This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan horse proxy - Hi-Jack this log

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You need to update SunJava.

Updating Java:
Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.
After doing the update lets give it a little time and let me know if you get any more warnings.
We're not done with this yet. Computer on for much of the day and nothing, then about 5 my OH saw a threat come up, but before he could do anything it had disappeared. It didn't show in the virus vault. Ran a scan of C drive and two threats in usual two places. Had a thorough search of the computer and anything to do with the GPS was deleted, all there was were some logs of journeys made using the GPS (terrible English hope it's not what you teach!) Rebooted computer ran scan again, nothing. Also ran scan in safe mode, nothing. In the last half an hour have had 4 threats all in C:\Documents and Settings|All Users\Documents\setup.exe none in GPS details. Yet. Rosalind
No, one time I was opening a game of Solitaire (sad I know) but I've tried several times and it's only happened once. Was copying a sudoku off a site I have used many times over the past couple of years without problems. Web browsing has been limited to main stream sites such as Amazon, hotmail, and some UK ones which are well used. I don't use MSN even though it is installed. I don't download music or videos.
Typed C:\Documents and Settings\All Users\Documents\setup.exe into "run" and got the reponse Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item. When I did this I got a threat warning, which I healed Tried again and got Windows cannot find 'C:\documents' . Make sure you typed the name correctly and then try again. To search for a file, click the start button, and then click search. Did this, in search got a brief glimse of the file, and then the threat, which I healed, nothing in the search then. Rosalind
Download Pocket Killbox
http://www.atribune.org/downloads/KillBox.exe


Then double-click on the killbox.exe program.

At the main screen of KillBox, select the option: Delete on Reboot
Then, in the Full Path of File to Delete box copy/paste the following entry:

C:\Documents and Settings\All Users\Documents\setup.exe

Press the button with a red circle and a white X (Delete File button)
KillBox will alert you: All listed files will be deleted on next Reboot
Click Yes
Next prompt will be: Files will be removed on reboot. Do you want to reboot now?
Select Yes


If your computer does not restart automatically, please restart it manually

"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Went fine until the press delete file button, then got:- Pending File Rename Operations Registry Data has been Removed by External Process. Presume it means it is sitting in the Virus Vault. Rosalind

Went fine until the press delete file button, then got:-

Pending File Rename Operations Registry Data has been Removed by External Process.

Presume it means it is sitting in the Virus Vault.

Rosalind

That should mean it removed the file.
Now we'll see what happens.
Except that it has supposedly healed/deleted Trojan horse Proxy.24.D 8 times I looked in the object details, and where it says healable - NO So why does AVG tell me that it has been successfully healed, now getting confused.

So why does AVG tell me that it has been successfully healed,

My guess is something else is installing it.

Lets make sure this one is gone as well

double-click on the killbox.exe program.

At the main screen of KillBox, select the option: Delete on Reboot
Then, in the Full Path of File to Delete box copy/paste the following entry:

C:\My Documents\GPS\Details\Setup.exe

Press the button with a red circle and a white X (Delete File button)
KillBox will alert you: All listed files will be deleted on next Reboot
Click Yes
Next prompt will be: Files will be removed on reboot. Do you want to reboot now?
Select Yes


If your computer does not restart automatically, please restart it manually

"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Same response as previously. Not had another threat with the path GPS details, after I managed to find some other folders with GPS logs in and deleted them. Prior to that I had another threat, same letters/numbers says it is successfully healed, but it is not. What would happen if I ignored the next one and then ran killbox?
I'll assume it's this one again?
C:\Documents and Settings\All Users\Documents\setup.exe

ignore the next one and then:

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

C:\Documents and Settings\All Users\Documents\setup.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI