JPI_Cache worm

JPI_Cache worm

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
JPI_Cache worm Phil 08-10-2006
---> Re: JPI_Cache worm David H. Lipman08-10-2006
---> Re: JPI_Cache worm David H. Lipman08-10-2006
Posted by =?Utf-8?B?UGhpbA==?= on August 10, 2006, 5:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I had a virus and manually deleted it as EZ antivirus would not. Now I am
left with pop ups and security warnings. I am using windows xp home. I have
run windows defender, spybot and lavasoft to no avail. Any one know how to
fix this?

--
Thank you,
Phil

--
Thank you,
Phil

Posted by David H. Lipman on August 10, 2006, 5:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I had a virus and manually deleted it as EZ antivirus would not. Now I am
| left with pop ups and security warnings. I am using windows xp home. I have
| run windows defender, spybot and lavasoft to no avail. Any one know how to
| fix this?
|
| --
| Thank you,
| Phil
|

Your use of thye word "worm" is loose. Chances are this is NOT the activity of
an Internet
worm but most likely a Trojan.

The Trojan was most likely a .CLASS file in a Java Jar (ZIP type file).

You say... "Now I am left with pop ups and security warnings"

Please post the EXACT text of the Pop-Ups and Security Warnings.

-----------

If you are using any version of Sun Java that is prior to JRE Version 5.0 update
5,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0 update 5. There are vulnerabilities in them and they are actively
being
exploited. It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.5.0_08

http://www.java.com/en/download/manual.jsp

or

http://java.sun.com/javase/downloads/index.jsp


1) Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete
files

2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

3) Dump the contents of your Sun Java cache -
Start --> settings --> control panel --> Java applet --> cache --> clear
or
Start --> settings --> control panel --> Java applet --> general -->
settings -->
delete files

4) Re-scan your system using your anti virus software.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?UGhpbA==?= on August 10, 2006, 6:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Will do the best I can from memory. The computer is at my daughters. I can go
back their after dinner if need be. Near the clock there is a yellow triangle
blinking with an exclamation point. When you click on that it brings you to a
web site to sell you spyware. A pop up screen for adult friend finder.
Another was Monaco golden ??? Mostly security advertisements and sex pop
ups. I manually did searches and deleted as they came up. I'm sorry don't
remember things exactly. I will go back after dinner. If this isn't enough
guidance I will post more. I did already update the java after the first
answer you posted.
--
Thank you,
Phil


"David H. Lipman" wrote:

>
> | I had a virus and manually deleted it as EZ antivirus would not. Now I am
> | left with pop ups and security warnings. I am using windows xp home. I have
> | run windows defender, spybot and lavasoft to no avail. Any one know how to
> | fix this?
> |
> | --
> | Thank you,
> | Phil
> |
>
> Your use of thye word "worm" is loose. Chances are this is NOT the activity
of an Internet
> worm but most likely a Trojan.
>
> The Trojan was most likely a .CLASS file in a Java Jar (ZIP type file).
>
> You say... "Now I am left with pop ups and security warnings"
>
> Please post the EXACT text of the Pop-Ups and Security Warnings.
>
> -----------
>
> If you are using any version of Sun Java that is prior to JRE Version 5.0
update 5,
> then you are strongly urged to remove any/all versions that are prior to
JRE/JSE
> Version 5.0 update 5. There are vulnerabilities in them and they are actively
being
> exploited. It is possible that is how you got infected with malware.
>
> Therefore, it is highly suggested that if there are any prior versions of Sun
Java
> to Version 5 on the PC that they be removed ASAP.
>
> The latest version is Sun Java JRE/JSE Version 5.0 Update 8
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version.
>
> Such as...
> C:\Program Files\Java\jre1.5.0_08
>
> http://www.java.com/en/download/manual.jsp
>
> or
>
> http://java.sun.com/javase/downloads/index.jsp
>
>
> 1) Dump the contents of your IE cache -
> Start --> settings --> control panel --> Internet options --> delete
files
>
> 2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
> Tools --> Options --> Privacy --> Cache --> Clear
>
> 3) Dump the contents of your Sun Java cache -
> Start --> settings --> control panel --> Java applet --> cache -->
clear
> or
> Start --> settings --> control panel --> Java applet --> general -->
settings -->
> delete files
>
> 4) Re-scan your system using your anti virus software.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by Elendil on August 10, 2006, 6:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You've added information and I think I've narrowed it down two two
possible malware infections. From what you're describing, it is a not a
virus you have but some type of spyware. What is the name of this
"anti-spyware" product that the yellow triangle is asking you to buy? At
any rate, try scanning with Ewido:

First download ewido anti-spyware from HERE and save that file to your
desktop.

1. Once you have downloaded ewido anti-spyware, locate the icon on
the desktop and double-click it to launch the set up program.
2. Once the setup is complete you will need to run ewido and update
the definition files.
3. On the main screen select the "Update" icon then click "Start
Update". The update will start and a progress bar will show the updates
being installed.
4. Once the update has completed select the "Scanner" icon at the top
of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and
then select "Quarantine".
6. Under "Reports"
* Select "Automatically generate report after every scan"
* Un-Select "Only if threats were found"

Close ewido anti-spyware and reboot your computer into Safe Mode.

1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
IMPORTANT: Do not open any other windows or programs while ewido
is scanning, it may interfere with the scanning proccess.
2. Select the "Scanner" icon at the top and then the "Scan" tab then
click on "Complete System Scan"
3. Ewido will now begin the scanning process, be patient this may
take a little time.
4. Ewido will list any infections found on the left hand side. When
the scan has finished, it should automatically set the recommended
action to Quarantine--if not click on Recommended Action and set it
there. Click the Apply all actions button. Ewido will display "All
actions have been applied" on the right hand side.
5. Click on "Save Report", then "Save Report As". This will create a
text file. Make sure you know where to find this file again (like on the
Desktop).
6. Close ewido.
7. Make a new reply to this thread and copy and paste your Ewido log
into the reply.

Your answer & Ewido log should give me the exact answer as to whether or
not you're infected with Winfixer or Spyware Quake. At any rate, DO NOT
BUY THE PRODUCT THAT THE YELLOW TRIANGLE IS ADVERTISING!!!

Phil wrote:
> Will do the best I can from memory. The computer is at my daughters. I can go
> back their after dinner if need be. Near the clock there is a yellow triangle
> blinking with an exclamation point. When you click on that it brings you to a
> web site to sell you spyware. A pop up screen for adult friend finder.
> Another was Monaco golden ??? Mostly security advertisements and sex pop
> ups. I manually did searches and deleted as they came up. I'm sorry don't
> remember things exactly. I will go back after dinner. If this isn't enough
> guidance I will post more. I did already update the java after the first
> answer you posted.

--
3rd Place Florida State Science & Engineering Fair Finalist
Grand Award & 1st Place Broward County Science Fair Winner
Discovery Channel Young Scientist Challenge Competitor
Moving onto high school while losing many friends, yet opening doors to
a new world…

Posted by =?Utf-8?B?UGhpbA==?= on August 10, 2006, 6:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
When you open the ad it is bringing me to spyguard.com. I will run over there
and hopefully have the info from the scan in approx 1.5 hrs.
--
Thank you,
Phil


"Elendil" wrote:

> You've added information and I think I've narrowed it down two two
> possible malware infections. From what you're describing, it is a not a
> virus you have but some type of spyware. What is the name of this
> "anti-spyware" product that the yellow triangle is asking you to buy? At
> any rate, try scanning with Ewido:
>
> First download ewido anti-spyware from HERE and save that file to your
> desktop.
>
> 1. Once you have downloaded ewido anti-spyware, locate the icon on
> the desktop and double-click it to launch the set up program.
> 2. Once the setup is complete you will need to run ewido and update
> the definition files.
> 3. On the main screen select the "Update" icon then click "Start
> Update". The update will start and a progress bar will show the updates
> being installed.
> 4. Once the update has completed select the "Scanner" icon at the top
> of the screen, then select the "Settings" tab.
> 5. Once in the Settings screen click on "Recommended actions" and
> then select "Quarantine".
> 6. Under "Reports"
> * Select "Automatically generate report after every scan"
> * Un-Select "Only if threats were found"
>
> Close ewido anti-spyware and reboot your computer into Safe Mode.
>
> 1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
> IMPORTANT: Do not open any other windows or programs while ewido
> is scanning, it may interfere with the scanning proccess.
> 2. Select the "Scanner" icon at the top and then the "Scan" tab then
> click on "Complete System Scan"
> 3. Ewido will now begin the scanning process, be patient this may
> take a little time.
> 4. Ewido will list any infections found on the left hand side. When
> the scan has finished, it should automatically set the recommended
> action to Quarantine--if not click on Recommended Action and set it
> there. Click the Apply all actions button. Ewido will display "All
> actions have been applied" on the right hand side.
> 5. Click on "Save Report", then "Save Report As". This will create a
> text file. Make sure you know where to find this file again (like on the
> Desktop).
> 6. Close ewido.
> 7. Make a new reply to this thread and copy and paste your Ewido log
> into the reply.
>
> Your answer & Ewido log should give me the exact answer as to whether or
> not you're infected with Winfixer or Spyware Quake. At any rate, DO NOT
> BUY THE PRODUCT THAT THE YELLOW TRIANGLE IS ADVERTISING!!!
>
> Phil wrote:
> > Will do the best I can from memory. The computer is at my daughters. I can
go
> > back their after dinner if need be. Near the clock there is a yellow
triangle
> > blinking with an exclamation point. When you click on that it brings you to
a
> > web site to sell you spyware. A pop up screen for adult friend finder.
> > Another was Monaco golden ??? Mostly security advertisements and sex pop
> > ups. I manually did searches and deleted as they came up. I'm sorry don't
> > remember things exactly. I will go back after dinner. If this isn't enough
> > guidance I will post more. I did already update the java after the first
> > answer you posted.
>
> --
> 3rd Place Florida State Science & Engineering Fair Finalist
> Grand Award & 1st Place Broward County Science Fair Winner
> Discovery Channel Young Scientist Challenge Competitor
> Moving onto high school while losing many friends, yet opening doors to
> a new world…
>

Similar ThreadsPosted
Worm VB.AS Aliases W32.Alcra.B and W32/Alcan.worm!p2p July 18, 2005, 8:37 am
WORM/DELF.FPV - new worm?? January 14, 2008, 6:58 am
new worm? June 20, 2006, 5:09 am
new worm i think November 22, 2006, 6:15 pm
RE NEW WORM November 23, 2006, 5:24 pm
Worm? November 11, 2008, 1:17 pm
Virus/worm? October 25, 2005, 2:29 am
Virus-Worm April 6, 2006, 5:43 pm
Worm Rontok April 20, 2006, 10:35 pm
W32.Sinnaka.A@mm worm May 2, 2006, 12:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy