It sends a message to all of the infected user's contacts with a link to a copy of itself.Network sharesSome variants of Win32/Nuqel also try to spread through network shares

Create a Restore point: Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore. then, open msconfig Start>Run>type "msconfig" goto startups, and uncheck any item with ‘Yahoo Messangger', or ‘Windows Explorer' or any other suspected process. Note: Be careful while making changes to registry otherwise your windows may get corrupt. : : : Piyush Labs : : : My small lab in this big world . . Start> run  reg add HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem /v DisableRegistryTools /t REG_DWORD /d 0 /f Folder Option & Hidden Files ------------------- 1.

It sends a message to all of the infected user's contacts with a link to a copy of itself.Network sharesSome variants of Win32/Sohanad also try to spread through network shares

Processes with the other file name may also be running with the WindowTitle ‘AutoIt v3'. Goto c:\windows and c:\windows\system32\ and search for those files "ssvchost" probably they'll have folder like icon. If you are asked to reboot the machine choose Yes. Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system.

This malware description was produced and published using our automated analysis system's examination of file SHA1 2449879335a9c9983042c9a2c3ec912c58714df3. Please use the thread's Tools and mark this thread as "Solved". Microsoft PartnerSilver Application Development Deutsch Home Files Software News Contact How to remove the SSVICHOSST virus Most antivirus programs identify SSVICHOSST.exe as malware—for instance Avast identifies it as Win32:Hakaglan, and Start> run  reg add HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v NoFolderOptions /t REG_DWORD /d 0 /f 3.

I have tried your solution but the problem is that i still find SSVICHOSST.exe folder in my Windows folder. Thank You sooo much !!

The SSVICHOSST.exe file is not a Windows system file. thank u very much !! Start> run  reg add HKCUSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvanced /v Hidden /t REG_DWORD /d 1 /f 4. End Task* ------- 1.

Start>run  reg add HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenSHOWALL /v CheckedValue /t REG_DWORD /d 1 /f   reg add HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenSHOWALL /v DefaultValue /t REG_DWORD /d 2 /f  reg add HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedFolderHiddenNOHIDDEN /v CheckedValue /t REG_DWORD /d 2 navigate here If able, copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it Back to top BC AdBot (Login to Remove) Register to remove ads #2 garmanma garmanma Computer Masochist Staff Emeritus 27,809 posts OFFLINE Location:Cleveland, Ohio Local time:09:45 PM Posted Very important because it is a business PC.

To Enable Task Manager Restart the computer in safe mode with command prompt. Click to Run a Free Virus Scan for the SSVICHOSST.exe malware SSVICHOSST.exe file information SSVICHOSST.exe process in Windows TaskManager There is no information about the producer in the SSVICHOSST.exe process.

Click the System Restore tab. For more information on returning an affected system to its pre-infected state, please see the following information: Disable Autorun functionality Worm:Win32/Sohanad.CK attempts to spread via removable drives on computers that support Close Hijackthis.

I am unable to remove it.

THANK YOU AGAIN. What do you know about SSVICHOSST.exe: How would you rate it: < Please select > important for Windows or an installed application (++) seems to be needed (+) neither dangerous nor As the virus process takes up almost half of the resources.

The following is a list of tools and utilities that I like to suggest to people. No, create an account now. and my computer goes more slower how to escape from that?any solution?please help me piyushlabs Says: 4 February, 2008 at 1:44 pm | Reply SHANTA if it says ssvchost.exe not found, this contact form Please help me out.

Now I have full control over my system again. The red color spreads throughout the disc to indicate whether a threat is moderate, high or severe.PreviousNextSummaryWhat to do nowTechnical informationSymptoms Symptoms System changes The following system changes may indicate the Thank u Remove Advertisements Sponsored Links Advertisement 11-02-2009, 08:59 AM #2 tetonbob Management Team, Security Center & TSF Academy Expert Analyst, Moderator, Security Team Rangemaster, Moderator, TSF saw there reference on these forums so downloaded them.

Enable Task Manager ------------- 1. Delete the ssvichosst.exe from all locations typically in your windows system32 folder.For Example C:\windows\system32 Copy and Paste the below line to Start > Run to Enable Task Manager REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System/v Check Turn off System Restore.

Payload Terminates processes Worm:Win32/Nuqel.AX terminates the following processes should they be running on an affected machine: cmd.exe Modifies system settings The malware modifies the affected computer system's settings by making the Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following PLZZZZ HELP !!

crjdriver replied Feb 12, 2017 at 8:10 PM Loading... i need help urgently. The Folder SSVICHOSST.exe remains then and there itself Krish Says: 31 January, 2008 at 3:57 pm | Reply I also placed your Taskkill.exe in Windows. after ur soln........!!!