Close

Results 1 to 10 of 10
  1. #1
    DF VIP Member QfanatiQ's Avatar
    Join Date
    Jan 2004
    Location
    Berkshire
    Posts
    3,944
    Thanks
    241
    Thanked:        131
    Karma Level
    437

    Default Cant remove and NEED to

    Fire up girlies PC to find a whole host of probs. To begin with a windows close box was comming up and giving 60 seconds to save before it rebooted... Got adaware and found laods of stuff, then got AVG and also got rid of some serious stuff. BUT i still cant get rid of these

    C:\windows\system32\WMIPRVSC . exe &
    C:\windows\system32\drivers\SVCHOST . exe

    AVG sees these as virus's but i can delete them, they wont let me, through AVG or through explorer.

    I thought i would boot up in safe mode but the PC does nto give me an option to.

    Any help GREATLY appreciated. Cheers.....Q

  2. #2
    DF VIP Member DaveTheRave's Avatar
    Join Date
    Feb 2004
    Location
    Dundee, United
    Posts
    1,041
    Thanks
    5
    Thanked:        2
    Karma Level
    295

    Default Re: Cant remove and NEED to

    what do you mean it wont give you the option too?

  3. #3
    DF Admin Mr Olympia's Avatar
    Join Date
    Feb 2001
    Location
    England
    Posts
    7,804
    Thanks
    477
    Thanked:        564
    Karma Level
    875

    Default Re: Cant remove and NEED to

    It seems like you have the Blaster worm.

    First off you need to go to Start>Run and type the following:

    shutdown /a

    This should stop the pc rebooting giving you time to download a patch.

    Then you can go to symantec web site and apply a fix.

    http://securityresponse.symantec.com...oval.tool.html.

    Hopefully this will work. Let me know how you get on.

  4. #4
    DF VIP Member QfanatiQ's Avatar
    Join Date
    Jan 2004
    Location
    Berkshire
    Posts
    3,944
    Thanks
    241
    Thanked:        131
    Karma Level
    437

    Default Re: Cant remove and NEED to

    Cheers, i wil try that tonight, got some of the way with AVG but there is still something there so will check that out.

    I thought there was an option to shutdown in safe mode, but forgot about F8

    Cheers.....Q

  5. #5
    DF VIP Member MajorFU's Avatar
    Join Date
    Dec 2000
    Location
    London
    Posts
    3,206
    Thanks
    106
    Thanked:        135
    Karma Level
    442

    Default Re: Cant remove and NEED to

    svchost.exe is not a virus as far as i am aware, its a networking driver or somat

    never heard of WMIPRVSC . exe so it could be bogus

  6. #6
    DF Admin Mr Olympia's Avatar
    Join Date
    Feb 2001
    Location
    England
    Posts
    7,804
    Thanks
    477
    Thanked:        564
    Karma Level
    875

    Default Re: Cant remove and NEED to

    Quote Originally Posted by MajorFU
    svchost.exe is not a virus as far as i am aware, its a networking driver or somat

    never heard of WMIPRVSC . exe so it could be bogus
    Yeah, svchost should be ok. As for WMIPRVSC, if I remember rightly I think it's a trojan or similar. I think that once this file is executed on your pc, it connects itself to an IRC channel and your pc is wide open to people who may nick info from your machine, product keys, personal files etc.

    Before you panic, do a search on the net for any info regarding this. I think I'm right about this file but I could be barking up the wrong tree.

  7. #7
    DF VIP Member Q-Buster's Avatar
    Join Date
    Nov 2000
    Location
    The Land Of Makebelieve
    Posts
    758
    Thanks
    0
    Thanked:        0
    Karma Level
    326

    Default Re: Cant remove and NEED to

    WMIPRVSC . exe seems to be 'malware', created by BKDR_SDBOT.RC.

    Installation and Autostart Techniques

    Upon execut1on, this malware drops a copy of itself as WMIPRVSC.EXE in the Windows system folder.

    It then creates the following autorun registry entries to enable its automatic execut1on at every system startup

    HKEY_CURRENT_USER\Software\Microsoft\Windows\
    CurrentVersion\Run
    Windows Update Process="wmiprvsc.exe"

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\RunServices
    Windows Update Process="wmiprvsc.exe"

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\Run
    Windows Update Process="wmiprvsc.exe"

    HERE

    Q-Buster

  8. #8
    DF VIP Member flipper321's Avatar
    Join Date
    Feb 2003
    Location
    Essex
    Posts
    2,696
    Thanks
    11
    Thanked:        131
    Karma Level
    474

    Default Re: Cant remove and NEED to

    There was an issue with svchost (I believe) as part of the welchia/nichi trojan, although not in that location as far as I am aware.

  9. #9
    DF VIP Member QfanatiQ's Avatar
    Join Date
    Jan 2004
    Location
    Berkshire
    Posts
    3,944
    Thanks
    241
    Thanked:        131
    Karma Level
    437

    Default Re: Cant remove and NEED to

    Cheers for all the help and pointers. Got it all sorted now and all the updates. Nice and stable.

    Cheers.....Q

  10. #10
    ABCMan
    Guest ABCMan's Avatar

    Default Re: Cant remove and NEED to

    ok, svchost can be hijacked there is also a couple of trojans that create false versions of that file in alternate locations

    http://www.liutilities.com/products/...brary/svchost/ (scroll towards the bottom, i've no idea on the quality of the program, but the site give LOADS of details of tasks that various programs use as well as details of almost all windows files, its very usefull for tracking what is what.

    there are detals of the first one and how to remove it here http://www.us.sophos.com/virusinfo/a...32sdbotcb.html

Similar Threads

  1. Anyone know a way to remove vocals from songs?
    By Fett in forum Music Factory
    Replies: 10
    Last Post: 17th July 2003, 07:59 PM
  2. how to remove vocal a song??
    By djdreamer_uk in forum Music Factory
    Replies: 1
    Last Post: 3rd April 2003, 03:28 PM
  3. Replies: 6
    Last Post: 12th November 2002, 08:03 PM
  4. BIG MISTAKE - remove X-ecutor to add MATRIX!
    By kringe in forum Microsoft Consoles
    Replies: 21
    Last Post: 25th October 2002, 01:23 AM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •