d2jsp
Log InRegister
d2jsp Forums > d2jsp > General Help > General Help Archive > Need Help With Viruses
123Next
Add Reply New Topic New Poll
Member
Posts: 18,448
Joined: Jun 20 2007
Gold: 343.07
Jul 18 2011 09:54am
I did a system scan and got 12 detections,and it said 7 of them were moved, but im pretty sure they didn't get removed/fixed.
Here's a log of what happened.
Begin scan in 'C:\'
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\18f94b81-411992db
[0] Archive type: ZIP
--> glass/mumux$vrkr.class
[DETECTION] Contains recognition pattern of the JAVA/Premarin.B Java virus
--> glass/mumux.class
[DETECTION] Contains recognition pattern of the JAVA/Exdoer.DH Java virus
--> glass/Zo666.class
[DETECTION] Contains recognition pattern of the JAVA/Premarin.A Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\774b2cd2-323c9c47
[0] Archive type: ZIP
--> rotor/zalux$vrkr.class
[DETECTION] Contains recognition pattern of the JAVA/Premarin.B Java virus
--> rotor/zalux.class
[DETECTION] Contains recognition pattern of the JAVA/Exdoer.DH Java virus
--> rotor/Zo666.class
[DETECTION] Contains recognition pattern of the JAVA/Premarin.A Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\7061701b-3d8128f3
[0] Archive type: ZIP
--> vload.class
[DETECTION] Contains recognition pattern of the JAVA/Stutter.U Java virus
--> vmain.class
[DETECTION] Contains recognition pattern of the JAVA/Stutter.K Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\6e9ba0e3-2be8c3f3
[0] Archive type: ZIP
--> vload.class
[DETECTION] Contains recognition pattern of the JAVA/Fester.D.1 Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\19feea27-60022ae1
[0] Archive type: ZIP
--> main.class
[DETECTION] Contains recognition pattern of the JAVA/Stutter.AN Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\73af3104-7c14b025
[0] Archive type: ZIP
--> folder/Ump_45.class
[DETECTION] Contains recognition pattern of the JAVA/Dldr.OpenS.NBG Java virus
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\4c81ed73-660014c7
[0] Archive type: ZIP
vmain.class
[DETECTION] Contains recognition pattern of the JAVA/Stutter.X Java virus
Begin scan in 'Q:\'
Search path Q:\ could not be opened!
System error [5]: Access is denied.
Member
Posts: 18,448
Joined: Jun 20 2007
Gold: 343.07
Jul 18 2011 09:56am
Beginning disinfection:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\4c81ed73-660014c7
[DETECTION] Contains recognition pattern of the JAVA/Stutter.X Java virus
[NOTE] The file was moved to the quarantine directory under the name '484bf436.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\73af3104-7c14b025
[DETECTION] Contains recognition pattern of the JAVA/Dldr.OpenS.NBG Java virus
[NOTE] The file was moved to the quarantine directory under the name '5005db61.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\19feea27-60022ae1
[DETECTION] Contains recognition pattern of the JAVA/Stutter.AN Java virus
[NOTE] The file was moved to the quarantine directory under the name '0255818f.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\6e9ba0e3-2be8c3f3
[DETECTION] Contains recognition pattern of the JAVA/Fester.D.1 Java virus
[NOTE] The file was moved to the quarantine directory under the name '64b5ceb9.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\7061701b-3d8128f3
[DETECTION] Contains recognition pattern of the JAVA/Stutter.K Java virus
[NOTE] The file was moved to the quarantine directory under the name '2136e37a.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\774b2cd2-323c9c47
[DETECTION] Contains recognition pattern of the JAVA/Premarin.A Java virus
[NOTE] The file was moved to the quarantine directory under the name '5e2fd110.qua'.
C:\Users\Mike\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1\18f94b81-411992db
[DETECTION] Contains recognition pattern of the JAVA/Premarin.A Java virus
[NOTE] The file was moved to the quarantine directory under the name '1245fd59.qua'.
End of the scan: Monday, July 18, 2011 11:50
Used time: 46:56 Minute(s)
Member
Posts: 17,029
Joined: Mar 28 2010
Gold: 519.00
Warn: 50%
Jul 18 2011 10:20am
easy way :

reformat and don't go to porn websites if u are not using a live cd ( i m saying part about porn because there is alllot of persons watching this in the internet )
Member
Posts: 8,153
Joined: Dec 30 2005
Gold: 1,333.63
Jul 18 2011 10:24am
If you don't want to reformat, start your computer in safe mode with networking. Then download Malwarebytes Anti-Malware and perform a full scan.
Member
Posts: 18,448
Joined: Jun 20 2007
Gold: 343.07
Jul 18 2011 10:24am
I don't want to reformat because I have not scanned in a while so I don't know when these appeared, and I also don't want to lose any information
Member
Posts: 18,448
Joined: Jun 20 2007
Gold: 343.07
Jul 18 2011 10:26am
I wish I could edit, but I can't.

iDGames, last night I also performed a full Malwarebtyes scan, and nothing was detected.

Do you think it's really worth it to scan in safe mode?
Member
Posts: 8,042
Joined: Feb 2 2011
Gold: 69,537.73
Trader: Trusted
Jul 18 2011 10:27am
Download & install Malwarebytes & spybot S&D (if u haven't done so already)

Reboot ur PC in safe mode (f4)

Scan ur pc with ur antivirus, malewarebytes & spybot to remove all threats on ur PC
Member
Posts: 8,153
Joined: Dec 30 2005
Gold: 1,333.63
Jul 18 2011 10:30am
Quote (Zelphar @ 18 Jul 2011 18:26)
I wish I could edit, but I can't.

iDGames, last night I also performed a full Malwarebtyes scan, and nothing was detected.

Do you think it's really worth it to scan in safe mode?


No, it doesn't matter if you scan in safe mode or in normal mode. But you often can't open any applications anymore - doesn't seem to apply in this case.

However, you should also run a different scanner like AVG Anti-Virus or Spy-Bot S&D and see if all viruses get removed.

This post was edited by iDGames on Jul 18 2011 10:31am
Member
Posts: 6,192
Joined: Dec 13 2010
Gold: 6,669.99
Jul 18 2011 02:12pm
Quote (Zelphar @ Jul 18 2011 01:26pm)
I wish I could edit, but I can't.

iDGames, last night I also performed a full Malwarebtyes scan, and nothing was detected.

Do you think it's really worth it to scan in safe mode?


from what i see, you visited a site with a java exploit
your anti-virus probably caught the file from automatically downloading in the first place but it modified some files in your java folder
or, it opened a backdoor which the attacker can do whatever with your computer and even steal your information

which anti-virus are you using? avira?
you should try a different one (do not use 2 at the same time)
avast and MSE are great and free
kaspersky is good also

and yes its worth scanning in safemode, the virus might be protecting itself

if you need more help, let me know
Member
Posts: 21,631
Joined: Mar 15 2011
Gold: 6,062.01
Jul 18 2011 02:18pm
RogueKiller
Go Back To General Help Archive Topic List
123Next
Add Reply New Topic New Poll