Virus or Hijack???

  • Thread starter Thread starter Jim Clark
  • Start date Start date
J

Jim Clark

I have a problem with internet explorer getting very slow,
to the point that pages just won't load after I have been
on for a little while. For example, if I try to load a
specific page after having browsed through 4 or 5 pages,
the new page may take a very long time to load, often not
loading ever. But if I exit internet explorer then launch
it fresh and type that same page URL in the address bar
then it will open immediately. Then again after a very
short time pages will load very slowly and the same
problem comes back.

I have found that this problem doesn't exist when I log
into the computer as the system administrator. Only when
I log in with my own user account. This is not a
practical solution, only a temporary work around.

I have compared all of the running processes shown in the
task manager and only two additional items show up when
logged in with my own user ID. Apoint.exe and
Realsched.exe. A search indicates that neither of these
are a threat.

I searched on all of the running processes and found one
named ssys.exe that is reported to be a threat. I am
unable to stop the process, and every attempt to remove it
from the registry fails. In the registry in appears as
*ssys.exe. When I delete it and then recheck it has
returned. And I don't find it in the folder that the
registry thinks it is in. Search doesn't find it on the
computer at all.

I've tried running several spyware programs and Virtumundo
keeps showing up using Adaware. I remove it but when I
scan again it has come back. I'm not sure that this or
the ssys.exe problem are related to the internet problem
because both are there when I log in as administrator or
with my own user account.

Any ideas or suggestions at this point would be greatly
appreciated.
 
First step is identifying what that is. Run an AV scan using an up to date
AV scanner such as www.grisoft.com which is free, if you haven't already. If
you have and nothing was found, do a second opinion scan from
http://housecall.antivirus.com and submit a copy of the suspicious file to
one or more AV vendors.

Network Associates (McAfee) <[email protected]>
Symantec (Norton) <[email protected]>
Trend Micro (PC-cillin) <[email protected]>

Command Software <[email protected]>
Computer Associates (US) <[email protected]>
Computer Associates (Vet/EZ) <[email protected]>
DialogueScience (Dr. Web) <[email protected]>
Eset (NOD32) <[email protected]>
F-Secure Corp. <[email protected]>
Frisk Software (F-PROT) <[email protected]>
Grisoft (AVG) <[email protected]>
H+BEDV (AntiVir): <[email protected]>
Kaspersky Labs <[email protected]>
Norman (NVC) <[email protected]>
Sophos Plc. <[email protected]>
 
Back
Top