Author Topic: Msn replicant  (Read 2917 times)

0 Members and 1 Guest are viewing this topic.

khonles

  • Guest
Msn replicant
« on: September 02, 2007, 12:21:56 PM »
Hi, everyone, I wasn't concentrating and foolishly opened a photo zip file while talking with a friend on msn and managed to load a replicant virus. It throws up two trojans which are instantly picked up by Avast! and I duly delete them, but when I sign on to explorer the next time the same thing happens again.
 I am not a techie but suspected the problem was in the registry and after some detective work isolated an entry :- HKEY_LOCAL_MACHINE\software\microsoft\windows\current version\run\microsoft visual application\winsyshp.exe

My friend had somebody isolate and delete her virus but the exe. filename at the end was different to mine so I am reluctant to delete this file, so I thought I had better seek your advice, cheers,

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89266
  • No support PMs thanks
Re: Msn replicant
« Reply #1 on: September 02, 2007, 02:44:34 PM »
A google search for the file name returns many hits, http://www.google.com/search?q=winsyshp.exe. This is just one of them, http://www.sophos.com/security/analyses/w32delfext.html.

- Most Delf Trojans add a Startup entry:  Startup Entry Name, SysService  - Process Name, SysService.exe
Use Task Manager to End the Process. Also to end the startup entry, Windows Start, Run, type 'msconfig without the quotes, in the new window select the Startup Tab, find the SysService entry and uncheck it.

If you really want to be sure then you should check it against a multi-engine scanner at: VirusTotal - Multi engine on-line virus scanner I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently 30 different scanners.
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. Whichever scanner you use, you can't do this with the file in the chest, you will need to move it out.

If avast isn't detecting this and others are you should send a sample to avast before dealing with it.
Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
« Last Edit: September 02, 2007, 02:46:27 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

khonles

  • Guest
Re: Msn replicant
« Reply #2 on: September 02, 2007, 09:17:07 PM »
Thanks David,
                never thought of doing a search on it, The learning curve goes on...Many thanks for your advice it will also serve me for any future attacks.

Les

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89266
  • No support PMs thanks
Re: Msn replicant
« Reply #3 on: September 02, 2007, 10:15:57 PM »
No problem, welcome to the forums.

Let us know how you get on.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security