MeowCat Posted July 17, 2011 ID:454851 Share Posted July 17, 2011 So I was looking at my startup programs on msconfig looking to see if I could turn some off to make my computer faster, and one of the programs was conhost.exe. I looked on the internet, and according to this site (http://www.bleepingc....exe-26261.html) as well as others, it's a malware. If it's located in system32, then it's a legitimate file, however, the malware version disguises itself as the legit one if it's located in appdata (which mine is).Anyways, I've run Malwarebytes (full scan) and as well Microsoft Security Essentials...and nothing has come up. I also tried looking for the file according to it's location path, but I can't find it (I've made all the hidden files show).Does anyone have any info on this? Am I just being insane in thinking the conhost is something bad? Any help is appreciated.Thank you. Link to post Share on other sites More sharing options...
Staff screen317 Posted July 20, 2011 Staff ID:455993 Share Posted July 20, 2011 Hi and welcome to Malwarebytes.Please update MBAM, run a Quick Scan, and post its log.Next, download DDS by sUBs and save it to your Desktop.Double-click on the DDS icon and let the scan run. When it has run two logs will be produced, please post only DDS.txt directly into your reply. Link to post Share on other sites More sharing options...
MeowCat Posted July 22, 2011 Author ID:457192 Share Posted July 22, 2011 .DDS (Ver_11-05-19.01) - NTFSx86 Internet Explorer: 7.0.6001.18000Run by Kevin at 13:22:29 on 2011-07-22Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.1978.833 [GMT -4:00].AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k rpcssc:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\SLsvc.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\system32\WLANExt.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Windows\system32\svchost.exe -k hpdevmgmtC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Windows\system32\svchost.exe -k imgsvcC:\Windows\System32\svchost.exe -k WerSvcGroupC:\Windows\system32\SearchIndexer.exeC:\Windows\system32\WUDFHost.exeC:\Windows\system32\DRIVERS\xaudio.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\system32\taskeng.exeC:\Windows\Explorer.EXEC:\Windows\system32\igfxsrvc.exec:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Microsoft Security Client\msseces.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exeC:\Windows\System32\mobsync.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\system32\conime.exeC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Internet Explorer\ieuser.exeC:\Windows\system32\DllHost.exeC:\Windows\system32\DllHost.exeC:\Users\Kevin\Desktop\dds.scrC:\Windows\system32\WSCRIPT.exeC:\Windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uStart Page = hxxp://ca.yahoo.com/uInternet Settings,ProxyOverride = <local>uInternet Settings,ProxyServer = http=127.0.0.1:52424BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dllBHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dllBHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No FileBHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dllBHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dlluRun: [sidebar] c:\program files\windows sidebar\sidebar.exe /autoRunuRun: [AdobeBridge] uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exemRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exemRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /StartmRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"mRun: [igfxTray] c:\windows\system32\igfxtray.exemRun: [HotKeysCmds] c:\windows\system32\hkcmd.exemRun: [Persistence] c:\windows\system32\igfxpers.exemRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkeymPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htmIE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htmIE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htmIE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exeIE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll/206IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLLIE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dllIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dllDPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cabDPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabDPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cabDPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabNotify: igfxcui - igfxdev.dll.================= FIREFOX ===================.FF - ProfilePath - c:\users\kevin\appdata\roaming\mozilla\firefox\profiles\b0f0x3wn.default\FF - prefs.js: browser.startup.homepage - hxxp://ca.yahoo.com/FF - prefs.js: network.proxy.http - 127.0.0.1FF - prefs.js: network.proxy.http_port - 52424FF - prefs.js: network.proxy.type - 0FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dllFF - plugin: c:\program files\veetle\player\npvlc.dllFF - plugin: c:\program files\veetle\plugins\npVeetle.dll.============= SERVICES / DRIVERS ===============.R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]R1 MpKsl909ded59;MpKsl909ded59;c:\programdata\microsoft\microsoft antimalware\definition updates\{eec1367c-583a-4130-a503-226064084aef}\MpKsl909ded59.sys [2011-7-22 28752]R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-3-25 193840]R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2010-3-15 127488]R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504].=============== Created Last 30 ================.2011-07-22 17:04:51 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{eec1367c-583a-4130-a503-226064084aef}\MpKsl909ded59.sys2011-07-22 17:04:27 6881616 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{eec1367c-583a-4130-a503-226064084aef}\mpengine.dll2011-07-15 02:12:56 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl2011-07-15 01:31:32 -------- d-----w- c:\users\kevin\appdata\local\Mozilla.==================== Find3M ====================.2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys.============= FINISH: 13:23:11.79 =============== Link to post Share on other sites More sharing options...
Staff screen317 Posted July 26, 2011 Staff ID:458442 Share Posted July 26, 2011 Hi,Please visit this webpage for instructions for running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofixWhen the tool is finished, it will produce a report for you.Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.-screen317 Link to post Share on other sites More sharing options...
Staff screen317 Posted August 10, 2011 Staff ID:464110 Share Posted August 10, 2011 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts