Forum |  HardWare.fr | News | Articles | PC | S'identifier | S'inscrire | Shop Recherche
2753 connectés 

 


 Mot :   Pseudo :  
 
Bas de page
Auteur Sujet :

syshid.exe

n°1855315
vancop
Posté le 20-12-2004 à 19:30:10  profilanswer
 

salut a tous
 
nous avons un serveur dedié, et depui une semaine il est tres malade
 
un ver, du moins sa y ressemble, s appelant syshid.exe s est invité. sa particularité est de créer une bonne 40aine de processus , donc de pompé toute les ressource en faisant tourner le cpu a 100%, evidement, impossible d areter ces processus.
 
aussi, il empeche l execution des fichier .exe .
 
est ce que vous avez des info sur cette saleté, et est ce que vous savez comment s en debarasser ?
 
merci de votre aide.


Message édité par vancop le 20-12-2004 à 19:33:19
mood
Publicité
Posté le 20-12-2004 à 19:30:10  profilanswer
 

n°1855535
acrobaze
Posté le 20-12-2004 à 22:15:43  profilanswer
 

On peut en savoir plus avec ça:
 
Télécharger "HijackThis" sur:
 
http://www.spywareinfo.com/~merijn/downloads.html
ou
http://www.lurkhere.com/~nicefiles/index.html
 
-Le poser dans un dossier spécialement créé pour lui (par exemple:
C:\HijackThis ).
-Le lancer -> "Scan" -> "Save log"
-Récupérer ce log/texte avec le bloc notes.
-Le copier/coller ici, dans une réponse,sans rien faire d'autre.

n°1859213
wfx
Posté le 23-12-2004 à 04:15:21  profilanswer
 

J'ai le meme soucis sur 2 postes de gens dans mon entourage, une vraie saleté.
 
Ce ver modifie les clés "exefile" dans la base de registre en y placant : syshid.exe "%1" %*
Cad qu'il s'auto-exécute au lancement de n'importe quel exe.
Il se mets également dans les clés "Run" pour s'exécuter au lancement du système.
 
On peut également le trouver avec les noms suivants :
svchsot.exe
srvsxc.exe
 
En général, il se place dans
C:\WINDOWS\SYSTEM
ou
C:\WUtemp
 
Pour l'instant pas réussit à le virer définitivement, mais réussit à conscrire ses exécutions.
 
Norton le voit, mais n'arrive pas à l'éradiquer.
 
Qqn a trouvé une solution ?
 
Update :
Sinon y a ca :
http://es.trendmicro-europe.com/en [...] .A&VSect=O
 
WFX


Message édité par wfx le 23-12-2004 à 04:50:13
n°1859379
brucomela
Posté le 23-12-2004 à 10:12:05  profilanswer
 

Hi everyone I'm definitely sorry if I can't explain in french (only read!) but PLEASE don't ban me...this is the only place on the Web speaking about this Virus, and I hope discussing is most important than language!
 
My problem is: every single App I try to launch gets a message box asking for a syshid.exe file which cannot be found. I can't run NAV, Enter registry or services or DOS, nothing.
 
Symptoms as above: a backdoor in C:\WUtemp a file Xlog.txt, a system.vbs file in autorun folder.
 
Hope to find some solution together. Thanks so much and forgive my english speaking!

n°1859548
acrobaze
Posté le 23-12-2004 à 11:09:53  profilanswer
 

brucomela
 
Could you do this:
 
Download HijackThis from:
http://www.cybertechhelp.com/html/ [...] .php/id/40
 
Create a new folder only for HijackThis (Example : C:\HJT).
Unzip it to this folder.
Click "Scan", after click "Save Log".
Save the log, and copy/paste it into your response to this thread.
Don't check or fix anything yet.

n°1859564
brucomela
Posté le 23-12-2004 à 11:18:42  profilanswer
 

No, unfortunately I cant run HijackThis on my server cause it's a .exe and gets blocked before launching, by a dialog box asking to locate syshid.exe.
 
