All Discussions > Steam Forums > Off Topic > Topic Details
This topic has been locked
Witchfynder Jun 26, 2018 @ 4:07pm
SCPToolkit contains malware
SCPToolkit contains malware.

If you turn on the feature in Windows Defender to have it alert you when unverified apps try to write to areas they shouldn't, and then install scptoolkit, you'll see that it tries to write to your MyVideos folder, and directly to your harddrive or memory.

It doesn't do it itself though, it somehow makes svchost.exe do it.
It does it not only when you install it, but when you uninstall it too.

Here are two entries from event viewer:

C:\Windows\System32\svchost.exe has been blocked from modifying %userprofile%\Videos by Controlled Folder Access.
Detection time: 2018-06-09T07:02:50.446Z
User: Win7corei3\Ken
Path: %userprofile%\Videos
Process Name: C:\Windows\System32\svchost.exe
Signature Version: 1.269.937.0
Engine Version: 1.1.14901.4
Product Version: 4.16.17656.18052


Controlled Folder Access blocked C:\Windows\System32\svchost.exe from making changes to memory.
Detection time: 2018-06-09T06:54:10.669Z
User: NT AUTHORITY\SYSTEM
Path: \Device\HarddiskVolume1
Process Name: C:\Windows\System32\svchost.exe
Signature Version: 1.269.937.0
Engine Version: 1.1.14901.4
Product Version: 4.16.17656.18052


It is common for apps to try to access your MyDocuments folder for legitimate reasons, like game saves or whatever, but they should not be accessing the Videos folder, and definitely should never ever write directly to memory. It says "path" is a hard disk drive in what I show above, so it appers that scptoolkit tried to bypass the OS and write directly to my disk.

THIS IS MALWARE!

If you don't believe me, turn on the Windows Defender feature to block access to protected folders (it is not turned on by default), and try installing or uninstalling scptoolkit.


< >
Showing 1-15 of 34 comments
ゆのーさん Jun 26, 2018 @ 4:14pm 
who cares pretty much everything is malware nowadays
Mio Jun 26, 2018 @ 4:16pm 
Originally posted by Yui <3:
who cares pretty much everything is malware nowadays
heyyyy don't said that! Your cute face isn't... ❤️
ゆのーさん Jun 26, 2018 @ 4:20pm 
Originally posted by Mio:
Originally posted by Yui <3:
who cares pretty much everything is malware nowadays
heyyyy don't said that! Your cute face isn't... ❤️
heey you have a cuter face :Heartyou:
I don't know what that is.
Cynd3r Jun 26, 2018 @ 5:15pm 
Originally posted by Tessa P. DeHart:
I don't know what that is.
A DS4 controller interface and drivers for windows
I had to look up what that even was. I’ll be sure to avoid that.
Blargo Jun 26, 2018 @ 6:26pm 
Used to use it on my older laptop to connect my DS3 controller.
One day it just decided to stop working. Controller wouldn't connect anymore. I always found that suspicious.
L7vanmatre Jun 26, 2018 @ 6:33pm 
Originally posted by Cynd3r:
Originally posted by Tessa P. DeHart:
I don't know what that is.
A DS4 controller interface and drivers for windows
Huh? You mean DualShock 4?

Asking since I use a PS4 controller on my PC and it works just fine directly, so I don't get why you'd need a third party.
L7vanmatre Jun 26, 2018 @ 6:52pm 
Originally posted by Bittman:
Originally posted by L7vanmatre:
Huh? You mean DualShock 4?

Asking since I use a PS4 controller on my PC and it works just fine directly, so I don't get why you'd need a third party.

Do you use it outside of Steam?
Ohh, does Steam make a compatibility thing for it to work?

Though I did use it on a Ubisoft game and it switched to the PS4 stuff.
DefraggedSSD Jun 26, 2018 @ 7:18pm 
Wait does that include scpserver? I used that forever. Never had an issue with it. Never had windows defender, f-secure or malwarebytes give a red flag or anything. Maybe it's in a more recent version?
Witchfynder Jun 26, 2018 @ 11:20pm 
It includes scpserver within it, I think. I'm referring to the ScpToolkit_Setup.exe for installing drivers to use PS3 & PS4 gamepads on the PC. I chose not to install the server portion when I installed it the first time, and it happened then also.

And I got it from github, which is supposed to be the definitive source for it.
SHA-1 hash of it is 5653EF3C4A216681502DD2EEAA7B2B8DCF8D4C1D.
I just tried downloading it again. Same hash.
If anyone downloaded it a year or two ago (they stopped devel in 2015) and has a different hash, please speak up.

The Windows Defender setting that alerted me is called "Controlled Folder Access". Search for that in the WIndows 10 settings gui. It is a good setting to know about anyway. It's a bit of a pain since it will sometimes block friendly apps (steam games included) when you first run them, and you'll have to whitelist them.

You can add folders to the list of protected folders as well. It defaults to Windows system folders, and your Documents, Pictures, Videos, Music, Deskop, and Favorites, as well as the Public versions of those.

O5 Jun 26, 2018 @ 11:22pm 
Originally posted by Yui <3:
Originally posted by Mio:
heyyyy don't said that! Your cute face isn't... ❤️
heey you have a cuter face :Heartyou:
Sorry to just butt in, but I have the cutest face of all. 💜
Last edited by O5; Jun 26, 2018 @ 11:23pm
kate Jun 26, 2018 @ 11:28pm 
Originally posted by MADHEM:
Originally posted by Yui <3:
heey you have a cuter face :Heartyou:
Sorry to just butt in, but I have the cutest face of all. 💜
Hey can I join the free compliment train? ♥💓💖
O5 Jun 26, 2018 @ 11:31pm 
Originally posted by melloh7:
Originally posted by MADHEM:
Sorry to just butt in, but I have the cutest face of all. 💜
Hey can I join the free compliment train? ♥💓💖
Hey, you're almost as cute as I am, ducko!
alicerinz Jun 26, 2018 @ 11:43pm 
Originally posted by MADHEM:
Originally posted by Yui <3:
heey you have a cuter face :Heartyou:
Sorry to just butt in, but I have the cutest face of all. 💜

No,i'm the cutest :PIM023: :borderlands2:
Last edited by alicerinz; Jun 26, 2018 @ 11:44pm
< >
Showing 1-15 of 34 comments
Per page: 1530 50

All Discussions > Steam Forums > Off Topic > Topic Details
Date Posted: Jun 26, 2018 @ 4:07pm
Posts: 34