Spyware, Viruses, & Security forum

General discussion

VIRUS ALERTS - July 1, 2004

by Marianna Schmudlach / July 1, 2004 12:41 AM PDT

Aliases
JS/Exploit-DialogArg.b trojan, Trojan.JS.Scob.a

Type
Trojan

Description
JS/Scob-A is a Java script trojan that is reported to be appended to HTML files on IIS machines.
JS/Scob-A downloads a file from a Russian website, this website is no longer accessible.

http://www.sophos.com/virusinfo/analyses/jsscoba.html

Discussion is locked
You are posting a reply to: VIRUS ALERTS - July 1, 2004
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: VIRUS ALERTS - July 1, 2004
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Troj/CWS-C
by Marianna Schmudlach / July 1, 2004 12:44 AM PDT

Aliases
TrojanDownloader.Win32.Small.lc, StartPage-CQ.gen trojan

Type
Trojan

Description
Troj/CWS-C is an adware Trojan which changes browser settings and modifies
the HOSTS file, so that when the user attempts to connect to selected
websites they are redirected to an alternative site.
Troj/CWS-C may also launch web pages, including pages containing sexual
content.

When the installation executable for Troj/CWS-C is first run it adds
its pathname to one of the following new registry entries to run itself on
startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\AddClass
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Host


More: http://www.sophos.com/virusinfo/analyses/trojcwsc.html

Collapse -
CWS Help
by Smooth72 / July 2, 2004 12:31 AM PDT
In reply to: Troj/CWS-C

Here is an easy one for you experts. Please help me get rid of this thing. I have run, CW Shredder, Ad-aware, Spybot, I also have spy sweeper set up. I get this URL that come up
res://prdyn.dll/index.html#10213

When I run ad-aware:
c:\windows\crno32.exe can not be terminated

When I run Spy sweeper:
cws_ns3 & cws_ns3 hijacker are on the system
cws_ns3 - crno32.exe is the software running

However when I quarantine, delete and reboot, the same CWS w/a different .exe comes up such as...
ntsu32.exe or syshq.exe or ipgy.exe

Long story short, I am probably missing something simple here...expert advice/direction/instruction appreciated!!

Collapse -
Re: CWS Help
by Marianna Schmudlach / July 2, 2004 1:57 AM PDT
In reply to: CWS Help

Hi Smooth72

there are several variants out at the moment and the "gurus" are working around the clock to analyze these "baddies". The solution which works for one does NOT work on a different computer Sad It all depends on "hidden" or "super hidden" dll's Sad

The best "help" I can offer is :

Please go to

http://www.spywareinfo.com/~merijn/files/HijackThis.exe

and download 'Hijack This!'.
Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log as a .txt file, and copy and paste its contents into your next post.

Most of what it lists will be harmless, so do not fix anything yet.

Post here:
http://www.computercops.biz/ or
http://www.wilderssecurity.com/

Collapse -
Re: CWS Help
by rello / August 29, 2004 4:16 PM PDT
In reply to: CWS Help

The Bottom line is that this new trojan is too tricky to remove, it attacks Internet Explorer which has a polethera of security problems the best way to solve this problem is to stop using IE. I installed Firefox as my new browser tonight and I'm having no problems. I am writing a business plan and using the internet as my main source of information and inspiration so the CWS trojan was really stressing me out. Firefox seems to be impurvious to the problem. The trojan is still running but it is only affecting IE. good luck

Collapse -
Troj/StartPa-BM
by Marianna Schmudlach / July 1, 2004 12:46 AM PDT

Aliases
INFECTED TrojanDropper.Win32.Small.hx

Type
Trojan

Description
Troj/StartPa-BM is a simple Trojan that changes default Internet Explorer
settings by modifying related registry entries.
Troj/StartPa-BM may drop the file sp.html in the temp folder along with two
randomly named dll files in the default system folder.

http://www.sophos.com/virusinfo/analyses/trojstartpabm.html

Collapse -
W32/Rbot-BZ
by Marianna Schmudlach / July 1, 2004 12:48 AM PDT

Aliases
Backdoor.Rbot.gen, W32.Spybot.Worm

Type
Win32 worm

Description
W32/Rbot-BZ is a worm which attempts to spread to remote network shares. It
also contains backdoor Trojan functionality, allowing unauthorised remote
access to the infected computer via IRC channels while running in the
background as a service process.
W32/Rbot-BZ spreads to network shares with weak passwords as a result of the
backdoor Trojan element receiving the appropriate command from a remote user.

W32/Rbot-BZ moves copies itself to the Windows system folder as
ZONEALARM.EXE and creates registry entries called 'Microsoft Update Machine'
under the following keys in order to run itself on system startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

W32/Rbot-BZ may set the following registry entries:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"

http://www.sophos.com/virusinfo/analyses/w32rbotbz.html

Popular Forums
icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

CNET FORUMS TOP DISCUSSION

Help, my PC with Windows 10 won't shut down properly

Since upgrading to Windows 10 my computer won't shut down properly. I use the menu button shutdown and the screen goes blank, but the system does not fully shut down. The only way to get it to shut down is to hold the physical power button down till it shuts down. Any suggestions?