nibblesandbits
Member
- Reaction score
- 0
- Location
- West Virginia
So I've been working on this laptop for about 3 hours now. Promised to only charge for one hour, so I NEED help. I'm desperate here, I refuse to nuke and pave this machine.
For some reason in Process Explorer there is a SVCHOST.exe process running under webroot's process. The problem was happening before webroot was installed, so I haven't removed it because I don't want to mess with reinserting a license and everything else, because it's not the problem. Anyway, if I let the computer sit there for a little while I see child processes appearing under SVChost... and it's iexplore.exe with arguments to get ads to play in the background. Normally, I'd find what crazy file name was causing the problem, suspend it, bring up windows explorer and then kill it and quickly delete the problem causing file. In this case, I don't know if it's safe to delete that SVCHOST in WINDOWS\SysWOW64. If it isn't safe, I don't know how to disinfect it. I've ran MBAM, ComboFix, AND SAS and none of them have even touched it. Also, the customer has ran McAfee, Webroot, and something else, I can't remember what they said.
I need help. He's going back to the college campus tomorrow and wants it back, not to mention I'm not making more than $60 on this job which sucks. I'm just going to keep googling and messing around, hopefully I'll find something or someone here will help me.
Thanks!
For some reason in Process Explorer there is a SVCHOST.exe process running under webroot's process. The problem was happening before webroot was installed, so I haven't removed it because I don't want to mess with reinserting a license and everything else, because it's not the problem. Anyway, if I let the computer sit there for a little while I see child processes appearing under SVChost... and it's iexplore.exe with arguments to get ads to play in the background. Normally, I'd find what crazy file name was causing the problem, suspend it, bring up windows explorer and then kill it and quickly delete the problem causing file. In this case, I don't know if it's safe to delete that SVCHOST in WINDOWS\SysWOW64. If it isn't safe, I don't know how to disinfect it. I've ran MBAM, ComboFix, AND SAS and none of them have even touched it. Also, the customer has ran McAfee, Webroot, and something else, I can't remember what they said.
I need help. He's going back to the college campus tomorrow and wants it back, not to mention I'm not making more than $60 on this job which sucks. I'm just going to keep googling and messing around, hopefully I'll find something or someone here will help me.
Thanks!
