Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-15-2004, 06:49 PM   #1
bllott
Confirmed User
 
Join Date: Mar 2004
Location: Everywhere
Posts: 2,368
How can I remove this virus ??

I have adaware running and i got some virus thing which would attempt to contaminate my computer every startup. Someone else went to use my computer and accepted the changes and now I have some messed up homepage + messed up fovorites and a whole bunch of sex sites.

This are the messages from what the changes did:

Quote:
Ad-watch Logfile, exported on 4/15/2004
Total number of events:7
hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:54 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Bar
Data:
New Data:http://mypoiskovik.com/sp.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:55 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Start Page
Data:http://www.clickbank.com/
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:56 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Start Page
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:03 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://www.microsoft.com/isapi/redir...ie&ar=iesearch
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:07 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:08 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\SearchUrl
Value:
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:09 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:
New Data:http://mypoiskovik.com/sp.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
How can I remove this?
bllott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 06:50 PM   #2
bllott
Confirmed User
 
Join Date: Mar 2004
Location: Everywhere
Posts: 2,368
why the hell did all those HAHAHAAHHAs come uP?
bllott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 06:50 PM   #3
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
all those 'hahaha's look serious.

Format C now!
StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 06:56 PM   #4
bllott
Confirmed User
 
Join Date: Mar 2004
Location: Everywhere
Posts: 2,368
Quote:
Originally posted by MaskedMan
all those 'hahaha's look serious.

Format C now!
that's all i need.. some more good humor..

this fucken virus is killing me.how the hell do I remove it?

i tried a bunch of sites and antivirus shit and spyware shit nothing is working
bllott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 06:58 PM   #5
StuartD
Sofa King Band
 
StuartD's Avatar
 
Join Date: Jul 2002
Location: Outside the box
Posts: 29,903
Seriously, I don't know. It looks like the coolsearch virus that's going around and there seems to be a million and one variations.

I don't know anyone that's successfully removed it, much less how they did it.

Sorry to hear you got stuck with it though.
StuartD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 06:58 PM   #6
Paparazzi
Confirmed User
 
Join Date: Mar 2002
Posts: 3,488
try these:
http://www.kephyr.com/misc/promo/scc...urce=bassindex
http://www.kephyr.com/spywarescanner...rce=bottomlink
Paparazzi is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 07:43 PM   #7
Gemini
Confirmed User
 
Join Date: Jan 2001
Location: o-HI-o
Posts: 7,183
Try this

http://www.securityworm.com/software...oolsearch.html


and then check - clean your hosts file.
__________________
<center><a target="_blank" href="http://dev.datedollars.com/index.php?s=signup&amp;aid=535&amp;cfg=aac"><img border="0" src="http://216.130.172.224/gfy/gsig.gif" width="490" height="100"></a><br><a href="http://dev.datedollars.com/index.php?s=signup&amp;aid=535&amp;cfg=aac" target="_blank"><b><font face="Arial"><font color="#FF99FF"> Buy me away from Slavedriver Smokey!<br>It's May Sig Sweeps!<font></b></center>
Gemini is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-15-2004, 08:55 PM   #8
webmaster x
Confirmed User
 
Join Date: Mar 2004
Posts: 4,400
Ooops! Sorry I can't help yur there.
webmaster x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-17-2004, 02:06 PM   #9
bllott
Confirmed User
 
Join Date: Mar 2004
Location: Everywhere
Posts: 2,368
for anyone else, this virus is comes from some popups on porn sites, so that's how I got it

I wasted a day, to find the way, but this how to remove that piece of shit for anyone else:

download and run:

http://fileforum.betanews.com/detail.php3?fid=965718306

download update and run:

http://www.spywareinfo.com/downloads...CWShredder.exe

download and run:

http://www.spywareinfo.com/downloads...HijackThis.exe

and delete any of these once the scan with HijackThis is done:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mypoiskovik.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mypoiskovik.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mypoiskovik.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hispeed.rogers.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mypoiskovik.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,hahahahahaha Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R3 - URLSearchHook: (no name) - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - (no file)
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com

now you can surt porn again all you want !!!
bllott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.