.com

    Computer name . . . . : DESKTOP-BKLQ5LP

       Windows . . . . . . . : 10.0.0.14393.X64/4

       User name . . . . . . : DESKTOP-BKLQ5LP\May Tinh

       UAC . . . . . . . . . : Enabled

       License . . . . . . . : Free

    Scan date . . . . . . : 2016-10-13 19:57:18

       Scan mode . . . . . . : Quick

       Scan duration . . . . : 8m 40s

       Disk access mode  . . : Direct disk access (SRB)

       Cloud . . . . . . . . : Internet

       Reboot  . . . . . . . : No

    Threats . . . . . . . : 0

       Traces  . . . . . . . : 216

    Objects scanned . . . : 4,336

       Files scanned . . . . : 4,336

       Remnants scanned  . . : 0 files / 0 keys

    Suspicious files ____________________________________________________________

    C:\Windows\system32\svchost.exe

          Size . . . . . . . : 44,496 bytes

          Age  . . . . . . . : 0.4 days (2016-10-13 09:51:48)

          Entropy  . . . . . : 6.0

          SHA-256  . . . . . : 438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7

          Product  . . . . . : Microsoft® Windows® Operating System

          Publisher  . . . . : Microsoft Corporation

          Description  . . . : Host Process for Windows Services

          Version  . . . . . : 10.0.14393.0

          Copyright  . . . . : © Microsoft Corporation. All rights reserved.

          RSA Key Size . . . : 2048

          Service  . . . . . : WpnUserService_4aa0e7

          Process Type . . . : Critical

          LanguageID . . . . : 1033

          Authenticode . . . : Valid

          Running processes  : 8, 84, 300, 836, 908, 1168, 1204, 1488, 1632, 1672, 1784, 2196, 2248, 2268, 3644, 7080

          Fuzzy  . . . . . . : 24.0

             The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

             This program is actively listening for inbound network connections.

             Time indicates that the file appeared recently on this computer.

             The file is in use by one or more active processes.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Starts automatically as a service during system bootup.

             This file's process is marked as system critical.

             The file is protected by Windows File Protection (WFP). This is typical for critical Windows system files.

             Program is code signed with a valid Authenticode certificate.

          Startup

             HKLM\SYSTEM\ControlSet001\Services\CDPUserSvc_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\MessagingService_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\OneSyncSvc_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\PimIndexMaintenanceSvc_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\UnistoreSvc_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\UserDataSvc_4aa0e7\

             HKLM\SYSTEM\ControlSet001\Services\WpnUserService_4aa0e7\

             HKLM\SYSTEM\CurrentControlSet\Services\AJRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\AppIDSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Appinfo\

             HKLM\SYSTEM\CurrentControlSet\Services\AppReadiness\

             HKLM\SYSTEM\CurrentControlSet\Services\AppXSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\AudioEndpointBuilder\

             HKLM\SYSTEM\CurrentControlSet\Services\Audiosrv\

             HKLM\SYSTEM\CurrentControlSet\Services\AxInstSV\

             HKLM\SYSTEM\CurrentControlSet\Services\BDESVC\

             HKLM\SYSTEM\CurrentControlSet\Services\BFE\

             HKLM\SYSTEM\CurrentControlSet\Services\BITS\

             HKLM\SYSTEM\CurrentControlSet\Services\BrokerInfrastructure\

             HKLM\SYSTEM\CurrentControlSet\Services\Browser\

             HKLM\SYSTEM\CurrentControlSet\Services\BthHFSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\bthserv\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\CDPUserSvc_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\CertPropSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\ClipSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\CoreMessagingRegistrar\

             HKLM\SYSTEM\CurrentControlSet\Services\CryptSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DcomLaunch\

             HKLM\SYSTEM\CurrentControlSet\Services\DcpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\defragsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceAssociationService\

             HKLM\SYSTEM\CurrentControlSet\Services\DeviceInstall\

             HKLM\SYSTEM\CurrentControlSet\Services\DevQueryBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\

             HKLM\SYSTEM\CurrentControlSet\Services\DiagTrack\

             HKLM\SYSTEM\CurrentControlSet\Services\DmEnrollmentSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dmwappushservice\

             HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\

             HKLM\SYSTEM\CurrentControlSet\Services\DoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\dot3svc\

             HKLM\SYSTEM\CurrentControlSet\Services\DPS\

             HKLM\SYSTEM\CurrentControlSet\Services\DsmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\DsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EapHost\

             HKLM\SYSTEM\CurrentControlSet\Services\embeddedmode\

             HKLM\SYSTEM\CurrentControlSet\Services\EntAppSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\EventLog\

