Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



Removal solution for Trojan.Sasfis

Networking & Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 27-02-2010
Member
 
Join Date: Nov 2009
Posts: 683
Removal solution for Trojan.Sasfis

Hi friends, Recently I have a purchased anew Samsung laptop and it is installed with Windows 7. But Trojan.Sasfis are infected my system and made my laptop very slow. It takes a long time to boot up and shut down. And I have tried to many anti virus on this malware but that none of the anti virus application can not able to remove this virus. Can any one will provide good removal solution?
Reply With Quote
  #2  
Old 27-02-2010
Steve123's Avatar
Member
 
Join Date: Feb 2008
Posts: 2,619
Re: Removal solution for Trojan.Sasfis

During Trojan.Sasfis Trojan is had run then it generate the given file:
  • %Temp%\1.tmp
Trojan.Sasfis worm makes changes the given registry entry:
  • HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Security\"AccessVBOM" = "1"
Reply With Quote
  #3  
Old 27-02-2010
Shen's Avatar
Member
 
Join Date: May 2008
Posts: 2,918
Re: Removal solution for Trojan.Sasfis

Trojan.Sasfis then opens Microsoft Word, if it is installed, and executes a VBA script which installs %Temp%\1.tmp and executes it.

Trojan.Sasfis Trojan then opens an examples of svchost.exe and push itself into the service.

Trojan.Sasfis Trojan then make copies its own as the given DLL file:
  • %System%\[RANDOMLY NAMED FILE]
Reply With Quote
  #4  
Old 27-02-2010
Zachary's Avatar
Member
 
Join Date: Jan 2006
Posts: 3,932
Re: Removal solution for Trojan.Sasfis

The Trojan then removes the original executable.

The Trojan makes changes the given registry entry, so which it begins when Windows boots:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = " Explorer.exe rundll32.exe %System%\[RANDOMLY NAMED FILE] [5 OR 6 RANDOM CHARACTERS]"
__________________
90% of everything is crap...except for crap, because crap is 100% crap
Reply With Quote
  #5  
Old 27-02-2010
Milton.J's Avatar
Member
 
Join Date: Apr 2008
Posts: 3,422
Re: Removal solution for Trojan.Sasfis

Try to restore the given registry entries to their previous values:
  • HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Security\"AccessVBOM " = "1"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Shell" = " Explorer.exe rundll32.exe %System%\[RANDOMLY NAMED FILE] [5 OR 6 RANDOM CHARACTERS]"
Reply With Quote
  #6  
Old 11-03-2010
Member
 
Join Date: Mar 2010
Posts: 1
Re: Removal solution for Trojan.Sasfis

Hello,

As my name says, I am a neophyte and need some help with this Trojan.Sasfis I have on my computer.

I have Norton, and it gave me some instructions:

1. Disable System Restore
2. Update the virus definitions
3. Run a full system scan
4. Delete any values added to the registry

I have done steps 1-3 and am stuck on #4. I tried to "delete the following registry subkey":

HKEY_CLASSES_ROOT\idid

I tried to delete the HKEY_CLASSES_ROOT, but it wouldn't let me as the function cannot be highlighted. I also tried to looked for an "\idid", but cannot find it. Where should I be looking?

I also have no idea how to restore:

HKEY_CURRENT_USER\Software\Microsoft\Office... what the last poster posted. (This is supposed to be my next step according to the instructions)


Can anyone please help me out?
Reply With Quote
  #7  
Old 11-03-2010
Member
 
Join Date: Feb 2010
Posts: 23
Removal solution for Trojan.Sasfis

In such that case i would suggest you to install AVG anti virus and i am sure this will remove all the Trojan form your system and at the same time it will also protect your system from malware, worms, root kit, backdoor etc.
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Removal solution for Trojan.Sasfis"
Thread Thread Starter Forum Replies Last Post
Removal solution for TROJ_FAKEAV.EAQ trojan Daniel23 Networking & Security 5 23-02-2010 04:34 AM
Removal solution for TROJ_AGENT.BWBF Trojan Eleeazar Networking & Security 4 04-02-2010 06:57 AM
Removal solution for TROJ_SCAR.AGQX trojan Filiberto Networking & Security 5 01-02-2010 07:32 PM
Removal solution for TROJ_RANSOM.IL trojan Daniel23 Networking & Security 4 31-01-2010 06:19 AM
Removal solution for TROJ_FAKEAV.XMS Trojan Balamohan Networking & Security 4 15-01-2010 05:45 AM


All times are GMT +5.5. The time now is 04:25 AM.