EQ2Interface.com
Search Downloads


Go Back   EQ2Interface > General Discussion > Chit-Chat

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Unread 06-11-2005, 10:16 AM
dc_roenfanz's Avatar
dc_roenfanz dc_roenfanz is offline
A Griffon
Interface Author - Click to view interfaces
 
Join Date: Mar 2005
Server: Unkown
Posts: 588
Default Possible exploit virus on my comp

I keep getting "infected" files when I run my virus scanner, but I have no idea how to get rid of it. The viruses indicated are:

Java.ByteVerify!exploit
Java.Shinwow.W

I WOULD like to get rid of these things, but the one I have doesnt seem to do it.
Any suggestions?


EDIT:

I downloaded and am currently running the AntiVir software that was talked about in another thread, and it seems to be taking care of the aforementioned ne'er-do-wells.
__________________

Last edited by dc_roenfanz : 06-11-2005 at 10:28 AM.
Reply With Quote
  #2  
Unread 06-11-2005, 10:51 AM
Laffs's Avatar
Laffs Laffs is offline
A Griffon
Interface Author - Click to view interfaces
 
Join Date: Dec 2004
Server: Runnyeye
Posts: 1,404
Default

This is good for getting shot of that stuff http://www.bulletproofsoft.com/
__________________
Laffs UI Mods
I can only please one person per day. Today is not your day. Tomorrow doesn't look to good either !
(Wicann on Runnyeye)
Reply With Quote
  #3  
Unread 06-12-2005, 08:55 AM
Kosmos's Avatar
Kosmos Kosmos is offline
A Griffon
Interface Author - Click to view interfaces
 
Join Date: Dec 2004
Server: Lucan DLere
Posts: 581
Default

Basically copies a file to your computer, then changes your registry to re-direct your internet explorer start page, and then deletes itself after it's made the changes.

This is probably included in some web site that you visit often.
Quote:
Upon opening an affected page on a vulnerable machine, Shinwow.F creates the following file: c:\331983981.dat. The trojan then executes Regedit.exe and uses the newly created dat file to modify the follwing registry entries:
,which is why you are getting the reinfection after you remove it.


If you have not already done so, you may need to update your virus definitions for the virus scanner you are using.

When you run it. Make sure you boot up in windows 'SAFE' mode.
And you have Windows System Restore Disabled.
Then run the Virus Scanner and let it repair/delete the files.
If that is not working for you, as you have said.
You may need to manually remove the files, and the associated registry entries.
Here are links to both the Trojens you have.


http://www3.ca.com/securityadvisor/v....aspx?id=36651

http://www3.ca.com/securityadvisor/p...x?id=453089160

If all else fails, then you will probably need to get a program called
HijackThis and find a step by step guid on cleaning the entire system of the trojen.
__________________
Kosmos
Qeynos Ranger (Retired)
Lucan D'Lere

Last edited by Kosmos : 06-12-2005 at 09:11 AM.
Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:19 AM.


Our Network
EQInterface | EQ2Interface | WoWInterface | LoTROInterface | ESOUI | MMOUI