| | |
Prompt kept taking me to download PurityScan
Thread Solved |
Hang on a while as I am going to try to get some higher help on this one for you. It probably came back because it needs to be deleted manually from the folder. Just leave it at the moment & I will get back.
Web-Based EnterpriseManagement (WBEM)
I checked this clsid {357AA41A-B7A8-4632-A27D-5B980B25CF43}
and found StripPlayer http://www.pestpatrol.com/pestinfo/s/stripplayer.asp
It's a dialer/downloader. May also include WinMgts, a trojan.
If you have *stripplayer* in program files or add remove programs, uninstall it. If you cannot then you will have to do it manually, possibly in safe mode. The WBEM folder has to go too, again, possibly in safe mode.
I checked this clsid {357AA41A-B7A8-4632-A27D-5B980B25CF43}
and found StripPlayer http://www.pestpatrol.com/pestinfo/s/stripplayer.asp
It's a dialer/downloader. May also include WinMgts, a trojan.
If you have *stripplayer* in program files or add remove programs, uninstall it. If you cannot then you will have to do it manually, possibly in safe mode. The WBEM folder has to go too, again, possibly in safe mode.
•
•
Join Date: May 2004
Posts: 9
Reputation:
Solved Threads: 0
You mean the whole WEBM folder? What about the other files inside that folder?
I don't think I have *stripplayer*, but I will double check. So basically I need to remove O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe? I have already try it once but again it will just replicated itself after I reboot.
I don't think I have *stripplayer*, but I will double check. So basically I need to remove O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe? I have already try it once but again it will just replicated itself after I reboot.
Instructions are to fix this with hijackthis:
O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe
Boot into safe mode & navigate to the WBEM folder, find the svchost.exe file there & delete it manually. Empty the recycle bin, TempIntFiles, & Windows\Temp folder contents. Do not delete the WBEM folder. Sorry, glad you checked back.
O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe
Boot into safe mode & navigate to the WBEM folder, find the svchost.exe file there & delete it manually. Empty the recycle bin, TempIntFiles, & Windows\Temp folder contents. Do not delete the WBEM folder. Sorry, glad you checked back.
•
•
Join Date: May 2004
Posts: 9
Reputation:
Solved Threads: 0
So basically you are saying to use Hijackthis to fix this file by check it from the list after I do another scan and then click fix? Then I re-boot my comp in safe mode and go into my hard drive to remove everything that shows O4 - HKLM\..\Run: [{357AA41A-B7A8-4632-A27D-5B980B25CF43}] C:\WINNT\system32\wbem\svchost.exe? How about the backup file that Hijackthis will save when I use it to clean in the first place?
So are you saying that this file is definitely the cause of my problme? Also I see this file get start up from the msconfig's System Configuration Utility. How can I delete that from this start-up? I don't want just uncheck it from the list. I want it to be delete from the option. How can I do that?
Thanks for your help!!
So are you saying that this file is definitely the cause of my problme? Also I see this file get start up from the msconfig's System Configuration Utility. How can I delete that from this start-up? I don't want just uncheck it from the list. I want it to be delete from the option. How can I do that?
Thanks for your help!!
Yes to most of what you are asking. Once in safe mode go to the WBEM folder & remove the svchost.exe file from there. I recommend that no backups be removed for a few days to be certain that your comp runs ok.
The ONLY place on your machine where that file should be is directly in the system32 folder, nowhere else.
Are you still getting the original problem?
The ONLY place on your machine where that file should be is directly in the system32 folder, nowhere else.
Are you still getting the original problem?
From answers that work:
Many viruses masquerade themselves as SVCHOST to escape detection. Some have names that are similar, such as SCCHOST, others actually drop a program file called SVCHOST in the Windows folder or a Windows sub‑folder.
Recommendation :
The first recommendation is a simple one : always have a good antivirus product which is regularly updated (automatically preferably) and always renew your updates subscription when it expires. To detect if you have a virus that calls itself SVCHOST, first see if its full path shows up in The Ultimate Troubleshooter as either C:\WinNT\System32\Svchost.exe or C:\Windows\System32\Svchost.exe – if it does not, then it is almost certain you have a virus. Secondly, if you have Windows 95/98/ME rather than Win2000/XP/2003, then it is also almost certain you have a virus. Thirdly, go to the Services tab of The Ultimate Troubleshooter and look for the following service – if you find it then you probably have a virus too :
Many viruses masquerade themselves as SVCHOST to escape detection. Some have names that are similar, such as SCCHOST, others actually drop a program file called SVCHOST in the Windows folder or a Windows sub‑folder.
Recommendation :
The first recommendation is a simple one : always have a good antivirus product which is regularly updated (automatically preferably) and always renew your updates subscription when it expires. To detect if you have a virus that calls itself SVCHOST, first see if its full path shows up in The Ultimate Troubleshooter as either C:\WinNT\System32\Svchost.exe or C:\Windows\System32\Svchost.exe – if it does not, then it is almost certain you have a virus. Secondly, if you have Windows 95/98/ME rather than Win2000/XP/2003, then it is also almost certain you have a virus. Thirdly, go to the Services tab of The Ultimate Troubleshooter and look for the following service – if you find it then you probably have a virus too :
Ok. What is the exact words of the prompt?
Delete your temp internet files. Delete the contents of all temp folders. You may have to show hidden folders. Empty the recycle bin. Disable system restore temporarily.
Go & have another online scan please. We will set a new system restore point later. Note that all previous restore points will be lost.
Delete your temp internet files. Delete the contents of all temp folders. You may have to show hidden folders. Empty the recycle bin. Disable system restore temporarily.
Go & have another online scan please. We will set a new system restore point later. Note that all previous restore points will be lost.
![]() |
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Aedin: (Yet Another) Rundll32 Error problem
- Next Thread: another bridge.dll....
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
acrobat adobe adware anti-malware anti-virussitesaccessissue antivirus apple attack avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial conficker connect control cyber cybercrime cyberwarfare ddos education email europe exam exploit fake fancheckvirus gaming gtaiv halloween herss.exe hijack hosting internet iphone kaspersky legal malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile parents patch pdf phishing police policeprovirusmba-mblockedinternetaccess president pro problem redirect report research risk rogueantivirus rootkit samhain sans search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen threat translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista volume vulnerability war warning windows worm yahoo zero-day zeroday






