Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
SVCHOST *32 instance has strong Hijack/Virus behind it
Message
<blockquote data-quote="Marker" data-source="post: 715690" data-attributes="member: 70546"><p>Hi there, </p><p></p><p>My problem is an svchost *32 file that has a strong hijack behind it, kicks in about 9 minutes after starting the pc. It kills every search for, or launch of antivirus software like adwcleaner / FRST.exe / Farbar and so on, it doesn't kill just any antivirus program just the ones that can do damage to the virus I guess. I think it's new virus because can't find any info that sounds just like mine except here on this site. </p><p><a href="https://malwaretips.com/threads/svchost-exe-32-issue.80026/" target="_blank">SOLVED - svchost.exe *32 Issue</a></p><p></p><p>My time window is small, 9 minutes before it kicks in and then it seems to become more active when I am active trying to locate and destroy. Very responsive like there is a person responding to what I do except that it's instant response. Cleverly made anyway..</p><p></p><p>How I got it.... totally my own doing, I tried to reactivate a copy of Word with the help of KMSpico. Umpf, stupid.</p><p>The one I think is the culprit is what I downloaded from:</p><p><a href="https://www.sadeempc.com/kmspico/" target="_blank">KMSpico 10.2.0 Final + Portable (Office and Windows 10 Activator) | SadeemPC</a></p><p>After executing the downloaded file a notepad file was visible full of code.</p><p></p><p>I think that was the code I am fighting now, but not getting anywhere :</p><p>svchost*32 can't be terminated or the OS terminates, there are no services connected to that instance of svchost, it runs under "user", most of the time that I have been working on this there are 2 instances of the svchost*32 and 1 of them is taking up 50% of the cpu. If I shut down windows I get a blue screen.</p><p>That's about it.</p><p>I will attach the requested FRST.txt and Addition.txt BUT they are from before the 9 minutes mark when the virus kicks in. After that time window FRST will not run in any way.</p><p></p><p>Please advise!</p><p></p><p>Thank you,</p><p></p><p>Mark</p></blockquote><p></p>
[QUOTE="Marker, post: 715690, member: 70546"] Hi there, My problem is an svchost *32 file that has a strong hijack behind it, kicks in about 9 minutes after starting the pc. It kills every search for, or launch of antivirus software like adwcleaner / FRST.exe / Farbar and so on, it doesn't kill just any antivirus program just the ones that can do damage to the virus I guess. I think it's new virus because can't find any info that sounds just like mine except here on this site. [URL="https://malwaretips.com/threads/svchost-exe-32-issue.80026/"]SOLVED - svchost.exe *32 Issue[/URL] My time window is small, 9 minutes before it kicks in and then it seems to become more active when I am active trying to locate and destroy. Very responsive like there is a person responding to what I do except that it's instant response. Cleverly made anyway.. How I got it.... totally my own doing, I tried to reactivate a copy of Word with the help of KMSpico. Umpf, stupid. The one I think is the culprit is what I downloaded from: [URL="https://www.sadeempc.com/kmspico/"]KMSpico 10.2.0 Final + Portable (Office and Windows 10 Activator) | SadeemPC[/URL] After executing the downloaded file a notepad file was visible full of code. I think that was the code I am fighting now, but not getting anywhere : svchost*32 can't be terminated or the OS terminates, there are no services connected to that instance of svchost, it runs under "user", most of the time that I have been working on this there are 2 instances of the svchost*32 and 1 of them is taking up 50% of the cpu. If I shut down windows I get a blue screen. That's about it. I will attach the requested FRST.txt and Addition.txt BUT they are from before the 9 minutes mark when the virus kicks in. After that time window FRST will not run in any way. Please advise! Thank you, Mark [/QUOTE]
Insert quotes…
Verification
Post reply
Top