MySpace confusion

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • picklemonkey
    Double hoodie beer monster
    • Jun 2004
    • 15373

    #31
    Re: MySpace confusion

    I still don't think it's myspace

    does Windows Explorer open? if so, open it, turn on the Address bar if it's off (View, Toolbars, Address Bar), then type in http://google.com.

    did it crash, or are you in google? if you're in google, go to View, Toolbars, and look for any additional crazy toolbars that shouldn't be there... they'll likely be unchecked. let me know if you see any

    Comment

    • Balanc3
      Platinum Poster
      • Jun 2004
      • 1278

      #32
      Re: MySpace confusion

      It wasn't myspace. It was a link he clicked on inside a message that he received in his myspace inbox.

      The toolbars were the first thing I removed after this site began loading up his computer.

      There were crazy links on his desktop. Ipod video, golden casino, Free Daily Porn, Shopiing, he got fucked up! Luckily I keep backup after backup after backup. I would just hate to have to have to full format recover!
      JourneyDeep .into the sound

      Comment

      • picklemonkey
        Double hoodie beer monster
        • Jun 2004
        • 15373

        #33
        Re: MySpace confusion

        and IE still doesn't load?

        1) download AutoRuns: http://www.sysinternals.com/Files/Autoruns.zip
        2) run autoruns.exe
        3) wait for the hourglass to disappear from the "Everything" tab (or, at least the IE tab)
        4) go to the Internet Explorer tab
        5) post a screenshot

        we're looking for any dll in there that doesn't have the publisher column filled in, or it says something other than a known good vendor (Microsoft, Adobe, etc)

        Comment

        • Balanc3
          Platinum Poster
          • Jun 2004
          • 1278

          #34
          Re: MySpace confusion

          Will do in the morning!

          Yea man, I've been running all sorts of removal tools for each piece of adware. But I'm missing at least 2 more removals before he's completely disenfected.
          Last edited by Balanc3; October 19, 2005, 08:15:03 AM.
          JourneyDeep .into the sound

          Comment

          • picklemonkey
            Double hoodie beer monster
            • Jun 2004
            • 15373

            #35
            Re: MySpace confusion

            btw... adware is a malicious program. Ad-aware is a program used to remove adware

            Comment

            • glacius
              Fresh Peossy
              • Jun 2004
              • 36

              #36
              Re: MySpace confusion

              scams scams scams
              my friendster gets flooded with those types of emails, my myspace has been safe so far..

              Comment

              • Balanc3
                Platinum Poster
                • Jun 2004
                • 1278

                #37
                Re: MySpace confusion

                rise and shine!

                JourneyDeep .into the sound

                Comment

                • picklemonkey
                  Double hoodie beer monster
                  • Jun 2004
                  • 15373

                  #38
                  Re: MySpace confusion

                  I'd uncheck the two Yahoos and the Safer Networking items and try starting up IE... if that doesn't work, try a File->Save As and post it in here for me

                  Comment

                  • Balanc3
                    Platinum Poster
                    • Jun 2004
                    • 1278

                    #39
                    Re: MySpace confusion

                    That yahoo stuff is ok, its part of his SBC Yahoo Experience! He's where I am at the moment.

                    Incident Status Location

                    Adware:Adware/QoolShown No disinfected C:\WINNT\SYSTEM32\KKDSKP.EXE

                    Adware:adware/consumeralertsystemNo disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\cassetup.exe

                    Adware:adware/qoologic No disinfected C:\WINNT\SYSTEM32\vgactl.cpl

                    Spyware:spyware/surfsidekick No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log

                    Adware:adware/virtualbouncer No disinfected C:\PROGRAM FILES\VBouncer

                    Adware:adware/elitebar No disinfected C:\WINNT\etb

                    Spyware:spyware/clipgenie No disinfected Windows Registry

                    Virus:W32/Mimail.C.worm Disinfected Archive Folders\Sent Items\FW: Re[2]: our private photos agaamrum\photos.zip[photos.jpg.exe]

                    Adware:Adware/ISearch No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\cmdinst.exe

                    Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\i66D.tmp

                    Adware:Adware/QoolShown No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\temp.fr217A

                    Virus:W32/Bagle.AB.worm Disinfected Personal Folders\Deleted Items\SpamTrap\**SPAM** Fax Message Received\the_message.vbs

                    Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Server Report\test.zip[test.exe]

                    Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Hello\uvlplk.scr

                    Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\vebpf\document.scr

                    Virus:W32/Mydoom.A.worm Disinfected Personal Folders\Deleted Items\Mail Delivery System\lnnyc.pif

                    Virus:W32/Bagle.F.worm Disinfected Personal Folders\Deleted Items\^_^ meay-meay!\Picture.scr

                    Virus:W32/Netsky.P.worm Disinfected Personal Folders\Deleted Items\Mail Delivery (failure snorton@npa412i.com)\message.scr

                    Virus:W32/Netsky.P.worm Disinfected Personal Folders\Deleted Items\Re: Mail Server\data.zip[details.txt .pif]

                    Virus:W32/Bagle.U.worm Disinfected Personal Folders\Deleted Items\atrrwkn.exe

                    Virus:W32/Zafi.B.worm Disinfected Personal Folders\Deleted Items\Check this out kid!!!\jennifer the wild girl xxx07.jpg.pif

                    Virus:W32/Bagle.pwdzip Disinfected Personal Folders\Inbox\Earthlink\RE: Protected message\Encrypted.zip

                    Virus:W32/Bagle.pwdzip Disinfected Personal Folders\Sent Items\FW: Protected message\Encrypted.zip

                    Spyware:Spyware/SurfSideKick No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1080\A0092201.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092943.exe

                    Spyware:Spyware/SurfSideKick No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092945.dll

                    Spyware:Spyware/SurfSideKick No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092947.exe

                    Adware:Adware/EliteBar No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092948.dll

                    Adware:
                    Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092953.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092954.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0092956.cpl

                    Virus:Trj/Agent.AKT Disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1082\A0093116.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1083\A0093122.dll

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1083\A0093123.exe

                    Virus:Trj/LdPinch.LD Disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1083\A0093124.exe

                    Virus:
                    Trj/Qoologic.B Disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1083\A0093125.dll

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\A0094106.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\A0094107.exe

                    Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\snapshot\MFEX-2.DAT
                    Adware:Adware/Yahoo No disinfected C:\WINNT\Downloaded Program Files\ycomp5_0_2_7.dll

                    Adware:Adware/EliteBar No disinfected C:\WINNT\etb\pokapoka76.exe

                    Adware:Adware/Pacimedia No disinfected C:\WINNT\system32\APD123.exe

                    Adware:Adware/QoolShown No disinfected C:\WINNT\system32\ccqmcan.exe

                    Adware:Adware/QoolShown No disinfected C:\WINNT\system32\dddsdsj.dll

                    Virus:Trj/Qoologic.B Disinfected C:\WINNT\system32\ddkad.dll

                    Adware:Adware/ConsumerAlertSystem No disinfected C:\WINNT\system32\dist001.exe

                    Adware:Adware/Qoologic No disinfected C:\WINNT\system32\ggkwg.dll

                    Adware:Adware/QoolShown No disinfected C:\WINNT\system32\kkdskp.exe

                    Adware:Adware/Qoologic No disinfected C:\WINNT\system32\kknokcr.dll

                    Adware:Adware/ISearch No disinfected C:\WINNT\system32\MTE2ODM6ODoxNg.exe

                    Adware:Adware/QoolShown No disinfected C:\WINNT\system32\qqykq.dat

                    Adware:Adware/Pacimedia No disinfected C:\WINNT\system32\sav2.exe

                    Spyware:Spyware/SurfSideKick No disinfected C:\WINNT\system32\SSK3_B5 Seedcorn 4.exe

                    Adware:Adware/Qoologic No disinfected C:\WINNT\system32\vgactl.cpl
                    Adware:Adware/QoolShown No disinfected C:\WINNT\system32\wuauclt.dll


                    It was several worms, just as suspected. IE will no longer crash saying fatal error, it just opens and then closes again. If you can tolerate that log, you can see I disenfected all virus' however lots of adware/spyware remain - still getting popups. I will try to get Steve to show me the source message from myspace and post it.
                    JourneyDeep .into the sound

                    Comment

                    • asdf_admin
                      i use to be important
                      • Jun 2004
                      • 12798

                      #40
                      Re: MySpace confusion

                      stop using IE. go to firefox.
                      dead, yet alive.

                      Comment

                      • Balanc3
                        Platinum Poster
                        • Jun 2004
                        • 1278

                        #41
                        Re: MySpace confusion

                        I had him start using Firefox yesterday when this happened. Trying to get his computer clean without full format recover. This is his business machine- sensitve data.
                        JourneyDeep .into the sound

                        Comment

                        • picklemonkey
                          Double hoodie beer monster
                          • Jun 2004
                          • 15373

                          #42
                          Re: MySpace confusion

                          can you post me an AutoRuns log?

                          Comment

                          • pimpmcknight
                            Getting Somewhere
                            • Jul 2004
                            • 133

                            #43
                            Re: MySpace confusion

                            The same exact thing has happened to me, and all the girls are hot who send the sh!t, what a waste...
                            Gooch...

                            Comment

                            • DreamGirlie
                              Platinum Poster
                              • Jun 2004
                              • 2137

                              #44
                              Re: MySpace confusion

                              i didnt read the whole thread sorry pickle...but i wanna have more myspace friends!

                              add me!



                              "Welcome to Hezbollah phone line, for terrorist supplies press 1."

                              Comment

                              • Balanc3
                                Platinum Poster
                                • Jun 2004
                                • 1278

                                #45
                                Re: MySpace confusion

                                Sorry Pickle, I've been using another machine.

                                Autoruns Log
                                JourneyDeep .into the sound

                                Comment

                                Working...