Virus Warning!!

Discussion in 'General Discussion' started by trance_fan, Mar 6, 2005.

Users Viewing Thread (Users: 0, Guests: 0)

  1. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
  2. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Should do, as long as the virus isn't fucking around with your java :up:

    AVG free edition is top-notch for the future though for virus protection.

    If no joy at all let me know and I'll burn that bootable cd with the av progs for ya.
  3. Guest

    millers got it n'all
  4. Nass

    Nass sound. Staff

    Joined:
    Oct 10, 2002
    Messages:
    9,570
    Likes Received:
    31
    Location:
    Limassol, Cyprus / Newcastle UK
    millers got a disease off cook and he's waving it in my direction.
  5. ianmc

    ianmc Registered User

    Joined:
    Apr 15, 2004
    Messages:
    4,153
    Likes Received:
    0
    Location:
    getting mad niggerish with charlie murphy
    yeah i got it aswell

    pic of me drunk at sea haha:lol:
  6. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
    I cant even open that Housecall link.

    I tried that link i posted above, and that doesnt seem to have ridded it.

    So if u could sort that cd out, that would be great Mike. Ta. :up:
  7. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Will burn it for the weekend and try and get it over to you, pm me your mob no :up:
  8. Miller

    Miller Registered User

    Joined:
    May 4, 2002
    Messages:
    15,542
    Likes Received:
    0
    Location:
    The Corner
    Sorry lads!:oops: Blame it on Cyber Gee, he give it to me, I didn't have a clue wtf was going on!:lol:
  9. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Just been rummaging around, and came up with a couple of things:

    It's the Kelvir worm that get's downloaded, once ran it downloads a Spybot worm and then you're pretty fucked. If any of you haven't removed this with ur virus scanners, the following may work:

    Reboot into safe mode (start-->run, type "msconfig" without the quotes, ok, click boot.ini tab, check /SAFEBOOT, click ok or apply, close window, restart)

    Go to C:\Windows\System, delete hotkeysvc.exe

    Delete c:\patch.exe if it's there

    Then go to Start-->run, type "regedit", ok, navigate to the following keys:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_CURRENT_USER\System\CurrentControlSet\Control\Lsa
    HKEY_CURRENT_USER\Software\Microsoft\Ole
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
    HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
    HKEY_USERS\.default\Software\Microsoft\Windows\CurrentVersion\Run
    HKEY_USERS\.default\System\CurrentControlSet\Control\Lsa
    HKEY_USERS\.default\Software\Microsoft\Ole

    In all of them, delete the value
    "CPQHotkeys - hotkeysvc.exe" that shows on the right-hand side

    Then go to
    HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
    and change the value of EnableDCOM to Y

    Then start-->run-->msconfig, boot.ini, uncheck /SAFEBOOT, restart. Once you've restarted, ctrl+alt+delte, see if hotkeysvc.exe process is running, if not = :up:

    The only problem is the file that it downloads with the Spybot worm, no idea what it is. The above might be enough to get ur av scanners up and running anyway to get rid of it.

    Let me know if this works, no-one tried to send me the file :( :cry: but trillian pro isn't as vulnerable so blocks anything like that :p
  10. M.C.E

    M.C.E 1981-2013

    Joined:
    Apr 16, 2002
    Messages:
    13,850
    Likes Received:
    6
    Location:
    Cullercoats
    GEEK

    But a good one :eek:
  11. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    :D It's my pillow talk. :king:
  12. M.C.E

    M.C.E 1981-2013

    Joined:
    Apr 16, 2002
    Messages:
    13,850
    Likes Received:
    6
    Location:
    Cullercoats
    :lol: :rolleyes:
  13. Cookee

    Cookee Registered User

    Joined:
    Jul 13, 2003
    Messages:
    16,366
    Likes Received:
    0
    :lol: LMFAO! Cheeky sod! Graham gave it to me and Stephen ya little bugger!!
  14. trance_fan

    trance_fan Registered User

    Joined:
    Nov 7, 2002
    Messages:
    9,022
    Likes Received:
    0
    I bow down to your immense GEEEEK status :worship: :lol:
  15. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Il give it a try in a bit Mike. Just about to go out now tho.

    Do i still need that cd off you aswell?
  16. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    That should hopefully sort it out enough to get housecall or avg up and running. If the Spybot worm's been active your machine will be clogged to shit with spyware, so I recommend using all three of these: Spybot , Adaware and Microsoft Anti-Spyware. After downloading, installing and updating them close your net connection before running them.

    The cd will be a bit useless against Kelvir as it's not up to date enough, unfortunately. :down: If you're still having probs I could do u a cd with the above progs and some other stuff too that might blast it if needs be :)
  17. Rossy

    Rossy . Staff

    Joined:
    Jul 31, 2004
    Messages:
    7,809
    Likes Received:
    180
    Location:
    Posts:456780000000000000000
    I think I got the spybot worm a while back when that blaster worm and a shit load of others started doing the rounds.

    It fucked my comp right over. Internet connection was fucked, certain websites wouldn't load and would cut off the net, windows update was completely fucked.

    I checked my internet connection status and realised that the reason I couldn't connect to websites was because my computer was sending out so much fucking information. I think it's the "ddos" attack mentioned here:

    http://securityresponse.symantec.com/avcenter/venc/data/w32.spybot.worm.html

    Basically, if enough people are launching one on a certain server it's going to fuck it over.
  18. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor

    Done everything you suggested Mike, then tried Housecall. It scanned my computer, found 61 infections, then made a clicking noise several times and went to "This page cannot be displayed". Tried again from the start, but same thing happened.

    With AV it said my security setting dont allow me to download it.

    So im still as riddled as a Bigg Market slut im afraid. :(
  19. Rossy

    Rossy . Staff

    Joined:
    Jul 31, 2004
    Messages:
    7,809
    Likes Received:
    180
    Location:
    Posts:456780000000000000000
    Paritition hard disk, all your good stuff on one disk, windows on the other. Formatt.
  20. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Bugger. Try this:

    Repeat the steps for booting into safe mode above. Delete C:\windows\system\hotkeysvc.exe (or possibly C:\windows\system32\) and c:\patch.exe if they have re-appeared

    Look in the C:\windows\system (or system32) folder for any of these: Bling.exe; Netwmon.exe; Wuamgrd.exe - find em, delete em. It may be called summinck else, any suspicious exe's, write them down and google them (You'll have to repeat everything here again though)

    The n go to regedit, check for the registry keys I posted earlier just in case. Then go to the following:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
    RunServices
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
    RunServices
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
    HKEY_CURRENT_USER\Software\Microsoft\OLE

    and delete any keys that have reference to the names you found in the system folder (eg Bling.exe)

    Exit regedit, then go to Start-->search-->all files and folders, type "tftp*.*" without the quotes, make sure c drive is selected, click more advanced options, check search system folders and search subfolders, then click search. If any files are found in any folder called startup, check to see if they have a size of zero bytes. If so, delete them.

    Then reboot normally as posted earlier.

    My reputation shalt be diminished if that don't work a little.

    Try using Firefox to download avg (if you can download firefox that is), I've just been remotely helping my mate sort out summinck similar and she had no probs downloading in Firefox, only ie.

    I've burned off a cd for ya with anti-virus, spyware and trojan stuff, but don't know when I'll be getting out, i could poss drop it thru your door monday morning, shall let you know.

    Good luck again :up:

Share This Page