PDA

View Full Version : VMhost.exe



DougH
2014-08-19, 21:41
I seem to have inadvertently acquired this in the last few days.
I have deleted it a couple of times from Program data/windows_os(c)/ProgramData/NetworkHostTask but it comes back again. SpyBot doesn'r seem to find it.
Any suggestions please?

tashi
2014-08-19, 22:51
Hello DougH,

For someone to take a look at the system please see the sticky which includes guidelines for this forum and instructions in post #2 on how to provide the preliminary DDS and aswMBR logs used for analysis.
http://forums.spybot.info/showthread.php?t=288

Then start a new topic providing the logs and a volunteer analyst will advise when available. :)

Best regards.

DougH
2014-08-19, 23:03
Thanks. Am away tomorrow but will do when I get back.

DougH
2014-08-20, 03:31
Hello DougH,

For someone to take a look at the system please see the sticky which includes guidelines for this forum and instructions in post #2 on how to provide the preliminary DDS and aswMBR logs used for analysis.
http://forums.spybot.info/showthread.php?t=288

Then start a new topic providing the logs and a volunteer analyst will advise when available. :)

Best regards.

A thought. I am using Windows 8, would simply reverting to an earlier restore point cure it?

tashi
2014-08-20, 17:01
Hello DougH,


A thought. I am using Windows 8, would simply reverting to an earlier restore point cure it?





Please do not use System Restore trying to remove an infection. Doing so would only serve to destroy a known restore point (dirty or not) and won't remove the malware. Let your helper advise you as to when a System Restore flush is called for.



http://forums.spybot.info/showthread.php?288-quot-BEFORE-You-POST-quot-%28Please-read-this-Procedure-Before-Requesting-Assistance%29-Updated :)

DougH
2014-08-22, 08:06
It seems to have resolved itself.

Via taskmanager, I closed the multiple tasks it caused to run gobbling up resources and deleted it but after a few hours it came back. This happened a few times.
Eventually I simply renamed VMHost.exe as xyzvmhost.exe and that appeared to stop it.
However on reawakening my PC yesterday, McAfee reported, blocked and removed an unspecified trojan.
The renamed file has now disappeared and my PC is running ok.

Thanks for your potential solutions anyway. I appreciate the effort you all put in.