Trojan horse BackDoor.Generic3.EKW

Trojan horse BackDoor.Generic3.EKW

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojan horse BackDoor.Generic3.EKW =?Utf-8?B?c3BnYW5kYXU=?= 09-09-2006
Posted by =?Utf-8?B?c3BnYW5kYXU=?= on September 9, 2006, 10:14 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Windows XP home edition SP2
IE 6.0.2900
AVG free edition
Spybot S&D

My daughter clicked on a link and I got infected with this virus.
I discovered the problem when I used Spybot S&D to scan my machine.
I used AVG free edition to scan the entire computer. There were four
instances of the virus in the System Volume Information\_restore.... location.
I was able to get into the System Volume Information and used AVG to move
the infected files into the Virus Vault.

Next, I re-ran Spybot S&D to get the exact message information related to
the problems discovered.
The registry has been changed by the trojan, and this is where my
question(s) lie:

1. HKLM\System\CurrentControlSet\Services\wscsvc\Start!=W=2
SpyBot S&D shows that the above line is a security breach, and it directs me
to this line in the registry.

Anyone know where I can get exact information? I have read the MS security
related to a similar version (Generic3.BGG), but the registry keys that
Microsfot refers to are called "wgavm" and "wgareg".... and apparently they
are bogus keys and need to be deleted...??

Question: Is wscsvc a legitimate entry? It would appear that wscsvc was an
added entry created by the trojan, but I am not sure. Can I delete the
entire "wscsvc" key?

2. There are changes made in the antivirus, firewall, and SP2update settings
that shut them down. Any advice on how to correct the registry entries would
be appreciated. I used Control Panel / Security settings, but the firewall
was "locked OFF", and it would appear that I have lost administrator
privileges to reset the firewall to "ON". Is it possible that the mscsvc key
controls these settings?

See below for relevant entries made by Spybot S&D:

Windows Security Center.AntiVirusDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusDisableNotify!=dword:0

Windows Security Center.AntiVirusOverride: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusOverride!=dword:0

Windows Security Center.FirewallDisabled: Settings (Registry change, nothing
done)

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\domainprofile\enablefirewall!=dword:1

Windows Security Center.FirewallDisabled: Settings (Registry change, nothing
done)

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\standardprofile\enablefirewall!=dword:1

Windows Security Center.FirewallDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallDisableNotify!=dword:0

Windows Security Center.FirewallOverride: Settings (Registry change, nothing
done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallOverride!=dword:0

Windows Security Center.SP2Update: Settings (Registry change, nothing done)

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0

Windows Security Center.UpdateDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\UpdatesDisableNotify!=dword:0


Any help would be appreciated.

Posted by =?Utf-8?B?UGFuZGFfbWFu?= on September 10, 2006, 6:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
My reply is at the bottom of your message :


"spgandau" wrote:

> Windows XP home edition SP2
> IE 6.0.2900
> AVG free edition
> Spybot S&D
>
> My daughter clicked on a link and I got infected with this virus.
> I discovered the problem when I used Spybot S&D to scan my machine.
> I used AVG free edition to scan the entire computer. There were four
> instances of the virus in the System Volume Information\_restore.... location.
> I was able to get into the System Volume Information and used AVG to move
> the infected files into the Virus Vault.
>
> Next, I re-ran Spybot S&D to get the exact message information related to
> the problems discovered.
> The registry has been changed by the trojan, and this is where my
> question(s) lie:
>
> 1. HKLM\System\CurrentControlSet\Services\wscsvc\Start!=W=2
> SpyBot S&D shows that the above line is a security breach, and it directs me
> to this line in the registry.
>
> Anyone know where I can get exact information? I have read the MS security
> related to a similar version (Generic3.BGG), but the registry keys that
> Microsfot refers to are called "wgavm" and "wgareg".... and apparently they
> are bogus keys and need to be deleted...??
>
> Question: Is wscsvc a legitimate entry? It would appear that wscsvc was an
> added entry created by the trojan, but I am not sure. Can I delete the
> entire "wscsvc" key?
>
> 2. There are changes made in the antivirus, firewall, and SP2update settings
> that shut them down. Any advice on how to correct the registry entries would
> be appreciated. I used Control Panel / Security settings, but the firewall
> was "locked OFF", and it would appear that I have lost administrator
> privileges to reset the firewall to "ON". Is it possible that the mscsvc key
> controls these settings?
>
> See below for relevant entries made by Spybot S&D:
>
>


Hello ! Slow things down , your computer is still not clean to touch the
registry.

