Solved

w32/Conficker!mem trojan

Posted on 2009-07-04
8
7,863 Views
Last Modified: 2013-11-08
w32/Conficker!mem trojan
svchost could not be repaired
c.JPG
0
Comment
Question by:tomar_10
8 Comments
 
LVL 3

Expert Comment

by:Saxtus
ID: 24778941
0
 

Author Comment

by:tomar_10
ID: 24778961
i have tried but it says nothinf foun you can see the log

But stinger says it exist

Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.

C:\Documents and Settings\admin>cd desktop

C:\Documents and Settings\admin\Desktop>cd conficker

C:\Documents and Settings\admin\Desktop\conficker>econfickerremover
Win32/Conficker worm Removal Tool build: Jun 22 2009 (c) 2009 ESET, spol. s r.o.

Usage: removaltool.exe <options>
Options:  -autoclean  - clean automatically without confirmation
          -reboot     - reboot machine after successful cleaning
          -force      - force deletion of Conficker-like scheduled tasks
Win32/Conficker worm has not been found active in the memory.
Do you want to perform scanning and cleaning anyway? (y/n)
Nothing was found.
Checking for Win32/Conficker.AA files:
Nothing was found.



0
 

Author Comment

by:tomar_10
ID: 24778966
i face this problem
c1info.JPG
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 3

Expert Comment

by:Saxtus
ID: 24778976
I was trying to save you from a lot bigger download.
Here it is: ftp://ftp.f-secure.com/anti-virus/tools/beta/fsmrt.zip
0
 
LVL 47

Accepted Solution

by:
rpggamergirl earned 500 total points
ID: 24779038
You would need to install the MS Patch mentioned in the link if you haven't yet.
http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx


And run removal like the tools below:
F-Secure Removal tool:
ftp://ftp.f-secure.com/anti-virus/tools/DownadupRemovalTool.zip
ftp://ftp.f-secure.com/anti-virus/tools/beta/f-downadup.zip

MS Malicous Removal tool:
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&disp 
laylang=en

Symantec's W32.Downadup Removal Tool:
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-011316-0247-99



Also good idea to run Combofix, it should replace svchost.exe if it finds a clean one in the system.

Please download ComboFix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
(If it doesn't run re-download but rename before saving to your desktop)


Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
 

If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix 

 
0
 

Author Comment

by:tomar_10
ID: 24779044
this tool dose not detect anything, its of no use.
0
 
LVL 13

Expert Comment

by:JeremySBrown
ID: 24780620
Try scanning with...Dr. Web Anti-Virus
http://www.freedrweb.com/
0
 
LVL 16

Expert Comment

by:warturtle
ID: 24867974
Hello,

Open this webpage and see how many images you can actually see:

http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

That will help us track down which variant of Conficker you have (and if you actually have it or not).

Hope it helps.
0

Featured Post

ScreenConnect 6.0 Free Trial

Want empowering updates? You're in the right place! Discover new features in ScreenConnect 6.0, based on partner feedback, to keep you business operating smoothly and optimally (the way it should be). Explore all of the extras and enhancements for yourself!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Run .exe file from network share 2 72
Best method to remove 360 Safety Guard from Windows 8 4 331
optimal method deal ransomware in files folders 9 119
Twitching screen 11 100
The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question