Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the HijackThis Log Help forum, or the "First Steps" link at the top right of each page.

Reply
 
Thread Tools
Old 12-27-2007, 01:24 PM   #1 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 4
OS: XP


s2gc.exe

I have just spent the hour searching the web and then this site about this particular file. Can someone give me some info on it and how to rid my pc of it? Thanks so much!

Rick
Rick_699669 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 01:39 PM   #2 (permalink)
alt
Registered User
 
alt's Avatar
 
Join Date: Dec 2007
Location: DFW Texas
Posts: 250
OS: xUbuntu, FedoraCore4, XP Pro SP2


Send a message via AIM to alt
Re: s2gc.exe

Quote:
S2GC.EXE
AUTOMATED SOFTWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:
DEFINITION OF: S2GC.EXE

* Safety Rating: Uncertain
* First seen: Sep 25 2006 (GMT)
* Last seen: Sep 25 2006 (GMT)
* File Size: 5,120 bytes


SOFTWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY
1. COVERT ANALYSIS OF: S2GC.EXE

* File Names Used: 2
* Paths Used: 1
* Common File Name: S2GC.EXE
* Common Path:
* Vendor Information: No Vendor details specified
* File Name Structure: Common
* File and Path Structure: Normal

2. RELATIONSHIP ANALYSIS OF: S2GC.EXE

* No relationship details available for this object

3. ACTIVITY ANALYSIS OF: S2GC.EXE

* The following behaviors have been observed for this object:
* Communicates with web sites using httpout protocols.

4. PROPAGATION ANALYSIS OF: S2GC.EXE

* Object Propagation Rate: Very Low (minimal spread)
* Copyright Prevx Limited 2005, 2006
Have you ran any Spyware removal software?
__________________
This message was sent from my iTimeTravel Device.

Last edited by alt : 12-27-2007 at 01:40 PM.
alt is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 01:42 PM   #3 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 4
OS: XP


Re: s2gc.exe

Ad-Ware and it did not detect it at all... Norton Firewall detected it with the "allow or block" rule. I ran my antivirus but it comes back clean.
Rick_699669 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 01:44 PM   #4 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 26,379
OS: 2000 Pro; XP Pro; XP Home


Re: s2gc.exe

Where is it located on your machine? Is it being called at startup?

What information is available (if any) on it's properties sheet?

Scan it also at VirusTotal

http://www.virustotal.com/en/indexf.html
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006


Please do not ask for help via Private Message.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 01:48 PM   #5 (permalink)
alt
Registered User
 
alt's Avatar
 
Join Date: Dec 2007
Location: DFW Texas
Posts: 250
OS: xUbuntu, FedoraCore4, XP Pro SP2


Send a message via AIM to alt
Re: s2gc.exe

If nothing will detect it and you know where the file is, you can manually delete it. If it won't let you because it is running, here is some software that will delete specified files before windows boots.

http://www.snapfiles.com/get/moveonboot.html
__________________
This message was sent from my iTimeTravel Device.
alt is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 01:50 PM   #6 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 26,379
OS: 2000 Pro; XP Pro; XP Home


Re: s2gc.exe

Rather than just delete it, probably better to find out more about it.

Prevx info is inconclusive, other than it's seeking http access.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006


Please do not ask for help via Private Message.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 02:11 PM   #7 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 4
OS: XP


Re: s2gc.exe

S2GC-0D3BA6F0.pf is what comes up in search on C: drive located in " windows/prefetch "
Rick_699669 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 02:27 PM   #8 (permalink)
alt
Registered User
 
alt's Avatar
 
Join Date: Dec 2007
Location: DFW Texas
Posts: 250
OS: xUbuntu, FedoraCore4, XP Pro SP2


Send a message via AIM to alt
Re: s2gc.exe

Quote:
Originally Posted by tetonbob View Post
Rather than just delete it, probably better to find out more about it.

Prevx info is inconclusive, other than it's seeking http access.

True, also could be used for something (non malicious). I have never heard of it, and there is a lack of info for it. Google doesn't even know!
__________________
This message was sent from my iTimeTravel Device.
alt is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 03:06 PM   #9 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 26,379
OS: 2000 Pro; XP Pro; XP Home


Re: s2gc.exe

Hi Rick_699669 -

Does s2gc.exe exist, or not? If all that's found is a prefetch reference, it may no longer be present.

Run a Windows search for s2gc* as well as for s2gc.exe

@ alt, I agree the lack of info makes it suspicious, which is why I'd like to find out more before just deleting it, if in fact it's still on the machine.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006


Please do not ask for help via Private Message.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 03:15 PM   #10 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 4
OS: XP


Re: s2gc.exe

Yes I ran a windows search and found what I put in the above post. Other than that, with the search ran both ways as you suggest, it is all that shows up. Norton however keeps alerting me as to whether I want to allow it to access the internet or not and shows as a "Low risk". I am now getting "banner type" ads popping up randomly as well that when right clicking on them lets me know it is in "flash" format. Don't know if those two are related or not...
Rick_699669 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-27-2007, 03:20 PM   #11 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 26,379
OS: 2000 Pro; XP Pro; XP Home


Re: s2gc.exe

They may well be....we may want to get some analysis logs from you.

When you go to Start > Search, have you clicked on More Advanced Options and checked the boxes for Search System Folders, Search hidden files and folders, and Search Subfolders ?


Let's do this also:

Please do this:

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  1. Close all applications and windows.
  2. Double-click on dss.exe to run it, and follow the prompts.
  3. When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
  4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt here.
  5. Please attach extra.txt to your post.
To attach a file to a new post, simply
  1. Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
  2. copy and paste the following into the "Upload File from your Computer" box:
    C:\Deckard\System Scanner\extra.txt
  3. Click Upload.

What DSS will do:
  • create a new System Restore point in Windows XP and Vista.
  • clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
  • check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.

---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006


Please do not ask for help via Private Message.

Last edited by tetonbob : 12-27-2007 at 03:22 PM.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 12-28-2007, 08:37 AM   #12 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 2
OS: XP SP2


Re: s2gc.exe

You could try this and see if it comes up with anything:

www.processlibrary.com/processscan/
fenkata is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 09:54 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82