My mom just got a Major "Drive By Download".......
Moderator: Moderators
-
nightwheel
- Senior Member
- Posts: 2018
- Joined: Mon Mar 19, 2007 11:49 am
- PSN Username: nightwheel
- 360 GamerTag: nightwheel94
- Steam ID: nightwheel
- Location: Kentucky, We are KFC
- Contact:
My mom just got a Major "Drive By Download".......
of a Spyware/Malware/Virus combo.
My mom's PC just got hit hard. And I mean Hard. She got a email in her hotmail that looked like it came from either MSNBC or CNN saying a Plane Crashed into a school and Killed a bunch of kids. Being the kind of person my mom is. She went to the link. Instead she got a drive by download of Antivirus XP 2008. A Very bad Spyware/Malware/Virus combo. And it installed it's self onto my mom's PC. In a attempt to she turned her computer off. But I was too late, Antivirus XP 2008 got done installing. She started her PC back up. Antivirus XP 2008 XP went nuts, Giving false Virus Threats and Changed her Background. We had to go download Spy Bot S&D. But what ever this thing is, Spy Bot had a hard time finding it.
Word of Caution, Don't Go to any links in emails that look like they came from CNN, MSNBC, Fox News, or any other major news networks or sites. You do NOT WANT "Antivirus XP 2008" on your computer. This thing infects both XP and Vista computers. And from what I have experienced so far, This thing is hard as heck to Kill
Thought you guys needed to Know and Warn ya.
My mom's PC just got hit hard. And I mean Hard. She got a email in her hotmail that looked like it came from either MSNBC or CNN saying a Plane Crashed into a school and Killed a bunch of kids. Being the kind of person my mom is. She went to the link. Instead she got a drive by download of Antivirus XP 2008. A Very bad Spyware/Malware/Virus combo. And it installed it's self onto my mom's PC. In a attempt to she turned her computer off. But I was too late, Antivirus XP 2008 got done installing. She started her PC back up. Antivirus XP 2008 XP went nuts, Giving false Virus Threats and Changed her Background. We had to go download Spy Bot S&D. But what ever this thing is, Spy Bot had a hard time finding it.
Word of Caution, Don't Go to any links in emails that look like they came from CNN, MSNBC, Fox News, or any other major news networks or sites. You do NOT WANT "Antivirus XP 2008" on your computer. This thing infects both XP and Vista computers. And from what I have experienced so far, This thing is hard as heck to Kill
Thought you guys needed to Know and Warn ya.
-
bicostp
- Moderator
- Posts: 10491
- Joined: Mon Mar 07, 2005 5:47 pm
- Steam ID: bicostp
- Location: Spamalot
- Contact:
Most importantly, isolate that computer!!! Either unplug every other computer from your network or put it in a DMZ. (We have a wireless box between the two firewalls, which is really helpful for this.) You want to keep your healthy machines safe.
The absolute last-ditch solution is to save all her stuff to a completely different volume, run the system restore CD, and pray like crazy the backups aren't infected. (Install legit antivirus software before re-connecting the backup drive. As long as there's no autorun files on it, you shouldn't get any surprises.) This worked for my cousin's Dell, which had 16 trojans in the temp directory, and wouldn't load Explorer, the command prompt, or even Notepad. (And this is with a limited account; imagine the kind of carnage he could have inflicted as an admin.) If you do this, I recommend running the PC Decrapifier first thing, to get rid of any OEM trash.
However, I like to give an existing install one chance to get clean, because migrating to a fresh install is never fun.
Don't trust System Restore with fixing it; in my experience it gets hammered by viruses.
Next, install and run AdAware. (Run it in Safe Mode with Networking, if possible.)
Then, as an administrator, run MSconfig (Start -> Run -> msconfig). Go under the Services tab, check the "Hide all Microsoft Services" box. Now uncheck everything. Also un-check everything in the Startup tab.
Run HijackThis, save a log, and post it here. We'll help you pick out the stragglers.
Once it's all clean, open the System properties panel, and remove all the old System Restore points by turning System restore off for a couple minutes and re-enabling it.
Anyone who says "Ubuntu will solve your problem" will get e-pimp-slapped.
EDIT:
http://www.bleepingcomputer.com/malware ... us-xp-2008
EDIT 2: Wrong forum.
Moving...
EDIT 3:
The absolute last-ditch solution is to save all her stuff to a completely different volume, run the system restore CD, and pray like crazy the backups aren't infected. (Install legit antivirus software before re-connecting the backup drive. As long as there's no autorun files on it, you shouldn't get any surprises.) This worked for my cousin's Dell, which had 16 trojans in the temp directory, and wouldn't load Explorer, the command prompt, or even Notepad. (And this is with a limited account; imagine the kind of carnage he could have inflicted as an admin.) If you do this, I recommend running the PC Decrapifier first thing, to get rid of any OEM trash.
