Welcome Guest ( Log In | Register )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide.
      
3 Pages V   1 2 3 >  
Closed TopicStart new topic
shinwow.bh buried in java cache files [RESOLVED], malware infection for two years
micha
post Apr 13 2008, 05:34 AM
Post #1


Member
**
Posts: 20
OS: XP



My computer shows the following infections:

c:/documentsandsettings/defaultuser/application data/Sun/Java/deployment/cache/6.0/56/3c28cc78-369889c4<HipointinstallsheildRT.class>
c:/documentsandsettings/Default User/application data/Sun/Java/Deployment/cache/javapi /v1.0/jar/eRT.jar-27406485-620c90b7.zip<HipointsheildRT.class>
c:/documentsand settings/owner/application data/sun/java/deployment/cache/6.0/56/3c28cc78-36989c4<hipointinstallshieldRT.class>
c:/documentsand settings/owner/application data/sun/java/deployment/cache/javapi
/v1.0/jar/eRT.jar27406485-620c90b7.zip<hipointinstallshield.RT.class>
c:/windows/system32/config/systemprofile/applicationdata/sun/java/deployment/cache
/6.0/56/3c28cc78-369899c4<hipointinstallshieldRT.class>
c:/windows/system32/config/systemprofile/applicationdata/sun/java/deployment/cache
/javapi/v1.0/jar/eRT.jar-27406485-620c907b7.zip<hipointinstallsheildRT.class>

My internet provider's CA cannot eliminate this virus. I get pop ups telling me I have encountered a problem and need to close, my computer slows down, until recently, I have even had excessive redirecting from a requested 'search' and it has been two years of fighting with this virus.
I was originally told I had a bad CA download, it was uninstalled and reinstalled.
I ran several scans and it, the virus still exists...
I have a 6yr old HP Pavillion with XP capability.
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 13 2008, 09:46 PM
Post #2


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Welcome to GTG.

Please read this topic and post your HijackThis log here when ready.

Go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix and follow the instructions on how to install the Recovery Console and run ComboFix. Go through all the steps until posting the log part. Post the combofix log here.
Go to the top of the page
 
+Quote Post
micha
post Apr 14 2008, 08:10 PM
Post #3


Member
**
Posts: 20
OS: XP



New to this site, so forgive me If I make 'replying or posting' mistakes...

I tried to download Combofix...
My computer says... "cannot rename Combofix...and then says cannot rename to Combofix2"(???)

I have Vundofix, LSPFix, and Winsockxpfix on my 'desktop'...
they are 'repair' scann and fix items offered from my CA, and Microsoft for my problems...
Also can these scanner's fight against each other and cause more havoc in my comp,
as they have helped some...I no longer have the 'error, windows needs to close prompts'...
confused1.gif
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 14 2008, 08:19 PM
Post #4


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Did you download ComboFix completely yet before trying to rename it? Make sure it's completely downloaded. If you want, restart the computer and try renaming it again. If it still gives you problems, leave it alone and just run it.

For the other tools you mentioned on your desktop, you may delete all of them. Those are only per use tools so they are only needed for a specific task.
Go to the top of the page
 
+Quote Post
micha
post Apr 14 2008, 09:02 PM
Post #5


Member
**
Posts: 20
OS: XP



Combofix never appeared in 'downloads', never appeared in add or remove programs, and never made it to my desktop?
I'm assuming it never completed it's download?
But still confused as to why my comp informed me it was trying to rename combofix, as if it downloaded and is hidden?

CA says shinwow.bh (trojan) is a low threat supposedly...besides its annoying daily appearance as an 'infection', can it do damage, to my comp if I leave it alone?
I see others on the internet aggravated by its appearance, and it's difficulty in removing...

Oh, I found the java plug in console and cleaned the 'cache', as recommended by CA from my frontier provider,
and it removed one of the above trojans:
c:/documentsand settings/owner/applicationsdata/sun/java/deployment/cache/6.0/56/3c28cc78-36989c4<hipointinstallshieldRT.class>
confused1.gif
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 14 2008, 09:05 PM
Post #6


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



If the only threat found is in the Java cache, I guess we can just aim to get rid of that part....

Go to http://www.java.com/en/download/help/5000020300.xml and see how to clear your Java cache or follow the instructions below:

Go into the Control Panel and double-click the Java icon (looks like a coffee cup).

- Under Temporary Internet Files, click the Delete Files button.
- There are three options in the window to clear the cache - Leave ALL 3 Checked
- Downloaded Applets
- Downloaded Applications
- Other Files
- Click OK on Delete Temporary Files window (Note: This deletes ALL the Downloaded Java Applications and Applets from the CACHE.)
- Click OK to leave the Java Control Panel.

See if you still have any issues after that.
Go to the top of the page
 
+Quote Post
micha
post Apr 15 2008, 01:07 AM
Post #7


Member
**
Posts: 20
OS: XP



Well that was grounds for a mini heart attack...lol
I went into Java, and completed the deletions requested.
Then I did a shutdown with startup...my 6 yr old HP Pavillion comp freaked!
It bounced back n forth between starting up and shutting down.
After watching this for a few minutes I acknowledged the black screens request to put it into safe mode,
and checked a few operating systems, and did another shut down with startup.
It came back up okay...this is the reason why I'm late in replying...
I'll run another scan of my c drive and see if anythings changed...
blink.gif lookaround.gif blushing.gif
Go to the top of the page
 
+Quote Post
micha
post Apr 15 2008, 03:52 AM
Post #8


Member
**
Posts: 20
OS: XP



ran virus scan in c drive and nothing has changed...
still have the same 5 shinwow.bh trojans trapped...

rolleyes1.gif ...rofl
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 15 2008, 08:30 PM
Post #9


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Did you make sure to select delete temporary files?
Go to the top of the page
 
+Quote Post
micha
post Apr 15 2008, 11:01 PM
Post #10


Member
**
Posts: 20
OS: XP



yes...temporary internet files... within java control panel, under general...

right?
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 16 2008, 07:44 AM
Post #11


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Yep, that's the one. If it still won't delete them, try deleting them manually to see if it helps:

c:\Documents and Settings\default user\application data\Sun\Java\deployment\cache\6.0\56\3c28cc78-369889c4
c:\Documents and Settings\Default User\application data\Sun\Java\Deployment\cache\javapi \v1.0\jar\eRT.jar-27406485-620c90b7.zip
c:\documentsand settings\owner\application data\sun\java\deployment\cache\6.0\56\3c28cc78-36989c4
c:\documents and settings\owner\application data\sun\java\deployment\cache\javapi\v1.0\jar\eRT.jar27406485-620c90b7.zip
c:\windows\system32\config\systemprofile\application data\sun\java\deployment\cache\6.0\56\3c28cc78-369899c4
c:\windows\system32\config\systemprofile\application data\sun\java\deployment\cache\javapi\v1.0\jar\eRT.jar-27406485-620c907b7.zip
Go to the top of the page
 
+Quote Post
micha
post Apr 16 2008, 01:21 PM
Post #12


Member
**
Posts: 20
OS: XP



That I have been looking for, and never am sure if I am in the right place...
Can you give me a location to go and the DYI explanation?
With your help I have eliminated 1 of the original 6...
So know I very much appreciate your time and patience!
smile.gif
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 16 2008, 01:31 PM
Post #13


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Were you able to locate any of those? Go into My Computer and C: drive. You can probably follow from there into the deeper folders and delete the specified files.
Go to the top of the page
 
+Quote Post
micha
post Apr 16 2008, 09:53 PM
Post #14


Member
**
Posts: 20
OS: XP



Ok, I chased down my computer, pulled up c drive...
Was amazed by the info I got to see...but no files with the numbers or info I was looking for...
Could it be buried deeper within my system, thought I looked at every file...
Any other suggestions...another place to go, did I miss something...
helpsmilie.gif
Go to the top of the page
 
+Quote Post
greyknight17
post Apr 17 2008, 06:46 PM
Post #15


Malware Expert
Group Icon
Posts: 15,719
From: New York
OS: Windows 98, XP, Vista, Mac OS X



Give this a try...

Download OTMoveIt2 at http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
* Save it to your desktop.
* Double-click OTMoveIt2.exe to run it. (Vista users, right click on OTMoveIt2.exe and select Run as an Administrator).
* Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

CODE
c:\Documents and Settings\default user\application data\Sun\Java\deployment\cache\6.0\56\3c28cc78-369889c4
c:\Documents and Settings\Default User\application data\Sun\Java\Deployment\cache\javapi \v1.0\jar\eRT.jar-27406485-620c90b7.zip
c:\documentsand settings\owner\application data\sun\java\deployment\cache\6.0\56\3c28cc78-36989c4
c:\documents and settings\owner\application data\sun\java\deployment\cache\javapi\v1.0\jar\eRT.jar27406485-620c90b7.zip
c:\windows\system32\config\systemprofile\application data\sun\java\deployment\cache\6.0\56\3c28cc78-369899c4
c:\windows\system32\config\systemprofile\application data\sun\java\deployment\cache\javapi\v1.0\jar\eRT.jar-27406485-620c907b7.zip


* Return to OTMoveIt2. Right click in the Paste List of Files/Folders to Move window (under the Yellow bar) and choose Paste.
* Click the red Moveit! button.
* A log of files and folders moved will be created in the C:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
* Close OTMoveIt2.

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 22nd November 2008 - 08:02 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.