             HKLM\SYSTEM\CurrentControlSet\Services\EventSystem\

             HKLM\SYSTEM\CurrentControlSet\Services\fdPHost\

             HKLM\SYSTEM\CurrentControlSet\Services\FDResPub\

             HKLM\SYSTEM\CurrentControlSet\Services\fhsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\FontCache\

             HKLM\SYSTEM\CurrentControlSet\Services\FrameServer\

             HKLM\SYSTEM\CurrentControlSet\Services\gpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\hidserv\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupListener\

             HKLM\SYSTEM\CurrentControlSet\Services\HomeGroupProvider\

             HKLM\SYSTEM\CurrentControlSet\Services\HvHost\

             HKLM\SYSTEM\CurrentControlSet\Services\icssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT\

             HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\irmon\

             HKLM\SYSTEM\CurrentControlSet\Services\KtmRm\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\

             HKLM\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\

             HKLM\SYSTEM\CurrentControlSet\Services\lfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\LicenseManager\

             HKLM\SYSTEM\CurrentControlSet\Services\lltdsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\lmhosts\

             HKLM\SYSTEM\CurrentControlSet\Services\LSM\

             HKLM\SYSTEM\CurrentControlSet\Services\MapsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService\

             HKLM\SYSTEM\CurrentControlSet\Services\MessagingService_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\MSiSCSI\

             HKLM\SYSTEM\CurrentControlSet\Services\NcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NcbService\

             HKLM\SYSTEM\CurrentControlSet\Services\NcdAutoSetup\

             HKLM\SYSTEM\CurrentControlSet\Services\Netman\

             HKLM\SYSTEM\CurrentControlSet\Services\netprofm\

             HKLM\SYSTEM\CurrentControlSet\Services\NetSetupSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcCtnrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NgcSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\nsi\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\OneSyncSvc_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\p2pimsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\p2psvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PcaSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PhoneSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\pla\

             HKLM\SYSTEM\CurrentControlSet\Services\PlugPlay\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPAutoReg\

             HKLM\SYSTEM\CurrentControlSet\Services\PNRPsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent\

             HKLM\SYSTEM\CurrentControlSet\Services\Power\

             HKLM\SYSTEM\CurrentControlSet\Services\PrintNotify\

             HKLM\SYSTEM\CurrentControlSet\Services\ProfSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\QWAVE\

             HKLM\SYSTEM\CurrentControlSet\Services\RasAuto\

             HKLM\SYSTEM\CurrentControlSet\Services\RasMan\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry\

             HKLM\SYSTEM\CurrentControlSet\Services\RetailDemo\

             HKLM\SYSTEM\CurrentControlSet\Services\RmSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcEptMapper\

             HKLM\SYSTEM\CurrentControlSet\Services\RpcSs\

             HKLM\SYSTEM\CurrentControlSet\Services\SCardSvr\

             HKLM\SYSTEM\CurrentControlSet\Services\ScDeviceEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\Schedule\

             HKLM\SYSTEM\CurrentControlSet\Services\SCPolicySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SDRSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\seclogon\

             HKLM\SYSTEM\CurrentControlSet\Services\SENS\

             HKLM\SYSTEM\CurrentControlSet\Services\SensorService\

             HKLM\SYSTEM\CurrentControlSet\Services\SensrSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\SessionEnv\

             HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\

             HKLM\SYSTEM\CurrentControlSet\Services\ShellHWDetection\

             HKLM\SYSTEM\CurrentControlSet\Services\shpamsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\smphost\

             HKLM\SYSTEM\CurrentControlSet\Services\SmsRouter\

             HKLM\SYSTEM\CurrentControlSet\Services\SSDPSRV\

             HKLM\SYSTEM\CurrentControlSet\Services\SstpSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StateRepository\

             HKLM\SYSTEM\CurrentControlSet\Services\stisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\StorSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\svsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\swprv\

             HKLM\SYSTEM\CurrentControlSet\Services\SysMain\

             HKLM\SYSTEM\CurrentControlSet\Services\SystemEventsBroker\

             HKLM\SYSTEM\CurrentControlSet\Services\TabletInputService\

             HKLM\SYSTEM\CurrentControlSet\Services\TapiSrv\

             HKLM\SYSTEM\CurrentControlSet\Services\TermService\

             HKLM\SYSTEM\CurrentControlSet\Services\Themes\

             HKLM\SYSTEM\CurrentControlSet\Services\tiledatamodelsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TimeBrokerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\TrkWks\

             HKLM\SYSTEM\CurrentControlSet\Services\tzautoupdate\

             HKLM\SYSTEM\CurrentControlSet\Services\UmRdpService\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UnistoreSvc_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\upnphost\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\UserDataSvc_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\UserManager\

             HKLM\SYSTEM\CurrentControlSet\Services\UsoSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicguestinterface\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicheartbeat\

             HKLM\SYSTEM\CurrentControlSet\Services\vmickvpexchange\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicrdv\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicshutdown\