However, I like to give an existing install one chance to get clean, because migrating to a fresh install is never fun.
Don't trust System Restore with fixing it; in my experience it gets hammered by viruses.
Next, install and run AdAware. (Run it in Safe Mode with Networking, if possible.)
Then, as an administrator, run MSconfig (Start -> Run -> msconfig). Go under the Services tab, check the "Hide all Microsoft Services" box. Now uncheck everything. Also un-check everything in the Startup tab.
Run HijackThis, save a log, and post it here. We'll help you pick out the stragglers.
Once it's all clean, open the System properties panel, and remove all the old System Restore points by turning System restore off for a couple minutes and re-enabling it.
Anyone who says "Ubuntu will solve your problem" will get e-pimp-slapped.
EDIT:
http://www.bleepingcomputer.com/malware ... us-xp-2008
EDIT 2: Wrong forum.
EDIT 3:
It's also very user unfriendly by nature, and no offense to Nightwheel's mom but if she doesn't know better than to click on links in unsolicited email she shouldn't even think about any Linux distribution, even one that tries to put a nice face on the system like Ubuntu. Linux as it stands now is a horrible desktop solution for the average home user.grossaffe wrote:But Ubuntu is more secure...
Last edited by bicostp on Wed Aug 13, 2008 11:18 am, edited 1 time in total.
Twitter
http://www.pcwgaming.com" onclick="window.open(this.href);return false;
If you want a Dropbox account, please use my referral link
http://www.pcwgaming.com" onclick="window.open(this.href);return false;
If you want a Dropbox account, please use my referral link
-
HotDog-Cart
- Portablizer
- Posts: 3804
- Joined: Sat Jul 16, 2005 12:07 pm
- PSN Username: Lythinca
- Steam ID: scythe_king
- Location: Your IP Address, Connecting...
- Contact:
Here man. Easist fix. Cnet goes by this too.
http://forums.cnet.com/5208-6035_102-0. ... ID=2798128
All you have to do is a system restore. I suggest, a restore to about a week ago. Just to be safe.
Ive gotten this before, and thats how I fixed it also. Just a simple system restore.
http://forums.cnet.com/5208-6035_102-0. ... ID=2798128
All you have to do is a system restore. I suggest, a restore to about a week ago. Just to be safe.
Ive gotten this before, and thats how I fixed it also. Just a simple system restore.

-
nightwheel
- Senior Member
- Posts: 2018
- Joined: Mon Mar 19, 2007 11:49 am
- PSN Username: nightwheel
- 360 GamerTag: nightwheel94
- Steam ID: nightwheel
- Location: Kentucky, We are KFC
- Contact:
We nearly got rid of it. Still got a few things left to get rid of apearntly. It installed a lovely screen saver of windows xp startup and then it would blue screen, all fake of course. I have made a HiJackThis log. I have in a minute or two
And bic, my mom is very smart when it comes to computers. She taught me a lot of what I know about computers today. It was one those slip ups that every body does sometime in their life. And to be honest, This isn't the first time Antivirus XP has try to get on my mom's PC. She ran into a site pop up a few weeks back for the same stupid thing.
Also, We have lost "Run" in the start menu. How do we get it back?
And bic, my mom is very smart when it comes to computers. She taught me a lot of what I know about computers today. It was one those slip ups that every body does sometime in their life. And to be honest, This isn't the first time Antivirus XP has try to get on my mom's PC. She ran into a site pop up a few weeks back for the same stupid thing.
Also, We have lost "Run" in the start menu. How do we get it back?
-
nightwheel
- Senior Member
- Posts: 2018
- Joined: Mon Mar 19, 2007 11:49 am
- PSN Username: nightwheel
- 360 GamerTag: nightwheel94
- Steam ID: nightwheel
- Location: Kentucky, We are KFC
- Contact:
Here's the log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:19:50 PM, on 8/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\SmileyPad\SmileyPad.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MostFun\Bin\MostFun.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = prairiehomemaker.com/forum/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SmileyPad] C:\Program Files\SmileyPad\SmileyPad.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Gold 17\Remind.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/rap ... loader.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://www.stonyfield.com/coupons/scriptX/smsx.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - http://www.miniclip.com/supergerball/mi ... Loader.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/ricochet/Reflex ... Loader.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/ins ... _v01_4.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resou ... NPUpld.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://www102.coolsavings.com/download/cscmv5X.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-U ... E_UNO1.cab
O16 - DPF: {701DC9DC-ACD5-4E94-85E3-F3F1ED68611A} (CWebClientCtl Object) - http://download.paltalk.com/webclient_p ... entctl.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/downloa ... YAX29b.cab
O16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) - http://www.shockwave.com/content/snailm ... nstall.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ ... brkpie.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/downlo ... ctxcab.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/Acti ... ontrol.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/ ... taller.exe
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/ ... taller.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/active ... anager.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b31267.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O24 - Desktop Component 0: (no name) - http://mfrost.typepad.com/cute_overload ... situde.jpg
O24 - Desktop Component 1: (no name) - http://www.bigideafun.com/veggietales/d ... ryboy2.gif
O24 - Desktop Component 2: (no name) - http://www.bigideafun.com/veggietales/d ... ryboy1.gif
--
End of file - 16682 bytes
-
bicostp
- Moderator
- Posts: 10491
- Joined: Mon Mar 07, 2005 5:47 pm
- Steam ID: bicostp
- Location: Spamalot
- Contact:
I nearly got hit by this thing when I went to another forum. They were running either Invision Powerboard or Simple Machines Forum. Unplugging my switch's backbone connection really quickly prevented infection; AVG came up clean, and there are no odd changes or weird files created today here.
