Regarding file conhost.exe in temp folder

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Abhishek
    PCHF Member
    • Sep 2017
    • 60

    #1

    Regarding file conhost.exe in temp folder

    Recently i found out about virus in my after i installed malware bytes in my pc and my pc had been showing two threats in C:\Windows\debug\lsmose.exe and C:\Windows\temp\conhost.exe . Malware bytes used to regenerate both files ,i deleted lsmosw.exe manually and it didnt generate but conhost.exe is generating again . Kindly suggest me a way to remove it and find out if there are any other viruses in my system. Btw i use panda free antivirus with malware bytes.
  • Rustys
    PCHF Member
    • Jul 2016
    • 7862

    #2
    Relocated to the Malware Removal section.

    @gus jmarket

    Comment

    • Abhishek
      PCHF Member
      • Sep 2017
      • 60

      #3
      I wish i could get a quick solution for this, don’t want my pc to be a home to viruses.

      Comment

      • jmarket
        PCHF Owner
        • Jan 2015
        • 7635

        #4
        Hey @Abhishek

        Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.

        If you are unsure if your operating system is 32 or 64 Bit please go HERE.

        Once downloaded right click the FRST desktop icon and select “Run as administrator” from the menu.



        If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
        Frst will open with two dialogue boxes, accept the disclaimer.


        Accept the default whitelist options,
        If the additions.txt options box is not checked please select it.
        Then select “Scan”



        Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.



        Please Copy and Paste the contents of these logs in your next post for review by our Security Team

        Comment

        • Abhishek
          PCHF Member
          • Sep 2017
          • 60

          #5
          Below are the attached files

          Comment

          • jmarket
            PCHF Owner
            • Jan 2015
            • 7635

            #6
            Thank you for the files.

            I won’t have a fix for you until later, so in the meantime, do the following for me please:

            We will need a log from AdwCleaner for further information.

            Please go HERE and download AdwCleaner to your Desktop. Once downloaded right click the new icon and select Run as Administrator from the context menu to open the program. It will open at the Dashboard tab and no further changes to the program are necessary at this stage.

            Click the Scan Now button.

            [IMG alt="oklj3amfOpqEpPVXnuqk79lHRApDnhPQVXn6z6Y3NoRuE Owdc4_mOGQu11P43d4Fb8OGSEeDJ_AsebIM9FWRakQeH_rBtmE r8_ua1VJwBd_Ws3-miUSngeShjQ7W5K4p6SytCWs2=w2400" width="627px" height="401px"]https://lh3.googleusercontent.com/oklj3amfOpqEpPVXnuqk79lHRApDnhPQVXn6z6Y3NoRuEOwdc4 _mOGQu11P43d4Fb8OGSEeDJ_AsebIM9FWRakQeH_rBtmEr8_ua 1VJwBd_Ws3-miUSngeShjQ7W5K4p6SytCWs2=w2400[/IMG]

            Allow AdwCleaner to start scanning and depending on the amount of data on your PC it may take some time. At the conclusion of the scan any content considered unnecessary will be displayed in the Scan Results box. Ensure all items are selected for removal and click “Clean & Repair”
            [IMG alt="7pQdUft-ojpPn88OGfzif4Zs2nG7cOkKWXOxq2hnIP5ll37IPbMzLUh9W3 aC0wQonD-NEIwql19Hh7DJiYPOF1HL71bdqy81MiaqpcsP5f0JtykiLSk-l96KByQKj1ou2rexlOpo=w2400" width="627px" height="401px"]https://lh3.googleusercontent.com/7pQdUft-ojpPn88OGfzif4Zs2nG7cOkKWXOxq2hnIP5ll37IPbMzLUh9W3 aC0wQonD-NEIwql19Hh7DJiYPOF1HL71bdqy81MiaqpcsP5f0JtykiLSk-l96KByQKj1ou2rexlOpo=w2400[/IMG]

            After selecting “Clean & Repair” another dialogue box may appear asking to restart now or later. If so choose “Clean & Restart Now”
            Once the PC has restarted if AdwCleaner does not restart then open it again and click “Log Files” tab on the left. All log files will be listed. If you have used the program previously you may have several logs to select from so double click the most recent “Clean” log and it will open a notepad file on your Desktop.

            Please COPY and PASTE the contents of that file in your next post

            We will need a log from Zemana, can you please download the free trial HERE. Save it to somewhere you can find, double click the downloaded file and start the installation. Accept the default install options and you can safely ignore any security warnings and allow Zemana to complete the install. Once completed click the new desktop icon https://pchelpforum.net/attachments/zamicon-jpg.786 to open the program. If Zemana opens and informs of any available updates allow it to so. Next change Zemana’s default from “Smart Scan” to Deep Scan as shown below.



            Then click scan



            When the scan is complete allow Zemana to Quarantine any infections found by clicking Next



            Once the infections are quarantined a message box will indicate success, then click the logs icon as below.



            Select the latest scan and choose Open Report from the upper menu. or simply double left click on the scan just run.



            The log will open as a text file. Please Copy and Paste the contents of that file in your next post

            I also see that you have multiple AVs installed. Please remove the following:

            ESET
            Avira
            Panda
            AVG
            GridinSoft

            You really only need Malwarebytes and Windows Defender. If you’re looking for a really good realtime anti-malware solution, stick to Malwarebytes and Emsisoft.

            After doing the following, please re-run FRST and post fresh logs in addition to any other logs I requested.

            Comment

            • Abhishek
              PCHF Member
              • Sep 2017
              • 60

              #7
              It might take some days for me to reply as im out of town ,please dont close this thread. I will reply as soon as i can. Thanks

              Comment

              • jmarket
                PCHF Owner
                • Jan 2015
                • 7635

                #8
                No worries I’ll keep this thread open.

                Comment

                • Abhishek
                  PCHF Member
                  • Sep 2017
                  • 60

                  #9
                  thanks you so much for your patience. The files asked by you are pasted and attached below , i expect a quick reply from your side. thanks again.
                  Adwcleaner log
                  [HEADING=1]-------------------------------[/HEADING]
                  [HEADING=1]Malwarebytes AdwCleaner 7.2.4.0[/HEADING]
                  [HEADING=1]-------------------------------[/HEADING]
                  [HEADING=1]Build: 09-25-2018[/HEADING]
                  [HEADING=1]Database: 2018-09-24.1 (Cloud)[/HEADING]
                  [HEADING=1]Support: https://www.malwarebytes.com/support[/HEADING]
                  [HEADING=1]-------------------------------[/HEADING]
                  [HEADING=1]Mode: Clean[/HEADING]
                  [HEADING=1]-------------------------------[/HEADING]
                  [HEADING=1]Start: 09-28-2018[/HEADING]
                  [HEADING=1]Duration: 00:00:15[/HEADING]
                  [HEADING=1]OS: Windows 7 Ultimate[/HEADING]
                  [HEADING=1]Cleaned: 13[/HEADING]
                  [HEADING=1]Failed: 0[/HEADING]
                  ***** [ Services ] *****

                  No malicious services cleaned.

                  ***** [ Folders ] *****

                  Deleted C:\Program Files (x86)\pandasecuritytb
                  Deleted C:\Users\SR\AppData\LocalLow\pandasecuritytb

                  ***** [ Files ] *****

                  No malicious files cleaned.

                  ***** [ DLL ] *****

                  No malicious DLLs cleaned.

                  ***** [ WMI ] *****

                  No malicious WMI cleaned.

                  ***** [ Shortcuts ] *****

                  No malicious shortcuts cleaned.

                  ***** [ Tasks ] *****

                  No malicious tasks cleaned.

                  ***** [ Registry ] *****

                  Deleted HKCU\Software\csastats
                  Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules|{6781912 A-C64B-44DC-B5B3-F854AC52FBDA}
                  Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules|{46A4770 2-FF06-4551-934F-AEBD2F9112D1}
                  Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules|{BA8A06F F-6FA3-4D60-9952-FBA86B11D53A}
                  Deleted HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\FirewallRules|{81EB7EE 5-A6E9-4DC1-83B6-8443CFE00A49}
                  Deleted HKCU\Software\PRODUCTSETUP
                  Deleted HKCU\Software\ProductSetup\Uninstall\0S1P1T1C1R1Mt T0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F
                  Deleted HKCU\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1 G1R1P1V0A1Q1Q0O1G
                  Deleted HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit

                  ***** [ Chromium (and derivatives) ] *****

                  No malicious Chromium entries cleaned.

                  ***** [ Chromium URLs ] *****

                  Deleted Ask
                  Deleted AOL

                  ***** [ Firefox (and derivatives) ] *****

                  No malicious Firefox entries cleaned.

                  ***** [ Firefox URLs ] *****

                  No malicious Firefox URLs cleaned.


                  [+] Delete Tracing Keys
                  [+] Reset Winsock


                  AdwCleaner[S00].txt - [2581 octets] - [28/09/2018 20:58:46]

                  ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

                  Zemana AntiMalware 2.74.2.150 (Installed)


                  Scan Result : Completed
                  Scan Date : 2018/9/28
                  Operating System : Windows 7 64-bit
                  Processor : 2X Intel(R) Core™2 CPU 4300 @ 1.80GHz
                  BIOS Mode : Legacy
                  CUID : 12250136D2543C336AC47B
                  Scan Type : System Scan
                  Duration : 8m 32s
                  Scanned Objects : 27267
                  Detected Objects : 2
                  Excluded Objects : 0
                  Read Level : SCSI
                  Auto Upload : Enabled
                  Detect All Extensions : Disabled
                  Scan Documents : Disabled
                  Domain Info : WORKGROUP,0,2
                  [HEADING=1]Detected Objects[/HEADING]
                  panda_url_filteringc.dll
                  Status : Scanned
                  Object : %programw6432%\panda security url filtering\panda_url_filteringc.dll
                  MD5 : 8893FE26DCA52E3793170EDA7AA1C565
                  Publisher : Visicom Media Inc.
                  Size : 355824
                  Version : 2.0.1.8
                  Detection : Adware:Win32/VisicomToolbar!Ep
                  Cleaning Action : Report as safe
                  Related Objects :
                  File - %programw6432%\panda security url filtering\panda_url_filteringc.dll
                  DLL - 1336 - C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe

                  Panda_URL_Filteringb.exe
                  Status : Scanned
                  Object : %programw6432%\panda security url filtering\panda_url_filteringb.exe
                  MD5 : D4B7E17CD168972A16991123BE84E7EF
                  Publisher : Visicom Media Inc.
                  Size : 246256
                  Version : 2.0.1.8
                  Detection : Adware:Win32/VisicomToolbar!Ep
                  Cleaning Action : Quarantine
                  Related Objects :
                  File - %programw6432%\panda security url filtering\panda_url_filteringb.exe
                  Process - 1336 - C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
                  [HEADING=1]Cleaning Result[/HEADING]
                  Cleaned : 0
                  Reported as safe : 2
                  Failed : 0

                  Comment

                  • Abhishek
                    PCHF Member
                    • Sep 2017
                    • 60

                    #10
                    What should i do next??

                    Comment

                    • jmarket
                      PCHF Owner
                      • Jan 2015
                      • 7635

                      #11
                      I have a partial fix for you.

                      Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system. Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply. Also post fresh FRST logs please

                      Comment

                      • Abhishek
                        PCHF Member
                        • Sep 2017
                        • 60

                        #12
                        Below are the attached 3 logs , let me know what to do next.

                        Comment

                        • jmarket
                          PCHF Owner
                          • Jan 2015
                          • 7635

                          #13
                          Do you have System Restore disabled?

                          Also please remove Panda. You have ESET, and more than one real-time antivirus causes issues

                          Comment

                          • Abhishek
                            PCHF Member
                            • Sep 2017
                            • 60

                            #14
                            System restore is turned on but i can’t make a restore point by myself and it doesn’t make one on its own. There is some issue with it i forgot to address in the starting of this thread(attached the screenshot of the issue when i try to create a restore point). Those are just some traces of Eset leftover,i just use panda. Still if you feel its a problem i would remove panda .

                            Comment

                            • jmarket
                              PCHF Owner
                              • Jan 2015
                              • 7635

                              #15
                              Are you able to boot into Safe Mode and create a restore point?

                              Comment

                              Working...