svchost.exe - Dangerous
%windir%\ime\svchost.exe
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
W32.Emiutao is a worm that spreads through removable storage devices. It also opens a back door on the compromised computer.
Related files:
%Windir%\IME\ime.exe
%Windir%\IME\svchost.exe
%Windir%\IME\Thumbs.db
%Windir%\IME\ime.sys
%Windir%\IME\Thumbs.sys
%UserProfile%\Start Menu\Programs\Startup\Adobe Gamma loader.lnk
%Windir%\IME\MSVBVM60.DLL
%Windir%\IME\MSWINSCK.DEP
%Windir%\IME\MSWINSCK.oca
%Windir%\IME\MSWINSCK.OCX
%Windir%\IME\mswsock.dll
%Windir%\IME\STDOLE2.TLB
%Windir%\IME\VB6.OLB
[DRIVE LETTER]\autorun.inf
[DRIVE LETTER]\Thumbs.dn\1.{3aea-1069-a2de-08002b30309d}\Thumbs.bat
[DRIVE LETTER]\Thumbs.dn\Desctop.ini
Kill the process %WinDir%\IME\svchost.exe and remove %WinDir%\IME\svchost.exe from Windows startup.