Showing posts with label Virus Removal. Show all posts
Showing posts with label Virus Removal. Show all posts

What is conhost.exe and Why Is It Running?

You are no doubt reading this article because you are wondering what on earth this conhost.exe process is doing in Task Manager, and why it’s running on your shiny new Windows 7 PC. We’ve got the answer for you.
image
So What Is It?
The conhost.exe process fixes a fundamental problem in the way previous versions of Windows handled console windows, which broke drag & drop in Vista.
It’s a completely legitimate executable—as long as it’s running from the system32 folder, and is signed by Microsoft. Scanning your computer for viruses is never a bad idea, though.
Wait, What? So Why Do I Need It?
Oh, you wanted more information? I suppose I can oblige with some background information. Essentially, there’s a problem with the way the console process works on previous versions of Windows—they are all hosted under the csrss.exe (Client Server Runtime Process) service. This process runs as a system-privileged account.
If you take a look at the command prompt on Windows XP, you’ll probably notice that the window doesn’t use the active theme at all. This is because the CSRSS process doesn’t have the ability to be themed.
image
If you take a look at the console in Windows Vista, it looks like it uses the same theme as everything else, but you’ll notice that the scrollbars are still using the old style (look closely). This is because the DWM (Desktop Window Manager) process handles drawing the title bars, but underneath it still works the same way, and the scrollbars are part of the window itself.
image
You might also notice that Windows Vista broke the ability to drag and drop files from Explorer straight into the command prompt. It just flat out doesn’t work, because of security issues between the CSRSS process running with a higher level of privileges.
Windows 7 Does It Differently
Checking it out in Process Explorer under Windows 7 shows that the conhost.exe process is running underneath the csrss.exe process.
image
The conhost.exe process sitting in the middle between CSRSS and cmd.exe allows Windows 7 to fix both of the problems in previous versions of Windows—not only do the scrollbars draw correctly, but you can actually drag and drop a file from Explorer straight into the command prompt:
image
And it’ll paste in the path onto the command line. (of course this example isn’t very useful).
image
Still Aren’t Convinced?
I can see our relationship has some trust issues. If you really want to be sure, check out the file properties for the conhost.exe executable, and you’ll see that the description says Console Window Host:
image
If you look at the details of the process from within Process Explorer, you’ll notice that the ComSpec is set to cmd.exe, a clear indication that it’s hosting the command prompt.
image
So now you know what the conhost.exe process does, and why you should never attempt to delete it. Ever.

[HOW TO] Remove Total Security 2009 virus/adware

Total Security or TotalSecurity or Total Security 2009 is a fake anti-spyware program. Which when installed on your PC shows some fake virus scan reports saying you have 25-30 trojans and you will have to download some stupid antivirus to remove them. It also blocks all websites on your computer. Your PC will slow down and will hang often. Some known symptoms of this virus are as below.
  • Your PC is slower than usual.
  • You get too many unnecessary pop-up windows.
  • Your PC shows some anti-virus running which you never installed.
  • Some of your settings are changed without your knowledge.
total-security

It is very easy to remove this program from your system. To remove this spyware from your computer follow the steps given below.
  • Open task manager and stop this processes. TotalSecurity 2009.exe, tsc.exe, Sc2C21UvvM.exe.
  • Delete following files. Winsource.dll, tsc.exe Sc2C21UvvM.exe winsource.dll TSC.lnk Help.lnk Registration.lnk Uninstall TSC.lnk and also delete the directory at C:\Program Files\TSC.
  • Remove registry entries of this files. To do this open registry editor and press F3.Then search for tsc.exe. Delete all the entries of that file from registry. Now search for TotalSecurity and Total Security and delete those entries too.Also look for winsource.dll file in registry and delete related entries from registry.
The virus should be removed from your system by doing this.
Now download and install free edition of AVG  to stay protected in future. Here is the download link.

Download AVG free edition

[HOW TO]Remove AntiVirGear/AntiVir Gear virus/adware

AntiVIrGear or AntiVir Gear is a adware+spyware program which pretends to be an Anti Spyware Software but actually the program itself is a Spyware. It gets installed in your PC automatically via some trojan or virus.
There is one free and easy to use tool available to remove AntiVirGear from your computer.It’s SmitFraudFix.exe. The download link for this tool is available at the end of this article. To use this tool first boot your PC in safe mode. Then run the SmitFraudFix.exe.When it comes to menu screen select the second option.
smitfraudfix-menu
When the AntiVirGear is removed from your computer a disk cleanup process will start. It will clean all temp files and other unnecessary crap. Once the disk cleanup is finished it will ask you whether you want to clean registry or not. Press Y and hit enter. After that your computer will reboot. When rebooted your computer will be free from AntiVirGear.
If you need any help to remove any kind of virus or spyware you can contact me at computertricks[at]etricks.in or post your queries in comments here.
Enjoy

free counters