Printable Version | Subscribe | Add to Favourites
New Topic New Poll New Reply
Author: Subject: troj simali.a
theconrodkid

posted on 23/8/04 at 10:07 AM Reply With Quote
troj simali.a

my virus thingy says ive got this virus,not too deadly but i,d like to get rid of it,any ideas troj simali.a





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
Peteff

posted on 23/8/04 at 10:50 AM Reply With Quote
Got to Trend micro and do an online scan.

http://housecall.antivirus.com/housecall/start_corp.asp

Won't your AV program get rid of it for you John? If it found it it should disinfect it.





yours, Pete

I went into the RSPCA office the other day. It was so small you could hardly swing a cat in there.

View User's Profile View All Posts By User U2U Member
theconrodkid

posted on 23/8/04 at 01:09 PM Reply With Quote
pete,housecall found it and says it cant delete it cos its connected to a prog that is needed,there are a couple of mentions on various sites about it but its all in swahili or summat





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
pbura

posted on 23/8/04 at 02:00 PM Reply With Quote
Here's some more info about it:

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.simali.html

Suggest trying to kill the running trojan process and running AV again. Probably the process will be one of these:

Loader.exe
Main.exe
Lass.exe
Msmsg.exe

Do CTL-ALT-DEL and see if one of these is running (or anything else that looks dodgy) and End Task. Then run the AV again.

Good luck!

Pete





Pete

View User's Profile E-Mail User View All Posts By User U2U Member
theconrodkid

posted on 23/8/04 at 03:40 PM Reply With Quote
did that,stil there





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
pbura

posted on 23/8/04 at 09:14 PM Reply With Quote
Sorry I was late getting back, Conrod.

IIRC, you run Windows 98? Try downloading this process viewer:

http://www.xmlsp.com/pview/prcview.htm

It will show everything that's running, including the trojan, so that you can kill the process and re-run AV. If that doesn't work, in PrcView you can do File>Save As, and save the process list to a text file. You could then cut-and-paste the process list here if you like, and we can try to figure out what to kill off.

Hope you read the link in my last post thoroughly. Getting rid of the bugger may involve editing your registry, which you might want to get some help with.





Pete

View User's Profile E-Mail User View All Posts By User U2U Member
theconrodkid

posted on 24/8/04 at 06:07 AM Reply With Quote
ive got XP,ta for yr help but thats all beyond me





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
pbura

posted on 24/8/04 at 11:20 AM Reply With Quote
Well, most likely the target of the trojan was a server and not a personal box. When these hackers get into a server they have a party with it. It can wait until you have a visitor who can clean it for you.

Damned writers of these things ought to be hung up by their balls





Pete

View User's Profile E-Mail User View All Posts By User U2U Member
theconrodkid

posted on 24/8/04 at 11:45 AM Reply With Quote
yup agree with your last sentance





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
JoelP

posted on 24/8/04 at 07:18 PM Reply With Quote
cheers for the links pete, its time i had a tidy out myself!






View User's Profile View All Posts By User U2U Member
theconrodkid

posted on 24/8/04 at 07:42 PM Reply With Quote
just run housecall again and its cleared it





who cares who wins
pass the pork pies

View User's Profile E-Mail User View All Posts By User U2U Member
mangogrooveworkshop

posted on 27/8/04 at 07:56 PM Reply With Quote
may still de lurking in system restore!






View User's Profile View All Posts By User U2U Member

New Topic New Poll New Reply


go to top






Website design and SEO by Studio Montage

All content © 2001-16 LocostBuilders. Reproduction prohibited
Opinions expressed in public posts are those of the author and do not necessarily represent
the views of other users or any member of the LocostBuilders team.
Running XMB 1.8 Partagium [© 2002 XMB Group] on Apache under CentOS Linux
Founded, built and operated by ChrisW.