0

Today, while I was doing some vector on Illustrator, suddenly it lags, even my cursor is stuck and moves slowly. I was playing some music at the same time, it got stuck too. Here's a screenshot of my task manager. It was listed as Svchost.exe*32 under the name Comodo Dragon and stays under Chrome. I used Kaspersky TDSSKiller, Microsoft Essential with no result.

I can't delete it because it was running. Whenever I stop the process, it restarts itself again. when finally I did managed to delete it, when I restart, there it is again. I had a couple of people using this computer these few days for some editing on Illustrator.

enter image description here

Simon
  • 3,943
  • 2
  • 24
  • 40
Gix
  • 1
  • 2

2 Answers2

1

Okay, if it is a virus and it is appearing again when you restart, try this:

  1. Note the location
  2. Restart in Safe Mode
  3. Delete the file from the File System
  4. Go to Start > Search for "Run" (or press Windows button + R)
  5. Type "MSConfig" and press enter
  6. Go to the "Startup" tab
  7. Look for the file in the list (May be under another name but 'Location' field should be correct but possibly shortened)
  8. Untick the selection
  9. Click Okay
  10. Restart

Be careful when editing in MSConfig, you can mess up your system if you start messing about with the wrong stuff in there.

This should get rid of it. When you logon next a message might show, just say you don't want MSConfig to show when you boot up

Let me know how it goes.

Skepi
  • 111
  • 2
  • Of coursed, in the general case rather than deleting the file it should be renamed and moved somewhere else, in case it really was not malware but some important system component. Then delete it once system operation seems normal again (or as "normal" as Windows ever gets). – Daniel R Hicks Apr 23 '13 at 11:53
  • As I said, be careful. I agree with Daniel. The only reason I said to delete was because the file was: "SVChost.exe" which it says is run by User "zam" and description is "Comodo Dragon. If this were a valid "SVChost.exe" it would be run by either System, Local, or Network. That and it would not be located in the Google Chrome AppData folder – Skepi Apr 23 '13 at 13:24
0

You could try to upload the file to: https://www.virustotal.com/de/

It should tell you that the file is a virus/malware.

You can then try to download autoruns (http://technet.microsoft.com/de-de/sysinternals/bb963902.aspx) and reboot in safe mode (F8). There search for the entry that runs this file and remove it. Maybe this is enough.

SaschaZorn
  • 59
  • 3