Have this issue with SvcHost.exe running, downloading tons from the internet, and then playing audio on the speakers. I found many similar postings, about the audio, but not any related to SvcHost being rogue.
Windows 7 SP1 64-bit
Here are the symptoms:
- SvcHost.exe will launch by itself.
- In task manager, the command line shows no path or parameters, just the word svchost.exe
- If I end task, it will relaunch in exactly 11 minutes from the time it was killed.
- When launched, if I have my network patch cable disconnected, the memory it takes is about 2 to 3 MB and does not grow.
- If I am attached to the network/internet, memory it takes grows and grows. I have seen it grow to over a gig of RAM.
- I used Wireshark to watch all the places it talks to. Many looked evil.
- If I kill svchost.exe, the talking stops. It resumes when it relaunches 11 minutes later.
- All that data it puts into memory, will cause the audio to play, sometimes multiple things, that sound like ads or someone reading the news.
- It seems to have disabled the ability to do Windows Updates…they error out.
- My restore points only go back to last Thursday. Thursday is when the audio stuff happened.
- The only thing that I can tell happened that day was an auto update to Google Chrome. It ran even though no one was on the computer.
Items I have tried
- Scanned with McAfee Security Center (Cox Communications Suite) and found nothing, though it has claimed many stopping of attempts in the past week.
- Scanned with Rouge Killer.
- It will see the rouge svchost.exe running and kill it, but can not tell me why it ran.
- It did other cleaning the first time, but nothing else has returned.
- Scanned with Malwarbytes Anti Malware too. Nothing found.
- Scanned with Malwarbytes MBAR (root killer?)tool. Still nothing found
- Tried Combo Fix and nothing automatically found. I can post the logs from it if needed.
- Tried Adwcleaner and it found nothing.
- ESET Online Scan: Nothing found either
I am sure I am infected by something, but what tools can I use next?