Perform stricktly the instructions here to remove all the malware you have :
http://pandaman.my.contact.bg
http://pandaman.my.contact.bg/Gen_MRI.htm

Leave Spybot S&D fix what is has found , the same applies to all other
applications offered.

After that , if you have problems with starting Windows Firewall from
Control Panel -> Windows Firewall , try and read these:

Due to an unidentified problem, Windows cannot start Windows Firewall error,
try:
Start->Run
type:
regsvr32 hnetcfg.dll
and press ENTER


Also read these:
http://support.microsoft.com/default.aspx?kbid=875357
http://support.microsoft.com/kb/920074/en-us



--
Panda_man
Bronze level Contributor

Posted by David H. Lipman on September 10, 2006, 8:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| Windows XP home edition SP2
| IE 6.0.2900
| AVG free edition
| Spybot S&D
|
| My daughter clicked on a link and I got infected with this virus.
| I discovered the problem when I used Spybot S&D to scan my machine.
| I used AVG free edition to scan the entire computer. There were four
| instances of the virus in the System Volume Information\_restore.... location.
| I was able to get into the System Volume Information and used AVG to move
| the infected files into the Virus Vault.
|
| Next, I re-ran Spybot S&D to get the exact message information related to
| the problems discovered.
| The registry has been changed by the trojan, and this is where my
| question(s) lie:
|
| 1. HKLM\System\CurrentControlSet\Services\wscsvc\Start!=W=2
| SpyBot S&D shows that the above line is a security breach, and it directs me
| to this line in the registry.
|
| Anyone know where I can get exact information? I have read the MS security
| related to a similar version (Generic3.BGG), but the registry keys that
| Microsfot refers to are called "wgavm" and "wgareg".... and apparently they
| are bogus keys and need to be deleted...??
|
| Question: Is wscsvc a legitimate entry? It would appear that wscsvc was an
| added entry created by the trojan, but I am not sure. Can I delete the
| entire "wscsvc" key?
|
| 2. There are changes made in the antivirus, firewall, and SP2update settings
| that shut them down. Any advice on how to correct the registry entries would
| be appreciated. I used Control Panel / Security settings, but the firewall
| was "locked OFF", and it would appear that I have lost administrator
| privileges to reset the firewall to "ON". Is it possible that the mscsvc key
| controls these settings?
|
| See below for relevant entries made by Spybot S&D:
|
| Windows Security Center.AntiVirusDisableNotify: Settings (Registry change,
| nothing done)
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
| Center\AntiVirusDisableNotify!=dword:0
|
| Windows Security Center.AntiVirusOverride: Settings (Registry change,
| nothing done)
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
| Center\AntiVirusOverride!=dword:0
|
| Windows Security Center.FirewallDisabled: Settings (Registry change, nothing
| done)
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\domainprofile\enablefirewal
| l!=dword:1
|
| Windows Security Center.FirewallDisabled: Settings (Registry change, nothing
| done)
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windowsfirewall\standardprofile\enablefirew
| all!=dword:1
|
| Windows Security Center.FirewallDisableNotify: Settings (Registry change,
| nothing done)
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
| Center\FirewallDisableNotify!=dword:0
|
| Windows Security Center.FirewallOverride: Settings (Registry change, nothing
| done)
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
| Center\FirewallOverride!=dword:0
|
| Windows Security Center.SP2Update: Settings (Registry change, nothing done)
|
|
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dwor
| d:0
|
| Windows Security Center.UpdateDisableNotify: Settings (Registry change,
| nothing done)
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
| Center\UpdatesDisableNotify!=dword:0
|
| Any help would be appreciated.

Trojan horse BackDoor.Generic3.EKW is not a virus. As the name indicates, it
was a Trojan.
C:\System Volume Information\_restore
Is the System Restore cache. If it was in the System Restore cache, then it
must have been
on the system to be cached but you don't note it present.



Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
trjan horse backdoor.Generic3.LFJ September 15, 2006, 7:07 am
trojan horse backdoor irc/sdbot.myx December 15, 2005, 5:29 pm
trojan horse IRC/backdoor.sdbot.myx December 15, 2005, 5:35 pm
Anybody got a fix for BackDoor.Generic3.LRT? October 27, 2006, 11:44 pm
Trojan Horse June 28, 2005, 11:58 pm
Trojan Horse (New?) July 17, 2005, 12:45 pm
Trojan Horse September 20, 2005, 6:15 pm
Trojan horse October 8, 2005, 2:29 am
Trojan Horse January 8, 2006, 11:06 am
Bla trojan horse??? February 9, 2006, 4:06 pm

The site map in XML format XML site map

Contact Us | Privacy Policy