trojan problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by sunrise, May 9, 2005.

  1. sunrise

    sunrise Private E-2

    I can't get into some of my programs, the screen goes blank and comes up with an error message. Pressing any key gets me back to where I was. I've done your recommended checks and I am infected with Trojan.ByteVerify and Dialer.Target. My AVG program identifies it but can't remove it. Can you help please?
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Typically no virus can be removed from Windows because it is in use. Go into safe mode and do the online scans. A follow up scan with Mcafeee Stinger would be helpful as well as any spyware programs. Also, using CCleaner, go to tools, startup programs and look for anything suspicious running and remove it.
     
  3. sunrise

    sunrise Private E-2

    I followed your advice and all seems well now. Thanks for your help. Great site!
     
  4. sunrise

    sunrise Private E-2

    No, I spoke too soon. The problem with the screen shutting down when I try to open some of the programs has returned. It seemed OK at first but it came back. Do you have any more ideas? Thanks.
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    After doing ALL of the above if you still have a problem:


    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  6. nachorios

    nachorios Private E-2

    Hi, i dont speak english very well but i have problems with trojan horses.
    I have read all tutorials and i have already done everything..i guess...but when i scan my pc again, appear the same viruses Trojan agent.abs, nail.exe and svchost.
    I installed all prgrams you wrote it but didn ´t work it
    can you help me please?
    Thanks a lot


    This my log file


    Edit by chaslang: THREAD HIJACK, unrequested inline log deleted.
     
    Last edited by a moderator: May 11, 2005
  7. sunrise

    sunrise Private E-2

    I've gone through the "do this first" advice. Trend Micro showed non cleanable problems but the other programs say the systen is OK. I've attached the Hijackthis log for you to look at. Thanks.
     

    Attached Files:

  8. sunrise

    sunrise Private E-2

    Also I do believe Nachorios has "hijacked" my thread!!! :D
     
  9. nachorios

    nachorios Private E-2

    And? what is the meaning of hijacked? do you knwo any solution for this problem?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not for long!

    Nachorios,

    Please post in your own thread. Thread hijacking is what you attempted to do when posting in a thread that does not belong to you.
     
  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    sunrise,

    Your HJT log is clean, can you advise of what AVG is detecting. Name and location if possible where we can manually remove it.

    Also, what problems are you currently having?
     
  12. sunrise

    sunrise Private E-2

    These are the AVG results.
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-6182d47b-59dca035.RB0
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-3a2ffe0f-6630e20b.RB0:\InsecureClassLoader.class
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-3a2ffe0f-6630e20b.RB0:\Installer.class
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-3a2ffe0f-6630e20b.RB0 Virus identified Java/ByteVerify Infected, Archiv
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-6182d47b-59dca035.RB0:\javautil.zip Trojan horse Proxy.16.Z Infected, Embedded object
    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-6182d47b-59dca035.RB0 Trojan horse Proxy.16.Z Infected, Archiv

    What happens is - during startup and when I try to open some programs and even sometimes when I try to access my C drive via My Computer - the screen goes blank and then comes up with this message. "A fatal exception OE has occurred at 0028:c1795D48 in VxD cmaudio(01) + 00029488. This was called from 0028:c1795D40 in VxD cmaudio(01) + 0029480."
    I hope this is useful to you. Thanks for you help.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Boot into Safe Mode with the viewing of hidden files and folders enabled per the tutorial.

    Navigate to the following folder and delete it.

    C:\WINDOWS\Application Data\Sun\Java\Deployment\cache

    After you remove the above folder, run CCleaner and then reboot back into Normal Mode. See if AVG complains anymore.

    Let me know!
     
  14. sunrise

    sunrise Private E-2

    OK, the scans now show no signs of infection. Thanks for that. I do still have the same problem with the screen shutting down though, as I decribed before. Any ideas what could be causing this? :confused:
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thats probably going to be Software related so I would post this in the Software Forum. Those guys will get you all fixed up.

    Good Luck!:)
     
  16. sunrise

    sunrise Private E-2

    I had a feeling this might not be virus related. I'll post in the Software Forum as you say. Thanks with your help in getting rid of the Trojan. :)
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    You should see this article on How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds