Monday, November 10, 2008

CWS.Svcinit Trojan

Removing CWS.Svcinit
Categories: Trojan,Backdoor,Hijacker
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

A desktop hijacker replaces the desktop wallpaper with advertising
for products and services on the desktop.

CWS.Svcinit Also known as:

[Kaspersky]Backdoor.Sinit.c,Backdoor.Sinit.f;
[Eset]Win32/Fakesvc.C trojan,Win32/Sinit.A trojan;
[Panda]Bck/Initsvc.B,Bck/Initsvc.C,Bck/Initsvc.D,Bck/Initsvc.E;
[Computer Associates]Backdoor/Sinit,Backdoor/SVC.58880,Win32.Sinit.A,Win32.Sinit.B,Win32.Sinit.C,Win32.Sinit.E,Win32/FakeSvc.C!Trojan,Win32/Sinit.C!Trojan

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\mssys.exe
[%SYSTEM%]\svcinit.exe
[%SYSTEM%]\svcpack.exe
[%WINDOWS%]\system\svcinit.exe
[%WINDOWS%]\system\svcpack.exe
[%WINDOWS%]\mssys.exe
[%SYSTEM%]\svcinit.exe
[%SYSTEM%]\svcpack.exe
[%WINDOWS%]\system\svcinit.exe
[%WINDOWS%]\system\svcpack.exe

How to detect CWS.Svcinit:

Files:
[%WINDOWS%]\mssys.exe
[%SYSTEM%]\svcinit.exe
[%SYSTEM%]\svcpack.exe
[%WINDOWS%]\system\svcinit.exe
[%WINDOWS%]\system\svcpack.exe
[%WINDOWS%]\mssys.exe
[%SYSTEM%]\svcinit.exe
[%SYSTEM%]\svcpack.exe
[%WINDOWS%]\system\svcinit.exe
[%WINDOWS%]\system\svcpack.exe

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices

Removing CWS.Svcinit:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:

No comments: