Remove Secefa. Description and removal instructions

 
Title: Secefa

Type: Worms
Severity scale:Secefa severity is 83  (83 / 100)
 
Secefa is a dangerous and complex Internet worm, which spreads to vulnerable computers running Microsoft Windows operating system with unpatched security flaws. It exploits certain vulnerabilities and does not require any user interaction. Once executed, Secefa silently installs itself to the system and runs a spreading routine. The worm's payload is comprised of several harmful functions. Secefa terminates running antiviruses, firewalls, security-related programs, some other applications and even few parasites. It alters the Windows registry in order to bypass and disable Windows Firewall, some system tools and components including the Registry Editor and System File Protection. Secefa also blocks access to popular security-related and online shopping web sites. The worm includes an integrated backdoor, which provides the attacker with unauthorized remote access to a compromised computer. The intruder can control the infected system and steal user sensitive information. Furthermore, Secefa can download from the Internet and install Gamqowi, which is a dangerous trojan with backdoor functionality. The worm automatically runs on every Windows startup.


Secefa properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Secefa removal:

remover for Secefa

Secefa manual removal:

Kill processes:
dodrrr.exe, msdef.exe, mstempf.exe, services.exe, ws3lib.exe, ftp.scr
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rpcser32g
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\rpcser32g
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Start=4
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Enable Firewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\services.exe=services.exe:*:enabled:services.exe
Delete files:
dodrrr.exe, msdef.exe, mstempf.exe, services.exe, ws3lib.exe, qwe.bat, ftp.scr
Misc:
Exact file location:
dodrrr.exe, mstempf.exe - C:\Windows or C:\Winnt
msdef.exe, services.exe, ws3lib.exe, qwe.bat, ftp.scr - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Secefa:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 26/11/05
Information updated: 26/11/05

Additional resources related to Secefa:

Attention: If you know or you have a website or page about Secefa removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Secefa parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites:
Related discussions: