AVG Trojan horse SHeur.ALJL?

  1. #11
    VopThis is offline Senior Member (Canada)

    Re: AVG Trojan horse SHeur.ALJL?

    The latest scan only found low risk COOKIES. New scans may only find minimal additional findings. We are now likely running into the law of diminishing returns with no clearly definable ends or results in sight.

    You still may have an older insecure JAVA version still left in Add/Remove Programs (Control Panel) - you need to uninstall that if applicable:

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"




    The last 5 restore points have not been reported in your subsequent DSS logs (at the beginning of each log):

    Main.txt
    Deckard's System Scanner v20071014.68
    Run by XXXXXXXXXX on 2008-01-14 15:58:58
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    76: 2008-01-14 15:59:06 UTC - RP342 - Deckard's System Scanner Restore Point
    75: 2008-01-14 01:33:01 UTC - RP341 - Restore Operation
    74: 2008-01-14 01:24:08 UTC - RP340 - Restore Operation
    73: 2008-01-14 01:13:14 UTC - RP339 - Restore Operation
    72: 2008-01-14 01:03:51 UTC - RP338 - Restore Operation


    -- First Restore Point --
    1: 2007-10-16 14:42:51 UTC - RP267 - Installing Simpsons Cartoon

    It would appear that restore points #'s 1-75 are no longer functional (and likely never will be). You could reset them and remove those but it will also wipe out all your functional restore points (RPs).

    Better to be vigil on your backups and to allow new RPs to be recorded while older RPs will get removed to make room for the new. You can monitor the above 5 latest RPs to see how it seems to be going.


  2. #12
    You still may have an older insecure JAVA version still left in Add/Remove Programs (Control Panel) - you need to uninstall that if applicable:

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    I can't find any reference in the Add/Remove Programs. But I checked the folder and done a Print folder for the details as below:

    C:\Program Files\Java\JRE1.5.0_10 18/01/2008 15:12:09 Size: 1.12 MB
    C:\Program Files\Java\JRE1.6.0_04 18/01/2008 16:55:18

    JRE1.5.0_10
    C:\Program Files\Java\JRE1.5.0_10\LIB (empty)

    C:\Program Files\Java\JRE1.5.0_10\LIB\EXT
    C:\Program Files\Java\JRE1.5.0_10\LIB\EXT\QTJava.zip

    ===================
    Can DSS be missing the RPs?
    I run the file srdiag.exe to get SR-RP.LOG and enclosed the RPs listed since the Deckard's System Scanner Restore Point. I have highlighted the one I made then used to Restore back:

    DirectoryName=RP342, Size=0, Type=12[MODIFY_SETTINGS], RestorePointName=Deckard's System Scanner Restore Point, RestorePointStatus=[VALID], Number=342l, Date=Monday January 14, 2008 15:59:6
    DirectoryName=RP343, Size=0, Type=13[CANCELLED_OPERATION], RestorePointName=Restore Operation, RestorePointStatus=[Cancelled], Number=343l, Date=Tuesday January 15, 2008 0:15:23
    DirectoryName=RP344, Size=0, Type=7[CHECKPOINT], RestorePointName=before installing power.reg to get my power options back, RestorePointStatus=[VALID], Number=344l, Date=Tuesday January 15, 2008 0:20:33
    DirectoryName=RP345, Size=0, Type=6[RESTORE], RestorePointName=Restore Operation, RestorePointStatus=[VALID], Number=345l, Date=Tuesday January 15, 2008 0:32:40
    DirectoryName=RP346, Size=0, Type=7[CHECKPOINT], RestorePointName=System Checkpoint, RestorePointStatus=[VALID], Number=346l, Date=Wednesday January 16, 2008 10:52:4
    DirectoryName=RP347, Size=0, Type=7[CHECKPOINT], RestorePointName=System Checkpoint, RestorePointStatus=[VALID], Number=347l, Date=Thursday January 17, 2008 11:15:4
    DirectoryName=RP348, Size=0, Type=7[CHECKPOINT], RestorePointName=System Checkpoint, RestorePointStatus=[VALID], Number=348l, Date=Friday January 18, 2008 12:39:4
    DirectoryName=RP349, Size=0, Type=1[APPLICATION_UNINSTALL], RestorePointName=Removed J2SE Runtime Environment 5.0 Update 6, RestorePointStatus=[VALID], Number=349l, Date=Friday January 18, 2008 14:47:20
    DirectoryName=RP350, Size=0, Type=1[APPLICATION_UNINSTALL], RestorePointName=Removed J2SE Runtime Environment 5.0 Update 10, RestorePointStatus=[VALID], Number=350l, Date=Friday January 18, 2008 14:48:50
    DirectoryName=RP351, Size=0, Type=13[CANCELLED_OPERATION], RestorePointName=Restore Operation, RestorePointStatus=[Cancelled], Number=351l, Date=Friday January 18, 2008 15:18:15
    DirectoryName=RP352, Size=0, Type=0[APPLICATION_INSTALL], RestorePointName=Installed Java(TM) 6 Update 4, RestorePointStatus=[VALID], Number=352l, Date=Friday January 18, 2008 16:54:31
    DirectoryName=RP353, Size=0, Type=7[CHECKPOINT], RestorePointName=System Checkpoint, RestorePointStatus=[VALID], Number=353l, Date=Saturday January 19, 2008 20:1:14
    DirectoryName=RP354, Size=0, Type=0[APPLICATION_INSTALL], RestorePointName=Installed SUPERAntiSpyware Free Edition, RestorePointStatus=[VALID], Number=354l, Date=Saturday January 19, 2008 20:53:6

    Processing Mount Point [D:\]
    No restore points for Mount Point [D:\]
    =================
    It would appear that restore points #'s 1-75 are no longer functional....
    I'm not sure what to look for in the RP details of the DSS log to show they are not functional?

    Once again thank you for your help with this.

  3. #13
    VopThis is offline Senior Member (Canada)
    Looks like the RPs are working: RP342-RP354. That is a favorable sign.

    Your unreliable uninstalls may be further indicators of a less than reliable PC. Try deleting the following FOLDERS - a desirable step:


    C:\Program Files\Java\JRE1.5.0_10
    C:\Program Files\Java\JRE1.6.0_04



    I will make one additional suggestion:

    Use the System File Checker (SFC) :
    (typical runtime is 30 minutes)


    Sometimes when you install third party software, it may overwrite important operating system files. This can cause instability - or worse. Windows XP includes a command line tool that you can use if you think this may have happened (for example, if you get a message box warning that there is a problem with a .dll or the system just seems unstable). Here's how to use it:
    1. Click Start | Run.
    2. In the Run box, type/copy&paste:
      SFC /scannow (notice the space plus slash).
    3. Windows will scan all protected Windows files to verify that they are intact and in their original versions. If they're not, corrupt, missing or incorrect files are replaced. You may be prompted to insert your Windows XP installation CD if your Dllcache folder (where Windows keeps a copy of essential system files) has become corrupt or has been deleted.

    To avoid the possibility of having to dig out and insert the OS CD, you can copy the i386 folder from the installation CD to your hard disk, and just point Windows there to find the files it needs. For instructions on how to do so, and more info about scannow, see:
    http://www.wxpnews.com/rd/rd.cfm?id=060117HT-Update_XP

  4. #14
    Thank you, I will do that next.

    But:
    Your unreliable uninstalls may be further indicators of a less than reliable PC. Try deleting the following FOLDERS - a desirable step:

    C:\Program Files\Java\JRE1.5.0_10
    C:\Program Files\Java\JRE1.6.0_04
    Isn't that the folder to the new Java Runtime Environment (JRE) 6 Update 4 I have just installed?

    =========================

    Regarding the RP log I included, it is quite long so I had edited just to include the latest ones that DSS didn't include. The log starts with:

    DirectoryName=RP268, Size=0, Type=7[CHECKPOINT], RestorePointName=INSATLLING NEWT network inventory scanner, RestorePointStatus=[VALID], Number=268l, Date=Thursday October 25, 2007 23:26:31

    ==========================

    I will now do the System File Checker and wait to hear from you regarding deleting the Jave folder.

    Thank you

  5. #15
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    C:\Program Files\Java\JRE1.6.0_04

    Isn't that the folder to the new Java Runtime Environment (JRE) 6 Update 4 I have just installed?
    Indeed, it is!! Sorry for my mistake.

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2