I am told there is a worm? in c:\windows\system32\ssvichosst.exe

I am told there is a worm? in c:\windows\system32\ssvichosst.exe.
What am i supposed to do with it? It comes up with a warning if i click delete, and what is this chest thing?
I can’t get any help with this,

Deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.

There is no rush to delete anything from the chest, a protected area where it can do no harm. Anything that you send to the chest you should leave there for a few weeks. If after that time you have suffered no adverse effects from moving these to the chest, scan them again (inside the chest) and if they are still detected as viruses, delete them.

So send it to the chest.

What is the error message ?
I assume that it is either, file in use or because the file is in the system32 folder ?

What do you mean you can’r get any help with this, you are just reporting it for the first time ???

It’s a worm.

http://spywarefiles.prevx.com/RRDDGD036916051/SSVICHOSST.EXE.html

Aliases: W32/Hakaglan.worm.gen (McAfee), W32/Sohana-R (Sophos)

Hi hobittual,

It is a worm, but important is how to remove this worm.

An extensive removal thread with instructions can be found here:
http://www.windowsreference.com/windows-xp/fix-for-ssvichosstexe-missing-error-when-windows-start-and-remove-ssvichosst-virus/
Check this with the following info:

remove ssvichost.exe from your computer as soon as possible.
Ssvichost.exe is Trojan/Backdoor.
This virus affects your system by

Disabling Task Manager
Disabling Registry Editor
Creates a startup entry to start upon system start and
Creates its own exe files in Shared Documents folder which appear like ordinary folders.
Disables Folder Options
Uses your 50% or more processor CPU

You can see that the folders in Shared Documents have an exe extension If you have unchecked Hide extensions for known file types in Folder Options.
Kill the process ssvichost.exe and remove ssvichost.exe from Windows startup.
Delete File named svichossst.exe

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“@”=[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“Yahoo Messengger”=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“Shell”=”Explorer.exe “

polonus

hey i am infected by this creepy worm VBS:AutoRun-S [Wrm] but the avast is giving some errors. that the program is in use.so pls suggest wat shld i do

@dindosasha1

Pls make another thread for ur problem^^

-AnimeLover^^