             HKLM\SYSTEM\CurrentControlSet\Services\vmictimesync\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvmsession\

             HKLM\SYSTEM\CurrentControlSet\Services\vmicvss\

             HKLM\SYSTEM\CurrentControlSet\Services\W32Time\

             HKLM\SYSTEM\CurrentControlSet\Services\WalletService\

             HKLM\SYSTEM\CurrentControlSet\Services\WbioSrvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Wcmsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wcncsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiServiceHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WdiSystemHost\

             HKLM\SYSTEM\CurrentControlSet\Services\WebClient\

             HKLM\SYSTEM\CurrentControlSet\Services\Wecsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WEPHOSTSVC\

             HKLM\SYSTEM\CurrentControlSet\Services\wercplsupport\

             HKLM\SYSTEM\CurrentControlSet\Services\WerSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WiaRpc\

             HKLM\SYSTEM\CurrentControlSet\Services\WinHttpAutoProxySvc\

             HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\

             HKLM\SYSTEM\CurrentControlSet\Services\WinRM\

             HKLM\SYSTEM\CurrentControlSet\Services\wisvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WlanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wlidsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\workfolderssvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WPDBusEnum\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService\

             HKLM\SYSTEM\CurrentControlSet\Services\WpnUserService_e4fd72\

             HKLM\SYSTEM\CurrentControlSet\Services\wscsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\

             HKLM\SYSTEM\CurrentControlSet\Services\wudfsvc\

             HKLM\SYSTEM\CurrentControlSet\Services\WwanSvc\

             HKLM\SYSTEM\CurrentControlSet\Services\XblAuthManager\

             HKLM\SYSTEM\CurrentControlSet\Services\XblGameSave\

             HKLM\SYSTEM\CurrentControlSet\Services\XboxNetApiSvc\

          Network Ports

             0.0.0.0:135 

             0.0.0.0:49665 

             0.0.0.0:49667 

             0.0.0.0:7680 

             192.168.1.79:50617 111.221.29.69:443

             192.168.1.79:50621 111.221.29.82:443

             192.168.1.79:50624 192.229.237.101:443

             192.168.1.79:50625 111.221.29.254:443

    [/code]

    Was this answer helpful?

    0 comments No comments
  4. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2016-10-13T12:51:47+00:00

    Certain embedded files that are part of legitimate programs and specialized fix tools (like AdwCleaner), may at times be detected by some anti-virus and anti-malware scanners as suspicious, a Risk Tool, Hacking Tool, Potentially Unwanted Program, a possible threat or even Malware (virus/trojan) when that is not the case. This occurs for a variety of reasons to include the tool's compiler, the files it uses, whether files are compressed, packed, or obfuscated to protect code, what behavior (routines, scripts, etc) it performs, any registry strings it may contain and the type of security engine that was used during the scan. Other legitimate files which may be encrypted or password protected in order to conceal itself so they do not allow access for scanning often trigger alerts by anti-virus software.

    When flagged by an anti-virus or security scanner, it's because the program includes features, behavior or files that appear suspicious or which can potentially be used for malicious purposes. Compressed and packed files in particular are often flagged as suspicious by security software because they have difficulty reading what is inside them. These detections do not necessarily mean the file is malicious or a bad program. It means it has the potential for being misused by others or that it was simply detected as suspicious or a threat due to the security program's heuristic analysis engine which provides the ability to detect possible new variants of malware. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them. In these cases the detection is a "false positive" and can be ignored.

    Most of the well known specialized tools we use against malware are written by experts/Security Colleagues at various security forums like Bleeping Computer, TechSupport, GeeksToGo, Emsisoft and other similar sites so they can be trusted...this includes any program hosted by BC for download. Unfortunately, many of these tools are falsely detected by various anti-virus programs from time to time for the reasons noted above. This in turn sometimes results in an inaccurate site rating/warning of potentially dangerous software when that is not the case.

    The problem is really with the anti-virus vendors who keep targeting these embedded files and NOT with the tools themselves. We can inform the developers but they have encountered this issue many times before and in most cases there isn't much they can do about it. Once the detection is reported to the anti-virus vendor, they are usually quick to fix it by releasing an updated definition database.

    Either have your anti-virus ignore the detection or temporarily disable it until you download and run the tool.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-10-13T11:51:08+00:00

    You're welcome, Loan74.

    Two things I want to mention:

    1)

    AdwCleaner is not an Anti-Virus product but only a Anti-Malware product.

    You might want to read: Supplementing your Anti-Virus Program with Anti-Malware Tools

    All of the products mentioned there, are safe to use.

    2)

    Your Chrome browser is outdated. You might want to update to Version 54.0.2840.59

    Have a good day :)

    Was this answer helpful?

    0 comments No comments