Problem at Startup - Hazim's Issue

  • Thread starter Thread starter hazim
  • Start date Start date
Click For Summary

Discussion Overview

The discussion revolves around a user's experience with a potential virus or worm on their Windows system, specifically related to a file named 'sevcst.exe'. Participants share various strategies for detecting and removing the file, as well as tools and methods for managing startup programs and system security.

Discussion Character

  • Exploratory
  • Technical explanation
  • Debate/contested
  • Homework-related

Main Points Raised

  • The original poster (hazim) reports a problem with a file that appears to be a virus or worm, noting suspicious properties and a connection to a hacker.
  • Some participants suggest using multiple antivirus programs to detect the issue, including AVG Free and Trend Micro Housecall.
  • One participant recommends booting into safe mode to remove the suspicious file.
  • Another suggests disabling system restore to prevent the file from replicating after deletion.
  • Several participants mention using 'autoruns' from Sysinternals to manage startup programs and monitor system processes.
  • There is a discussion about the compatibility of different antivirus programs, with one participant questioning whether to remove PC Tools before installing AVG.
  • The original poster later reports successfully deleting the file in safe mode and resolving the issues, but notes that AVG did not detect anything afterward.

Areas of Agreement / Disagreement

Participants generally agree on the need for antivirus measures and the utility of specific tools like 'autoruns', but there are varying opinions on the effectiveness of different antivirus programs and the best approach to take for removal. The discussion includes both shared strategies and individual experiences, indicating no consensus on a single solution.

Contextual Notes

Limitations include the lack of detailed information about the nature of the file and the effectiveness of the proposed solutions, as well as the potential for differing results based on individual system configurations.

Who May Find This Useful

This discussion may be useful for users experiencing similar issues with potential malware on their Windows systems, as well as those seeking advice on antivirus tools and system management techniques.

hazim
Messages
34
Reaction score
0
I got this problem about two weeks ago.. as you see in the first picture, "windows cannot find 'C:\WINDOWS\Config\sevcst.exe'..." I searched for the file and i found a file with the same name but in system32, even as you see in its properties in the other picture, this file seems as a virus or worm..I have seen before the same properties as this file in another files with names: "Pictures", and "My Pictures" and also with the same icon...I hope to get more information about this virus/worm (kaspersky didn't detect it). what is strange is the comments in "other version information in the file's properties as you can see where there is written "Designed and Programed by: X-LEB the most dangerous hacker in the Middle-East!" note that I'm from Lebanon (in Middle East) and "LEB" refers to Lebanon!

hope anyone help me get out these two problems.

hazim.

http://www.imagehosting.com/out.php/i1571143_untitled.JPG

http://www.imagehosting.com/out.php/i1571153_untitled1.JPG
 
Computer science news on Phys.org
Boot into safemode and remove it from there.
 
You may have to turn off system restore when you delete it. If you don't, the file may replicate itself the next time you boot up.
 
Also get a copy of 'autoruns' from sysinternals - it lists all the programs that are set to run at startup and allows you to turn them off.
It's also useful for keeping track of all those toolbar utils that everythign decides to install.
 
mgb_phys said:
Also get a copy of 'autoruns' from sysinternals - it lists all the programs that are set to run at startup and allows you to turn them off.
It's also useful for keeping track of all those toolbar utils that everythign decides to install.
You can do the same thing for free through the control panel and the administrative tools.
 
Autoruns is free and conveniently lists all the apps started by the dozen different mechanisms - they are all listed in the registry, this is just easier.
 
The Services dialog gives you pretty much the same thing. It tells you what loaded and if it is automatically loaded. You can turn things on and off as well. It is pretty helpful if you don't already have some other software to do it.

Free is good. I haven't been able to find a free version of software that does that. I have tried some others and they were ok, but the trial was over pretty quickly.
 
Wow ! Great thread
I'm currently running SpyBot S&D, which seems to protect my Reg. Also i have PC Tools, which seems to filter a lot of adware, but I'm not too happy with it's total performance, i don't think it is anti-vir?
If i try Avg, should i remove PC Tools first, or would they be compatible with each other?
 
  • #10
thanks all for information and attention...I just deleted that file in safe mode and system restore disabled, and the problems were solved...i installed AVG and and scanned the pc, it didn't detect anything...thanks for you.
 

Similar threads

  • · Replies 5 ·
Replies
5
Views
3K
Replies
5
Views
2K
  • · Replies 2 ·
Replies
2
Views
2K
  • · Replies 5 ·
Replies
5
Views
3K
Replies
2
Views
6K
  • · Replies 3 ·
Replies
3
Views
2K
  • · Replies 1 ·
Replies
1
Views
2K
  • · Replies 1 ·
Replies
1
Views
5K
  • · Replies 1 ·
Replies
1
Views
3K
Replies
10
Views
5K