DelphiFAQ Home Search:

bla.exe / Scvhost.exe trojan horse keeps coming back!

 

comments9 comments. Current rating: 5 stars (4 votes). Leave comments and/ or rate it.

Question:

I cannot get rid of this trojan horse bla.exe. I first found it after I kept getting error messages from WinAmp ('Illegal Operation' on drive C:) even though I was not running WinAmp and I have WinAmp installed on drive E:.

I started the computer in safe mode, twice, and removed both of them and they just keep coming back.

Answer:

bla.exe belongs to the W32.HLLW.Gaobot worm. This worm attempts to spread to network shares with weak passwords. W32.HLLW.Gaobot also provides a hacker access to the infected computer through IRC. It uses the DCOM RPC vulnerability (tcp port 135, Windows XP) and the RPC locator vulnerability (tcp port 445).

There is a upx compressed version of this worm, the compressed version is classified as W32.HLLW.Gaobot.AE
It affects computers with Windows NT, Windows 2000 and Windows XP.

Besides running as bla.exe, it may also arrive on your computer as Scvhost.exe, WincfgM32.exe or Winhlpp32.exe.

To remove this trojan horse, you need to follow these steps:
  1. Disable System Restore (Windows XP only)
  2. Restart the computer in Safe mode or VGA mode.
  3. Run an updated virus scanner and run a full system scan and delete all the files detected as W32.HLLW.Gaobot.
  4. Delete the value that was added to the registry under
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    There delete "Config Loader"="scvhost.exe"
    and in
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
    delete "Config Loader"="scvhost.exe"
  5. Now boot again in normal mode


Content-type: text/html

Comments:

2007-02-03, 08:35:28
gchosking@hotmail.cm from United States  
rating
Thanks for the breifing - the scvhost.exe, everytime I'd reboot. I get this pop-up screen. After 50 clicks it would finally go away. Going to try what you suggest, if this doesn't work the next step is reformating.

Again Thanks
2007-03-16, 02:37:14
anonymous from South Africa  
i'm confused, just now i went onto another web page and it said that scvhost was a program that u need to run XP and that if i delete it my computeer wont run, now ur saying it is a virus and i should delete it!!!! what should i do?
2007-03-18, 15:34:46   (updated: 2007-03-18, 15:39:18)
anonymous from Mitchelton in Queensland, Australia  
rating
scvhost is a system file used for networking. XP will run without it but your network won't work properly including your internet connection. This is why worm and virus writers target this exe and infect it, because you really can't do without it.

You will need to extract an original copy of scvhost.exe from your WindowsXP CD after you have removed the infected one. Then you will need to reapply SP2, to get the updated version. You may be able to extract it straight from SP2, though I've never tried.
2007-04-14, 16:20:19
anonymous from United States  
CAREFUL: the virus is scvhost.exe; the Windows file that should be allowed to run is svchost.exe
2007-10-31, 06:16:12
anonymous from Bangalore, India  
rating
SCVHOST.exe is a left over of a virus infection,i had this message(windows could not find scvhost.exe) pop up everytime i start the computer.This happened immedietly after i ran a full AVG scan on the system and it did clean the system-but for this message-it appears like a trojan infection.Also the trojan block several administrative privelages like disabling your task manager,disabling regedit and removing the folder options from the tools menu in the explorer window.it just makes sure that you would not be able to see those infected files....And Oh...it also blocks the different partitions of the harddrive=you get a open with window-it makes the computer believe that the drive is an application/program, by creating a autorun file in every drive/partition...which is hidden by the way and there is no way you can locate those files.but you can delete those files from the command prompt window.
These are the steps which i suggest you do...
1)clean the system by running a full system scan using the latest AVG anti virus
2)in case of task manager being disabled,follow these steps http://support.micr..kb/555480
3)in case of regedit being disabled follow these-locate this registkey
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVerVersio
>n\Policies\System]
>'DisableRegistryTools'=dword:00000000
4)in case the partitions/drives are blocked/dont open-then follow these steps
goto command prompt and type in
del c:\autorun.* /f /s /q /a and enter

del d:\autorun.* /f /s /q /a enter

del e:\autorun.* /f /s /q /a enter
here c,d and e could be your partitions/drives on your computer
This applies to all the partitions that you have and also to any thumbdrives which may have been infected by the trojan

And as for the scvhost.exe pop up,the registry tweak mentioned in the first blog should do the trick
Good Luck...
2008-02-04, 05:15:34
anonymous from United Kingdom  
be for u try to delete SCVHOST.exe from system32 i ues to stop system restore then reboot
into safemode then delete SCVHOST.exe then ues registry editor to find all entres of
SCVHOST and delete them then boot as norm and no mater wot i do sumway sum how it
allways gets back on my computer sumtimes after 6m or 12 and that cus the net is loaded
wae it but after lots of looking n submiting dif verints to Eset NOD32 now stops it be for it
starts :D
oh and if u get the 60s shutdown popup goto start>run then cmd then enter shutdown -r and
that will abort the shutdown that SCVHOST.exe started to stop it from being removed
off ur pc
2008-04-12, 12:38:10
anonymous from Philippines  
you might want to try this site for detailed repair
http://borgetech.bl..om-pc.html
2008-10-08, 22:50:43
[hidden] from Pakistan  
rating
You've mentioned we should disable system restore to get rid of scvhost.exe, so after we're done, shall we not enable system restore again? Sorry im a newbie in thie system restore thing...
2010-05-21, 21:04:56
anonymous from Pakistan  
windows can not find scvohst.exe in my computre

 

 

NEW: Optional: Register   Login
Email address (not necessary):

Rate as
Hide my email when showing my comment.
Please notify me once a day about new comments on this topic.
Please provide a valid email address if you select this option, or post under a registered account.
 

Show city and country
Show country only
Hide my location
You can mark text as 'quoted' by putting [quote] .. [/quote] around it.
Please type in the code:

Please do not post inappropriate pictures. Inappropriate pictures include pictures of minors and nudity.
The owner of this web site reserves the right to delete such material.

photo Add a picture: