GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   How can I remove this virus ?? (https://gfy.com/showthread.php?t=270030)

bllott 04-15-2004 06:49 PM

How can I remove this virus ??
 
I have adaware running and i got some virus thing which would attempt to contaminate my computer every startup. Someone else went to use my computer and accepted the changes and now I have some messed up homepage + messed up fovorites and a whole bunch of sex sites.

This are the messages from what the changes did:

Quote:

Ad-watch Logfile, exported on 4/15/2004
Total number of events:7
hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:54 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Bar
Data:
New Data:http://mypoiskovik.com/sp.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:55 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Start Page
Data:http://www.clickbank.com/
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:04:56 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Start Page
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:03 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:http://www.microsoft.com/isapi/redir...ie&ar=iesearch
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:07 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\Main
Value:Search Page
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:08 PM - Registry modification detected
Root:HKEY_CURRENT_USER
Key:Software\Microsoft\Internet Explorer\SearchUrl
Value:
Data:
New Data:http://mypoiskovik.com/index.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
4/15/2004 6:05:09 PM - Registry modification detected
Root:HKEY_LOCAL_MACHINE
Key:Software\Microsoft\Internet Explorer\Search
Value:SearchAssistant
Data:
New Data:http://mypoiskovik.com/sp.htm

Possible browser hijack attempt (Accepted)

hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahahahahahahahahahaha hahahahahahahahahahahahahahahahaha=
How can I remove this?

bllott 04-15-2004 06:50 PM

why the hell did all those HAHAHAAHHAs come uP?

StuartD 04-15-2004 06:50 PM

all those 'hahaha's look serious.

Format C now!

bllott 04-15-2004 06:56 PM

Quote:

Originally posted by MaskedMan
all those 'hahaha's look serious.

Format C now!

that's all i need.. some more good humor..

this fucken virus is killing me.how the hell do I remove it?

i tried a bunch of sites and antivirus shit and spyware shit nothing is working

StuartD 04-15-2004 06:58 PM

Seriously, I don't know. It looks like the coolsearch virus that's going around and there seems to be a million and one variations.

I don't know anyone that's successfully removed it, much less how they did it.

Sorry to hear you got stuck with it though.

Paparazzi 04-15-2004 06:58 PM

try these:
http://www.kephyr.com/misc/promo/scc...urce=bassindex
http://www.kephyr.com/spywarescanner...rce=bottomlink

Gemini 04-15-2004 07:43 PM

Try this

http://www.securityworm.com/software...oolsearch.html


and then check - clean your hosts file.

webmaster x 04-15-2004 08:55 PM

Ooops! Sorry I can't help yur there.

bllott 04-17-2004 02:06 PM

for anyone else, this virus is comes from some popups on porn sites, so that's how I got it

I wasted a day, to find the way, but this how to remove that piece of shit for anyone else:

download and run:

http://fileforum.betanews.com/detail.php3?fid=965718306

download update and run:

http://www.spywareinfo.com/downloads...CWShredder.exe

download and run:

http://www.spywareinfo.com/downloads...HijackThis.exe

and delete any of these once the scan with HijackThis is done:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mypoiskovik.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mypoiskovik.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mypoiskovik.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hispeed.rogers.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mypoiskovik.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,hahahahahaha Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R3 - URLSearchHook: (no name) - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - (no file)
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com

now you can surt porn again all you want !!!


All times are GMT -7. The time now is 08:24 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123