Показано с 1 по 15 из 15.

Trojan agen/gen-cdesc.(149) & Trojan Win32.Sirefef.a

  1. #1
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27

    Thumbs down Trojan agen/gen-cdesc.(149) & Trojan Win32.Sirefef.a

    Post an earlier problem with Trojan agen/gen-cdesc.(149) and got AVZ and HijackThis to work after running Kaspersky bootable cd which removed Trojan Win32.Sirefef.a.
    These trojans were preventing various programs to work and making them unaccessible. My system is in a mess and I am not quite sure if I am clean of trojans.
    I have uploaded the logs.

    Thank you
    Последний раз редактировалось ChrisB; 12.10.2009 в 02:49.

  2. #2
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для AndreyKa
    Регистрация
    08.01.2005
    Адрес
    Россия
    Сообщений
    13,624
    Вес репутации
    1287
    Run AVZ. Choose from the menu "File" => "Custom scripts", copy/paste code below and run it:
    Код:
    begin
     ExecuteRepair(6);
     RegKeyIntParamWrite('HKLM','SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer','NoDriveTypeAutoRun', 221);
     DeleteFile('C:\Documents and Settings\Christine Blackmore\Start Menu\Programs\Startup\is-3CHD0.lnk');
     DeleteFile('C:\Documents and Settings\Christine Blackmore\Start Menu\Programs\Startup\is-UD3NM.lnk');
     DeleteFile('C:\Documents and Settings\Christine Blackmore\Start Menu\Programs\Startup\is-5JADE.lnk');
     DeleteFile('C:\Documents and Settings\Christine Blackmore\Start Menu\Programs\Startup\is-5UT0G.lnk');
     DeleteFile('C:\Documents and Settings\Christine Blackmore\Start Menu\Programs\Startup\is-UMI96.lnk');
     FSResetSecurity('C:\Program Files\hijackThis\HijackThis1991.exe\HijackThis1991.exe..exe');
     FSResetSecurity('C:\Program Files\Internet Explorer\iexplore.exe');
     FSResetSecurity('C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe');
     FSResetSecurity('C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe');
     FSResetSecurity('C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE');
    end.
    Do you have any problem?

    Remove virusinfo_cure.zip file from your #1 message.
    Последний раз редактировалось AndreyKa; 11.10.2009 в 03:04.

  3. #3
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27

    Windows is in a mess

    Run script OK but I think the trojan has made a mess of the operation of windows.
    Problems: Tried to check windows firewall but a message "Cannot start the windows firewall/internet connection sharing (ICS) service."
    Tried to install Kaspersky internt security but windows just shuts down.
    Can any body help.
    I have uploaded new log files.

    Thank you
    Вложения Вложения

  4. #4
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    843
    Hello.
    execute the script:
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
    QuarantineFile('C:\WINDOWS\Tasks\A78034C191D3AFC1.job','');
    QuarantineFile('C:\WINDOWS\Installer\14b01f.msi','');
    QuarantineFile('C:\Program Files\Common Files\Windows Live\.cache\64559f901c992c7\fssclient_x86.msi','');
    QuarantineFile('C:\Program Files\Common Files\Windows Live\.cache\4bd9a4dc1c971e0\fssclient_x86.msi','');
     QuarantineFile('c:\docume~1\christ~1\applic~1\slowbe~1\Ooze sect five.exe','');
     DeleteFile('c:\docume~1\christ~1\applic~1\slowbe~1\Ooze sect five.exe');
     BC_DeleteFile('c:\docume~1\christ~1\applic~1\slowbe~1\Ooze sect five.exe');
    DeleteFile('C:\WINDOWS\Installer\14b01f.msi');
    DeleteFile('C:\Program Files\Common Files\Windows Live\.cache\64559f901c992c7\fssclient_x86.msi');
    DeleteFile('C:\Program Files\Common Files\Windows Live\.cache\4bd9a4dc1c971e0\fssclient_x86.msi');
    DeleteFile('C:\WINDOWS\Tasks\A78034C191D3AFC1.job');
    BC_DeleteFile('C:\WINDOWS\Tasks\A78034C191D3AFC1.job');
    BC_DeleteFile('C:\WINDOWS\Installer\14b01f.msi');
    BC_DeleteFile('C:\Program Files\Common Files\Windows Live\.cache\64559f901c992c7\fssclient_x86.msi');
    BC_DeleteFile('C:\Program Files\Common Files\Windows Live\.cache\4bd9a4dc1c971e0\fssclient_x86.msi');
    BC_ImportquarantineList;
    BC_Activate;
    ExecuteSysClean;
    RebootWindows(true);
    end.
    After restart, upload quarantine via the link http://virusinfo.info/upload_virus_eng.php?tid=56877 as it's described in the app.3 of the rules and make new logs.

