An undetectable malware, how to effectively remove from the system.

Battousai001

Senior member
Oct 27, 2004
214
0
0
Hi guys, I need help. My colleague got his workstation infested. After thorough checking of his workstation I have concluded that it was infested by a malware, the initial symptoms are weird and garbled character message on yahoo messenger and weird garbled message appearing on spreadsheets which is very annoying. This malware also disabled a lot of system functions such as registry editor, task bar, tools/folder options, msconfig, services etc.

I have installed a myriad of antispyware/antiadware such as lavasoft's ad aware, spybot search and destroy and microsoft's windows defrender (the workstation has a mcafee enterprise antivirus installed prior to infestation), after thorough scanning the antispywares have found lots of malware in the system and i have removed it through the antispyware. After reboot I noticed that this advanced malware is still in the system and realized that the myriad of anytispyware has no match with this type of infestation.

After further checking I learned that this malware has a central file named "SCVHSOT.EXE" and I made further google searches and found this substantial information:

http://www.prevx.com/filenames...68-X1/SCVHSOT.EXE.html

But before I came across that information I have tried this one extensive solution I got from google:

http://www.daniweb.com/blogs/entry1746.html

The procedure on that site above helped a bit, as in the task manager and registry editor didn't work at all previously, and now they appear for a fraction of a second and disappear so I still cant get into the registry editor and task manager and I cant find the other accessory files of the malware.

I have tried the "Prevx CSI free PC checker" at http://www.prevx.com and I was surprised that this is the only scanner than can see these malware files but I cant use it to clean the system as it needs to be purchased.

I made further search and have found a very informative solution which I will be trying tomorrow and will give you an update, but if you guys have some other tips and advice please do share it as I am still not sure if I will be able to remove this malware using the instruction at this

http://piyushlabs.wordpress.co...glannew-foldersvchost/

Well to share with you guys, one thing I learned from this is that not all popular antispyware or antimalware can detect infestations like this, just like according to this site http://www.prevx.com (if ever they are highly credible) check the graph on the front page.
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
Originally posted by: Battousai001
I have installed a myriad of antispyware/antiadware such as lavasoft's ad aware, spybot search and destroy and microsoft's windows defrender (the workstation has a mcafee enterprise antivirus installed prior to infestation), after thorough scanning the antispywares have found lots of malware in the system and i have removed it through the antispyware. After reboot I noticed that this advanced malware is still in the system and realized that the myriad of anytispyware has no match with this type of infestation.
Unfortunately all of those applications have inadequate detection and removal capabilities and are in a sense "worthless". If you run thru my malware guide chances are you'll nuke your infestations. Good luck!

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Also,

1) if you have an Information Technology person, let them know about the infection. It can be important for them to know about.

2) you might want to take steps to prevent future attacks and here are some steps to consider (adapt as needed, I don't know your work/computer scenario).
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Originally posted by: mechBgon
Also,

1) if you have an Information Technology person, let them know about the infection. It can be important for them to know about.

Big ditto, here.

Battousai001, mech's point was was the first question I had when I read your post, i.e., why isn't your friend's IT Dept. working to fix this?

Anyway, just telling us that "SCVHSOT.EXE" is on your friend's computer doesn't provide enough information. It can be a backdoor bot, or a trojan that spreads via network shares, etc. It depends on what it's doing in the Registry. Unfortunately, most times, it does have backdoor functionality.

If you want to help your friend, I can assist you. Have your friend run HijackThis, version 2.0.2, and PM me his HijackThis log.

 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
It's possible that Battousai001 is the IT dept.
 

Battousai001

Senior member
Oct 27, 2004
214
0
0
Hi guys, sorry for the late reply, heres an update. The malware has been removed by our system administrator. I dont know how he did it because I was out of the office. Actually my colleague is not a techie so he is the only one who got infected. I work for the other department and my colleague was unable to report this until this morning. Anyway Thanks for all the replies!
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |