Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > freezing up

Reply
 
 
Maine4Us
Guest
Posts: n/a

 
      07-22-2007
I too have been experiencing frequent freeze ups. I scanned for spyware using
several different programs. Finally Adware-Pro (the last one I tried) found
212 parasites!!!! My system has not froze up since. My question is---in
looking at the session logs from Webroot SpySweeper this entry keeps coming
up---anyone know what it means??


Operation: Registry Access
Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
11:22 AM: Tamper Detection
Operation: Registry Access
Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
11:22 AM: Tamper Detection

 
Reply With Quote
 
 
 
 
Mr. Arnold
Guest
Posts: n/a

 
      07-22-2007

"Maine4Us" <> wrote in message
news:E9C92EA1-90D6-4322-A4B1-...
>I too have been experiencing frequent freeze ups. I scanned for spyware
>using
> several different programs. Finally Adware-Pro (the last one I tried)
> found
> 212 parasites!!!! My system has not froze up since. My question is---in
> looking at the session logs from Webroot SpySweeper this entry keeps
> coming
> up---anyone know what it means??
>
>
> Operation: Registry Access
> Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
> Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> 11:22 AM: Tamper Detection
> Operation: Registry Access
> Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
> Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> 11:22 AM: Tamper Detection



Now, malware can use something like Svchost.exe. Svchost.exe, a key O/S
component running out of the System32 directory, can host O/S programs and
non O/S programs, even malware programs can be hosted by Svchost.exe to do
something on its behalf.

So, it's not Svchost that's doing it as Svchost does nothing on its own it
just hosts other programs and provides the means.

 
Reply With Quote
 
Maine4Us
Guest
Posts: n/a

 
      07-22-2007
So is this something that is bad? What's the Target line mean?
Thanks for your help.

"Mr. Arnold" wrote:

>
> "Maine4Us" <> wrote in message
> news:E9C92EA1-90D6-4322-A4B1-...
> >I too have been experiencing frequent freeze ups. I scanned for spyware
> >using
> > several different programs. Finally Adware-Pro (the last one I tried)
> > found
> > 212 parasites!!!! My system has not froze up since. My question is---in
> > looking at the session logs from Webroot SpySweeper this entry keeps
> > coming
> > up---anyone know what it means??
> >
> >
> > Operation: Registry Access
> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> > 11:22 AM: Tamper Detection
> > Operation: Registry Access
> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> > 11:22 AM: Tamper Detection

>
>
> Now, malware can use something like Svchost.exe. Svchost.exe, a key O/S
> component running out of the System32 directory, can host O/S programs and
> non O/S programs, even malware programs can be hosted by Svchost.exe to do
> something on its behalf.
>
> So, it's not Svchost that's doing it as Svchost does nothing on its own it
> just hosts other programs and provides the means.
>
>

 
Reply With Quote
 
Mr. Arnold
Guest
Posts: n/a

 
      07-22-2007

"Maine4Us" <> wrote in message
news:2B6EAC8B-6C74-4ED1-9F4A-...
> So is this something that is bad? What's the Target line mean?
> Thanks for your help.
>


I don't know what it means. However, nothing should be changing the
register, unless you're installing software that you know about. And maybe,
if the registry is being changed and you don't know about it, then maybe
you should surf the Web using a Limited User account, if you're not using
one.

Maybe, you can get some more information from the links.

http://www.google.com/search?hl=en&q...=Google+Search

Maybe you can take a tool like Process Explorer and look at what any given
Svshost is hosting. Maybe, you'll spot something that shouldn't be hosted,
like malware.

 
Reply With Quote
 
Jon
Guest
Posts: n/a

 
      07-22-2007

"Maine4Us" <> wrote in message
news:E9C92EA1-90D6-4322-A4B1-...
>I too have been experiencing frequent freeze ups. I scanned for spyware
>using
> several different programs. Finally Adware-Pro (the last one I tried)
> found
> 212 parasites!!!! My system has not froze up since. My question is---in
> looking at the session logs from Webroot SpySweeper this entry keeps
> coming
> up---anyone know what it means??
>
>
> Operation: Registry Access
> Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
> Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> 11:22 AM: Tamper Detection
> Operation: Registry Access
> Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
> Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> 11:22 AM: Tamper Detection
>





SpySweeper protecting its own registry entries from 'tampering' by the looks
of it.

A quick google turned up this on one page, which should show you what the
initials stand for

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSHRMD\0000]
"DeviceDesc"="Spy Sweeper Hookrack MiniDriver"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSIDRV\0000]
"DeviceDesc"="Spy Sweeper Interdiction Driver"

--
Jon


 
Reply With Quote
 
Maine4Us
Guest
Posts: n/a

 
      07-22-2007


"Mr. Arnold" wrote:

>
> "Maine4Us" <> wrote in message
> news:2B6EAC8B-6C74-4ED1-9F4A-...
> > So is this something that is bad? What's the Target line mean?
> > Thanks for your help.
> >

>
> I don't know what it means. However, nothing should be changing the
> register, unless you're installing software that you know about. And maybe,
> if the registry is being changed and you don't know about it, then maybe
> you should surf the Web using a Limited User account, if you're not using
> one.
>
> Maybe, you can get some more information from the links.
>
> http://www.google.com/search?hl=en&q...=Google+Search
>
> Maybe you can take a tool like Process Explorer and look at what any given
> Svshost is hosting. Maybe, you'll spot something that shouldn't be hosted,
> like malware.
>
> thanks for the info i will see what i can find

 
Reply With Quote
 
Maine4Us
Guest
Posts: n/a

 
      07-22-2007


"Jon" wrote:

>
> "Maine4Us" <> wrote in message
> news:E9C92EA1-90D6-4322-A4B1-...
> >I too have been experiencing frequent freeze ups. I scanned for spyware
> >using
> > several different programs. Finally Adware-Pro (the last one I tried)
> > found
> > 212 parasites!!!! My system has not froze up since. My question is---in
> > looking at the session logs from Webroot SpySweeper this entry keeps
> > coming
> > up---anyone know what it means??
> >
> >
> > Operation: Registry Access
> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> > 11:22 AM: Tamper Detection
> > Operation: Registry Access
> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> > 11:22 AM: Tamper Detection
> >

>
>
>
>
> SpySweeper protecting its own registry entries from 'tampering' by the looks
> of it.
>
> A quick google turned up this on one page, which should show you what the
> initials stand for
>
> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSHRMD\0000]
> "DeviceDesc"="Spy Sweeper Hookrack MiniDriver"
>
> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSIDRV\0000]
> "DeviceDesc"="Spy Sweeper Interdiction Driver"
>
> --
> Jon
>
>
> thanks Jon, so it might be nothing to worry about. I hope. How do you google something like this??


Denise
 
Reply With Quote
 
Jon
Guest
Posts: n/a

 
      07-22-2007

"Maine4Us" <> wrote in message
news:0B187249-5E09-4DFB-B19C-...
>
>
> "Jon" wrote:
>
>>
>> "Maine4Us" <> wrote in message
>> news:E9C92EA1-90D6-4322-A4B1-...
>> >I too have been experiencing frequent freeze ups. I scanned for spyware
>> >using
>> > several different programs. Finally Adware-Pro (the last one I tried)
>> > found
>> > 212 parasites!!!! My system has not froze up since. My question is---in
>> > looking at the session logs from Webroot SpySweeper this entry keeps
>> > coming
>> > up---anyone know what it means??
>> >
>> >
>> > Operation: Registry Access
>> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
>> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
>> > 11:22 AM: Tamper Detection
>> > Operation: Registry Access
>> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
>> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
>> > 11:22 AM: Tamper Detection
>> >

>>
>>
>>
>>
>> SpySweeper protecting its own registry entries from 'tampering' by the
>> looks
>> of it.
>>
>> A quick google turned up this on one page, which should show you what the
>> initials stand for
>>
>> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSHRMD\0000]
>> "DeviceDesc"="Spy Sweeper Hookrack MiniDriver"
>>
>> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSIDRV\0000]
>> "DeviceDesc"="Spy Sweeper Interdiction Driver"
>>
>> --
>> Jon
>>
>>
>> thanks Jon, so it might be nothing to worry about. I hope. How do you
>> google something like this??

>
> Denise





To google it you can use portions of the error message eg 'LEGACY_SSHRMD' or
'LEGACY_SSHRMD' along with something like "Tamper Detection" and see what
turns up.

I'd also run this command from an elevated command prompt (right-click >
Run as administrator), to verify the integrity of your files (since it's
clearly been infected).

sfc /scannow

Also if you want to be thorough then this command will show what services
each 'svchost.exe' is hosting.

tasklist /svc

You can use this information ensure that the services that are running
should be running.

Otherwise, and perhaps simpler, you could run your various spyware
detection tools again and verify that they give you the all clear.


--
Jon


 
Reply With Quote
 
Maine4Us
Guest
Posts: n/a

 
      07-23-2007


"Jon" wrote:

>
> "Maine4Us" <> wrote in message
> news:0B187249-5E09-4DFB-B19C-...
> >
> >
> > "Jon" wrote:
> >
> >>
> >> "Maine4Us" <> wrote in message
> >> news:E9C92EA1-90D6-4322-A4B1-...
> >> >I too have been experiencing frequent freeze ups. I scanned for spyware
> >> >using
> >> > several different programs. Finally Adware-Pro (the last one I tried)
> >> > found
> >> > 212 parasites!!!! My system has not froze up since. My question is---in
> >> > looking at the session logs from Webroot SpySweeper this entry keeps
> >> > coming
> >> > up---anyone know what it means??
> >> >
> >> >
> >> > Operation: Registry Access
> >> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSIDRV\
> >> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> >> > 11:22 AM: Tamper Detection
> >> > Operation: Registry Access
> >> > Target: \SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHRMD\
> >> > Source: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
> >> > 11:22 AM: Tamper Detection
> >> >
> >>
> >>
> >>
> >>
> >> SpySweeper protecting its own registry entries from 'tampering' by the
> >> looks
> >> of it.
> >>
> >> A quick google turned up this on one page, which should show you what the
> >> initials stand for
> >>
> >> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSHRMD\0000]
> >> "DeviceDesc"="Spy Sweeper Hookrack MiniDriver"
> >>
> >> [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\ LEGACY_SSIDRV\0000]
> >> "DeviceDesc"="Spy Sweeper Interdiction Driver"
> >>
> >> --
> >> Jon
> >>
> >>
> >> thanks Jon, so it might be nothing to worry about. I hope. How do you
> >> google something like this??

> >
> > Denise

>
>
>
>
> To google it you can use portions of the error message eg 'LEGACY_SSHRMD' or
> 'LEGACY_SSHRMD' along with something like "Tamper Detection" and see what
> turns up.
>
> I'd also run this command from an elevated command prompt (right-click >
> Run as administrator), to verify the integrity of your files (since it's
> clearly been infected).
>
> sfc /scannow
>
> Also if you want to be thorough then this command will show what services
> each 'svchost.exe' is hosting.
>
> tasklist /svc
>
> You can use this information ensure that the services that are running
> should be running.
>
> Otherwise, and perhaps simpler, you could run your various spyware
> detection tools again and verify that they give you the all clear.
>
>
> --
> Jon
>
>
> Thanks Jon...what is an elevated command prompt??

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Vista Freezing dtcar Windows Vista Performance 2 11-28-2007 02:57 PM
IE 7 freezing up belindaloo Windows Vista General Discussion 7 10-24-2007 11:17 AM
freezing Home14 Windows Vista General Discussion 4 07-08-2007 07:35 AM
Freezing hellinoftroy Windows Vista General Discussion 1 06-02-2007 06:15 AM
Freezing in RC1 Paul hayward Windows Vista Performance 3 10-08-2006 09:26 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59