Hidden Object, Rootkit
Posted: Fri Aug 10, 2007 9:20 am
A friend of mine gave me his Fujitsu Siemens SCALEO P to sort out because it was badly infected. i installed Kaspersky AV and ran a full system scan, it found 26 threats, 9 of which were Trojans and 1 was a 'Virus Package' (whatever that means), the rest were Ad/Spyware. I then installed and ran SpyBot - Search and Destroy, it found 185 entries which were all dealt with.
The thing is Kaspersky is still showing a threat, a pop up appears with "detected: riskware Hidden object Running process: C:\WINDOWS\system32\wscphost.exe", it asks if i want to Quarantine, Terminate or Allow. Of course i selected Quarantine, but i got an error, a few minutes later it popped up again and this time i selected Terminate. My friend has a legit key on the case itself, but he can't find his Windows XP Home disc, and i have XP Pro, otherwise i would just format and reinstall Windows. I tried searching Google for both wscphost and wscphost.exe, which found absolutely NOTHING.
I went in to the System32 folder to try and manually delete this file, but i couldn't find it despite using the Folder Options to show hidden and protected files. Then i tired using the Command Prompt in Windows to delete it, but it says File Not Found. After that i thought about trying Safe Mode, so i rebooted and selected 'Safe Mode with Command Prompt'. Once it loaded up i went in to C:\WINDOWS\System32 and typed Del wscphost.exe, and it appeared to work, i didn't get 'File not Found'.
I haven't had any more pop ups from Kaspersky, never the less, i am still not completely happy that i have totally dealt with this thing, so that's why i am asking if anyone here can tell me what i need to do, or if you think what i have done is enough? Any advice or comments are welcome.
Thanks.
The thing is Kaspersky is still showing a threat, a pop up appears with "detected: riskware Hidden object Running process: C:\WINDOWS\system32\wscphost.exe", it asks if i want to Quarantine, Terminate or Allow. Of course i selected Quarantine, but i got an error, a few minutes later it popped up again and this time i selected Terminate. My friend has a legit key on the case itself, but he can't find his Windows XP Home disc, and i have XP Pro, otherwise i would just format and reinstall Windows. I tried searching Google for both wscphost and wscphost.exe, which found absolutely NOTHING.
I went in to the System32 folder to try and manually delete this file, but i couldn't find it despite using the Folder Options to show hidden and protected files. Then i tired using the Command Prompt in Windows to delete it, but it says File Not Found. After that i thought about trying Safe Mode, so i rebooted and selected 'Safe Mode with Command Prompt'. Once it loaded up i went in to C:\WINDOWS\System32 and typed Del wscphost.exe, and it appeared to work, i didn't get 'File not Found'.
I haven't had any more pop ups from Kaspersky, never the less, i am still not completely happy that i have totally dealt with this thing, so that's why i am asking if anyone here can tell me what i need to do, or if you think what i have done is enough? Any advice or comments are welcome.
Thanks.