If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
does Windows Explorer open? if so, open it, turn on the Address bar if it's off (View, Toolbars, Address Bar), then type in http://google.com.
did it crash, or are you in google? if you're in google, go to View, Toolbars, and look for any additional crazy toolbars that shouldn't be there... they'll likely be unchecked. let me know if you see any
It wasn't myspace. It was a link he clicked on inside a message that he received in his myspace inbox.
The toolbars were the first thing I removed after this site began loading up his computer.
There were crazy links on his desktop. Ipod video, golden casino, Free Daily Porn, Shopiing, he got fucked up! Luckily I keep backup after backup after backup. I would just hate to have to have to full format recover!
1) download AutoRuns: http://www.sysinternals.com/Files/Autoruns.zip
2) run autoruns.exe
3) wait for the hourglass to disappear from the "Everything" tab (or, at least the IE tab)
4) go to the Internet Explorer tab
5) post a screenshot
we're looking for any dll in there that doesn't have the publisher column filled in, or it says something other than a known good vendor (Microsoft, Adobe, etc)
Yea man, I've been running all sorts of removal tools for each piece of adware. But I'm missing at least 2 more removals before he's completely disenfected.
Last edited by Balanc3; October 19, 2005, 07:15:03 AM.
I'd uncheck the two Yahoos and the Safer Networking items and try starting up IE... if that doesn't work, try a File->Save As and post it in here for me
Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\A0094106.exe
Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\A0094107.exe
Adware:Adware/QoolShown No disinfected C:\System Volume Information\_restore{B4353CB4-AAAB-4E18-9A0C-7AB27E1BB4D9}\RP1084\snapshot\MFEX-2.DAT Adware:Adware/Yahoo No disinfected C:\WINNT\Downloaded Program Files\ycomp5_0_2_7.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\etb\pokapoka76.exe
Adware:Adware/Pacimedia No disinfected C:\WINNT\system32\APD123.exe
Adware:Adware/QoolShown No disinfected C:\WINNT\system32\ccqmcan.exe
Adware:Adware/QoolShown No disinfected C:\WINNT\system32\dddsdsj.dll
Adware:Adware/ConsumerAlertSystem No disinfected C:\WINNT\system32\dist001.exe
Adware:Adware/Qoologic No disinfected C:\WINNT\system32\ggkwg.dll
Adware:Adware/QoolShown No disinfected C:\WINNT\system32\kkdskp.exe
Adware:Adware/Qoologic No disinfected C:\WINNT\system32\kknokcr.dll
Adware:Adware/ISearch No disinfected C:\WINNT\system32\MTE2ODM6ODoxNg.exe
Adware:Adware/QoolShown No disinfected C:\WINNT\system32\qqykq.dat
Adware:Adware/Pacimedia No disinfected C:\WINNT\system32\sav2.exe
Spyware:Spyware/SurfSideKick No disinfected C:\WINNT\system32\SSK3_B5 Seedcorn 4.exe
Adware:Adware/Qoologic No disinfected C:\WINNT\system32\vgactl.cpl
Adware:Adware/QoolShown No disinfected C:\WINNT\system32\wuauclt.dll
It was several worms, just as suspected. IE will no longer crash saying fatal error, it just opens and then closes again. If you can tolerate that log, you can see I disenfected all virus' however lots of adware/spyware remain - still getting popups. I will try to get Steve to show me the source message from myspace and post it.
I had him start using Firefox yesterday when this happened. Trying to get his computer clean without full format recover. This is his business machine- sensitve data.
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment