Trojan Horse JS/Uniz.B

abhong

Member
Aug 17, 2005
143
0
0
yep, it just popped up as i was doing my regular scheduled scanning on my AVG Pro.

tried googling but did not get much info.
anyone got some good tips/ideas?

currently i run:

Comodo Firewall Pro
AVG Pro
Spyware Doctor

and as for web, i use Firefox with no-script...

maybe i got sloppy or was click happy somewhere...

thanks.
 

John

Moderator Emeritus<br>Elite Member
Oct 9, 1999
33,944
1
0
JS typically indicates Javascript. You're using FF w/ no-script? SAS, AVGAS, a-squared, Kaspersky, F-Secure, and a few other are great at detecting and removing trojans. Click the first link in my sig for more info.
 

abhong

Member
Aug 17, 2005
143
0
0
Thanks very much for the quick reply John... things like these are so frightening these days, with so much personal work being done over the internet.

i do have FF with no-script... but i may have been careless at one point... it seems that it is/was located in the firefox folder.

i had the free version of AVG AS and working on HJT log atm.

anything else i should do?

someone once told me the best way to be 100% sure is to get a clean start...

this thought frightens the crap out of me...

i will check out your linkie shortly...

thanks again.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Also, where was this file located? If it was in your browser cache, that doesn't necessarily mean you're infected, it just means your browser visited a page that had a malicious script, whether the script actually ran or not. And even if it ran, it may not have delivered its payload.

If the script was on a page where you're allowing JavaScript, however, then that would increase the concern. That can happen. Were you using an Administrator-class user account?
 

abhong

Member
Aug 17, 2005
143
0
0
i am running as admin... i know, i shouldn't, right?

here's a screenshot of where it was.

Text

in case it's too small to read...

c:\Documents and Settings\ahong\Local Settings\Application Data\Mozilla\Firefox\Profiles\vxmjz9td.default\Cache\25F02E5Dd01

thanks!
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Well, like Mech posted, it's in your Cache folder. Sounds like AVG got it, so just clean out your cache.

Go to the Control Panel and double-click the Java Icon.
Under Temporary Internet Files, click the Delete Files button.
There are three options in the window to clear the cache. Leave ALL 3 checked:
- Downloaded Applets
- Downloaded Applications
- Other Files

Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Java Control Panel.
 

abhong

Member
Aug 17, 2005
143
0
0
thank you for the replies...

Medea, i dont have a Java Icon in my control panel... any other way of getting rid of Temp Internet Files and doing what you told me to do?

sorry, i am noobish at these dthings.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Originally posted by: abhong
thank you for the replies...

Medea, i dont have a Java Icon in my control panel... any other way of getting rid of Temp Internet Files and doing what you told me to do?

sorry, i am noobish at these dthings.

Sorry about that! That's what happens when I post before noon...

It's in your Firefox cache - not Java's cache.

In Firefox, click Tools > Advanced tab. Where it says Cache, click "Clear Now". Then set a very low number for MB of space for the cache. Personally, mine is set at O (zero) which you can set at if you have a high-speed connection. If you have a dial-up, then you may want to put a small number there.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |