Author Topic: need help pleaze  (Read 2673 times)

0 Members and 1 Guest are viewing this topic.

luigi67

  • Guest
need help pleaze
« on: October 16, 2004, 06:50:22 AM »
hello everyone..am new to this formum...not sure where to posr my problem but so far it looks like this is the right place to be..im new to all this puter stuff and have ran into a few problems..i have windows xp pro..things have been going pretty good for awhile then i seemed to be getting all of these viruses..i had norton anti-virus but a freind told me about avast..it has found a couple things...oh i also have hijackthis and spybot..everything is updated and i run them regularly..on the scan i ran tonight i found 3 things......
Win32:Wintrim-012[trj]
Win32:Wintrim-008[trj]
and i didnt get the other name but it is in:
c:/WINDOWS/iNetPal/m3tsp.8exe/[upx]file...

ive noticed that some people have put on thier hjt report and i can do that if you need me too..the viruses have been moved to the chest but i would like to get rid of them completely..


i do alot of surfing and i know you can pick up things alot so like i said i do run my protection twice a week if not everynight..


i would like to thank you for all the help i hope to recieve...
please respond and im sure i will be at this site for a long time.
havent had a chance to check out everything yet but will love doing it...
thank you..

techie101

  • Guest
Re:need help pleaze
« Reply #1 on: October 16, 2004, 08:00:01 AM »
Quote
..things have been going pretty good for awhile then i seemed to be getting all of these viruses..
:D It doesn't seem like you have a lot of viruses, but a replicating one.

Quote
i had norton anti-virus but a freind told me about avast..
Have you removed Norton?  If so, what instructions did you use and from what source?  If Norton is not properly removed,  the remnants could cause future trouble for you and Avast.

Quote
the scan i ran tonight i found 3 things......
Win32:Wintrim-012[trj]
Win32:Wintrim-008[trj]
and i didnt get the other name but it is in:
c:/WINDOWS/iNetPal/m3tsp.8exe/[upx]file...
The third one is more than likely a variant of Wintrim.

The group of Wintrim variants described here are trojans that try to circumvent security settings in Internet Explorer by adding a 'Trusted Publisher' to the list of certificates that Internet Explorer will always accept. Wintrim.U has been distributed as a UPX-packed DLL that is 9,728 bytes in size.
The trojan creates the following registry key to ensure that its DLL is loaded by explorer.exe:

HKCR\CLSID\{469C7080-8EC8-43A6-AD97-45848113743C}\InprocServer32\(Default) = <location of original execution>\ThreadingModel = "Apartment"
You can locate and delete this key manually.  HKCR is short for H- key Current User.  If you do not know how to go into the Registry, ask for instuctions.

Since you have moved the infected files to the chest, you can open up the Chest and delete them.  Once this is done, rerun a full Avast scan with it set to "Thorough" and "include Archives".  This is done by clicking the icon on the scanner to select the hard drive.  A small box will open with a "checkbox" in it.

Quote
ive noticed that some people have put on thier hjt report and i can do that if you need me too..
No, it will not be necessary.  I actually find them too lengthy.
 ;D

The first and foremost defense is a good firewall.  Do you have one installed?  If not, I can recommend some excellent freeware.

A layered defense is the way to go:
Firewall
Antivirus
Antispyware/malware (resident running)
Antispyware/malware (manual scanner backup)
Popup killer (or browser with a PK included)
Spam filter for your email client

Optional:
Cookie filter
Process Guard

Some nice freeware at:
www.snapfiles.com
www.wantdbest.com

I do not believe you mentioned your OS, but if you have IE, adjust the security settings for max protection.
If you have Windows XP with the SP2 download, read up on the security protection console.

You have taken a good step by coming here.  Ask all the questions you like.  Someone will always be here to help.  ;)

Good luck.
« Last Edit: October 16, 2004, 08:06:53 AM by Techie101 »

luigi67

  • Guest
Re:need help pleaze
« Reply #2 on: October 16, 2004, 08:01:04 PM »
well thank you very much for the info only if i could understand it....lmao....i do not know how to go into the registry...i will go to the site you gave and see about them...i removed norton in the control panel..thats all i did with it...should i have done more?like i said im not real puter savoy at all,you could call me a virgin with noooo knowledge whatso ever..lmao...i use mozilla firefox to go through everything and i use outlook express for my mail...if you nee any more info just let me know and ill supply it for you...thank you for your help so far i hope i can get all this taken care of...so far you have been a godsend..thank you again...

                            tina a.k.a  luigi.