Re: Trojan Horse, JAVA/BYTE Verify, MS03-011

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 05/30/05


Date: Mon, 30 May 2005 15:11:10 -0400

From: "jlee" <jlee@discussions.microsoft.com>

| Hello,
|
| I recently tried to delete virusus from my AVG Anti-virus vault and it
| appears that the Trojan horse virusus (quantity 3) are released into my
| Winows Internet Explorer 5.5.
|
| Probably should have left well enough alone.
|
| I have Windows 95 and when I launch Explorer, the address defaults to:
| res://C:\WINDOWS\system32\shdocpa.dll/security.htm
|
| Is there a way to extract the viruses. I tried to change the properties in
| the Internet Explorer - but the launch always goes back to the address above.
|
| I appreciate your advice.
| --
| Sincerely,
|
| jlee

1) Dump the contents of your IE cache -
        Start --> settings --> control panel --> Internet options --> delete files

2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
       Tools --> Options --> Privacy --> Cache --> Clear

3) Dump the contents of your Sun Java cache -
        Start --> settings --> control panel --> Java applet --> cache --> clear
          or
        Start --> settings --> control panel --> Java applet --> general --> settings -->
        delete files

4) Download the TrendMicro Sysclean Front End

Download the utility SYSCLEAN_FE at the following URL --
http://www.ik-cs.com/got-a-virus.htm
SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package.
Direct URL --
http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe

5) Execute; SYSCLEAN_FE.EXE
        Choose; Unzip
        Choose; Close

        Execute; c:\sysclean\SYSCLEAN_FE.BAT
        { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
        when you get to the menu dhoose [1] so you can boot into Safe Mode.

6) If you are using WinME or WinXP, disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

7) Reboot your PC into Safe Mode and shutdown as many applications as possible.

8) Execute; c:\sysclean\SYSCLEAN_FE.BAT
        { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
       Choose [2] on the menu and let SYCLEAN.COM scan your computer.

9) Restart your PC and perform a "final" Full Scan of your platform
       Execute; c:\sysclean\SYSCLEAN_FE.BAT
       { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
       Choose [2] on the menu and let SYCLEAN.COM scan your computer.

10) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
        System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),

11) Reboot your PC.

12) If you are using WinME or WinXP, create a new Restore point

* * Please report back your results * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: JS:Isbar [Trj]
    ... Download the TrendMicro Sysclean Front End ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ...
    (alt.computer.security)
  • Re: i got a virus
    ... There are anti virus News Groups specifically for this type of discussion and you are not ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.windowsupdate)
  • Re: derbiz.com
    ... Download the TrendMicro Sysclean Front End ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.windowsupdate)
  • Re: FCRX7.exe - anybody know what this is??
    ... Download the TrendMicro Sysclean Front End ... Execute; SYSCLEAN_FE.EXE ... If you are using WinME or WinXP, disable System Restore ...
    (microsoft.public.windowsxp.general)