Results 1 to 10 of 15

Thread: Re: XEVSJGB

Hybrid View

  1. #1
    forte agent Guest

    Re: XEVSJGB

    What is the set of files that were loaded from a web site I was
    looking at last night while researching re-inking kits.
    the files were xevsjgb.exe and xevsjb.dll.
    My computer now tries to dial out when I start up .Zonealarm reports
    windows explorer tring to access the internet.

  2. #2
    Dick Hazeleger Guest

    Re: XEVSJGB

    forte agent wrote:

    > What is the set of files that were loaded from a web site I was
    > looking at last night while researching re-inking kits.
    > the files were xevsjgb.exe and xevsjb.dll.
    > My computer now tries to dial out when I start up .Zonealarm reports
    > windows explorer tring to access the internet.


    Hi "Forte Agent",

    What is IS, I don't know, except it is a dialer... My suggestions are
    those mostly suggested here:

    1. Run AdAware (be sure to get build 181 and the most recent update)
    2. Run Spybot Search and Destroy (also updated to the most recent
    definitions)
    3. Run HiJack this (just in case)

    if all this comes to no result...

    4. Run TDS3 (Trojan Defense Suite) to see whether you have a trojan
    aboard.

    Running SpywareBlaster occassionaly when your system has been cleaned
    of whatever is trying to phone home isn't a bad idea either.

    In the above I assumed that you have an active and updated AV-program
    running on your system and that you already executed a system scan...
    If not... then do so!

    Adaware: www.lavasoft.de
    Spybot Search and Destroy: http://security.kolla.de/
    HiJack This: http://www.spywareinfo.com/~merijn/
    TDS3: http://www.diamondcs.com.au/
    SpywareBlaster: www.javacoolsoftware.com

    Av-programs:

    www.symantec.com
    www.macafee.com
    www.sophos.com
    www.grisoft.com

    And I am sure I forgot a few. Hope this helps getting you on the road
    again!
    Dick

  3. #3
    mto Guest

    Re: XEVSJGB


    "forte agent" <pgmeyer@gte.net> wrote in message
    news:rpcaivsb22dqsl076s5iman9ies8e5etgp@4ax.com...
    > What is the set of files that were loaded from a web site I was
    > looking at last night while researching re-inking kits.
    > the files were xevsjgb.exe and xevsjb.dll.
    > My computer now tries to dial out when I start up .Zonealarm reports
    > windows explorer tring to access the internet.


    Google has no clue. Try Spybot Search and Destroy and AdAware - make sure
    you update both after downloading before running them. (They are both free)
    When you're done make sure you run the Immunize function in Spybot advanced
    mode.



  4. #4
    Dick Hazeleger Guest

    Re: XEVSJGB

    mto wrote:

    >
    > "forte agent" <pgmeyer@gte.net> wrote in message
    > news:rpcaivsb22dqsl076s5iman9ies8e5etgp@4ax.com...
    > > What is the set of files that were loaded from a web site I was
    > > looking at last night while researching re-inking kits.
    > > the files were xevsjgb.exe and xevsjb.dll.
    > > My computer now tries to dial out when I start up .Zonealarm reports
    > > windows explorer tring to access the internet.

    >
    > Google has no clue. Try Spybot Search and Destroy and AdAware - make
    > sure you update both after downloading before running them. (They are
    > both free) When you're done make sure you run the Immunize function
    > in Spybot advanced mode.



    Hi MTO and Forte Agent,

    I did a bit of searching on "virus", "trojan" and "worm" in combination
    with "random file name" and in all categories quite a number of these
    critters that would match showed up, also one came up with the
    description "dialer" attached to it.

    Having said that, it seems to me that executing a system wide scan with
    an up-to-date AV-product (I mentioned only a few in my first reply)
    would be the first thing to do, to make sure that something of a
    virus/trojan/backdoor is lurking on the system. After that I would
    advise FA to run BOTH AA and SS&D. For immunizing I would advise both
    SD&D's immunize option AND SpywareBlaster (Which is advised to be the
    better one of the two, even by Patrick).

    Regards
    Dick

  5. #5
    mto Guest

    Re: XEVSJGB


    "Dick Hazeleger" <Dick@post_it_in_the_newsgroup.com> wrote in message
    news:viatctsmsk36f5@corp.supernews.com...
    > mto wrote:
    >
    > >
    > > "forte agent" <pgmeyer@gte.net> wrote in message
    > > news:rpcaivsb22dqsl076s5iman9ies8e5etgp@4ax.com...
    > > > What is the set of files that were loaded from a web site I was
    > > > looking at last night while researching re-inking kits.
    > > > the files were xevsjgb.exe and xevsjb.dll.
    > > > My computer now tries to dial out when I start up .Zonealarm reports
    > > > windows explorer tring to access the internet.

    > >
    > > Google has no clue. Try Spybot Search and Destroy and AdAware - make
    > > sure you update both after downloading before running them. (They are
    > > both free) When you're done make sure you run the Immunize function
    > > in Spybot advanced mode.

    >
    >
    > Hi MTO and Forte Agent,
    >
    > I did a bit of searching on "virus", "trojan" and "worm" in combination
    > with "random file name" and in all categories quite a number of these
    > critters that would match showed up, also one came up with the
    > description "dialer" attached to it.
    >
    > Having said that, it seems to me that executing a system wide scan with
    > an up-to-date AV-product (I mentioned only a few in my first reply)
    > would be the first thing to do, to make sure that something of a
    > virus/trojan/backdoor is lurking on the system. After that I would
    > advise FA to run BOTH AA and SS&D. For immunizing I would advise both
    > SD&D's immunize option AND SpywareBlaster (Which is advised to be the
    > better one of the two, even by Patrick).
    >
    > Regards
    > Dick


    In general I have found Google to be pretty efficient at hunting up a
    specific exe or dll name - which is what I meant when I said that Google had
    no clue. I agree that this is either a random name virus/trojan/etc. or
    something new that just hasn't been posted about anywhere yet.



Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •