Computer Forums  

Go Back   Computer Forums > Software > Security Software

Security Software Protect your computer from internet nasties... firewalls, antivirus, and everything computer security related belongs here.

Register Now for FREE!

Fill out the form below for your free account and start posting today!


Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Agree to forum rules 

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 20/02/09, 14:49
Newbie
 
Join Date: 20 Feb 2009
Posts: 6
Natalie105 is on a distinguished road
Default Trojan Horse BHO.HJE

Last night I was browsing on the net, didn't download anything, and a few minutes later, AVG warned me that I had multiple threats. I managed to get rid of most of them but one. It's called

Trojan Horse BHO.HJE

Please can someone tell me
- What this is
- How I've got it
- What it will do to my computer
- How to get rid of it?

I have done a full computer slow scan with AVG but it didn't detect any threats. I also went into Safe Mode to try and get rid of it from there but I don't think it worked! I can't seem to get rid of it!

It's in the 'Web Shield Findings' on AVG and it says

Infection: Torjan Horse BHO.HJE

Object: childhe.com\pas\apstpldr.dll.html?affid=177047&vid =&guid=86CDCF432A2448AAD9DD189B624542543

Process: C:\WINDOWS\explorer.exe

I'd really appreciate it if someone could tell me steps on how I can remove this? Otherwise I'm going to have to wipe my disk which I really do not want to do!

Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 20/02/09, 15:46
Thaylok's Avatar
Life is Weird, Embrace IT
 
Join Date: 06 Jun 2007
Location: Dallas Texas, USA
Posts: 688
Thaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond repute
Default Re: Trojan Horse BHO.HJE

Sounds like a Drive-by download. Very common, especially in a browser like Internet Explorer.

BHO means Browser Helper Object..... a Plug-in (could be an active-X control).

Turning off the Add0on (plug-in) depends on the version of Internet Explorer.

As an interim, go to the link below. Run the Trend Micro Housecall virus scanner. It will take some time.

In your case, I'd suggest using the Javascript version. I'd normally recommend the Active-X option, but not this time. See if that can help.

Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro USA

After that, you can normally start IE in safe mode (no Add-ons) by going to START>Accessories>System T0OLS> Internet Explorer (No Add-Ons)
You should have this option if you are using IE 7 or 8.

Select the Tools option (usually a button on the toolbar area near the right if you are using IE7 or 8), then select the option for MANAGE ADD-ONs.
Find the addon you did not install and disable it.

You can play with the Internet Options... Advanced tab and REMOVE the check to the segment for Enable third-party browser extensions.

There are other options to take to protect yourself, but i need to go work around the house as the wife is letting me know that my day off is not a day off for me.
__________________
I'm here, you may now make your next two wishes.

Beat Me, Whip Me, Make Me Use Windows!!

Every Piece of Electronic Equipment runs on a finite amount of smoke. The systems are normally very efficient at reclaiming the smoke and recycling it, however, should you do something to let the smoke out, your system will become useless.

SAVE THE SMOKE !!

New PC :
New: Phenom 9500 Quad 2.2, 4gb ram XP Pro 64-bit (Sata 0), XP Pro 32 bit (sata 1), 40 eide HDD (music), Pioneer Blu-Ray Burner, HP Multidisk CD-RW/DVD-Rom, 2x250 Seagate HDD's, ATI Radeon 3870, Asus M3A32-MVP Deluxe WiFi-AP

Old PC:
P4 1.5GHz, 768 Ram, hda-80Gb (80Ubuntu), DVD R/RW
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 20/02/09, 16:27
Newbie
 
Join Date: 20 Feb 2009
Posts: 6
Natalie105 is on a distinguished road
Default Re: Trojan Horse BHO.HJE

Thanks for your help, I'll try those steps after I've finished work around the house What about if i'm using FireFox. I use FireFox mainly but sometimes when I click on my e-mails from MSN, Internet Explorer comes up automatically. I'll do what you've suggested and if that hasn't worked then I'll let you know :]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 20/02/09, 18:22
Thaylok's Avatar
Life is Weird, Embrace IT
 
Join Date: 06 Jun 2007
Location: Dallas Texas, USA
Posts: 688
Thaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond repute
Default Re: Trojan Horse BHO.HJE

If you are using Firefox, I'd recommend getting NoScript as an Add-On Extension and usig it religiously.
It will block scripts on a page by default for each script source. You can trust each page publisher (yahoo, google *ROFL* MSN...). Or you can specifically perma-distrust someone (like google analytics :-) ) .

But overall, it will help to prevent Drive-by downloads and even Click-jacking. I love it and use it, yes even with compuforums.

Edit: Now back to hanging Pictures in the house for the BOSS (wife)
__________________
I'm here, you may now make your next two wishes.

Beat Me, Whip Me, Make Me Use Windows!!

Every Piece of Electronic Equipment runs on a finite amount of smoke. The systems are normally very efficient at reclaiming the smoke and recycling it, however, should you do something to let the smoke out, your system will become useless.

SAVE THE SMOKE !!

New PC :
New: Phenom 9500 Quad 2.2, 4gb ram XP Pro 64-bit (Sata 0), XP Pro 32 bit (sata 1), 40 eide HDD (music), Pioneer Blu-Ray Burner, HP Multidisk CD-RW/DVD-Rom, 2x250 Seagate HDD's, ATI Radeon 3870, Asus M3A32-MVP Deluxe WiFi-AP

Old PC:
P4 1.5GHz, 768 Ram, hda-80Gb (80Ubuntu), DVD R/RW

Last edited by Thaylok; 20/02/09 at 18:23. Reason: add a line
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 20/02/09, 19:07
Kilobyte
 
Join Date: 19 Feb 2009
Posts: 78
1993gandy is on a distinguished road
Default Re: Trojan Horse BHO.HJE

start your computer in safe mode and run your anti-virus
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 20/02/09, 20:50
Newbie
 
Join Date: 20 Feb 2009
Posts: 6
Natalie105 is on a distinguished road
Default Re: Trojan Horse BHO.HJE

I've done everything that's been suggested now. About to do another full scan in Safe Mode. In the AVG Web Shield Findings it still says the Trojan is there and the icon hasn't been changed to one which implies it has been removed/healed. How do I make sure this has been removed?

Thanks for your help :]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 20/02/09, 23:35
Thaylok's Avatar
Life is Weird, Embrace IT
 
Join Date: 06 Jun 2007
Location: Dallas Texas, USA
Posts: 688
Thaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond reputeThaylok has a reputation beyond repute
Default Re: Trojan Horse BHO.HJE

Can you open a file explorer and delete the file from the quarantine area? It may be neutralized, but not deleted. Maybe that is all it needs now.
__________________
I'm here, you may now make your next two wishes.

Beat Me, Whip Me, Make Me Use Windows!!

Every Piece of Electronic Equipment runs on a finite amount of smoke. The systems are normally very efficient at reclaiming the smoke and recycling it, however, should you do something to let the smoke out, your system will become useless.

SAVE THE SMOKE !!

New PC :
New: Phenom 9500 Quad 2.2, 4gb ram XP Pro 64-bit (Sata 0), XP Pro 32 bit (sata 1), 40 eide HDD (music), Pioneer Blu-Ray Burner, HP Multidisk CD-RW/DVD-Rom, 2x250 Seagate HDD's, ATI Radeon 3870, Asus M3A32-MVP Deluxe WiFi-AP

Old PC:
P4 1.5GHz, 768 Ram, hda-80Gb (80Ubuntu), DVD R/RW
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 21/02/09, 13:46
Newbie
 
Join Date: 20 Feb 2009
Posts: 6
Natalie105 is on a distinguished road
Default Re: Trojan Horse BHO.HJE

Quote:
Originally Posted by Thaylok View Post
Can you open a file explorer and delete the file from the quarantine area? It may be neutralized, but not deleted. Maybe that is all it needs now.
How do I do that?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 21/02/09, 14:13
mel8again's Avatar
Gigabyte
 
Join Date: 07 Apr 2008
Location: Niagara Falls, Canada
Posts: 385
mel8again will become famous soon enoughmel8again will become famous soon enough
Default Re: Trojan Horse BHO.HJE

Quote:
Originally Posted by Natalie105 View Post
How do I do that?
Double click on AVG icon in the system tray. When the screen opens click on History and then Virus Vault. Delete everything you find in the Virus Vault and then do another scan.
__________________
EVGA 650i mobo with Intel e8400 Core 2 Duo
4 gigs OCZ 800 ddr2 ram and 160 gig sata hard drive
EVGA GTS 250 SC - Windows 7
See my test at http://www.pcpitstop.com/betapit/sec.asp?conid=23014579
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 21/02/09, 14:41
Newbie
 
Join Date: 20 Feb 2009
Posts: 6
Natalie105 is on a distinguished road
Default Re: Trojan Horse BHO.HJE

Quote:
Originally Posted by mel8again View Post
Double click on AVG icon in the system tray. When the screen opens click on History and then Virus Vault. Delete everything you find in the Virus Vault and then do another scan.
There's nothing in the Virus Vault and I've just done a full slow scan. It appears in the Web Shield Findings.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 22/02/09, 19:36
New Member
 
Join Date: 20 Feb 2009
Posts: 22
splice is on a distinguished road
Default Re: Trojan Horse BHO.HJE

It could be embedded in your system restore folder. The only way to get rid of it, if that's where it is, is to turn off system restore, reboot, then turn system restore back on again. That will delete everything out of your system restore folder. The problem with AVG is that they don't tell you where it's located. I use it myself.
__________________
Intel Core 2 Duo 2.4Ghz-Intel P965 Express (DP965LT)
AMD HD 3850 512MB VRAM-Creative SB X-Fi 64MB XRAM
4GB RAM
250GB SATA boot drive-750GB SATA game drive
450w PSU-KDS 19" LCD monitor
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 00:10.


Content © Copyright 2005-2010 CompuForums. All Rights Reserved. Some content © Copyright of the respective owners.
Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.0