svchost.exe virus help

StealthGus

ProCombat's Neighbor
Community Manager
Joined
Jun 8, 2011
Messages
2,633
So as you guessed yes i got the svchost.exe virus my computer will randomly spike to 100% cpu usage blue screen then shut down i have tried everything i know but still nothing I NEED HELP!
 
Step 1) I don't care what anyone here tells you, don't use combofix unless you really trust them and yourself to know what you're doing.

Step 2) To start please try to download and install and run a FULL scan with Malwarebytes Anti-Malware if you have any trouble with this step please let me know
 
I remember this virus, was ugly. Are you sure you've updated your computer completely? IE: Windows Updates?
 
Step 1) I don't care what anyone here tells you, don't use combofix unless you really trust them and yourself to know what you're doing.

Step 2) To start please try to download and install and run a FULL scan with Malwarebytes Anti-Malware if you have any trouble with this step please let me know

Full scans on Malwarebytes are useless. Just do a quick scan, trust me. I studied malware analysis.
 
You should be running malware scans in safemode if you are not already. The obvious reasoning behind this is less drivers and services are loaded and most of the time allows your anti malware software catch and remove any infections that would otherwise be protecting itself from anti malware programs. Another program I would download and run first is RKILL from bleeping computer. This program kills any extra services or programs that would be running even in safemode that shouldn't be and thus you're able to remove persistent malware that insists on running even in safemode.

So the steps to take are:

1. Download RKILL from bleepingcomputer.com on a non infected computer if at all possible.

2. Download Malwarebytes free edition on a non infected computer if possible.

3. Download TDSSKILLER from Kaspersky Labs (free)

4. Transfer these files to your infected computer with usb flash drive (if you downloaded the above files with another computer).

5. Reboot to safe mode by restarting the computer and start pressing F8 when the BIOS or manufacturer splash screen ends. Choose safe mode with networking on the list displayed.

6. Run RKILL (right click run as administrator if using Vista or Win 7)

7. Run TDSSKILLER (right click run as administrator if using Vista or Win 7) remove any infections it finds as this is a rootkit detector.

8. Run Malwarebytes, check for updates and then run a full scan while in safe mode.

9. Remove all infections found.

10. Reboot to normal desktop and see if your issue has been resolved.


Another note to consider is if this problem persists, you will need to turn your system restore off and in the process of doing this deleting all restore points. Some infections will back themselves up in your restore point in case of it's removal, it can continue to harm your computer. Let us know how this turns out please.


Full scans on Malwarebytes are useless. Just do a quick scan, trust me. I studied malware analysis.

It is not useless considering I personally do this for a living and have proven full scans do find additional infections when quick scans have not found all of the infections on a computer. I'm all ears if you would like to prove this otherwise. Until then I'll continue to instruct customers to perform full scans.
 
Last edited:
Ok I think I got rid of it no more boosting to 100% CPU usage so I think we are good hopefully
 
Why not do a full scan anyway? I mean either way it's not like it's hurting anything.
 
Why not do a full scan anyway? I mean either way it's not like it's hurting anything.

Most infections are located within certain locations this means you can eliminate a lot of time by not scanning some locations. This works 9/10 times but there are still extreme cases that a full scan is needed.
 
Most infections are located within certain locations this means you can eliminate a lot of time by not scanning some locations. This works 9/10 times but there are still extreme cases that a full scan is needed.

Exactly, so unless time is an issue a full scan should be used.
 
Why not do a full scan anyway? I mean either way it's not like it's hurting anything.

A full scan can take up to two hours to complete, whereas a quick scan will take about 5 minutes. A full scan will search in some places where malware cannot even reach, so it renders it useless most of the time.

If you want to waste your time scanning the whole drive, go ahead! Be wary that MBAM will take up a huge chunk of CPU mem usage, so you can't play a game efficiently unless you have a very powerful CPU. :p

Exactly, so unless time is an issue a full scan should be used.

Even the creators of MBAM suggest that you perform a quick scan.

Though it offers a full-scan option, Malwarebytes recommends that you perform the quick scan first, as that scan usually finds all of the infections anyway. Depending on your computer, the quick scan can take anywhere from 5 to 20 minutes, whereas the full scan might take 30 to 60 minutes or more.
http://www.pcworld.com/article/243818/how_to_remove_malware_from_your_windows_pc.html
 
Last edited:
90% of my job is virus removal and most of the time we use quick scans only. Unless there is reason to believe that the infection is in some crazy odd place then there no reason to run a full scan, just wasted time.
 

Latest posts

Back
Top