Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Major virus hassles - Win32/hakaglan.G - SCVVHSOT.EXE folder

Reply  
Thread Tools
computertechie's Avatar
Senior Member with 145 posts.
 
Join Date: Jul 2007
Location: England
Experience: Loads
27-Nov-2007, 05:16 PM #1
Major virus hassles - Win32/hakaglan.G - SCVVHSOT.EXE folder
Turned up at a client site this morning to fix a reported synchronisation problem.

A message came up to do with C:\Windows\system32\SCVVHSOT.EXE, so I could tell straight away it was a virus.

On 3 computers, one of them being their main "server" computer it also has the following problems:
- Task Manager is greyed out
- Folder Options has vanished
- Can't run MSConfig
- Can't run regedit

Six hours later....and the customer paying by the hour....a few machines are still playing up.

Started off by doing a scan with AVG Pro, which cleaned up some stuff, then did a Spybot scan which cleaned up a bit more, but the problems remain.

Then loaded the 30-day trial for NOD32, which cleaned up over 1500 infiltrations on one of the computers. Many occurences of Win32/hakaglan.G worm. But it still had the above problems.

Their "server" computer (XP) was still on 25% of the NOD scan when I left tonight and was already up to about 6500 infiltrations!

Has anyone else had this problem with SCVVHSOT.EXE or the mentioned virus before? Are there any removal tools which might do the job??
Nesjemannen's Avatar
Computer Specs
Member with 230 posts.
 
Join Date: Nov 2007
Location: Norway!
Experience: Advanced
27-Nov-2007, 06:16 PM #2
1. Do your virus scans in Safe Mode.

2. Try this spyware tool ( to get the most crap away) :
http://www.superantispyware.com/down...NTISPYWAREFREE

After fully scanning your computer in Safe Mode ( Cut the virus' "Air supply" )
post a Hijackthis log in the Malware and HJT forum.

And yea - It is a virus, or actually a worm - the W32/SillyFDC-AE
____

Good Luck!
bearone2's Avatar
Account Disabled with 5,855 posts.
 
Join Date: Jun 2004
Location: hawaii
Experience: Advanced
27-Nov-2007, 06:21 PM #3
Quote:
Originally Posted by computertechie
Turned up at a client site this morning to fix a reported synchronisation problem.

A message came up to do with C:\Windows\system32\SCVVHSOT.EXE, so I could tell straight away it was a virus.

On 3 computers, one of them being their main "server" computer it also has the following problems:
- Task Manager is greyed out
- Folder Options has vanished
- Can't run MSConfig
- Can't run regedit

Six hours later....and the customer paying by the hour....a few machines are still playing up.

Started off by doing a scan with AVG Pro, which cleaned up some stuff, then did a Spybot scan which cleaned up a bit more, but the problems remain.

Then loaded the 30-day trial for NOD32, which cleaned up over 1500 infiltrations on one of the computers. Many occurences of Win32/hakaglan.G worm. But it still had the above problems.

Their "server" computer (XP) was still on 25% of the NOD scan when I left tonight and was already up to about 6500 infiltrations!

Has anyone else had this problem with SCVVHSOT.EXE or the mentioned virus before? Are there any removal tools which might do the job??
you charge a client by the hour and do an online virus scan, great service to the customer.

it's easier to prevent the virus as opposed to eliminating it afrter the fact but then you're paid by the hour.
computertechie's Avatar
Senior Member with 145 posts.
 
Join Date: Jul 2007
Location: England
Experience: Loads
27-Nov-2007, 06:53 PM #4
Paid by the hour, but sadly straight to the boss not me :-( Plus I'd rather get that sort of job done within 3 hours or so and not take the stress home with me (It's nearly 11pm now).

I looked up this link on the Sophos web site:
http://www.sophos.com/security/analy...illyfdcae.html
But it's a bit of a ******* when you can't get into regedit to delete the offending keys :-( Think that's the first time I've seen a virus disable Task Manager. If only I could get into Task Manager and regedit, I'd be ok.

I'll tell the customer to try out that Free Superantispyware package - they'll try and do as much as they can themselves to keep support costs down.

Is that package likely to remove that virus?
bearone2's Avatar
Account Disabled with 5,855 posts.
 
Join Date: Jun 2004
Location: hawaii
Experience: Advanced
27-Nov-2007, 08:48 PM #5
i doubt it.

f it's a client/more than one machine, why hasn't someone sugested an onboard virus protection system, free or $$$$.

anti spyware isn't virus protection.
Nesjemannen's Avatar
Computer Specs
Member with 230 posts.
 
Join Date: Nov 2007
Location: Norway!
Experience: Advanced
28-Nov-2007, 10:54 AM #6
I know Antispyware isn't virus protection - But it will help take the most crap away.

And he/she should already have a virusscanner of some kind.
bearone2's Avatar
Account Disabled with 5,855 posts.
 
Join Date: Jun 2004
Location: hawaii
Experience: Advanced
28-Nov-2007, 04:15 PM #7
you're dreaming.

maybe not unless you, the tech folks mentioned it.
you said the client wanted to keep $$$ down.

you did an avg scan, then a 30 day nod32 install, so it doesn't sound like any av protection was installed and why the system got hosed.
computertechie's Avatar
Senior Member with 145 posts.
 
Join Date: Jul 2007
Location: England
Experience: Loads
28-Nov-2007, 04:27 PM #8
AVG Pro has been in place there for ages. It failed.

Think the offender was the person in the office running Kazaa!

We left it running NOD32 scans last night in normal mode. Then I told the client to run it in Safe Mode.

They can now access Task Manager, MSConfig and regedit :-)

Have pointed them to that Sophos link and told them what registry keys to delete.
bearone2's Avatar
Account Disabled with 5,855 posts.
 
Join Date: Jun 2004
Location: hawaii
Experience: Advanced
29-Nov-2007, 10:14 PM #9
if they delete enuff registry stuff, you can come back for another 6 hour payday.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:18 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.