PDA

View Full Version : Trojans up the butt.


ShardOfJustice
05-20-2004, 06:27 PM
I am scanning my system, and I have 3 trojans detected so far:

Downloader-JU
VB/Psyme
and
Exploit-mhtredir.gen

So far on my infected files box i deleted mhtredir, but now it says access is denied even though its deleted, and the other two I can't touch. I have installed the latest DAT's, but havent restarted yet, and I don't know where i should look for an updated explorer to take out the vulnerability. Any help on virus removal and update of my explorer would be helpful...

Rick
05-20-2004, 07:32 PM
A Little more info is needed
Like what version of windows are you running?

If it is winXP.
then trun off auto restore
Then reboot into safe mode and scan from there

classicsoftware
05-20-2004, 10:39 PM
I Recommend a FULL Security Scan.

1) Download, install and update Spybot. (http://download.com.com/3000-2144-10122137.html?part=104443&subj=dlpage&tag=button)

2) Download, install and update Adaware. (http://download.com.com/3000-8022-10214379.html?tag=lst-0-2)

3) Create a folder called HJT.

4) Download and install HijackThis (http://download.com.com/3000-8022-10227352.html?tag=lst-0-4) in the HJT folder.

5) Run Spybot and fix everything it finds

6) Shutdown your computer. Full shutdown DO NOT re-start.

7) Run Adaware and fix everything it finds.

8) Shutdown your computer. Full Shutdown DO NOT re-start.

9) Run an on line scan from Trend Micro (http://housecall.trendmicro.com/) and or Bitdefender. (http://www.bitdefender.com/scan/licence.php)

10) Run HijackThis from HJT folder. Do not run it from the TEMP or Temporary Internet Files folder as you will be unable to restore the backups created by HJT. After the scan is complete create a log file. DO NOT fix anything unless instructed to by an expert here.

11) Post the contents of the log and the results from the previous scans back here for evaluation.

PrntRhd
05-20-2004, 11:06 PM
One of those is a Java exploit, after you get this cleaned up upgrade to Sun J2RE as it will not let the trojans execute. One of the others is an Active-X issue.
Follow the posted advice.

ShardOfJustice
05-21-2004, 06:18 PM
Ok, I followed my McAfee scanner's instructions and updated my DATs, and did a full scan of the computer, and had internet disconnected all the while. Everything seems to be fine now...

PrntRhd
05-21-2004, 09:45 PM
Please run the HJT and post a log so we can check, just to be sure.

ShardOfJustice
05-22-2004, 09:58 AM
I'll have to continue on Sunday since I'm about to leave for the weekend (its 6:57 in the morning), but I will run the HJT and report back.

(I still don't notice any problems either...)