Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Is Conhost.exe supposed to run at startup??


  • Please log in to reply
9 replies to this topic

#1 WilliamJ1999

WilliamJ1999

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 06 November 2014 - 01:47 PM

Hey guys so recently i downloaded a torrent from a website and i have reverted back to a old Saved Backup however what i have noticed is in the startup everytime i check on task manager conhost.exe is always running without a Path Location or Description. I went to search my C: for Conhost as a whole and found 15 conhost.exe's located in winsxs/backup/ and winsxs/amd64_................. and 1 in Windows/System32 (Definite legit). Is the 15 Conhost's in the winsxs folder legit? and why does conhost run at startup?

 

Also the 15 i suggest aren't legit are unremovable as it just says you must have the permission from TrustedInstaller to delete this file.

 

 

 

 

Thanks

Attached Files


Edited by WilliamJ1999, 06 November 2014 - 03:06 PM.


BC AdBot (Login to Remove)

 


#2 WilliamJ1999

WilliamJ1999
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 07 November 2014 - 11:32 AM

Please reply somebody



#3 JohnC_21

JohnC_21

  • Members
  • 24,420 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:13 PM

Posted 07 November 2014 - 01:32 PM

Take a look at this thread. Not showing the command line of conhost is kind of suspicious. I can only suggest to run Process Explorer or Process Hacker as linked to in the thread and see what program is running using conhost.

 

What is conhost.exe and Why Is It Running?


Edited by JohnC_21, 07 November 2014 - 01:35 PM.


#4 WilliamJ1999

WilliamJ1999
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 07 November 2014 - 01:46 PM

Hi just checked with process explorer and went onto the conhost.exe properties and the path is N/A

Attached Files



#5 JohnC_21

JohnC_21

  • Members
  • 24,420 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:13 PM

Posted 07 November 2014 - 02:12 PM

I am not sure why that would be. As far as the 15 in WinSXS, I think those are legit. The conhost in System32 is signed by Microsoft, correct?  I am not sure why it is running in Task Manager. I just looked at TaskManager on a Windows 7 computer and conhost was not there, only csrss. Maybe somebody else on the forum can answer. If you are concerned you can start a thread in the "Am I infected Forum. Somebody there may be able to help.



#6 WilliamJ1999

WilliamJ1999
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 07 November 2014 - 02:14 PM

Okay, i will do and yes the system32 conhost is signed by microsoft.



#7 WilliamJ1999

WilliamJ1999
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 07 November 2014 - 02:16 PM

By the way would this make sense as to why the path name is unfound because previously my computer was harmed by the Rovnix_C virus and i had reformatted my drive/partiotions and reinstalled windows fresh would this have anything to do with the multiple conhost's?



#8 JohnC_21

JohnC_21

  • Members
  • 24,420 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:13 PM

Posted 07 November 2014 - 02:34 PM

I would think the virus you had would still be present if you did a full format. If you did a Quick Format, the virus may still have been present but I could not confirm that. If you do not get any response after three days in the Am I infected Forum, there is a link at the top of the Forum that you can click.



#9 WilliamJ1999

WilliamJ1999
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:02:13 AM

Posted 07 November 2014 - 03:34 PM

No that virus is fully gone now it is no longer detected by my Antivirus it's all fresh and okay



#10 JohnC_21

JohnC_21

  • Members
  • 24,420 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:13 PM

Posted 07 November 2014 - 03:50 PM

If you scan with HitmanPro and nothing is detected then I would assume you are safe. I tried to find anything related your blank properties of conhost but could find nothing.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users