I was hit by a slew of Java Script Exploits as well as Trojans this past week

Hello:
On 7/10/2012, my desktop machine got hit by a slew of Virus and Trojans which even though removed, they are impacting the use of my computer. Information below.
First 7.10/2012 Trojan win32/Tibs.IT Severe Threat detected by Microsoft security essentials and Quarantined
Second 7/11/2012 0332 Trojan Win32/Tibs.It Severe Threat ditto ditto ditto and Quarantined
Third 7/15/2012 ExploitJava/CVE-2012-0507.CG SEVERE THREAT AND QUARANTINED BY MSE.
Fourth 7/15/2012 Exploit:Java/CVE-2012-1723.F SEVERE THREAT AND QUARANTINED MY MSE.
Since I have run Avast, it has not picked up on any of these in my system, but the damage seems to be done and wonder how I can reverse it? If I were to do a system restore before any of this ever happened would I be able to fix my machine myself. I know that the registry has been corrupted and that Microsoft has an "autoruns" program that they charge 100 bucks to run. Do you know of any place where I could obtain a similar program so that I can do this myself. I do know that in "autoruns" the YELLOW registry items need to be deleted. That being said can you help me please? I don't want to have to go through reformatting everything and starting all over :(. Days it takes and I end up losing a lot of stuff in the process. Thank you.
in addition, according to Avast Internet Security Report, look what sections of my computer are blocked or disabled from scanning.
Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.22.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Georg :: GEORG2-PC [administrator]
Protection: Enabled
7/22/2012 04:54:59
mbam-log-2012-07-22 (04-54-59).txt
Scan type: Custom scan (C:\Users\Georg\Pictures\ME - Copy\ME\Picture 4.jpg|)
Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled: Memory | Startup | Registry | Heuristics/Extra
Objects scanned: 0
Time elapsed: 14 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Can anyone help me with this? This trojan is in my email and programs and causing havoc everywhere. So far, I see how it works by disabling the main sections of the computer that are need to be scanned to get rid of it. How can I fix this?
Thanks.
geoff

Hi,
It would also be a good idea to post in a dedicated security forum. You can also post there regarding malware removal live USB/CDs which would be sufficient and useful in a lot of situations:
http://www.bleepingcomputer.com/forums/forum79.html
http://www.spywarewarrior.com/index.php
http://www.spywareinfoforum.com/
http://www.wilderssecurity.com/
Please also note that [http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx Autoruns] is a free program.

Similar Messages

  • I am still having problems accessing java script sites.  Anyone else having this problem?

    I am still having problems accessing java script sites.  Anyone else having this problem?

    Javascript can be left on, but Java (which is something very different) should generally be turned off.
    Apple barred Java from running on Macs, leaving companies that rely on Java plug-ins out in the cold.
    Apple blocked Java 7 Update 11 by adding it to the banned list in XProtect.
    This was the second time in two weeks that Apple has blocked Oracle's code from running on Macs. This time Java is blocked through Apple's XProtect anti-malware feature.
    Java has come under fire as the means by which hackers have been able to gain control of computers. In April 2012 more than 600,000 Macs were reported to have been infected with a Flashback Trojan horse that was being installed on people's computers with the help of Java exploits. Then in August Macs were again at risk due to a flaw in Java, this time around, there was good news for Mac users: Thanks to changes Apple has made, most of us were safe from the threat.
    Unwilling to leave its customers open to potential threats Apple decided it's safer to block Java entirely.
    Macs running OS X Snow Leopard and beyond are affected.
    UPDATE for those running Lion or Mountain Lion:
    Oracle on Friday February 1 released a new version reportedly addressing vulnerabilities seen with the last build.
    Apple disabled Java 7 through the OS X XProtect anti-malware system, requiring users to have at least version "1.7.0_10-b19" installed on their Macs. The release dated February 1 carries the designation "1.7.0_13-b20," meeting Apple's requirements.
    Oracle "strongly recommends" applying the CPU fixes as soon as possible, saying that the latest Critical Patch Update contains 50 new security fixes across all Jave SE products.
    Update foror Snow Leopard users:
    Apple have issued update 12 for Java for OS 10.6:
    http://support.apple.com/kb/DL1573
    Note:  On systems that have not already installed Java for Mac OS X 10.6 update 9 or later, this update will configure web browsers to not automatically run Java applets. Java applets may be re-enabled by clicking the region labeled "Inactive plug-in" on a web page. If no applets have been run for an extended period of time, the Java web plug-in will deactivate.

  • I am unable to connect to my home wifi, i was fine in a hotel this past week with the wifi

    Question I am unable to connect to my home wifi, I was fine in a hotel this past week with their wifi, I am not that technical and need help also how do I find my operating system info??

    Go to settings, general, about, and you will see "version." That will indicate what your operating system is such as 5.0.1 which is the most recent upgrade.
    As for the wifi, you might try going to settings, then general, then at the bottom reset, then click on reset network settings. Back out of everything and then when you log back onto your wifi it will ask you for your local password (assuming you gave it one when your router was set up). Enter it and you should be good for go.  At least this worked for me.
    Good luck.

  • Internet explorer allows me to open certain information/tabs which are somehow connected to java script but Firefox won't. This just started happening a few days agoyet my javca script is enabled. what is the problem/fix. I'm a novice with computers

    I am not sophisticated at understanding computer language. What I know is that 3 things have happened in the last 2 weeks.
    1.My yahoo account which I go to from Mozilla firefox 4.0.1 now requires me to click on a link that says it disables updates. Then my homepage seems to be ok/normal except:
    2.One of the email links tries to open a site called Ok Cupid and that site is really distorted and unreadable
    3. another website www.texastrails.org has a tab called 'docs' which can be reached from "member portal". There should be documents in Word and adobe reader on the left side of the screen which can be opened normally. These do not exist now and the texas trails webmaster says it has to do with Java Script. (it does open in Internet Explorer)
    Why would these two sites open in IE but not firefox?
    Note that I went to "My Computer" and found I have environment 5.0 Java6 update 24 and J2SE Runtime environment 5.0update 6 on different lines. I have no clue what these mean:-)
    I also click on Firefox "tools" and see that java is checked/enabled.

    This is not an answer. I have the same problem, what gives? None of the "solutions" have worked. The only thing left I haven't tried is resetting my IP an disabling my routers firewall, which is dangerous. Guess I might just keep on using IE instead, sure it's annoying, but hey it works.

  • Installed a wireless canon Pixma MX432 printer back in November for use with my Mac Book Air. All was working normally until this past week when I began getting a message, "printer not connected." What is going on? Netgear Wireless N Router seems to be ok

    My new canon Pixma MX432 printer is not printing. It was printing fine until about ten days ago. I use a Netgear Wireless N router, which is also new. What do I need to do. I get a message when trying to print that says "printer not connected." In addition, my old Gateway laptop will still print fine apparently because it has a cable connection to the printer. Puzzled!

    Have you tried rebooting the router? I would unplug it, wait a few seconds, then plug it back in. Be sure you know the password etc. if that doesn't work, try unplugging and rebooting the printer. Good luck!

  • Recently I have been going to websites, like facebook, and no pics come up. I have Win XP. Everything was fine until this past week. I did try to reinstall it. The pics came up at first and now they don't again.

    For some reason, I cannot get up any pictures now. I had a problem with Google Chrome at the same time. I am not sure whether it is related so I want to find out if anyone else had this problem. FYI: I uninstalled the Google Chrome.

    If images are missing then check that you aren't blocking images from some domains.
    You can use these steps to check if images are blocked:
    * Open the web page that has the images missing in a browser tab.
    * Click the website favicon ([[Site Identity Button]]) on the left end of the location bar.
    * Click the "More Information" button to open the "Page Info" window with the Security tab selected (also accessible via "Tools > Page Info").
    * Go to the <i>Media</i> tab of the "Tools > Page Info" window.
    * Select the first image link and scroll down through the list with the Down arrow key.
    * If an image in the list is grayed and there is a check-mark in the box "<i>Block Images from...</i>" then remove that mark to unblock the images from that domain.
    See also:
    * http://kb.mozillazine.org/Images_or_animations_do_not_load

  • How to chcek if Java Script is enabled for the browser

    Hi all,
    I wanted to know if there was any way to check if Java Scripts is enabled in the browser on which the jsp screen is being displayed. This type of check should be in Java and im working on a struts framework.
    Thanks

    There are multiple ways of doing it. Depends on wether you need this information only at the Client (browser) or do you need it at the Server.
    In case of Client its trivial. You could do it in HTML:
    <div id="jsEnabled" style="visibility:hidden">
    JavaScript is enabled
    </div>
    <div id="jsDisabled">
    JavaScript is disabled
    </div>The first div contains the text "JavaScript is enabled" while the second one says "JavaScript is disabled". The first div is also made hidden. Now, we attach the checkJavaScriptValidity function to the onload event of the page.
    <body onload="checkJavaScriptValidity()">checkJavaScriptValidity hides the second div and make the first one active. If JavaScript is enabled you will see the first div which says "JavaScript is enabled". If JavaScript is disabled you will see the second div which says "JavaScript is disabled".
    <script language="javascript" type="text/javascript">
    function checkJavaScriptValidity()
    document.getElementById("jsEnabled").style.visibility = 'visible';
    document.getElementById("jsDisabled").style.visibility = 'hidden';
    </script>But I guess since you want it to do it in Java, you'll need this information at the Server side as Browsers dont execute Java code. In that case you could just do an HTTP hit from a javascript function on load with information about the current session. But I still do not understand why would need this information at the server side as your purpose seems to be to ask the user to enable Javascript on his browser.

  • Copy and paste Java script for password protecting a page?

    I need to password protect one page which I want to call my LOGIN page on a site I'm making in Dreamweaver CS5.5.  Unfortunately I know that the hosting company I'm using does not have the ability to allow me password a single directory on the server end to accomplish this (I know STRANGE)   .... SO
    I found some code online - java script that I can just copy and paste into the <head> section of my page.  This might be a silly question but is this a 'safe' way to do this?    (I don't need anything fancy and the people whom will be accessing this page will all have the SAME password, so I don't need a registration form or anything fancier...)
    Any thoughts?

    Ugg I totally knew you would all say that (because I already knew that would offer me the easiest solution), change hosts and now I'm embarrassed to say that YES I am paying for the hosting; BUT, I have to explain that I'm with this hosting company because way back when I started that site I needed something super user friendly because I was just learning.  Now I have learned more and have started to use Dreamweaver.  I just stayed with the same hosting and will use FTP to upload my new more updated site.  In the company's defense even though they do offer a way to FTP a site up, their main objective (I think) is to have a really easy way for people to get a site up without knowing anything about code or css or anything; and they operate under the assumption that MOST of their customers will be using their super easy software and not use FTP.  That is why I think they are limited to what they offer, at least that is my take on it.  My more recent sites do not use this company as I have tried to learn and 'move up'. 
    Anyway I guess if I don't want to switch hosting I still have the same problem.  Is it really that difficult to make something that has just one use ID and password which would be the same thing for every person?  Might be a great learning experience for me?
    Yep it might be time for me to switch hosting....  sigh.  What to do.....

  • Captivate 8: How to add a button onto a question slide to invoke some java script?

    I have some question slides where the user has to guess an item on a picture. Because the picture is very small, I want to add a zoom button which calls a function in my LMS to popup the picture in a bigger window. I could not find a way to add a button where I can call java script, so I tried to solve this by using a smart shape with option "use as button" set and adding the java script action. This works fine for the popup but now the submit button on the slide no longer works. Clicking the submit button just disables the answers and stays on the current slide even if I did not click onto the shape button previously. How can I achieve my goal to display a bigger picture of an image on my slide on the users request?
    I also tried the "ImageView" widget, but this is not a practicable solution.
    Thanks,
    Martin

    I think I found the solution: In the "Timing" tab for the shape there is an option "Pause After" which was set to 1,5 seconds. I cleared this options and now the submit button is working again.
    Martin

  • Exploits (Java Script, Flash, ActiveX) - SAP principles found where?

    Hi people!
    SAP releases support for rich Web Browser applications in Web Dynpro (Flash).
    The use of the Web Browser as FrontEnd in Business transactions will grow in the future.
    Every week we read of new exploits in applications that enriches the Web Browsers.
    It could be Java Script, Flash or ActiveX. Like this for example:
    http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers
    Some exploits has over the years been so severe that users have been recommended to deactivate the application until a solution is delivered.
    If we are dependent of the Web Browser application for important Business Transactions it becomes more problematic to deactivate it.
    I am looking for information around this area. I have not found anything in SAPNet or SDN, but I have some problems knowing where to look. I have not found this aspect somewhere.
    If you have information of official documents or URLs, please provide it in this thread.
    Cheers,
    Lasse

    Hi,
    I'm not 100% sure if this will help, but you could have a look at two places:
    SAP Security Guides: [https://websmp210.sap-ag.de/securityguide]
      There are security guides for all applications / installations giving recommendations on how to secure the systems.
    SAP Security notes: [https://websmp102.sap-ag.de/securitynotes]
    These SAP OSS notes describe security issues in various SAP components including web applications. On monthly basis security issues and their solutions are published here
    Kind regards
    Maaike

  • Java Script in Bex Web Application Designer

    I have created a web template in Bex WAD, written some java script function, i want to call this function on page load of every page,currently this function is getting called as soon as the first page is loaded but when i click on Next page or Prev page to show next 100 records then this function is not getting called, is there any way where in this function should be called always when user moves from one page to another.

    Hi thirumurugan
    The following link will solve your problem..
    http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/c01e9b01-abab-2d10-6687-96fc7bc39084?quicklink=index&overridelayout=true
    Regards,
    Ranganath.

  • How to set Preferences such that new tabs open to same page as active when Command-T was hit?

    On opening a new tab, the tab by default opens to thumbnails based on recent history. A la Safari, I want the new tab to open *to same page as was active when Command-T was hit*. What are the specific steps to take, to set as the default (preference), new pages to open to "Same page"? ("Same page" is Safari's check box in its Preferences.)
    Note, I have navigated available Mozilla Support, and using about:config have reset browser.newtab.url so that the new tab appears blank (discontinuing tracking of recent history for this purpose).
    Note, more importantly, I have found this Support Forum article, which, though challengingly written, has given me a temporary solution:
    * https://support.mozilla.org/en-US/questions/891635
    (The temporary solution for the Mac OS is to Command-click on the "Reload current page" icon in the url/Address box in the browser toolbar, which opens a new tab in the same window.)
    However, I would still like to set this as a permanent Preference, and would ask someone communicate a solution to me. Cheers, LeProf

    ''LeProf_7272 wrote:''
    if I can possibly just create a new config line
    You can't, which is why I suggested the above add-ons. There is no option in the UI or hidden preference in Firefox that can duplicate a tab whenever you open a new tab. ''browser.newtab.url'' can only be set to a fixed address, not whatever address happens to be open in the current tab.
    The are only two built-in methods for duplicating a tab:
    # Hold down the '''Option''' key and drag the tab to a new position on the tab bar.
    # Hold down the '''Command''' key and click the Reload button in the address bar.
    * [[Use mouse shortcuts to perform common tasks in Firefox]]
    You can make feature requests by filing enhancement bug reports, or by opening the Help menu and clicking Submit Feedback.
    * https://developer.mozilla.org/docs/Mozilla/QA/Bug_writing_guidelines
    * https://input.mozilla.org

  • How can I restore my itunes library onto my new PC. My old PC was hit by a virus and I was unable to export it ??

    Quite a while ago my 'old' PC was hit by a virus and I was unable to extract any data from it. When I got a new PC I could not find a way to recover my library from itunes so reluctantly I signed up for a new account. Is there some way that I can contact itunes to see about having my old library restored on my new PC ??  I even had money in the account that was unused !!

    If for some reason you have failed to maintain a backup copy of your computer ( not good), then you can redownload some itunes purchases in some countries.
    Downloading past purchases from the App Store, iBookstore, and iTunes Store
    Why would you start a new account?  Why no use the same account on the new computer?

  • My iphone was hit by a car, however the back is totally intact as well as the sim card. Is there a way for me to back up my phone to my computer/icloud, so when I get my new iPhone, I can sync all of my old data to it?

    Need help with my broken iPhone4s. It was hit by a car, and I need to know how to back up my data to my computer/iCloud so when I get my new iPhone I can sync it to there and still have all my old data, such as contacts, photos, apps, etc.

    If you had iCloud backup turned on, and it made a backup - yes.  If you didn't have iCloud backup turned on - but were using iCloud for Contacts, calendars, etc.  You will get the contacts and calendars, etc back.
    Purchases made with your appleID can be redownloaded as long as they are still available in the iTunes store.
    If you connected your phone to a computer with iTunes, there may be a backup on there as well.

  • I have an open case. I can't get a response from Adobe. My computer was hit by lightening and cannot be repaired. It had Photoshop on it. I want to get a copy of Photoshop for my new computer using the serial

    My computer that had Adobe Photoshop CS6 on it was hit by lightening and cannot be repaired. I want to get a copy of Photoshop for my new computer. I have an open case, but I cannot get Adobe to respond to it. I have sent the serial# and a copy of the license. Every time I try the chat function to get help, I get dropped with the message "chat is no longer available." I WANT MY PHOTOSHOP!

    This is a user forum, not a channel to address Adobe. As your fellow users and volunteers, we'll be happy to help you if we can.
    You can download the CS6 trial version just like anybody else.
    Once you download it, you can install it, input your serial number, register it and apply all necessary updates.
    An alternative, if you know how to access your Adobe account, under My Products you'll find your Photoshop CS6 registration, next to which you should find a link to download CS6 if you originally bought it as a download

Maybe you are looking for