mikewerts
Joined: 26 Mar 2008 |
Posts: 0 |
|
|
 |
Posted: Wed Apr 09, 2008 1:16 pm |
|
 |
 |
 |
 |
My clamwin recently detected files infected with this, but I could not find anythin on the web about this strain. All of the files were JS files... no idea how they got in my temporary internet files though I was looking throught a lot of JS instruction sites at the time...
Here's the log:
C:\Documents and Settings\mwerts\Local Settings\Temporary Internet Files\Content.IE5\1IT24Y4S\UR[1].js: Trojan.Downloader.JS.Agent-2 FOUND
C:\Documents and Settings\mwerts\Local Settings\Temporary Internet Files\Content.IE5\AVZUGWQ3\GCION[1].js: Trojan.Downloader.JS.Agent-2 FOUND
C:\Documents and Settings\mwerts\Local Settings\Temporary Internet Files\Content.IE5\AVZUGWQ3\LoggedOut[1].js: Trojan.Downloader.JS.Agent-2 FOUND
C:\Documents and Settings\mwerts\Local Settings\Temporary Internet Files\Content.IE5\I6WAPIJQ\UA[1].js: Trojan.Downloader.JS.Agent-2 FOUND
C:\Documents and Settings\mwerts\Local Settings\Temporary Internet Files\Content.IE5\UT1LME4W\GDSRScripts[1].js: Trojan.Downloader.JS.Agent-2 FOUND
I deleted all of these since they didn't seem to have any meaning but how could have they gotten on my system and what would they do?
Thanks,
Mike
|
|
sherpya
Joined: 22 Mar 2006 |
Posts: 0 |
Location: Italy |
|
 |
Posted: Thu Apr 10, 2008 5:42 pm |
|
 |
 |
 |
 |
while visiting a bad site, they are .js files, js files are loaded on html page requests so you got them in the cache
this does not mean you are infected, but just visited pages with this content
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sat Apr 12, 2008 12:56 am |
|
 |
 |
 |
 |
If they become active, trojan downloaders will download the real malware onto your computer. Malware has now shifted from being primarily email-based to Web site based, and it is frequently broken up into several components.
You can clear your Internet Explorer cache periodically. There is some helpful information at:
https://support.f-secure.com/enu/home/virusproblem/howtoclean/cleaniecache.shtml on the Web that tells how to clear it. I believe you can also clear it by using the disk cleanup utility (Start/AllPrograms/Accessories/SystemTools/Diskcleanup.
Regards,
|
|