Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 05:52:25 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212220
Posts
24530
Topics
57708
Members
Latest Member:
zebadee
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
help needed! PC slow & infected
« previous
next »
Pages:
[
1
]
2
Author
Topic: help needed! PC slow & infected (Read 5365 times)
suhasmk
Newbie
Offline
Posts: 6
help needed! PC slow & infected
«
on:
September 29, 2007, 12:28:36 PM »
I find my computer running very slowly. This is happening from just few days.
I regularly update my anti-virus and other similar programs. Whenever i scan my computer, it takes plenty hours to scan just a few files.
I cannot even open task manager and run regedit.
Please help me in this regard...
«
Last Edit: November 13, 2007, 08:01:07 AM by Soyabeaner
»
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3199
Re: help needed!
«
Reply #1 on:
September 29, 2007, 12:42:59 PM »
Greetings,
If you can't open task manager or regedit, it's surely a malware.
Have you installed anything new this week or visited some site you haven't before?
Download HijackThis(
http://216.180.233.162/~merijn/programs.php#hijackthis
) and run it and save the logfile, then post it here(not the file, copy the text from the logfile instead), to see if there's anything that's suspicious.
Also try Spybot S&D and Lavasoft Ad-aware.
Ragwing
Logged
Forum Policy
FAQ's
If you should need help or have a question, feel free to
PM
me.
suhasmk
Newbie
Offline
Posts: 6
Re: help needed!
«
Reply #2 on:
September 30, 2007, 04:55:03 AM »
I installed certain programs from my pen drive.
I ran spybot and ad-aware. Spybot detected the problem (with task manager) and but didn't get it corrected.
However i have posted the log file. Please see attachment.
Moderator Edit: Please do NOT post HJT logs; they are simply too long. Instead, upload them as an attachment.
«
Last Edit: November 13, 2007, 05:17:02 PM by Soyabeaner
»
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: help needed!
«
Reply #3 on:
September 30, 2007, 05:09:54 AM »
Quote
C:\WINDOWS\system32\SSVICHOSST.exe
This one is a virus called SSVICHOSST.exe is W32/Sohana-R. a think it's a rootkit.
Try A-squared downloadable here :
http://www.emsisoft.com/en/software/download/
Try scanning in safe mode with this
please post your advance
Xan
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
zvaragabor
Comodo Loves me
Offline
Posts: 109
Re: help needed!
«
Reply #4 on:
September 30, 2007, 05:33:13 AM »
Uhh, suhasmk, your computer is a malware farm.
Tick, then fix these:
C:\WINDOWS\system32\SSVICHOSST.exe
C:\WINDOWS\system32\SSVICHOSST.exe
(yes, there are two of this)
R3 - URLSearchHook: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe SSVICHOSST.exe
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O1 - Hosts: 203.27.235.25 www. payseal.icicibank.com
O1 - Hosts: 210.210.19.82 www. sifymall.com
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\SSVICHOSST.exe
O4 - HKLM\..\Policies\Explorer\Run: [status] present
O4 - HKUS\S-1-5-18\..\RunOnce: [yisouu.dll] Regsvr32.exe /s C:\PROGRA~1\YiSou\yisouu.dll (User 'SYSTEM')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O17 - HKLM\System\CCS\Services\Tcpip\..\{48A41D8E-AED2-41C8-B82F-B28467017BBC}: NameServer = 202.144.95.4,202.144.66.6
O18 - Protocol: ebk - {1E411CE8-FE8B-4973-B8E0-6EA2CC3C6B06} - C:\WINDOWS\system32\ebkp.dll
Also run a full scan in safe mode with disabled system restore.
«
Last Edit: September 30, 2007, 06:00:06 AM by zvaragabor
»
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: help needed!
«
Reply #5 on:
September 30, 2007, 05:41:32 AM »
Quote
Uhh, suhasmk, your computer is a malware farm.
LOL
Quote
C:\WINDOWS\system32\SSVICHOSST.exe
Yeah, still got one right
Xan
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
suhasmk
Newbie
Offline
Posts: 6
Re: help needed!
«
Reply #6 on:
September 30, 2007, 06:23:32 AM »
Thank you zvaragabor. I tried your way. I could not find when i ran hijackthis.
C:\WINDOWS\system32\SSVICHOSST.exe
C:\WINDOWS\system32\SSVICHOSST.exe
However, i can run regedit and task manager.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: help needed!
«
Reply #7 on:
September 30, 2007, 06:35:03 AM »
Please send another log file so we can see that you're totally secure
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
suhasmk
Newbie
Offline
Posts: 6
Re: help needed!
«
Reply #8 on:
September 30, 2007, 08:16:09 AM »
here is my log file. i couldn't remove C:\WINDOWS\system32\SSVICHOSST.exe & C:\WINDOWS\system32\SSVICHOSST.exe
how can i remove that?
«
Last Edit: November 13, 2007, 05:10:58 PM by Soyabeaner
»
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: help needed!
«
Reply #9 on:
September 30, 2007, 08:38:44 AM »
I can't see no problem any more but I'm not really an expert, still try a scan in safe mode (I hope you now how to do it? If not just say) and scan with avg, adaware, and spybot to be complete sure.
Also a saw 1 thing, it's no longer BoClean 4.24 it's 4.25 now, you should consider updating him
Hope I could help ya
Xan
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
zvaragabor
Comodo Loves me
Offline
Posts: 109
Re: help needed!
«
Reply #10 on:
September 30, 2007, 09:17:53 AM »
I cannot see the SSVICHOSST.exe in the new report too.
As alaertsxan mentioned, try a scan in safe mode. I would also recommend a-Squared free to run. It's a good antispy too.
Anyway, which antivirus do you use?
«
Last Edit: October 01, 2007, 10:00:43 AM by zvaragabor
»
Logged
suhasmk
Newbie
Offline
Posts: 6
Re: help needed!
«
Reply #11 on:
September 30, 2007, 10:32:02 AM »
I use AVG free-edition anti-virus, Spybot, Ad-aware and Comodo BOClean.
Logged
suhasmk
Newbie
Offline
Posts: 6
Re: help needed!
«
Reply #12 on:
October 05, 2007, 10:26:50 AM »
Greetings,
Finally Comodo BOClean came to my rescue. It detected and healed that particular virus.
Logged
little mermaid
Newbie
Offline
Posts: 1
Re: help needed!
«
Reply #13 on:
October 27, 2007, 11:21:20 AM »
I have the same problem
and this is the log file in the next reply
plzzzzzzzzzzz tell me what should I do !!!!!!!!!!!!!?
«
Last Edit: November 13, 2007, 05:11:21 PM by Soyabeaner
»
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3199
Re: help needed!
«
Reply #14 on:
October 27, 2007, 11:40:07 AM »
Quote from: little mermaid on October 27, 2007, 11:21:20 AM
I have the same problem
and this is the log file in the next reply
plzzzzzzzzzzz tell me what should I do !!!!!!!!!!!!!?
If none of the above works, post your own topic in 'Virus/Malware Removal Assistance'.
Include what security products you use, and include a HijackThis log(
http://216.180.233.162/~merijn/programs.php#hijackthis
).
Ragwing
Logged
Forum Policy
FAQ's
If you should need help or have a question, feel free to
PM
me.
Tags:
problem in my pc
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.165 seconds with 20 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com