Author Topic: problems whth cisvc.exe  (Read 8240 times)

0 Members and 1 Guest are viewing this topic.

feebright

  • Guest
problems whth cisvc.exe
« on: June 21, 2007, 08:20:37 AM »
     2007-6-21 10:28:08   SYSTEM   600   Sign of "Win32:Trojan-gen. {VC}" has been found in "D:\share\cisvc.exe" file. 
      but cisvc.exe is the system file .
      why?

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: problems whth cisvc.exe
« Reply #1 on: June 21, 2007, 08:52:01 AM »
If this suspect 'cisvc.exe' really is part of your operating OS, shouldn't it be loading from C:\WINDOWS\system32\cisvc.exe ?
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

feebright

  • Guest
Re: problems whth cisvc.exe
« Reply #2 on: June 21, 2007, 08:53:45 AM »
If this suspect 'cisvc.exe' really is part of your operating OS, shouldn't it be loading from C:\WINDOWS\system32\cisvc.exe ?

  Yes,my os is windows2000,thank you!

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: problems whth cisvc.exe
« Reply #3 on: June 21, 2007, 09:03:52 AM »
Okay then, if Avast! quarantines it, it shouldn't cause you any problems.

Some malware, like NETSKY, disguise themselves by using system file names but this one's location is way out of left field.
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: problems whth cisvc.exe
« Reply #4 on: June 21, 2007, 10:58:34 PM »
Okay then, if Avast! quarantines it, it shouldn't cause you any problems.
I suggest that 'system' files are 'moved' and not send to Chest.
Chest is not available in Safe Mode and if a system file is needed to boot, the user won't be able to restore them.
Sending to the 'moved' files folder is easier to restore it. Even infected, some files are needed to boot and you must 'clean' your computer before booting, otherwise, your system will be locked (can't boot).
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89214
  • No support PMs thanks
Re: problems whth cisvc.exe
« Reply #5 on: June 21, 2007, 11:26:51 PM »
The problem being many users don't know which are system files or think a file is a system file but in the wrong location as in this detection. So it isn't so clear cut as many users aren't able to make that distinction.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: problems whth cisvc.exe
« Reply #6 on: June 22, 2007, 12:28:27 AM »
The problem being many users don't know which are system files or think a file is a system file but in the wrong location as in this detection. So it isn't so clear cut as many users aren't able to make that distinction.
The user can't make the distinction but will pay its price... not booting...
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89214
  • No support PMs thanks
Re: problems whth cisvc.exe
« Reply #7 on: June 22, 2007, 01:03:09 AM »
If it truly is an important system file that is required to boot, surely it won't matter if it is in the chest or moved folder, if it isn't in its original location 'it won't boot,' safe or otherwise.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: problems whth cisvc.exe
« Reply #8 on: June 22, 2007, 02:05:53 AM »
feebright, that file was found in D:\shared...
Assuming the OS is on C:, it hints to me that the file is likely not important for the system, and also possibly you are using a p2p program which downloads to a shared folder?
If that is the case, it is quite possibly malware inadvertently downloaded.
Windows 10,Windows Firewall,Firefox w/Adblock.

Offline Vladimyr

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1639
  • Super(massive black hole) Poster
Re: problems whth cisvc.exe
« Reply #9 on: June 22, 2007, 05:00:40 AM »
I suggest that 'system' files are 'moved' and not send to Chest.
Chest is not available in Safe Mode and if a system file is needed to boot, the user won't be able to restore them.
Sending to the 'moved' files folder is easier to restore it. Even infected, some files are needed to boot and you must 'clean' your computer before booting, otherwise, your system will be locked (can't boot).

Good general advice. Renaming is my preference too, however in this case I considered it extremely unlikely that a malware would have made the OS dependent on a file located in D:\share\. Tarq57's suggestion makes a lot of sense.
There is a way that seems right to a man,
       but in the end it leads to death
.” - Proverbs 16:25

feebright

  • Guest
Re: problems whth cisvc.exe
« Reply #10 on: June 22, 2007, 06:31:08 AM »
feebright, that file was found in D:\shared...
Assuming the OS is on C:, it hints to me that the file is likely not important for the system, and also possibly you are using a p2p program which downloads to a shared folder?
If that is the case, it is quite possibly malware inadvertently downloaded.

     the file is location at C:\WINDOWS\system32\cisvc.exe .when i delete the file ,and copy the file from another os,avast also alarm it as Win32:Trojan-gen

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: problems whth cisvc.exe
« Reply #11 on: June 22, 2007, 06:58:47 AM »
OK, that's slightly at odds with what was reported in your first post. Try uploading the file to http://www.virustotal.com/en/indexf.html and see if any other scanners detect it.
I suspect Avast detected it originally because of the weird location originally reported.
Does it (or anything similar) actually exist in D:\shared?
Windows 10,Windows Firewall,Firefox w/Adblock.

mauserme

  • Guest
Re: problems whth cisvc.exe
« Reply #12 on: June 22, 2007, 07:00:30 AM »
C:\WINDOWS\system32\cisvc.exe is probably legitimate but other locations might indicate Family Keylogger

http://www.castlecops.com/s1203-cisvc_exe.html

Do others have acces to your computer?

I would also suggest Virus Total for all instances of the file.

feebright

  • Guest
Re: problems whth cisvc.exe
« Reply #13 on: June 22, 2007, 07:07:03 AM »
OK, that's slightly at odds with what was reported in your first post. Try uploading the file to http://www.virustotal.com/en/indexf.html and see if any other scanners detect it.
I suspect Avast detected it originally because of the weird location originally reported.
Does it (or anything similar) actually exist in D:\shared?

    The file located at d:/share  is the copy file from another os,thanks!

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: problems whth cisvc.exe
« Reply #14 on: June 22, 2007, 01:18:19 PM »
If you could post the size of that file, and the version number (Find the file and right click, select properties) that may be useful. On my XP system its 5632 bytes (5.5Kb) and version 5.1.2600.2180, described as Content index service. May be same or slightly different on Win2K. If it's very different, I'd be a bit suspicious.
Did VirusTotal flag it at all?
Windows 10,Windows Firewall,Firefox w/Adblock.