Computing.Net > Forums > Security and Virus > trojan trying to execute script? =(

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

trojan trying to execute script? =(

Reply to Message Icon

Name: echobunny
Date: September 17, 2003 at 08:25:57 Pacific
OS: win xp pro
CPU/Ram: pIII 700
Comment:

i have started getting alerts from NAV to stop/allow a suspisous script to be run. this is what it looks like in the log

Date: 9/17/2003, Time: 16:08:36, Iain on PC
Script Blocking detected suspicious activity.
File: C:\WINDOWS\system32\-Embedding
Object: FileSystem Object
Activity: GetSpecialFolder
This script was stopped.

i have bene getting a LOT of backdoor/subseven trojans trying to access my pc for a while now which i have posted about. i wondered if maybe when ive turned the firewall off for a bit it has managed to get in and install this.

what shuld i do? i cant find this system32\-Embedding. i have done an online trojan scan but found nothing and am currently scanning with norton but i suspect nothing will turn up. what should i do. am i ok as long as i keep denying the script to be run untill i remove it?

what is it and how do i get rid of it?



Sponsored Link
Ads by Google

Response Number 1
Name: echobunny
Date: September 17, 2003 at 09:20:43 Pacific
Reply:

ok its turned out to be verifierbug.class which had infected C:\Documents and Settings\Iain\JPI_CA~1\jar\1.0\archive.jar-27b6d965-1594bea1.zip

i quarantined and deleted it but it has already come up again saying its is trying to excecute


0

Response Number 2
Name: echobunny
Date: September 17, 2003 at 11:41:51 Pacific
Reply:

ok ive just realised the warning is only coming up when i go to google.com

when in google it says "thispage cannot be displayed"

whats going on???!

please someone reply :(


0

Response Number 3
Name: sxshep
Date: September 17, 2003 at 16:51:01 Pacific
Reply:

Might be relevent, been seeing a fair amount of verifier bug stuff lately. Of note, the site approvedlinks .com is a known pain associated with the CoolWebsearch highjacker.

Message 3 in thread
From: Andrew Clover (and-google@doxdesk.com)
Subject: Re: Installation methods


View this article only
Newsgroups: alt.privacy.spyware
Date: 2003-08-21 19:15:29 PST

John Ives <aaaaaaaaa@hotmail.com> wrote:

> What I want to know is are there any known Spyware programs/Hijackers out
> there that install by using Java (maybe using a security weakness) or by
> some other similar means?

Yes. The most widely-used Java-related vulnerability is the ActiveXComponent
bug in IE, which has been used to install TinyBar and various other
home/search repeat-hijackers.

Another more recently exploited hole is the bytecode verifier bug in the
MS JVM; so far I've only seen this used to run plain hijackers (eg.
approvedlinks.com).

--
Andrew Clover
mailto:and@doxdesk.com
http://www.doxdesk.com/

Full Thread

Can't hurt to run CWShredder at the bottom of this page:

http://www.spywareinfo.com/~merijn/cwschronicles.html

Read the story as well, as I said it can't hurt.

hth
shep


0

Response Number 4
Name: Imp
Date: September 17, 2003 at 19:31:36 Pacific
Reply:

Why don't you try Trojan Remover, this freeware for one month, downloadable at:
http://www.simplysup.com/tremover/details.html
The most popular anti-trojan program so easy to use ? made especially for unexperienced users...


0

Response Number 5
Name: echobunny
Date: September 18, 2003 at 05:47:52 Pacific
Reply:

i tried trojan remover and thanks for all the info sxshep

what im not sure about is wether it has installed itself on my pc and nortion is stopping it from running this script when i go to google.com

or wether it hasnt installed at all and i can somehow remove it. because none of the remover tools have come up with anything. so even thought its not doing anyting bad does this still mean its made itself impossible to remove as described in that article.


0

Related Posts

See More



Response Number 6
Name: Lukas
Date: September 18, 2003 at 11:16:11 Pacific
Reply:

Hi echobunny,

I had exactly the same thing, with google and stuff.
Some info about this is on:
http://www.computing.net/windows2000/wwwboard/forum/51763.html

(read the third message to "fix" this.
That helped me to "deactivate" it, but I don't know how it came in, or if it is still lurking around somewhere.

Good luck.


0

Response Number 7
Name: echobunny
Date: September 19, 2003 at 04:00:33 Pacific
Reply:

i dont get the bit about the additional host file. where and how do i find this? and what do i do about the modified one?


0

Response Number 8
Name: Lukas
Date: September 19, 2003 at 10:46:36 Pacific
Reply:

Remove all the entries starting with
64.191 from
c:\windows\hosts
c:\windows\system32\drivers\etc\hosts

Or wherever you windows files are.

And follow the explorer clearing instructions from the other message.

That got rid of the proxying for me, but I don't know if some trojan is still lurking around in memory. I am searching, but couldn't find anything yet.


0

Response Number 9
Name: jayguevara
Date: September 22, 2003 at 14:54:28 Pacific
Reply:

I've had the same problem since yesterday. My AVG AntiVirus picked up the VerifierBug.class4 and removed it but i will have to check my reg for any rogue keys. Apparently there is a security weakness within the java console regarding ActiveX controls from websites, links, etc.


0

Sponsored Link
Ads by Google
Reply to Message Icon

how to recover Partition ... Adaware update



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: trojan trying to execute script? =(

trying to recover from Hijack www.computing.net/answers/security/trying-to-recover-from-hijack/8078.html

All about trojans www.computing.net/answers/security/all-about-trojans/2899.html

trying to recover my system www.computing.net/answers/security/trying-to-recover-my-system/8156.html