Soldato
- Joined
- 16 Jan 2003
- Posts
- 10,882
- Location
- Nottingham
Just out of interest, was UAC enabled or disabled?
Have you tried stopping the process using rkill? It may try and block it but I find the .scr one works best. Once it has stopped the process you can run Mbam.
http://www.bleepingcomputer.com/download/rkill/
I tried all the different version of rkill, it blocked all of them!
I'm reformatting now....
What browser were you using?
Is it patched and up to date?
What programs require java, any updated versions of them that can run within a secure environment?
It is possible you have been hit by something close to zero day which is exploiting
http://arstechnica.com/security/2012/08/critical-java-exploit-spreads/
a mess within java even while up to date.
Unsure if Java has been patched in last couple of days, but exploits for this flaw are out there.
There are also some issues with disabling java
http://www.informationweek.com/secu...va-zero-day-attack-second-bug-found/240006431
have a good read at that for some tips.
Just out of interest, was UAC enabled or disabled?
Do you run Java? Before last night, being up-to-date wasn't good enough. Do you run Win7 with UAC enabled?
You should definitely consider enabling interactive plug-in mode.
Chrome: Settings > Advanced settings > Content settings > Plug-ins > Click to play
Firefox: about:config in your URL bar and then search for and enable the plugins.click_to_play
Great protection against Drive-by malware attacks.
Anybody interested in security ought to have UAC enabled (assuming you were running as administrator)
disabled
I got this the other day, no idea where from using Firefox. I don't have UAC enabled because I just find it a pain in the ass most of the time.
Would UAC have stopped the trojan horse from installing tho?
It managed to escape AVG, even tho AVG detected it, and said it quarantined the file.
Whilst we are on the subject, Comodo Dragon looks interesting.
It's worth pointing out though that there are two people in this thread who got infected by this and both had UAC disabled.