  5. #5
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27

    New log files

    Run script, uploaded quarentine flie and have made new log files.
    Вложения Вложения

  6. #6
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    843
    I see nothing harmful in your logs. Your system seems to be clean. If you have problems with your system's work, could you describe them here, please?

  7. #7
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27
    Still have problems: Tried to check windows firewall but a message "Cannot start the windows firewall/internet connection sharing (ICS) service."
    Tried to install Kaspersky internt security 2009 on CD but windows just shuts down.
    Install Kaspersky internwt security 2010 trialware but did not install properly not all services are working and when I trie to up date I can not get a full update.
    When windows starts windows finds new hardware scsi adapter but I can not find the drivers. I intalled new Nvidia graphic drivers to see if that would cure hardware problem but did not solve the problem.

  8. #8
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    843
    about the first problem: open the command line and execute the command:
    Код:
    sc query sharedaccess
    Copy results here if it's possible. And make also this log.

  9. #9
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27

    Here is the log file

    Ran "sc query sharedaccess" but could not see what was in the command window it appeared to quickly.
    I have ran GMER and have uploaded log file number 18.
    Вложения Вложения
    • Тип файла: log 18.log (1.2 Кб, 4 просмотров)

  10. #10
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    843
    My fault - I should have explained more correctly. What you should do is to run cmd.exe command. The console interface will appear - a black window with the command line. You should type sc query sharedaccess command there and press "enter". Then you will be able to see the results and copy them and insert them in your post here.
    As for Gmer log - it adds nothing new - there is nothing harmful or even suspicious there.
    Последний раз редактировалось Numb; 19.10.2009 в 15:20.

  11. #11
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27
    Here is the results-

    SERVICE_NAME: sharedaccess
    TYPE : 20 WIN32_SHARE_PROCESS
    STATE : 1 STOPPED
    (NOT_STOPPABLE,NOT_PAUSABLE,IGNORES_SHUTDOWN)
    WIN32_EXIT_CODE : 1068 (0x42c)
    SERVICE_EXIT_CODE : 0 (0x0)
    CHECKPOINT : 0x0
    WAIT_HINT : 0x0

  12. #12
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    843
    Ok. It seems that this service is stopped. To start it again and to make it to start automatically, run one by one the follow commands:
    Код:
    sc start sharedaccess
    sc config sharedaccess start= auto
    After that try to check windows firewall again.

  13. #13
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27
    Ran "sc start sharedaccess" result "StartService FAILED 1068:"
    Ran "sc config sharedaccess start= auto result "changeServiceConfig SUCCESS"

    firewall still has the message "Cannot start the windows firewall/internet connection sharing (ICS) service."

  14. #14
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    967
    Execute this script in avz or avptool:
    Код:
    begin
    ExecuteRepair(6);
    ExecuteRepair(8);
    ExecuteRepair(9);
    RebootWindows(true);
    end.
    Computer will reboot.Then:
    Right-click My Computer > Manage > Services and Applications >
    Services. In the right-hand pane, scroll down to right-click on the
    Internet Connection Firewall and select Properties. Click the
    Dependencies Tab. Make sure that all of the listed system
    components/services are shown as started in the Services list.
    Also, you can try this: http://support.microsoft.com/default...tMeFixItMyself
    Personally, i did disable windows firewall, because don't like it
    Последний раз редактировалось drongo; 21.10.2009 в 02:00.

  15. #15
    Junior Member Репутация
    Регистрация
    26.09.2009
    Сообщений
    10
    Вес репутации
    27

    Thank you

    Tried the above solutions but did not work.
    I have now reinstalled windows and everything is OK and runs faster and better.

    Thank you all for your help in removing the trojan and trying to solve windows problems.

    ChrisB

Похожие темы

  1. Вирус Trojan:Win64/Sirefef
    От АлексейМурианно в разделе Помогите!
    Ответов: 2
    Последнее сообщение: 31.05.2012, 18:50
  2. вирус trojan:win32/Sirefef
    От kate11 в разделе Помогите!
    Ответов: 7
    Последнее сообщение: 10.04.2012, 17:43
  3. Вирус Trojan:Win64/Sirefef...
    От grinog4 в разделе Помогите!
    Ответов: 9
    Последнее сообщение: 29.12.2011, 15:49
  4. Ищу описание Trojan.Win32.Scar.Btuw, Trojan.MulDrop, Trojan.Siggen1, Trojan.PWS.Ibank
    От v119 в разделе Описания вредоносных программ
    Ответов: 1
    Последнее сообщение: 15.03.2010, 13:56
  5. Trojan agen/gen-cdesc.(149)
    От ChrisB в разделе Malware Removal Service
    Ответов: 2
    Последнее сообщение: 29.09.2009, 18:51

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.00265 seconds with 22 queries