virus ?
Viruses got you down? Spyware making your system sluggish? Post here for support on all your security needs.

Moderators: Management, Forum Experts

virus ?

Postby bobseptic on Mon Jan 27, 2003 6:32 pm

i downloaded a program patch from kazzalite, scanned it for viruses, none detected. i clicked on the downloaded file which was a patch & winjava tryed to access the internet, i clicked NO and shortly after all the icons dissapeared on my desktop. i restarted and seconds after zonealarm shut itself down and so did avg antivirus. i restarted it only to have it shut down again.

i traced the problem to startup in msconfig, i found winjava and wsock32 had been added. they are listed under common startup.

i unticked them and rebooted, all seems fine but HOW DO I REMOVE THESE ITEMS FROM STARTUP?

i looked in there location c:WINDOWS\java\apps\winjava.exe
and c:WINDOWS\java\apps\wsock32.exe but the folder is EMPTY (i have settings set to show hidden files etc in folder options)

Is this a virus/trojan?

any help appreciated folks wtf
User avatar
bobseptic
PRO Level 5
PRO Level 5
 
Posts: 168
Joined: Sun Jul 28, 2002 11:08 am
Location: Belfast, Northern Ireland.

Postby SCgone on Mon Jan 27, 2003 6:47 pm

If it was wsock32.dll then it could be the Happy99 virus. That renames wsock32.dll to wsock32.ska and creates a new wsock32.dll. I would certainly download another virus scanner and run it to make sure. A virus would be capable of turning off ZA and I know one targets Norton Antivirus.
SCgone
PRO ELITE
PRO ELITE
 
Posts: 12847
Joined: Thu Mar 14, 2002 7:59 pm
Location: South Carolina, USA

re wsock and winjava

Postby bobseptic on Mon Jan 27, 2003 7:25 pm

the 2 files are called wsock32.exeCommon Startup 36kb, winjava.exeCommon Startup 28kb, i found them in search and they are presently in the rcycle bin. they both had todays date stamp and relevant time.

How do i know if the proper wsock has been renamed?
it is currently in the i386 folder WSOCK32 4.61kb 18/08/2001 13.00 in capital letters whereas the virus is in lower case.

Help Please :no

can a virus rename a file and keep the previous date?

i did full avg search and nothing came up, avg is uptodate

HOW DO I REMOVE THESE ITEMS FROM STARTUP?
:-?
Last edited by bobseptic on Mon Jan 27, 2003 7:27 pm, edited 1 time in total.
User avatar
bobseptic
PRO Level 5
PRO Level 5
 
Posts: 168
Joined: Sun Jul 28, 2002 11:08 am
Location: Belfast, Northern Ireland.

Postby Yappinator on Mon Jan 27, 2003 7:26 pm

housecall

Scan without registering

and also try:

Anti-trojan



yaps
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 11:12 pm
Location: On. Canada


Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 1 guest