Don't know how to work out this situation cause I cant launch any App.

n°1859581
Prems
Just a lie
Posté le 23-12-2004 à 11:24:31  profilanswer
 

Take the HDD on another PC, run an AV software, then put it back in the server.


---------------
Ratures - Cuisine
n°1859606
acrobaze
Posté le 23-12-2004 à 11:35:33  profilanswer
 


Have you tried in safe mode?

n°1859622
brucomela
Posté le 23-12-2004 à 11:44:39  profilanswer
 

Those both seem to be good ways...at the moment I haven't tried em cause I'm controlling server on remote, and I should check if I can keep doing that in safe mode (using Symantec PC Anywhere, guess not).
 
I think I will phisically take a visit at my server and try safe mode first otherwise move HD, following your advices.
 
Thank u for the moment, I will let u know if any solution worked...it's a real mess being unable to front the virus with traditional instruments (AV, registry, services and so on)!!

n°1859681
acrobaze
Posté le 23-12-2004 à 12:07:55  profilanswer
 


Ok. Let me know if the safe mode helped you.
And if it's possible, post an HijackThis log.

mood
Publicité
Posté le 23-12-2004 à 12:07:55  profilanswer
 

n°1859744
brucomela
Posté le 23-12-2004 à 12:40:23  profilanswer
 

Sure I will after Xmas Acrobaze, you've been very kind and helpful.  
 
Tnx And Bon Noel! (correct?! ;) )

n°1859776
squal16
Posté le 23-12-2004 à 12:50:32  profilanswer
 


J'ai une solution, j'ai ete attaqué par le fameux syshid et j'ai pu m'en débarasser complétement, regardez à l'adresse suivante :
 
http://www.generation-nt.com/apps/ [...] opic=26714
 
 
bon courage  
 
Squal16

n°1859780
acrobaze
Posté le 23-12-2004 à 12:51:04  profilanswer
 


Yes! Merry Christmas!

n°1859824
brucomela
Posté le 23-12-2004 à 13:13:55  profilanswer
 

Squal 16, tnx for suggestion: I've read the topic but my french speech is not so..technical!...to understand it (sigh!)...Could you possibly resume or try to xplain (in english possibly) how I should proceed according to that topic pliz? Thank u so much, you are all giving me a hope!

n°1859883
acrobaze
Posté le 23-12-2004 à 13:36:04  profilanswer
 

He deleted the files: SYSHID.exe, server.dll and system.vbs.
 
and edited the registry
from :
HKEY_CLASSES_ROOT\exefile\shell\open\command = syshid.exe "%1" %*
to:
HKEY_CLASSES_ROOT\exefile\shell\open\command = "%1" %*
 
-----
 
Ps :You have a tool for the registry here:
http://www.annoyances.org/exec/show/article07-102
(But delete the files before).


Message édité par acrobaze le 23-12-2004 à 15:38:03
n°1860141
brucomela
Posté le 23-12-2004 à 15:29:30  profilanswer
 

Ok: I deleted server.dll and system.vbs (second time, after reboot or some event they will be re-created) and I cant find any Syshid.exe. After deletion still I cant launch regedit or any app...should actually try safe mode...
 
Another hint: found a malicious presence in C:\wutemp srvsxc.exe, should be kind of backdoor: it's active in process group, impossible to stop cause in use, impossible to delete for same reason. I could remove it only immeditaly after reboot, but it was re-created...damn!!!

n°1860164
acrobaze
Posté le 23-12-2004 à 15:36:59  profilanswer
 

Make sure that you can see the hidden files and folders as explained here:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

n°1860182
brucomela
Posté le 23-12-2004 à 15:45:56  profilanswer
 

Done Acrobaze, I can see all files, hidden included...is it strange that also message box asks to locate syshid.exe after an app gets launched?
 
Shall I transfer syshid.exe spontaneously on my Server!? (harakiri!)...

n°1860201
acrobaze
Posté le 23-12-2004 à 15:57:12  profilanswer
 

brucomela a écrit :

.is it strange that also message box asks to locate syshid.exe after an app gets launched?
 


 
It's because of this line in the registry:
HKEY_CLASSES_ROOT\exefile\shell\open\command = syshid.exe "%1" %*  
 
-----
 
Can you delete syshid.exe, now? (In safe mode if needed...)

n°1860214
brucomela
Posté le 23-12-2004 à 16:05:13  profilanswer
 

Cant work in safe mode in this moment, Im in remote mode, Server is 50 km far, I'll reach it physically after Xmas.
 
Anyway I cant even find any syshid.exe, and sounds strange also to me the fact that registry points to an exe which is lacking (and was never deleted!)...unless the aim is to generate continuously the message box to locate syshid.exe...if only I could make regedit now!!...

n°1860226
acrobaze
Posté le 23-12-2004 à 16:13:24  profilanswer
 


U can perhaps try "Registrar Lite":
http://www.resplendence.com/reglite

n°1860244
wfx
Posté le 23-12-2004 à 16:21:25  profilanswer
 

Don't forget to disable Windows Restauration Service and purge the "Preftech" Directory.
 
TrendMicro announce, they can detect it, try an online scan !!!
 
Another solution, if you want to launch an EXE files, rename it as BAT file and launch it, it works fine, even for regedit.exe => regedit.bat.
 
"A fighter that came back from a long but victorious combat :P"
WFX

n°1860279
brucomela
Posté le 23-12-2004 à 16:40:45  profilanswer
 

..good idea!!...I've tried with an App and it works...now I'm gonna spoil the whole registry...great, great, great...tnx I'm gonna fight...u'll receive news from me!

n°1860283
Pasteque d​e plomb
Anti-bobo
Posté le 23-12-2004 à 16:44:30  profilanswer
 

brucomela a écrit :

Hi everyone I'm definitely sorry if I can't explain in french (only read!) but PLEASE don't ban me...this is the only place on the Web speaking about this Virus, and I hope discussing is most important than language!
 
My problem is: every single App I try to launch gets a message box asking for a syshid.exe file which cannot be found. I can't run NAV, Enter registry or services or DOS, nothing.
 
Symptoms as above: a backdoor in C:\WUtemp a file Xlog.txt, a system.vbs file in autorun folder.
 
Hope to find some solution together. Thanks so much and forgive my english speaking!


 
Et en mode sans échec ça donne quoi (safe mode)?

n°1860288
brucomela
Posté le 23-12-2004 à 16:47:49  profilanswer
 

great, great...works!!...I've removed entry from registry and I'm running apps...NAV is running and I'm ready to win the battle!...thank u so much to u all, U gave me a great help!! Merry Xmas again my friends!

n°1860446
wfx
Posté le 23-12-2004 à 18:28:42  profilanswer
 

Congratulations !
 
Hope you won't receive another "gift" like this one tomorrow night LOL
 
P.S.
If you have 2 mins, browse the other forums and post your experience and your solution for people who are in trouble like you were ;-)

n°1860545
acrobaze
Posté le 23-12-2004 à 19:45:51  profilanswer
 


Great!

n°1867665
Aiexis
PC hanté
Posté le 29-12-2004 à 14:33:30  profilanswer
 

Salut
J'ai été "attaqué" par cette chose également.
Merci pour vos explications qui m'ont bien aidé !
j'utilise Remote Administrator (équivalent de PC-Anywhere) et j'ai entendu parler d'une faille sur le port 4889 (port par défaut de Remote administrator)
Bien pénible ce truc quand même.. ca m'a bouffé une matinée !
 
A+  :hello:

mood
Publicité
Posté le   profilanswer
 


Aller à :
Ajouter une réponse
 

Sujets relatifs
Plus de sujets relatifs à : syshid.exe


Copyright © 1997-2025 Groupe LDLC (Signaler un contenu illicite / Données personnelles)