Scvhost still on my computer?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Arlong, Feb 24, 2009.

  1. Arlong

    Arlong Private E-2

    Hello,

    Yesterday I found out that I had scvhost on my computer. So today I did all of the procedures adviced in your cleaning tutorial. It was awesome. Now, when I started looking back at the log of SuperAntiSpyware I saw that the files were actually just quaranteed not deleted. I would like to uninstall SuperAntiSpyware, but what happenes to the files then? I would not like to join a botnetwork again, which is what google told me what scvhost does. Also, is it safe for me if the files are in the quaranteen?

    So, I will attach here logs from all of the programs that were recommended in the tutorial.

    Thanks

    ps. I have vista so I can't use sdfix to get rid of it.
    pps. So, I didn't find Spybot's, or ccleaner's logs so please tell me if you need them.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the last requested log from running MGtools before we can continue. Attach the C:\MGlogs.zip file.
     
  3. Arlong

    Arlong Private E-2

    Okay, will do!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are basically clean but one log in MGlogs.zip was incomplete. Did you notice any error messages while running MGtools? Goto the C:\MGtools folder and double click on the ShowNew.bat file and wait for it to finish running. When it finishes, a notepad window should open with a log in it. You can close this window. Then attach the new MGlogs.zip file which should be updated if ShowNew.bat ran properly.


    Note: You can SUPERAntiSpyware's Manage Quarantine button to remove anything you want from its quarantine. Things in quarantine are no longer a problem.
     
  5. Arlong

    Arlong Private E-2

    I do not remember receiving any error messages while doing the check, but now when I try to execute ShowNew.bat it says 'your OS version is unsupported by ShowNew.bat'. It doesn'tt give me any notepad file, but something happens in the folder since the files "jump" around a little. Neither has it created a new mglogs.zip, I suspect. I believe this because it says it was last modified two day ago. But, to be sure I might as well attach it here.

    Edit: I can't. The forum software says I already have uploaded it to the thread.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you using a non-English version of Windows?

    Your Windows Version information shows the below:

    Microsoft Windows [versio 6.0.6001]

    Instead of:

    Microsoft Windows [Version 6.0.6001]

    Since it did not say Version, this is why ShowNew.bat did not recognize your OS to be supported. Please download the attach ShowNew.zip file to your C:\MGtools folder. Then extract the ShowNew.bat file from this ZIP file into the C:\MGtools folder. Now try running the new ShowNew.bat file. Hopefully it runs. If so, attach the new MGlogs.zip file.
     

    Attached Files:

  7. Arlong

    Arlong Private E-2

    Yes I am actually not on an english windows, but the Finnish version of it. I really didn't know that it would make a difference.

    So, to the point. This time I was able to run the shownew and was able to retrieve the new logs and the .txt. One thing, though, made me wonder, since the last thing the program said was deflated 79% and the it gave me the .txt and stopped. Then I had to manually close the window so I hope I didn't do it in the middle of some reaaalllyyyy loooooong scan.

    Well, anyhow here's the new logs it gave me.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it did because the word version was coming out as version which is not what I was looking for in the program when I try to recognize which version of Windows is running.

    Yes that is what I said to do in message # 4. ;)

    This log is also clean but it shows that you need to do the below.


    Uninstall the below old versions of software:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 7


    Now reboo your PC.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds