Windows 10: Heavily Infected by svchost.exe and Poweliks.

Discus and support Heavily Infected by svchost.exe and Poweliks. in AntiVirus, Firewalls and System Security to solve the problem; I mention Poweliks because it's the only virus that comes to mind that closes Chrome. It's also located the in registry so it could be hidden. I tried... Discussion in 'AntiVirus, Firewalls and System Security' started by Wynona, Apr 5, 2018.

  1. simrick Win User

    Heavily Infected by svchost.exe and Poweliks.


    Hi.
    Thanks for posting your steps (MBAM offline, then RKILL steps, then Poweliks cleaner). I'm sure it will help others in the future who come here with similar problems.

    I would suggest running an ESET online scan for a final "all-clear", just to be sure.

    Then, get some Macrium imaging in place, and run it regularly. It's much easier to recover from things this way. *Wink
    Backup and Restore with Macrium Reflect Windows 10 Tutorials

    Cheers!
     
    simrick, Apr 13, 2018
    #16

  2. Hello

    I will do this now and set up a backup.

    Thank you.
     
    youngtomlin, Apr 13, 2018
    #17
  3. simrick Win User
    Great. You're very welcome. *Smile
     
    simrick, Apr 13, 2018
    #18
  4. Heavily Infected by svchost.exe and Poweliks.

    Quick update. Eset came back all clear and Macrium backups are now in place.

    *Smile
     
    youngtomlin, Apr 14, 2018
    #19
  5. Good to hear! Thanks for posting back with an update.

    You will thank yourself time and time again in the future with Macrium. Total life saver.
     
    Access Denied, Apr 14, 2018
    #20
  6. simrick Win User
    Brilliant!
    If you have any issues with the operating system, let us know - could be some DISM commands will fix things.
    Matter of fact, you might run sfc /scannow from an admin command prompt to make sure the OS is in good shape after that attack.
    Cheers. *Thumbs
     
    simrick, Apr 14, 2018
    #21
  7. simrick Win User
    Hi.
    I have to disagree with this statement. If it is impossible to clean specific infections (like Poweliks), then tools would not be available to clean them. Yes, there are certain infections that simply cannot be completely cleaned because they modify too many system files. In these cases, it's clearly recommended to perform a clean install. But many infections are easy to clean, and take less time that a clean install, PLUS setting up all the user's personal software and licenses.

    Unfortunately, there are many users who don't have imaging software/backups in place when they come here for help. Yes, it's good to recommend, but doesn't help at that point.

    This is only true if the backup is not connected to the system at the time of infection, or after infection. Ransomware will attack all files, including connected external drives and network shares. So it's important to mention that the backups should be offline/disconnected from the computer when not being used. It should also be mentioned that the paid version of Macrium now has Image Guard, to prevent manipulation of the backups by nefarious actors.
     
    simrick, Apr 14, 2018
    #22
  8. jimbo45 Win User

    Heavily Infected by svchost.exe and Poweliks.

    Hi there

    I always have 100 disconnection from Internet when taking backups and immediately store the backup device offline. My Backups on Windows are run via a read only bootable USB to load the backup / restore program.

    I should have mentioned that in the post!!

    I have to disagree though that using a Virus cleanser type program is quicker than re-storing a clean system -- especially when SSD's and USB 3 devices are involved -- on an SSD a typical Windows restore probably won't take more than 15 mins (if that) and you have 100% certainty your system is clean.

    As for DATA backups you need to control that in any way you see fit - there's no "one size fits all" method of data backups.
    However the main problem here is how to know whether any DATA files have been corrupted by any attack -- this actually is not a trivial exercise and here I'm interested to know how people check for "Data corruption" -- note I'm on about DATA here (personal files etc) rather than the OS which we've covered.

    It's possible for an attack say on your DATA files which you might not know about - that's where a lot of these AV programs fail -- they might be good at protecting the OS but DATA is an increasingly valuable commodity. You can't just compare old and new files - they usually aren't in readable ASCII format.

    I've found the only way that seems "semi-reliable" is any time I've changed a file is to re-open it again with whatever application -- e.g EXCEL or multi-media program for music / video and if it is OK then I send it away to a temporary file on my Linux NAS server for final update at the end of the day. Not perfect but I can't think of anything better here - so I'm open to ideas.

    No we've got people more used to the idea of backing up and protecting the OS - we need now to start sorting out the best way of protecting data before it gets saved to backups / cloud servers / NAS boxes etc.

    Cheers
    jimbo
     
    jimbo45, Apr 14, 2018
    #23
Thema:

Heavily Infected by svchost.exe and Poweliks.

Loading...
  1. Heavily Infected by svchost.exe and Poweliks. - Similar Threads - Heavily Infected svchost

  2. Pc heavily underpeforming.

    in Windows 10 Gaming
    Pc heavily underpeforming.: my pc has a 12900k, 4060ti, 32 g of ram, and other great specs. My pc was built by myself, and lags and freezes with low on fps on not high demanding games. For example, on cs go it freezes about twice per round, 5-10 seconds per time on not high settings. I also experience...
  3. Pc heavily underpeforming.

    in Windows 10 Software and Apps
    Pc heavily underpeforming.: my pc has a 12900k, 4060ti, 32 g of ram, and other great specs. My pc was built by myself, and lags and freezes with low on fps on not high demanding games. For example, on cs go it freezes about twice per round, 5-10 seconds per time on not high settings. I also experience...
  4. Svchost blocked

    in Windows 10 Software and Apps
    Svchost blocked: Hey i am Evan I am having problem in my computer When i go to ms-store > download and updates > then when i click get updates then ms store lags and a message come from my antivirus svchost.exe blocked . And in my pc i can't update my apps like minecraft , roblox . Please...
  5. heavily modifying the windows OS

    in Windows 10 Network and Sharing
    heavily modifying the windows OS: you guys probably won't know this, but I want to know if MS's servers can see ANY activity that I do on my local drives if I'm connected to the internet? that includes *anything*. More than likely, not even Nadella knows this, but I wouldn't put it past MS to be sniffing...
  6. Svchost blocked

    in Windows 10 Ask Insider
    Svchost blocked: When I open mozilla firefox, windows defender blocks svchost.exe from accessing secured folder %userprofile%/Videos Can anyone help me out with this one and tell me why is this happening? submitted by /u/Dalrew [link] [comments]...
  7. windows infected by a .exe virus

    in AntiVirus, Firewalls and System Security
    windows infected by a .exe virus: My windows is infected by an .exe virus which as turned mostly folders and files to .exe even the windows defender could stop https://answers.microsoft.com/en-us/protect/forum/all/windows-infected-by-a-exe-virus/54cd0c93-797f-42a9-9231-ee04bb83b675
  8. Error with svchost

    in Windows 10 BSOD Crashes and Debugging
    Error with svchost: I have been recieveing messages for the past two or three days now. When I go full screen, this message randomly pops up. "svchost.exe - application error The instruction at 0x00007FF8A305C686 referenced memory at 0x00007FF8C82D1A78. The memory could not be read. Click...
  9. Svchost virus?

    in AntiVirus, Firewalls and System Security
    Svchost virus?: Hi i just discovered the svchost trojan and have a few questions is it a rootkit virus and will completely wiping my hard drive destroy it....
  10. svchost

    in Windows 10 BSOD Crashes and Debugging
    svchost: An aplication in the path C:\Windows\syswow\ is running in the background and it consumes 60% of my cpu how to i stop it? I think it as something about Net Framework our something like that but im not sure. My Windows version is 1607...
Tags: