My computer was compromised- virus svchost.exe?

Anonymous
2016-08-30T07:08:19+00:00

Few today my computer strange phenomenon

I'm opening the web page , suddenly shows up table Command Prompt (Admin) and then turn off the ejector

and many other phenomena also itself turned up and turned off the ejector, I do not turn on them up ?

I used UnHacMe, Avira, HitmanPro, Malwarebytes Anti ESET Smart Installer to scan but do not have the virus?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

50 answers

Sort by: Oldest
  1. Anonymous
    2016-09-02T05:17:56+00:00

    A few days ago suddenly table C: \ WINDOWS \ system32 \ cmd.exe self open up then turn off the ejector, this phenomenon has occurred 3 times 

    I use HitmanPro scan it out suspicious files, I yes should  delete it no?

    Suspicious files ____________________________________________________________

    C:\WINDOWS\system32\svchost.exe

          Size . . . . . . . : 44,496 bytes

          Age  . . . . . . . : 26.1 days (2016-08-07 06:56:07)

          Entropy  . . . . . : 6.0

          SHA-256  . . . . . : 438B6CCD84F4DD32D9684ED7D58FD7D1E5A75FE3F3D12AB6C788E6BB0FFAD5E7

          Product  . . . . . : Microsoft® Windows® Operating System

          Publisher  . . . . : Microsoft Corporation

          Description  . . . : Host Process for Windows Services

          Version  . . . . . : 10.0.14393.0

          Copyright  . . . . : © Microsoft Corporation. All rights reserved.

          RSA Key Size . . . : 2048

          Service  . . . . . : WpnUserService_49e153

          Process Type . . . : Critical

          LanguageID . . . . : 1033

          Authenticode . . . : Valid

          Running processes  : 8, 388, 856, 908, 924, 988, 1096, 1512, 1660, 1756, 1864, 1880, 2396, 2480, 2944, 3644, 8104

          Fuzzy  . . . . . . : 22.0

             The file is completely hidden from view and most antivirus products. It may belong to a rootkit.

             This program is actively listening for inbound network connections.

             The file is in use by one or more active processes.

             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.

             Starts automatically as a service during system bootup.

             This file's process is marked as system critical.

             The file is protected by Windows File Protection (WFP). This is typical for critical Windows system files.

             Program is code signed with a valid Authenticode certificate.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-09-14T13:31:53+00:00

    Hi,

    C:\WINDOWS\system32\svchost.exe is a system file in Windows. Deleting this file will cause a problem with your PC.

    For us to better assist you with your concern, we need the following information:

    • Which browser are you using to access websites?
    • Have you tried to access a webpage using another browser and check if the same issue occurs?
    • Have you done any changes on your devices prior to this issue?

    We'll wait for your response.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2016-09-14T21:54:07+00:00

    [withdrawn]

    Was this answer helpful?

    0 comments No comments
  4. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  5. Anonymous
    2016-09-23T03:48:40+00:00

    Hey dude did you find a way to fix it because right now i have the exact samething.

    Was this answer helpful?

    0 comments No comments