New Malware.j

New Malware.j

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
New Malware.j tiago 08-29-2005
Posted by tiago on August 29, 2005, 6:02 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello All...

I Have a problem, that AV detects that virus in svcproc.exe located in
c:\windows... that file is associated to the servise "System Startup
Procedure".. i have disable that service, but when i restart the computer
the virus apeears again..

my computer is XP SP2 (english)

any ideias to remove teh virus?

regards
Tiago



Posted by Malke on August 29, 2005, 2:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman wrote:

>
> | Hello All...
> |
> | I Have a problem, that AV detects that virus in svcproc.exe located
> | in c:\windows... that file is associated to the servise "System
> | Startup Procedure".. i have disable that service, but when i restart
> | the computer the virus apeears again..
> |
> | my computer is XP SP2 (english)
> |
> | any ideias to remove teh virus?
> |
> | regards
> | Tiago
> |
>
> Please submit a sample of "svcproc.exe" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In
> addition, unless told otherwise, Virus Total will provide the sample
> to all paricipating vendors.
>
> When you get the report, please post back the exact reults.
>
>
> Disable the service, run the AV software and clean the PC to remove
> the infector.
>
> Remove the service using the attached Resource Kit Tool
>
> Execute; delsrv ServiceName
>

Although it is always a good idea to submit an unknown file to Virus
Total, this is actually not an unknown file. Tiago, the first step when
you get something like this is always to Google the name. Here's a
Google search using "svcproc.exe":

http://www.google.com/search?q=svcproc.exe&btnG=Search&hl=en&lr=

You will see from the many links that this is hijacking malware related
to the vile Aurora/Nail/ABetterInternet cr*p. Here are general malware
removal steps:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

To add to that (I'm actually working on getting this new information on
the website now), you should download the new VX2 Ad-aware add-on from
Lavasoft. After you install Ad-aware (or if you already have it
installed), put the add-on files in Ad-aware's Plugins directory. Then
run the Add-on. Afterwards, there may still be these files in the
Windows directory:

C:\WINDOWS\ffsnvqmgpiy.exe
C:\WINDOWS\rramcx.exe

Delete them.

You should still go through systematic scanning for malware, but this
should get rid of the offender you posted about.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by tiago on August 31, 2005, 5:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Tanks Mlke and David..... The results of the scan:

Results of a file scan
This is a report processed by VirusTotal on 08/31/2005 at 11:04:59 (CET)
after scanning the file "svcproc.exe.Vir" file.
Antivirus Version Update Result
AntiVir 6.31.1.0 08.31.2005 TR/Stervis.D
Avast 4.6.695.0 08.29.2005 Win32:Stervis
AVG 718 08.29.2005 Generic.AMF
Avira 6.31.1.0 08.31.2005 TR/Stervis.D
BitDefender 7.0 08.31.2005 no virus found
CAT-QuickHeal 8.00 08.30.2005 Trojan.Stervis.d
ClamAV devel-20050725 08.31.2005 no virus found
DrWeb 4.32b 08.31.2005 no virus found
eTrust-Iris 7.1.194.0 08.30.2005 no virus found
eTrust-Vet 11.9.1.0 08.31.2005 no virus found
Fortinet 2.41.0.0 08.31.2005 W32/ProcKill
F-Prot 3.16c 08.31.2005 no virus found
Ikarus 0.2.59.0 08.30.2005 no virus found
Kaspersky 4.0.2.24 08.31.2005 Trojan.Win32.Stervis.d
McAfee 4570 08.30.2005 potentially unwanted program ProcKill-CR
NOD32v2 1.1205 08.30.2005 no virus found
Norman 5.70.10 08.29.2005 W32/Stervis.D
Panda 8.02.00 08.30.2005 Trj/Stervis.D
Sophos 3.97.0 08.31.2005 no virus found
Symantec 8.0 08.30.2005 no virus found
TheHacker 5.8.2.097 08.30.2005 no virus found
VBA32 3.10.4 08.30.2005 Trojan.Win32.Stervis.d