It's kind of amusing how they poorly disguise it as legit software.
Keep your eyes peeled. If you see anything out of the ordinary pop up here, PLEASE make a post about it in F42!
@nightwheel: Sorry, I didn't know your mom was that technologically inclined. From what I've seen, finding someone who really knows what to do in these situations isn't very easy. Unfortunate, but it keeps people like us in business. I just went by the apparent majority of end-users, and (admittedly) the Joe Sixpack end user stereotype.
You can get the Run command with the [Windows key] + R key combo.

It's kind of amusing how they poorly disguise it as legit software.
Keep your eyes peeled. If you see anything out of the ordinary pop up here, PLEASE make a post about it in F42!
@nightwheel: Sorry, I didn't know your mom was that technologically inclined. From what I've seen, finding someone who really knows what to do in these situations isn't very easy. Unfortunate, but it keeps people like us in business. I just went by the apparent majority of end-users, and (admittedly) the Joe Sixpack end user stereotype.
You can get the Run command with the [Windows key] + R key combo.
*e-pimp-slap*DK wrote:I've had that virus before. My solution was just to install Ubuntu. My computer illiterate family seem to be happy with it.
Twitter
http://www.pcwgaming.com" onclick="window.open(this.href);return false;
If you want a Dropbox account, please use my referral link
http://www.pcwgaming.com" onclick="window.open(this.href);return false;
If you want a Dropbox account, please use my referral link
-
HotDog-Cart
- Portablizer
- Posts: 3804
- Joined: Sat Jul 16, 2005 12:07 pm
- PSN Username: Lythinca
- Steam ID: scythe_king
- Location: Your IP Address, Connecting...
- Contact:
-
nightwheel
- Senior Member
- Posts: 2018
- Joined: Mon Mar 19, 2007 11:49 am
- PSN Username: nightwheel
- 360 GamerTag: nightwheel94
- Steam ID: nightwheel
- Location: Kentucky, We are KFC
- Contact:
No Because when the thing installed it's self. It removed all of my mom's old restore points and set a restore point of it's own. I thought it would not be safe to restore to that point.HotDog-Cart wrote:Did you do a system restore like I said?
Also, The idiotic thing is gone. Got rid of it. Everything seems to be back to normal.
bicostp wrote:*e-pimp-slap*DK wrote:I've had that virus before. My solution was just to install Ubuntu. My computer illiterate family seem to be happy with it.

what, you mean you haven't run into that nasty virus called "linux" yet? I've heard terrible things about it.DK wrote:bicostp wrote:*e-pimp-slap*DK wrote:I've had that virus before. My solution was just to install Ubuntu. My computer illiterate family seem to be happy with it.Don't slap me. Always wanted an excuse to convert my family desktop to penguin power and that virus was the thing that swayed me to Linux. No nasty virii yet
-
Kazaryster
- Posts: 107
- Joined: Sun Jul 13, 2008 5:37 pm
What your avatar is a linux penguin.grossaffe wrote:what, you mean you haven't run into that nasty virus called "linux" yet? I've heard terrible things about it.DK wrote:bicostp wrote:*e-pimp-slap*DK wrote:I've had that virus before. My solution was just to install Ubuntu. My computer illiterate family seem to be happy with it.Don't slap me. Always wanted an excuse to convert my family desktop to penguin power and that virus was the thing that swayed me to Linux. No nasty virii yet
oh no, I've been infected! The linux virus has taken over my computer! NOOOOOOOO!!!!Kazaryster wrote:What your avatar is a linux penguin.grossaffe wrote:what, you mean you haven't run into that nasty virus called "linux" yet? I've heard terrible things about it.DK wrote:bicostp wrote:*e-pimp-slap*DK wrote:I've had that virus before. My solution was just to install Ubuntu. My computer illiterate family seem to be happy with it.Don't slap me. Always wanted an excuse to convert my family desktop to penguin power and that virus was the thing that swayed me to Linux. No nasty virii yet
