Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 1st April 2003   #1
Inactive
 
Profile:
Join Date: Mar 2003
Posts: 6
Computer Experience:
Intermediate
granja Reputation Level


Unhappy SVCHOST32.exe

DOES ANYONE KNOW HOW TO DELETE THE FOLLOWING VIRUS FILES FROM MY COMPUTER "SVCHOST32.exe" THE FOLDER NAME IS "Litmus"....

I have tried delete, but it tells me access is denied...
It keeps coming back though,,, a couple of times I did delete the entire folder, ran a virus check, and it was not there... but as soon as I reboot it appears again.....


PLEASE HELP!!!


THANK YOU,,,

granja is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 1st April 2003   #2
Inactive
 
Profile:
Join Date: Aug 2002
Location: CA
Posts: 491
Computer Experience:
interbeginienced
mr.mark Reputation Level


you must be using mIRCclient?

based on the creation of the svchost32.exe file, my guess is that you have this trojan (or a variant) residing on your computer.

check out the tech details and removal instructs and see if any of it applies.

hth



mark

mr.mark is offline  
Old 5th April 2003   #3
Inactive
 
Profile:
Join Date: Mar 2003
Posts: 6
Computer Experience:
Intermediate
granja Reputation Level


Angry Can't Delete or Quarantine?

this is the message I get from AntiVirus program...

Unable to delete the file
C:\WINNT\litmus\SVCHOST32.exe
Make sure the file is not write-protected or
currently in use. On a network, varify that you
have propper access rights to delete the file.


Please Help.... what can I do...?????

granja is offline  
Old 5th April 2003   #4
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


Here it is:

http://securityresponse.symantec.com...mus.203.b.html

print these manual instructions

download the latest virus defs but do not run

boot to safe mode

Do the manual clean as directed

to insure it has not parked itsself it the temps do the following

Configure CleanMgr to max settings
Go to Start-Run and type

cleanmgr /sageset:1
The above need only be ran once (these settings will be remembered as the default until another sageset is ran).

It will present a menu select all except compress, then

Go to Start-Run and type

cleanmgr /sagerun:1
As long as /sageset above has been ran on this computer from now on the /sagerun is the only thing that needs to run.

Then run a full virus scan with norton

After rebooting back to full mode (if you are now parinoid) just to be sure get a 2nd opinion from one or both of these

http://www.bitdefender.com/scan/licence.php

http://www.pandasoftware.com/actives..._principal.htm

Mike

mflynn is offline  
Old 5th April 2003   #5
Inactive
 
Profile:
Join Date: Aug 2002
Location: CA
Posts: 491
Computer Experience:
interbeginienced
mr.mark Reputation Level


the reason i thought the poster might be infected with Backdoor.IRC.Zcrew is because of the creation of the svchost32.exe file... which is what is now on granja's system.

Backdoor.Litmus.203.b copies itself as %windir%\Random\Svchost.exe.

i think granja can view the symantec data and determine from the reg entries and other files just what infection exists.

my other concern is that granja does not have NAV, which changes things around considerably.

btw, mike, i have been conducting trial installations of KAV on a few operating systems... i really like that program, PLUS it found an archived email from three years ago that was infected with I-Worm.KakWorm, which blew me away because i must have run a thousand scans with NAV since then and no detection was forthcoming.



mark

mr.mark is offline  
Old 5th April 2003   #6
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


He should look for both!

KAV huh!

How is its CPU load? Although Virus protection is primary this is definately my next concern.

I'll have a look!

Thanks Mark.

Mike

mflynn is offline  
Old 7th April 2003   #7
Inactive
 
Profile:
Join Date: Aug 2002
Location: CA
Posts: 491
Computer Experience:
interbeginienced
mr.mark Reputation Level


hey mike
Quote:
KAV huh! How is its CPU load?
good question. it sucked, to the point that w2k was being bogged down. i uninstalled KAV (actually i restored each os via drive image), and was ready to accept that KAV was incompatible with my systems, but then i was given an idea by a poster on dslreports...

why not keep NAV as memory resident and just install the scanner component of KAV? excellent idea! <g>

i went back and reinstalled KAV, this time *not* uninstalling NAV at all (but of course disabling it temporarily during KAV installation), making use of the custom installation feature which offers the choice of making KAV the mem resident or not (KAV calls it Monitor).

works like a charm!! zero memory load, no conflicts with NAV, let alone the other programs on my machines, and i get the full blown protection of KAV's deep, unpacking engine technology whenever i want to run a scan.

i couldn't be happier right now, having a back up AV with the reputation of Kaspersky, and being able to keep NAV right where i like it, which for me has been as my main, go-to antivirus program.

edit in: btw, this is all 30-day full version free trial stuff with KAV... most excellent.



mark


Last edited by mr.mark; 7th April 2003 at 00:41.
mr.mark is offline  
Old 8th April 2003   #8
Inactive
 
Profile:
Join Date: Aug 2002
Location: CA
Posts: 491
Computer Experience:
interbeginienced
mr.mark Reputation Level


granja

regarding your private message....
Quote:
Please help...(svchost.exe) @ windows task manager I get the following message when I try to STOP process on "svchost.exe" ACESS IS DENIED What can I do??
first of all, your best chance for problem resolution here is via the main board and not via pm. on the main board, you get the help of many minds. in pm exchange with moi, you may not get the answers you need.

that said, i would refer you to your own post that says the problem file is svchost32.exe... "DOES ANYONE KNOW HOW TO DELETE THE FOLLOWING VIRUS FILES FROM MY COMPUTER "SVCHOST32.exe"

yet in the pm, quoted above, you mention trying to stop svchost.exe, which is a legitimate windows service that needs to run.

next i would advise you to refer to the directions for cleaning that both mike and i linked for you in previous posts. i would say that most, if not all, of what you require should be found there.

hth



mark

mr.mark is offline  
Old 8th April 2003   #9
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


Same as Mark!

In reply to your email!

We have already told you what to do!

Uninstall IRC or MIRC, THEN do the below!

But here is more ammo for you to use!

A description
http://www.trendmicro.com/vinfo/viru...CREW.A&VSect=T

Online Virus scanners

http://housecall.antivirus.com/
http://www.pandasoftware.com/actives..._principal.htm

http://www.anti-trojan.net/at.asp?l=en&t=onlinecheck

Mike

mflynn is offline  





Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]