Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 11-04-2003, 03:23 AM   #1
WidowSEXplorer
Registered User
 
Join Date: Jul 2003
Posts: 10
a new fucking virus wants to fuck all of us

I found that virus yesterday. What is this Virus doing:
1. It changes the links on the pages you are opening with IE. The links are leading to "http://thesten.com/main/k.php?key=FETISH". It changes the category acording to the page content.
2. Chanes your main page and search pages.
3. Changes your host file.
4. Downloads thefolowing files from internet:
iedll.exe
loader.exe
DNSerr.exe

I found a similar virus on spermatrix.com
What I've done to remove teh virus:
1. First search the regestry for "thesten" and delete all the entryes I found.
2. Delete this 3 files I mentioned.
3. Then downloaded this software.
http://www.spywareinfo.com/~merijn/f...hijackthis.zip
!!!IMPORTANT. Do not fix everything the software finds. Just the host files and if there is iedll.exe,loader.exe or DNSerr.exe runned. If you remove everything then you must reinstall it.
WidowSEXplorer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 03:29 AM   #2
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
not if you're running mozilla firebird it doesn't
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 03:30 AM   #3
jeroman
So Fucking Banned
 
Join Date: Oct 2002
Location: Norway or UK or...damn, where am I
Posts: 356
adaware pro takes care of similar stuff like this
jeroman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 03:31 AM   #4
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
and while you're at it, why don't you replace that exploit prone MS outlook with mozilla thunderbird .
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 03:34 AM   #5
WidowSEXplorer
Registered User
 
Join Date: Jul 2003
Posts: 10
The problem is that I din't catch the virus trough the e-mail. It is a web based virus and it infects the serfers from a webpage.
__________________
<font color="#66cc00" size="-1">It's not important how big you are... the point is how big you want to be!</font>
WidowSEXplorer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:16 AM   #6
WidowSEXplorer
Registered User
 
Join Date: Jul 2003
Posts: 10
do you remember this virus ththrous popups when you have sextracker? The new one is worst because it will still your traffic. Imagine that infected surfer goes to your webpage. This virus changes the link on your page and when the surfer clicks on your page it goes to http://thesten.com or another page but not to your traders or galleries. I think this can become a serious problem for all of us.
__________________
<font color="#66cc00" size="-1">It's not important how big you are... the point is how big you want to be!</font>
WidowSEXplorer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:25 AM   #7
buzzard
Confirmed User
 
buzzard's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: Midwest
Posts: 1,276
praise jebus
buzzard is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:27 AM   #8
MattO
The O is for Oohhh
 
Join Date: Feb 2003
Location: AUSTIN TEJAS
Posts: 10,861
you need Mozilla Pterodactyl
MattO is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:30 AM   #9
Spice
Registered User
 
Join Date: Feb 2003
Posts: 83
WOW, I got the same exact thing here. It scared the shit outta me at first seeing half of my links going to thesten.com. I thought that someone hacked my server. After refreshing, it went away. I think that I'd better run my adware program to make sure that it's gone. I do have Norton Net Security 2004, but sometimes when I'm looking at pages, it doesn't display all of the images, so I disable it to view them.
Spice is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:39 AM   #10
Spice
Registered User
 
Join Date: Feb 2003
Posts: 83
I'd bet that the owner of that domain has something to do with it ;(
Spice is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:41 AM   #11
TheViper
Confirmed User
 
Join Date: Mar 2003
Location: the streets.
Posts: 2,560
iedll.exe is a nasty fucker for sure, if you remove it by hand it installs itself again after a few minutes or on boot up.
TheViper is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 06:46 AM   #12
Gemini
Confirmed User
 
Join Date: Jan 2001
Location: o-HI-o
Posts: 7,183
Email his host and get his plug pulled and then as he moves from host to host... follow his b*tt and tell each host. lol Amazing how fast they take them down when they see it for themselves. If the host doesn't respond, step up the food chain to the upstream provider.
__________________
<center><a target="_blank" href="http://dev.datedollars.com/index.php?s=signup&amp;aid=535&amp;cfg=aac"><img border="0" src="http://216.130.172.224/gfy/gsig.gif" width="490" height="100"></a><br><a href="http://dev.datedollars.com/index.php?s=signup&amp;aid=535&amp;cfg=aac" target="_blank"><b><font face="Arial"><font color="#FF99FF"> Buy me away from Slavedriver Smokey!<br>It's May Sig Sweeps!<font></b></center>
Gemini is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 07:38 AM   #13
WidowSEXplorer
Registered User
 
Join Date: Jul 2003
Posts: 10
Spice

It can't just gone and there is no antivirus for this shit because it's "handmade". The antivirus companies does not even know about it but it will be to late when they learn about it. Spermatrix is site with about 200k traffic daily. Can you imagine howmany people get infected. Probably 100 000 everyday.
__________________
<font color="#66cc00" size="-1">It's not important how big you are... the point is how big you want to be!</font>
WidowSEXplorer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 07:42 AM   #14
Seb From Holland
Confirmed User
 
Join Date: May 2002
Location: The Netherlands
Posts: 2,747
Just make your host file read only.
Seb From Holland is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 07:44 AM   #15
jacker
Confirmed User
 
Join Date: Oct 2003
Location: Montreal, Canada
Posts: 215
My buddy got hit at home...he managed to find the files and delete them but it really messed his PC up. Thanks for the info re: cleaning the bug out.

Cheers
James
__________________
James Acker
PaySystems Corporation
1-866-699-9021 x2109
[email protected]
icq: 60019103
jacker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 07:47 AM   #16
pudcat
Confirmed User
 
Join Date: Mar 2003
Posts: 1,169
Quote:
Originally posted by goBigtime
and while you're at it, why don't you replace that exploit prone MS outlook with mozilla thunderbird .


while you're at it... try Linux, bsd macosx or whatever... it's amazing how little you need to be worried about viruses, crashes, the computer going super slow for no particular reason... and your work might even speed up a little
__________________
SUBMIT YOUR BABE GALLERIES

PROMOTE YOUR BLOG HERE

always looking for hardlinks icq #207011694

Thunder-Ball.net, good for hardlink exchanges
pudcat is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 09:06 AM   #17
WidowSEXplorer
Registered User
 
Join Date: Jul 2003
Posts: 10
The problem is not in the host file and not even in my computer. The problem is with the thousands of clicks that this motherfucker will still from all of us.
__________________
<font color="#66cc00" size="-1">It's not important how big you are... the point is how big you want to be!</font>
WidowSEXplorer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 11-04-2003, 09:11 AM   #18
loverboy
When it rains, it pours
 
Industry Role:
Join Date: May 2003
Posts: 20,609
im well protected w/ Windows XP ICF
loverboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.