> David H. Lipman wrote:
>
>>
>> | Hello All...
>> |
>> | I Have a problem, that AV detects that virus in svcproc.exe located
>> | in c:\windows... that file is associated to the servise "System
>> | Startup Procedure".. i have disable that service, but when i restart
>> | the computer the virus apeears again..
>> |
>> | my computer is XP SP2 (english)
>> |
>> | any ideias to remove teh virus?
>> |
>> | regards
>> | Tiago
>> |
>>
>> Please submit a sample of "svcproc.exe" to Virus Total --
>> http://www.virustotal.com/flash/index_en.html
>> The submission will then be tested against many different AV vendor's
>> scanners.
>> That will give you an idea what it is and who recognizes it. In
>> addition, unless told otherwise, Virus Total will provide the sample
>> to all paricipating vendors.
>>
>> When you get the report, please post back the exact reults.
>>
>>
>> Disable the service, run the AV software and clean the PC to remove
>> the infector.
>>
>> Remove the service using the attached Resource Kit Tool
>>
>> Execute; delsrv ServiceName
>>
>
> Although it is always a good idea to submit an unknown file to Virus
> Total, this is actually not an unknown file. Tiago, the first step when
> you get something like this is always to Google the name. Here's a
> Google search using "svcproc.exe":
>
> http://www.google.com/search?q=svcproc.exe&btnG=Search&hl=en&lr=
>
> You will see from the many links that this is hijacking malware related
> to the vile Aurora/Nail/ABetterInternet cr*p. Here are general malware
> removal steps:
>
> http://www.elephantboycomputers.com/page2.html#Removing_Malware
>
> To add to that (I'm actually working on getting this new information on
> the website now), you should download the new VX2 Ad-aware add-on from
> Lavasoft. After you install Ad-aware (or if you already have it
> installed), put the add-on files in Ad-aware's Plugins directory. Then
> run the Add-on. Afterwards, there may still be these files in the
> Windows directory:
>
> C:\WINDOWS\ffsnvqmgpiy.exe
> C:\WINDOWS\rramcx.exe
>
> Delete them.
>
> You should still go through systematic scanning for malware, but this
> should get rid of the offender you posted about.
>
> Malke
> --
> Elephant Boy Computers
> www.elephantboycomputers.com
> "Don't Panic!"
> MS-MVP Windows - Shell/User



Posted by David H. Lipman on August 31, 2005, 10:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Tanks Mlke and David..... The results of the scan:
|
| Results of a file scan
| This is a report processed by VirusTotal on 08/31/2005 at 11:04:59 (CET)
| after scanning the file "svcproc.exe.Vir" file.
| Antivirus Version Update Result
| AntiVir 6.31.1.0 08.31.2005 TR/Stervis.D
| Avast 4.6.695.0 08.29.2005 Win32:Stervis
| AVG 718 08.29.2005 Generic.AMF
| Avira 6.31.1.0 08.31.2005 TR/Stervis.D
| BitDefender 7.0 08.31.2005 no virus found
| CAT-QuickHeal 8.00 08.30.2005 Trojan.Stervis.d
| ClamAV devel-20050725 08.31.2005 no virus found
| DrWeb 4.32b 08.31.2005 no virus found
| eTrust-Iris 7.1.194.0 08.30.2005 no virus found
| eTrust-Vet 11.9.1.0 08.31.2005 no virus found
| Fortinet 2.41.0.0 08.31.2005 W32/ProcKill
| F-Prot 3.16c 08.31.2005 no virus found
| Ikarus 0.2.59.0 08.30.2005 no virus found
| Kaspersky 4.0.2.24 08.31.2005 Trojan.Win32.Stervis.d
| McAfee 4570 08.30.2005 potentially unwanted program ProcKill-CR
| NOD32v2 1.1205 08.30.2005 no virus found
| Norman 5.70.10 08.29.2005 W32/Stervis.D
| Panda 8.02.00 08.30.2005 Trj/Stervis.D
| Sophos 3.97.0 08.31.2005 no virus found
| Symantec 8.0 08.30.2005 no virus found
| TheHacker 5.8.2.097 08.30.2005 no virus found
| VBA32 3.10.4 08.30.2005 Trojan.Win32.Stervis.d

McAfee recognized this not as a virus or Trojan but as malware "ProcKill-CR" --
http://vil.nai.com/vil/content/v_133396.htm

Note that this can be used in both bad and good applications. Thus "potentially
unwanted
program" and can have the propensity of being used nefariously.

You can use the following Multi AV tool to scan your system which has the McAfee
scanner as
one of its modules.


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart
scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE.
It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line
Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
malware September 5, 2005, 11:16 am
Malware March 5, 2006, 7:39 am
VBS: Malware (GEN) March 14, 2006, 3:11 pm
Spyware/malware July 20, 2005, 6:09 am
Is ewgef.exe malware? November 12, 2005, 12:03 am
RE: SafetyDefender MalWare April 22, 2006, 5:41 am
Re: SafetyDefender MalWare April 30, 2006, 5:11 pm
pup/malware removal help May 17, 2006, 3:10 pm
Could someone let me know if the following is Malware or related? April 30, 2007, 10:06 pm
What kind of malware might this be? May 20, 2007, 4:50 pm

The site map in XML format XML site map

Contact Us | Privacy Policy