Trojan Exploit.JAVA.CVE-2012 - Unwanted Xmas Present - Please help remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by LancashireLass, Dec 25, 2012.

  1. LancashireLass

    LancashireLass Private E-2

    Kapersky delivered a message this morning saying that 'disinfection impossible' and recommends to either delete or 'do nothing'
    As I am worried it may have already spread I would like help in removing it completely please.
    I have read the read and run me first pages.
    I have not run CSS cleaner as I have been experiencing missing programs in my add/remove programs section (Corel Graphics Suite).
    I have done everthing else and have attached all logs.
    Please let me know what to do next.
    Thank you.
    Lynn
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Are you purposely set up to use a proxy server?

    Did you knowingly place these into your trusted zone?
    By the way, where exactly is the threat kaspersky is finding? Give me the full file path to what it's hitting on please.
     
  3. LancashireLass

    LancashireLass Private E-2

    Hi and thank you for your reply.
    I have rebooted the machine (Dell 1720 Inspiron Lapton) into normal boot mode

    No I should not be on a proxy server. I have not set this up and was unaware of it.

    Yes those url's should be in my trusted zone.

    Yes full path of what Kaspersky says is a trojan is:
    C:\Users\Lynn\appdata\locallow\sun\java\deployment\cache\6.0\22\18e9a7d6-52723fad

    Do I need to run the scans again in normal start up mode?
    Thanks again.
    Lynn
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Lynn.

    That looks to be a false positive.

    What are these?

    • C:\ProgramData\3002.abs
    • C:\ProgramData\3002.xml


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*

    After clicking Fix exit HJT.

    Now go to C:\MGTools\analyse.exe and double click it to run it. Opt to do a system scan and save a log file.

    Attach the log file here.
     
  5. LancashireLass

    LancashireLass Private E-2

    Hi Kestrel,
    Thank you for your help.
    Sorry I don't know what these are.
    C:\ProgramData\3002.abs
    C:\ProgramData\3002.xml

    On the .xml one I get the message saying that i.e. has restricted the running of scripts or active x and the line below is in the browser window:
    <Antivirus Name="Kaspersky PURE 2.0" Ver="12.0.1.288" DefFile="" DefDate="" UpToDate="" Status="" />

    I have run the fix as instructed and have attached the log.
    Thank you again.
    Lynn
    PS Hope you enjoyed your Christmas
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had a lovely quiet Christmas, hope you did too :) Thanks.

    delete these:
    C:\ProgramData\3002.abs
    C:\ProgramData\3002.xml

    How are things running?
     
  7. LancashireLass

    LancashireLass Private E-2

    Yes, nice Christmas thanks but glad its over for another year :-D

    I've just deleted those two files but not rebooted yet.
    I've also not ignored or deleted what Kasperky said was a trojan so I'm still getting the exclamation mark.
    Is it OK to choose the recommended ignore option or should I choose the 'delete'?

    Things seem to be running OK except for major problems on the dual monitor setup which was working fine but now constantly looses the settings and has to be reset all the time.

    Anything else to do now?
    Lynn
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have Kaspersky delete it on second thoughts. It will not hurt. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. LancashireLass

    LancashireLass Private E-2

    Hi Kestrel,
    I have now followed all the instructions.
    Thank you so much for all your help and advice, it has been much appreciated.
    All the best for the New Year.
    Lynn
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome, and Happy New Year to you and yours too Lynn. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds