Ive Got A Virus Again

Discussion in 'Technology' started by Vin, Apr 23, 2005.

Users Viewing Thread (Users: 0, Guests: 0)

  1. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Can you see a Java Plugin option in Control Panel? I'm guessing if you can't you are using M$'s Java VM

    Try this instead:

    Go to Start-->Run, and copy and paste the following into the box:

    RunDll32 advpack.dll,LaunchINFSection java.inf,UnInstall

    And hit enter and close.

    Then delete these files/folders:
    C:\Windows\Java\
    C:\Windows\Inf\java.pnf
    C:\Windows\System32\jviw.exe
    C:\Windows\System32\wjview.exe

    Then go to Start-->Run, type "regedit", navigate to and delete the following entries:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExplorer\AdvancedOptions\JAVA_VM

    Then go here: http://www.java.com/en/download/manual.jsp and install the Sun Java RTE

    Once installed, go into Control Panel-->Java Plugin, click the cache tab, and un-check enable caching.

    Sorted :up:
  2. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Housecall doesn't work with Firefox at all unfortunately :(

    Do what I said above and try IE again to use Housecall, but IE may have been hijacked by some spyware, hence the error.
  3. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Forgot to add, reboot before installing Sun Java. (and turn off system restore too)
  4. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InternetExpl
    orer\AdvancedOptions\JAVA_VM


    Ive just gone and deleted the whole Internet Explorer Folder on this one! Shit!

    I take it thats bad. Is there anything i can do? :spangled:
  5. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Did you turn off system restore already? If not, that may work - otherwise you'll have to do a repair of windows from the cd. Only if there is a problem though
  6. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Java Plugin doesnt appear in my Control Panel. :confused:
  7. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    What do you mean? Have you uninstalled M$ Java VM and installed Sun Java? Are you looking at Control Panel in classic or category view? You'll want classic, select on left.
  8. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Found it now, in Classic View. But there isnt a cache tab.

    Its calling it Java and not Sun Java like you keep calling it. Have i installed the right Java? I just clicked on the first one on the download page.
  9. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    It's the right Java - it's made by Sun Microsystems, why I'm calling it Sun Java. I may be referring to the cache in an earlier version, sorry

    Under the general tab, where it says temporary internet files, click settings, click view applets, and you can disable cache in there.

    third time Sorted. :D
  10. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Still cant get Housecall working on IE.

    When i open IE, AVG still keeps blocking these two viruses. So i think theres still a problem.
  11. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Could you post up the locations of the files that AVG are detecting are infected?

    Also, if you go back into the Java Plugin thingy and delete the temp internet files - that may help.
  12. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Right, i started IE again, and it came up with these two.

    C:\WINDOWS\mfccz32.exe
    C:\WINDOWS\sdkjc.exe

    It actually comes up with different ones each time. I checked in the Virus Vault. But they are always in the same location and always the same size, 11.12kb and 32.62kb.
  13. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    They're viruses/trojans (not just exploits like byteverify), they'll also be in the registry so running at startup, why you can't use housecall - giz a wee while to find out removal
  14. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Download HijackThis: http://www.majorgeeks.com/download3155.html, and unzip it to a folder directly on the C drive, eg: C:\Hijack\ - you must make sure it is unzipped and not running from a temporary folder

    Then open it and select 'do a system scan and save the logfile', save the log somewhere you can find it, close hijackthis, and copy and paste the contents of the log here.

    I'll run through it but I may not be able to tell you what to do next until tomorrow.
  15. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Cheers Dodge. :D
  16. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    No worries - keeps me busy :D :up:
  17. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Your 'majorgeeks' link doesnt work.
  18. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
  19. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,580
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Ive extracted it onto C:\ but when i open it, it tells me its started from a temporary folder.

    Have i done something wrong here?
  20. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    You need to extract HijackThis from the zip file - easiest way is to go into the zip folder, right-click on the program and select cut - then go to the C:\Hijack\folder and paste, so it is no longer inside a folder that is zipped, then run it :up:

    Or, if you're using winzip or winrar, you need to specify a location to extract it to, or it will extract to a temp folder.

Share This Page