activex prohibited after uninvited 'install.exe'

  • Thread starter Mark or Libbie McCutcheon
  • Start date
M

Mark or Libbie McCutcheon

Running XP and Norton Security on a cable modem service.

Had an install.exe sneak into the c drive, unknowingly. Son didn't run it.
He did have a question about allowing something to run and he says he said
no.

I think we ended up with a virus. The security settings are right, but
activex still gives 'your current security settings prohibit running activex
controls on this page. As a result, the page may not display correctly'.

I cannot run my virus scan because of this error. I can't look at the log or
anything. I've already uninstalled and reinstalled it. Even ran the scan on
their website which had to download an activex exe to run, but I still get
this msg.

Also, at startup it says 'lshosts32.exe from c:\windows\system32 is
unsigned, do I want to allow it to run? I have said no, and temporarily
renamed it so it won't try to run again. Do I need this file?

Also, unfortunately I think I loaned my XP CD out, It's an upgrade version I
bought when XP first came out, so I can't use the CD to fix this file.

I DO have WinXP on my D drive, but it's not accessing my current Norton, and
when I tried yesterday to start Norton from Program files, it said a dll did
not exist. Haven't tried since reloading Norton.

Am going to try a scan in safemode again.

The Symantec Internet scan found threats: dialer.moviefile; adware.CDT;
mediatickets.exe; adware.overpro. But no virus.

But my search did not find some of these files where the computer said they
were.

Any help will be great! I need this computer for my business!
 
W

Wesley Vogel

lshosts32.exe is added by Added by Troj/Sdbot-UY. Found in the Windows
system folder.

[[Troj/Sdbot-UY is a backdoor Trojan which runs in the background as a
service process and allows unauthorised remote access to the infected
computer via IRC channels.

Troj/Sdbot-UY copies itself to the Windows system folder as lshosts32.exe
and creates the following registry entries to ensure it is run at system
logon:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
LSASS Authority
lshosts32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
LSASS Authority
lshosts32.exe

Troj/Sdbot-UY can be instructed by a remote user to retrieve system
information and download and execute remote files on the infected
computer. ]]

Troj/Sdbot-UY
http://www.sophos.com/virusinfo/analyses/trojsdbotuy.html

--
Hope this helps. Let us know.

Wes
MS-MVP Windows Shell/User

In
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top