Trend Micro Housecall

G

guyf

I have been having problems with my PC for a couple of weeks now.
First it wouldn't shut down then I was stopped from using Registry
First Aid because it couldn't create a registry backup. Permission was
denied. Windows live messenger was not working, Yahoo widgets engine
would not install and Adaware would not connect to update its
definitions.

Windows beta defender, spybot search and destroy, spyware blaster and
Norton 2006 all found nothing wrong except for one or two cookies and
MRU's. All of them are fully up to date.

My clue came from Yahoo help on installing the widget engine. They said
there had been cases of a clean up helping to solve the problem. So i
searched this forum and then took a link to Trend Micro Housecall. It
found a trojan and several instances of malware and greyware. Although
it took a long time to scan and eradicate the problems my problems are
solved for the moment.

So, in short, thanks to all out there who take the time to offer
advice.

Guy, UK
 
D

David H. Lipman

From: "guyf" <[email protected]>

| I have been having problems with my PC for a couple of weeks now.
| First it wouldn't shut down then I was stopped from using RegistryFirst Aid because it
| couldn't create a registry backup. Permission wasdenied. Windows live messenger was not
| working, Yahoo widgets enginewould not install and Adaware would not connect to update
| itsdefinitions.
|
| Windows beta defender, spybot search and destroy, spyware blaster andNorton 2006 all found
| nothing wrong except for one or two cookies andMRU's. All of them are fully up to date.
|
| My clue came from Yahoo help on installing the widget engine. They saidthere had been
| cases of a clean up helping to solve the problem. So isearched this forum and then took a
| link to Trend Micro Housecall. Itfound a trojan and several instances of malware and
| greyware. Althoughit took a long time to scan and eradicate the problems my problems
| aresolved for the moment.
|
| So, in short, thanks to all out there who take the time to offeradvice.
|
| Guy, UK-- guyf



If you are using any version of Sun Java that is prior to JRE Version 5.0 update 6,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0 update 6. There are vulnerabilities in them and they are actively being
exploited. It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 6 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.5.0_08


http://www.java.com/en/download/manual.jsp

or

http://java.sun.com/javase/downloads/index.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1

For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *
 
J

Jeff

David said:
From: "guyf" <[email protected]>

offeradvice.

Guy, UK-- guyf



If you are using any version of Sun Java that is prior to JRE Version
5.0 update 6,
then you are strongly urged to remove any/all versions that are prior
to JRE/JSE
Version 5.0 update 6. There are vulnerabilities in them and they are
actively being exploited. It is possible that is how you got
infected with malware.

Therefore, it is highly suggested that if there are any prior
versions of Sun Java
to Version 6 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.
Sorry to butt in but now I a worried. I have a new notebook with XP MCE and
when I looked at the C:\Program Files\Java I see a folder named jre1.5.0_04.
I guess that is too old (in this brand new PC). Do I just uninstall Java
through Add/Remove apps and install the new java in its place?

Jeff
 
M

Malke

Jeff said:
David said:
From: "guyf" <[email protected]>
[Snip]
offeradvice.

Guy, UK-- guyf

If you are using any version of Sun Java that is prior to JRE Version
5.0 update 6,
then you are strongly urged to remove any/all versions that are prior
to JRE/JSE
Version 5.0 update 6. There are vulnerabilities in them and they are
actively being exploited. It is possible that is how you got
infected with malware.

Therefore, it is highly suggested that if there are any prior
versions of Sun Java
to Version 6 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.
Sorry to butt in but now I a worried. I have a new notebook with XP
MCE and when I looked at the C:\Program Files\Java I see a folder
named jre1.5.0_04.
I guess that is too old (in this brand new PC). Do I just uninstall
Java through Add/Remove apps and install the new java in its place?

Jeff

Jeff - Yes.
http://www.java.com/en/download/index.jsp

Malke
 
D

David H. Lipman

From: "Jeff" <[email protected]>


| Sorry to butt in but now I a worried. I have a new notebook with XP MCE and
| when I looked at the C:\Program Files\Java I see a folder named jre1.5.0_04.
| I guess that is too old (in this brand new PC). Do I just uninstall Java
| through Add/Remove apps and install the new java in its place?
|
| Jeff
|

That is a vulnerable version and should be removed and replaced with the latest version.

http://java.sun.com/javase/downloads/index.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
 
G

guyf

David said:
From: "guyf" (e-mail address removed)

| I have been having problems with my PC for a couple of weeks now.
| First it wouldn't shut down then I was stopped from usin
RegistryFirst Aid because it
| couldn't create a registry backup. Permission wasdenied. Windows liv
messenger was not
| working, Yahoo widgets enginewould not install and Adaware would no
connect to update
| itsdefinitions.
|
| Windows beta defender, spybot search and destroy, spyware blaste
andNorton 2006 all found
| nothing wrong except for one or two cookies andMRU's. All of them ar
fully up to date.
|
|Hello David,

Here are the results.

Firstly, Yes I did have two versions of Java. Version 1.4.2_07 and v
update 6.
I eliminated 1.4.2_07 and updated to version 5 update 8 as per advice.
I installed and ran super anti-spyware and found several trackin
cookies and worm.Svxhost/32 which were deleted.
I then followed your multi_av.exe instructions and ran (in safe mode
all the tests.
Sophos and Trend micro came up clean but Kaspersky found amongst othe
things "trojan downloader.BAT.Ftp.ab" which it deleted.

After all this I wonder what good Norton 2006 is.
I run Norton 2006, Spybot, spywareblaster, ad-aware, crap-cleaner an
now BHOdemon2 on your recommendation. I also use Registry First aid t
clean up. Windows beta defender is also in the PC.

Is this all necessary? I ask because you don't mention spywareblaste
in your first reply to my post.

What is your best suite of protection on a day to day basis?

Best regards and thanks for your help

Gu
 
D

David H. Lipman

If you don't practice Safe Hex and on't maintain you computer with all Critical Updates,
HotFixes and security related updates then yes, they WIOLL all be needed.

If you learn to practice Safe Hex and keep yopur PC up-to-date the use for many anti malware
applications is mitigated.
 
J

Jeff

David H. Lipman said:
From: "Jeff" <[email protected]>


| Sorry to butt in but now I a worried. I have a new notebook with XP MCE
and
| when I looked at the C:\Program Files\Java I see a folder named
jre1.5.0_04.
| I guess that is too old (in this brand new PC). Do I just uninstall
Java
| through Add/Remove apps and install the new java in its place?
|
| Jeff
|

That is a vulnerable version and should be removed and replaced with the
latest version.

http://java.sun.com/javase/downloads/index.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1

Thank you. I uninstalled my version and installed the newer version.
Thanks.

I usually do not allow Java to run in my browser but better safe than sorry.

Jeff
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top