CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

SIMcss ........Russian Trojan?? Bug??

 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
kelco

Guest
IP: 65.49.*.*






PostPosted: Tue Nov 04, 2003 9:15 pm    Post subject: SIMcss ........Russian Trojan?? Bug??
Reply with quote

The first part of this question is more just a FYI to see if anyone has any experience with a particular trojan. The second part is a question.

Part 1
I was trying to help my dad (over the phone since he lives 1500 miles away) with a computer problem. This is a case of the myopic leading the blind. His NAV (all definitions up to date) kept picking up a virus and freezing his machine. We found three trojans (blackbox, dummy, and verifier_byte question). NAV said that it couldn't fix them, but quarantined them. However, as soon as dad would open Outlook Express, a NAV alert would jump up warning him about these trojans again, and would freeze his machine. He would then have to reboot his computer twice since the first boot would invariably come up as a black screen.

NAV identified one other file that seemed to be causing much of this problem. It was named "SIMcss" and was in his Windows directory. I did a search on the web for him and only got two hits on SIMcss (using Google). One site was in Russian, but had the word "BUG" in front of the searched term. The second was BoCleaner's site, which identified this trojan as one of the "unique" trojans that BoCleaner would clean (frankly, the fact that only one application seems to have heard of and can clean a trojan gets the conspiracy juices running even in a trusting guy like me).

Anyway, I was just wondering if anyone had even heard of this trojan.

Part 2
In the end, my dad took his computer to his "computer guy" who fixed it for him. When he returned the computer, he made two comments about dad's web cam. I don't own a webcam, so I didn't know what to tell my dad when he asked me about it. I would appreciate it if anyone else could answer this for me.

The first thing he said had to do with drivers and their need to be loaded first, so it is a discussion that is outside the interests of this board. The second thing he said, however, was that any computer camera should be kept covered when it is not being used since any camera can be accessed remotely by a knowledgeable hacker. Is this true? It doesn't sound right to me, but what do I know.

Thanks for any information you can give me.

Back to top
phoenix22

Welcome back our old Site Admin
Premium Member

Joined: Mar 08, 2002
Posts: 4661
Location: APO SF96383
Premium

PostPosted: Wed Nov 05, 2003 12:31 am    Post subject:
Reply with quote

first thing yo should do is separate part 1 an2. Start a second thread about the wcam in General Hardware.........I'll move this also into the av section.....


_________________
101st Abn Div. (AirAssault) "Rendezvous With Destiny!" "Night Stalkers/Phoenix Flight" For Buddy...who lived it! Whiskey for my men and beer for my horses! H.A.L.O!, 5th Grp., MACV-SOG, 160th AVN Grp., VFW
Back to top
View users profile Send private message Visit posters website
BillC

Captain
Captain
Premium Member

Joined: Jun 25, 2003
Posts: 456

MVP Premium

PostPosted: Wed Nov 05, 2003 8:47 pm    Post subject:
Reply with quote

About 'SIMcss'....it is a trojan. Seems it is a new one for November. I've not found a removal tool, but could suggest a couple of online scans to try to see if they can pick it up and kill it:

TrendMicro

GFi Trojanscan

I know that Kaspersky has it in their data base, but I'm not sure of other AV programs.

Back to top
View users profile Send private message Visit posters website
kelco

Guest
IP: 65.49.*.*






PostPosted: Thu Nov 06, 2003 12:52 am    Post subject: SIMcss cleaner
Reply with quote

Thanks for your responses. As I say, Bill, BoCleaner (BoClean?) suggests that their app will clean it. They also mention a SIMcss.2 in the list of trojans that their software will clean.

Back to top
Frazin78

Guest
IP: 24.192.*.*






PostPosted: Sat Nov 22, 2003 3:28 am    Post subject:
Reply with quote

I was infected with the Trojan as well. After spending a few hours on the net I figured out a way to remove the virus without any programs.

I rebooted my computer in safe mode, I went into my windows directory and deleted the entire folder that was holding the virus. NAVPMC. It has been 5 days since I removed the files and Norton doesn't throw anymore warning messages. Did a full scann and it's gone. Smile

Here are the links that help you restart your windows in safe mode.

XP http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001060608000039?Open&src=con_web_nam&docid=2002051411085406&nsf=nav.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=

2000
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2000030212233639?Open&src=con_web_nam&docid=2002051411085406&nsf=nav.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=

98 or ME
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/1999101916343139?Open&src=con_web_nam&docid=2002051411085406&nsf=nav.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=

Back to top
trojan simcss

Guest
IP: 193.250.*.*






PostPosted: Mon Nov 24, 2003 7:43 pm    Post subject: Re: SIMcss cleaner
Reply with quote

kelco wrote:
Thanks for your responses. As I say, Bill, BoCleaner (BoClean?) suggests that their app will clean it. They also mention a SIMcss.2 in the list of trojans that their software will clean.

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer