![]() |
Got pop-up virus from http://00hq.com
I went to some site yesterday and got this fucking pop up virus, it just start's coming up at differnt times.
the site is http://00hq.com, it pops up a page1.html and a page2.html. Anyone know where I would look to get rid of it. I'm gettin ready to strangle the bastard, if I could find him. At the same time the default page for my browser got changed to http://searchv.com. That I could change, but I never had this shit happen before. Thanks |
Oh yeah, I know about the home pages getting changed alot.
That's not the problem now. The problem is the pop-ups from http://00hq.com which have been happenning since yesterday and my computer was shut down for a number of hours and it started again today. |
I got hit with that on Friday,
Ad-aware and spybot don't get rid of it either. |
http://sunday.ru
Has a java Exploit virus on there webpage.. Guys know of any others? sunday.ru is a freebie hosting co. |
Some reaons I am lagging and I post two times werid..
|
KMR Guy
Are you sayin the exploit virus at the .ru site will help or it does the same thing as what http://00hq.com does Thanks |
El Pres
So you still have it then....? |
Housecall is handy for getting rid of those JS buggers
|
Quote:
Untill I can spend some time to get rid of it, I'm using netscape! hehe I tried to download Housecall but got an error. |
Yeah, the same thing happened to me when I tried to download housecall.
Doesn't bother netscape though........hmm.....netscape gets so little use not even worth writing a virus for I guess I guess this shouldn't that be hard to figure out......but..ah..well... thanks anyway |
investigation not going too quickly....
http://searchv.com which installed as my default browser owns http://00hq.com If anybody knows the way to go on this it would be appreciated. thanks |
Quote:
I was hit too, because he submits about 20 galleries a day. Also, he added the following domains to hosts file. So when you visit those sites, you'll see popups. sexyrabbit free6 thehun sexocean xnxx easypic Popups are from 00hq.com and v61.com, something like http://www.v61.com/redirect.php?adsite1 |
A nice huy
Wow, thanks.......this is a great thing to read... I'll have to see if I can find the wsock32.dll and winsock.dll files on the web.......... I got a 4 year old compaq presario, that was the best thing out at the time and I never had to use the windows CD...... I got no idea where that is...... I may just by a new one.......I've been lookin for the last 3 months....it could be the easiet thing to do right now......then I get the windows CD too....:) lol...... |
A nice huy
Are you saying that he somehow added those popups to servers of all those sites and everyone sees them. I be honest with you, I spend alot time buying domain names and all the things people do with scripts and mischivous things I just never had the time to get involved in.... sexyrabbit free6 thehun sexocean xnxx easypic |
I just found a thread from late in 2002, where it appears somebody had the same thiing happen with http://xxx-school-girls.com
http://www.experts-exchange.com/Mana..._20409944.html |
I FOUND THE BASTARD FILES**##!!$$#%* :stoned
After reading the thread I posted it pretty much said to look in your windows folder for an .exe file... which I did and there theys was.... 2 bastard files... I knew the date and about the time it happened, so they were just sittin there with.......no place to hide :Graucho --------------------- the obvious badie was a file called - winshow.cfg and it contained this below, BaseURL="http://00hq.com/ad.php?code=" ShowPause=180 ShowLimit=10 UpdatePause=1 UpdateURL="http://00hq.com/update/" THE EVIL 00hq caught bareass naked :Graucho I hope it's a female virus. -------------- the other file is a - dict.dat which I don't know what this is about but, I think it's some russain mixed in with a little somethin else: :Kissmy ?.Fb#ɍhM)6If~t?B?+@Me?'4X c#**&̐h?DSfuiz?a'9Xb?xz?8 ;W*??<GWc? /tt?T7JV$ ؿxE?<FZ岻m???;No}d?;Gaq_ z?X;IMj(ҝ??F.CS.?z??(?3Cr /?=cd ,?,?5.V}!?IWU?{?G2b/*ST!c?q_C?(fE!ij@p??6-UR?%?K.ZX?oK6fR&* there were alot of russian links to the site, and as we say, not that this says anything about other russian sites. :Buck: |
Is this the same as the Gator search popup? I got this recently when I do a search on google by default another window pops up with search results PPC probably associated with Gator corp. I'm usually pretty good about not allowing web installs with that. Any ideas how to get rid of it? Is it something simple in WindowsXP menu?
|
I don't know if anyone will find this useful but I thought I'd post it anyway - it helped me clean up my computer a little bit actually!
http://www.doxdesk.com/parasite/ |
Oh man, I don't know....this is the first time I got involved in something like this....I was grazy all day...
I'm goin go out and do me some celebratin and some :Kissmy :Kissmy I don't got the xp.....but 1 thing for sure....it's on your machine....which isn't that bad because it's not goin anywhere and probably in the windows folder too..... if you know the day or about the day it happened, just view your windows folder with the details showing for all the files and check the dates for a small file size and take a look at them both of the files I found were just 1 kb.... :GFYBand :) |
SON OF A BITCH....IT'S BACK.....!!!
I CAN'T FUCKIN BELIEVE......!!! OH SHIT......!!! I DELETEED THOSE FUCKERS TOTALLY OFF MY MACHINE!!! OH FUCK......!!! WHAT THE FUCK.......!!! |
THEY REPRODUCED......
I CAN'T BELIEVE IT...... THEY FUCKIN REPRODUCED..... OH SHIT.......!!! |
Quote:
I THOUGHT I too was free of my virus when I ran virus scan and there was no sight of it. So I shut my computer off, and came back later, booted back up and wham..it was back! HOW HOW I asked myself too. Then after doing a little reading on the virus I found out that it HIDES a copy of itself in the windows/temp directory..usually as some sort of inane .tmp file. So, I went in and deleted ALL the files in the windows/temp directory after running my virus program again, and was able to get rid of all of them but ONE..yep..the virus..Windows wouldn't let me delete it cuz it said "in use". So, I pondered what I should do next and what I finally did (WHICH WORKED!), was rebooted but hit the old f8 (now, this is for win98se, so don't know how it works on xp or 2k) and booted up in dos. While there, I went over and THEN deleted all the temp files and FINALLY, I had triumphed! For what it is worth.. |
run this online anti-virus
http://housecall.trendmicro.com/ then download zone alarm pro from: www.downloads.com and download reg run from: www.downloads.com and then you are protected from anything on the web see ya :) |
Centurion and geps
Thank you for your experiences WHAT I JUST DID.... I GOT THE BASTARDS THIS TIME....!!! SO I'M BACK TO THIS.........:Kissmy :Kissmy Since the file was going to reproduce, I went into the - winshow.cfg - file and deleted everything in it and saved it, so it is still there, but it doesn't do anything. THE GOOD TIMES ARE SO SWEET.......!!! :Kissmy :GFYBand My ass is startin to get a little sore though from all the swayin back and forth.... Centurion and geps, I will try those things you mentioned. I like the part about triumphing.... Someone else and myself did try to download the housecall file, but we both got error messgaes. Thanks though for the possibilities of what to do. |
A few weeks back, I had a simular problem.
Bought a program online, called: PEST PATROL Amazing program, cleaned up tons of stuff that anti virus missed. |
Quote:
|
Wendy
Thanks about the pest control program..... Sounds like I want to GET ME SOME of them PESTY CONTROLLERS......!!!! :stoned :GFYBand |
| All times are GMT -7. The time now is 01:36 AM. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123