SCVHOSTS one step ahead of me

Discussion in 'Malware Help (A Specialist Will Reply)' started by pedestrian, Nov 24, 2007.

  1. pedestrian

    pedestrian Private E-2

    My system is occupied by SCVHOSTS.EXE. My Zone Alarm firewall says it is blocking its many attempts to connect. The SUPERAntiSpyware I installed yesterday shows it running in the Not Recognized category.

    I tried following step by step the READ & RUN ME FIRST. Malware Removal Guide. But the Trojan seems to be one step ahead of me. When I try Run with msconfig for startup cleaning, the screen flashes and disappears. (I have XP and it used to work before.) When I try to bring out hidden files, the Tools menu in Explore screen shows only these options - Map Network Drive..., Disconnect Network Drive..., and Synchronize... No Folder Options.

    Please help me with different steps. I have not yet downloaded Hijack This. (I am not a Major Geek. Not even a Geek...) Thank you very much.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Try the below version of the READ ME. This is a new shorter and better version. Click the below link not the one you see in the sticky thread in the forum page.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    Read & RUN ME FIRST Before Asking for Support

    If you cannot do certain steps, just skip them and continue all the way thru. When you finish doing all steps, attach the requested logs and explain what you could not do so that we know all the problems you had.
     
  3. pedestrian

    pedestrian Private E-2

    Thank you very much. It worked. What also helped was that during the process I replaced the older NOD32 I had with the AVG free virus protector and in the initial scan it identified the files with this trojan and removed them. Your guidance regarding System Restore was particularly useful in ensuring that it did not surface again.
    Thank you very much for all the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome, but you should consider attaching all of the requested logs just to make sure you are really clean. Problems like this often do not come alone.
     
  5. pedestrian

    pedestrian Private E-2

    Am attaching the Combofix and MGlogs files. The reports page of AVG AntiSpyware shows no reports even though I had checked the box to automatically generate reports after every scan.

    I had gone to Normal startup mode as suggested by you and after the process was over, I had switched back to selective start up mode. Now whenever I boot the computer, a screen appears asking me to choose normal start up mode and undo changes made using system configuration utility. Please advise which start up mode I should use.

    The system is significantly slower than it used to be. What should I do to overcome this? Thank you for your help.
     
  6. pedestrian

    pedestrian Private E-2

    Just one more info. When the AVG Anti-Virus deleted four files, they were SAB12B.Zip in Temp, hinhem.scr and scvhosts.exe in Windows and blastclnnn.exe in system32. All of them showed as Trojan horse Generic_c.DIQ under item details. I was able to run msconfig only after this clean up. Thank U.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything. You have to make sure you browse to the files and select them and then also click upload to actually attach them.
     
  8. pedestrian

    pedestrian Private E-2

    Sorry, Let me try again. The last time too the preview showed the attached files. Hope this succeeds now.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not show any malware problems but I do have a few non-malware things you shoud do.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  10. pedestrian

    pedestrian Private E-2



    I do not have Avenger. Should I get it? Have done all you said. MGlogs attached. No more startup mode prompt. Speed has certainly improved to some extent. My Zone Alarm blocks svchost.exe and jusched.exe (Java?). Should it? Thank you very much.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No it is not necessary to block svchost.exe as long as it is the one running from your system32 folder. jusched.exe is just for automatic updates to Sun Java. You don't really need this to always be running and thus you can just have HijackThis fix the below startup;


    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"


    After fixing that, ZoneAlarm should not mention it again since it is not running anymore. (That's is until the next time you install a new Sun Jave version).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds