Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Strange happening with ETrust

Dec 21, 2005 8:37PM PST

I have all definititions up to date for this antivirus program; however, yesterday as I went to a website looking for some information after doing a google search, the website loaded up and I immediately got a message from ETrust that ten exploits had infected my system and the path all showed that they were .jpg files but that they were all in one folder for SUN/JAVA/ and ultimately the JAR folder.

I never got an option to clean them, but was told I needed to reboot the computer to do so. I did...when I got back to the desktop, I ran the virus program again, and the same files in the same location were detected again, and where I would normally be able to see that they had been cleaned, this was not given to me...just the scan/close options. I closed the ETrust window, went to the folder that held the files, highlighted them all, and deleted them all with my Mutilate program so they bypassed the recycle bin and were overwritten seven times.

Rebooted the computer, ran the scan again, and came up empty.

I then got on the net, went to housecall, ran a full system scan and had 12 worms/trojans detected and deleted them all....and immediately lost my internet connection for my satellite modem. Rebooted the computer, still no internet although the lights on my modem were all good to go (got a taskbar message saying I had limited or no connectivity though).

So I figured that the infected files couldn't be cleaned and were actually deleted by housecall...so I ran SFC /SCANNOW and fixed/replaced all files automatically with the XP cd....rebooted the computer, and back on the net.

Went back to housecall, ran a new scan, and came up clean.

My biggest question since things seem to be fine now is what happened with ETrust that it couldn't remove the original ten .jpg files? According to the program, I have the latest definitions available after I tried to 'update' it, so I'm a little confused about why it was unable to remove these, and why didn't it find the trojans/worms that housecall found? After all these years of owning InoculateIT and now ETrust (same company), should I be looking around for new protection?

TONI

Discussion is locked

- Collapse -
Nothing Catches Everything
Dec 22, 2005 12:40AM PST

It's why I don't just rely on my internal AV program but do online scans every week as well.

ETrust's heuristics may have detected the java trojans but not had up-to-date definitions to do actual removal (best guess uou had a variant that it was able to detect but that it wasnt able to remove).

As for Housecall finding ones the other missed, it's why you cant just rely on whatever is on your PC. Your scanners are only as good as their definitions. If nothing you are using has definitions for that particular trojan, then maybe you aren't using enough protection.

I personally have 6 scanners on my system plus do 2-3 online scans per week. I also have tons of download protection (Spywareblaster, Spyguard, Spybot, MSAS). Stuff still sneaks in.. but doesnt execute (because I also have registry portectors).

Take nothing for granted. There is no such thing as "too much" protection. Unfortunately there also doesn't seem to be a 'perfect" cocktail of scanning programs that catches everything.

The battle goes on...

- Collapse -
Toni, Curious Which Version Of Java?
Dec 22, 2005 1:33AM PST

There are a few exploits which have been fixed in the newest version of Sun's Java and it should prevent those types of things from happening..Anything prior to JRE 1.4.2_09 is vulnerable to many such exploits. You might need to upgrade to a newer version..

The .jpg file were placed in the the Sun Java "cache" folder which acts much like Internet Explorer's "Temporary Internet Files" folder.

I find it interesting that .jpg files were detected at all..Although the exploit itself should be identified, I suspect they were'nt actually .jpg files.

Hope this helps.

Grif

- Collapse -
I had Version 5 update 5
Dec 22, 2005 2:35AM PST

Just updated after your post to Version 5 update 6 (1.5.0_06)

TONI

- Collapse -
Java Control Panel
Dec 22, 2005 2:44AM PST

has options for 'allow tracing' and 'allow logging'...is this to be able to trace bad stuff back to where it came from? Or is it to allow others to trace me?

TONI

- Collapse -
Toni, They're 'Debugging' Tools..
Dec 22, 2005 3:04AM PST
- Collapse -
Toni, Make Sure To Uninstall Previous Versions..
Dec 22, 2005 3:07AM PST

There has been some discussion of a potential vulnerbility IF the previous versions are left on the machine..Even after you've installed the most recent version, you should be able to access the "Add/Remove Programs" and uninstall the previous versions.

Hope this helps.

Grif