Help!

svichoost.exe anyone?

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Symantec/Norton RSS
Next:  Outerinfo!?! Saved log file  
Author Message
umiwangu



Joined: Apr 19, 2005
Posts: 23

Location: Mangochi, Malawi

PostPosted: Mon Nov 05, 2007 5:09 pm    Post subject: svichoost.exe anyone?

I recently got a call from a client who said their newish computer was running very slowly. It has Norton AV '07 on it and the definitions were about 10 days old. I went over to their place and sure enough, there was a virus, but Norton wasn't picking it up at all.

Task Manager and Registry Editing are both disabled. The main culprit seemed to be a process called svichoost.exe. Actually I think it was in all CAPS (when will these guys ever learn?). I was able to get the Task Manager back, but of course I lost it again each time I rebooted/logged on. I tried doing a full system scan in safe mode, but it says that the computer is clean.

I also tried enabled the regedit again, but in order to save the changes, I have to logoff and the virus just disables it again. I'm pretty sure that svichoost.exe is included with the Shell key (HKML/software/microsoft/windows nt/winlogon or something like that), so unless I can edit the registry without regedit, I can't really figure out how to get rid of it. I could just re-install windows, but I'd rather try to get the bugger.

The bummer is that there isn't much info out there. Sophos mentions svichoost.exe in a couple virus profiles, including W32/Sohana-AE, which I'm pretty sure this is it. Trend Micro calls it WORM_SOHANAD.DU. They mention a Symantec uses (W32.Imaut), but that is a different virus. BTW, TrendMicro only reports 4 infections of this virus. Nice to know we get hit with front-line stuff here. I have at least two computers with it.

So, any ideas anyone? What's an easy way to edit the registry without regedit?

I must say this incident has shaken my faith in Norton. Smile

BTW, I have a copy of the virus, if anyone wants to take a look at it.
Back to top




User: inactive
Posts:



PostPosted: Sat Nov 10, 2007 9:20 am    Post subject: Re: svichoost.exe anyone? [Login to view extended thread Info.]

Same old crap....different name and different day.

The first thing I'd do, as a computer tech specializing in computer security, is to remove Norton. It's obviously doing no good and just loading down the system.
Uninstall it and then use the Norton Removal Tool found at the link in my signature line, to clean up what the uninstall missed or ignores.

Then download AVG 7.5 FREE. Put the download file on a CD and take it with you to the client. If it will install, get the current updates and run a full scan.

I did the above on a clients PC one day and AVG found and removed 150 viruses that Norton had missed. Actually 149 because Norton did report one virus, but said it could not remove it. Cheeeech!
My customer was livid, because she had just paid for another year of Norton AV. She called Symantec while I was still there and demanded her money back. I don't know if she ever got it, or not.

Then there are two more programs that you should include on that Util's CD.
One is "Trojan Hunter" .... even the 30 day free trial will find and remove things that even AVG isn't designed to remove.

Next, is "SpyHunter". The free trial will show malware that none of the others find. It will display the path and file names, but won't remove anything till you buy the program. I used it to assist in cleaning up several badly infected PC's before I broke down and bought the program.

You should also have a DOS boot disk with NTFS4DOS on it. With that you can boot up a computer with an NTFS hard drive and go in and remove files that you know to be viruses, trojans or worms. I've added NTFS4DOS to my Ghost boot CD......makes a great service tool.

But, get your stuff together on one CD that you can take with you to the client. Some things you'll have to install to the clients PC, but some can actually be run from the CD.

Another option is to remove the clients HD and install it on your own PC as a slave, where you can use the security software on your own PC to scan that drive. I do this often when a HD appears to be hopelessly infected.

Here is a list of the (Mostly FREE) software that I use to clean up a PC and keep it clean.

************************************
These are the programs I use every day to keep my own PC and the PC’s
of all my customers, spotlessly clean of malware.
I suggest every person having any Virus or Spyware issues get these programs
and use them immediately.
Do check for updates to all your security software on a DAILY basis.

SPYWARE/Trojan BLOCKERS/REMOVERS:

Trojan Hunter, is a first class Trojan Horse Virus removal program.
The downloaded version is a 30 day, Fully Functional, free trial.
Use the Free Trial to clean up a Dirty system or buy the retail license to have a year of full service plus updates.
Download "Trojan Hunter" here:
http://www.misec.net/trojanhunter/

From the web page, just click "Download Free Trial Version"
It's a 5.9 meg download.

Spybot Search & Destroy:
(a great anti Spyware program.)
Can be downloaded from:
http://www.safer-networking.org/en/download/index.html

For instructions on how to set up Spybot for best operation,
See my Spybot Setup instructions on this webpage.
http://users.wildblue.net/xpguru43/

AdAware 2007 FREE:
Another top notch anti Spyware program.
A great companion program to Spybot S&D.
Can be downloaded from:
http://www.lavasoftusa.com/
Click the Green button on right side of screen.

Spyware Blaster:
a great Spyware Blocker.
Protects both I.E. and Mozilla Firefox.
Can be downloaded from:
http://www.javacoolsoftware.com/spywareblaster.html
*DO NOT use in conjunction with Microsoft Office
(the two programs don’t seem to like each other)

SpyHunter:
A Spyware Elimination Utility
Finds things the others don't.
A retail product, ($29.95 for a one year subscription)
but, the 30 day trial will let you know if you have any malware on your HD.
Download from:
http://www.enigmasoftwaregroup.com


ANTI-VIRUS PROTECTION:

World famous AVG FREE will keep your computer free of viruses,
trojans, dialers, etc.
By default, it updates and scans for viruses on a daily basis.
AVG 7.5 FREE, can be downloaded from:
http://free.grisoft.com/doc/5390/lng/us/tpl/v5

Scroll down the page to "FREE Downloads" and then click on:
AVG Anti-Virus Free Edition 7.5
That takes you to the next page where you can select:
avg75free_488a1157.exe (or the currently posted version)
Save the file to your desktop and run the install from there.
If you have an older version of AVG free already installed,
use the 'Repair Install' option when installing v. 7.5.
Immediately get updates. More than one may be required.

Block Pop-Ups:
Many pieces of Spyware, Trojans, etc., get into your computer via
a pop-up on your screen, warning you that you may be infected, etc., ect., etc.
You can block almost all pop-ups by using Mozilla Firefox and its great pop-up blocker.
Firefox is absolutely FREE and as easy to use as any browser.
And with over a half a billion downloads, its quickly becoming world famous.
You can download the latest version here:
http://www.mozilla.com/en-US/firefox/

REGISTRY CLEANER:

"Easy Cleaner 2", the best Registry Cleaner I've found so far.
Can be downloaded from:
http://personal.inet.fi/business/toniarts/ecleane.htm
Just scroll down to "Download & Installation" and click on the first floppy disk symbol.

************************************

I have on occasions, cloned an infected HD so that if my further work to clean it, results in it being trashed, I always have that clone to restore and try again. Critical data files can always be extracted from a clone, eliminating the possibility of data loss.

Feel free to PM me for any further help. There's way more to this thing than is easy to post here.

Good Luck,
The Shadow Cool
Back to top
drwho07



Joined: Nov 29, 2007
Posts: 1546

Location: Central FL, USA

PostPosted: Thu Jun 12, 2008 12:55 pm    Post subject: [Login to view extended thread Info.]

Since that last post, Norton AV has continued to be "Bloatware" and ineffective in keeping a PC safe and clean.

The answer is still, remove it with the Norton Removal Tool and replace it with the new and even more powerful, AVG 8.0 FREE,
Available for easy download, Here!

Immediately get the latest updates and run a full scan.

Happy Computing!

The Doctor Cool
Back to top
umiwangu



Joined: Apr 19, 2005
Posts: 23

Location: Mangochi, Malawi

PostPosted: Thu Jun 12, 2008 1:10 pm    Post subject: [Login to view extended thread Info.]

Have you run into anyone who doesn't trust free stuff? Smile

I've tried the new AVG, but I don't like the banners and it's not the most friendly for a computer that's offline all the time.

So I'll stick with Avast for now.
Back to top
drwho07



Joined: Nov 29, 2007
Posts: 1546

Location: Central FL, USA

PostPosted: Thu Jun 12, 2008 1:40 pm    Post subject: [Login to view extended thread Info.]

Duh!

There are NO banners! Just one little offer to upgrade to the PAID version.
it's on the bottom of the main AVG window and if you'll just pull that window down the bottom of your screen, you won't even see it. Wink

AVG 8.0 is still the best FREE AV/AS/AT software there is. Period!

But, if your PC is never on the internet, then why do you need an AV/AS program? EH? Confused

If it's not on the internet, the program can't stay updated anyway and would soon fall into disrepair. So just shut it off and don't worry any more about it.

I guess, all in all, I don't understand your complaint! Question Question Question

Cheers Mate!
The Doctor Cool
Back to top
umiwangu



Joined: Apr 19, 2005
Posts: 23

Location: Mangochi, Malawi

PostPosted: Thu Jun 12, 2008 2:29 pm    Post subject: [Login to view extended thread Info.]

But doesn't that banner keep popping out?

And for computers that are online, it's usually dial-up, and the AVG link-checker takes too much of the precious bandwidth.

As for AVG being the best out there... When I used AVG 7.5 one time, it couldn't take care of a virus running in memory... that NAV killed at once. Of course, things have changed, and NAV is a huge piece of bloatware, but still...

This is the third-world we're talking about, so if any internet access at all, usually dial-up. 99% of the viruses come through memory sticks. Really.

And it's not my computer, but most of the 30,000 people in this small town I live in. Smile

Anyway, thanks for the help. Maybe I can get people weened off of B. Gates and back on something a bit more secure (not that they paid him anything, but still).
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> Symantec/Norton All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum