Results 1 to 13 of 13
  1. #1
    XTerminator is offline Upgraded User
    Join Date
    Dec 2004
    Posts
    3,118
    Hi Everyone,



    Incase you get a message from me or anyone else on Yahoo Instant Messenger with similar text and links as below:



    Code:
    "check out my new personal website : h t t p : / / mytermex .com c0ol !!! "
    OR

    Code:
    "there's going to be a meteor shower tonight : h t t p : / / nsl-school .org / ?i d=18388 << "
    OR

    Code:
    "check this link for me : h t t p : / / nsl-school . org /? i d=forum . Why I cannot surf this site ??? "


    PLEASE PLEASE DONOT CLICK ON THE LINKS



    THIS IS A Backdoor trojan/worm/adware WHICH INFECTED MY COMPUTER SOMEHOW and has infected many others too. Asked around to a few friends and it seems it has infected loads of people.



    INCASE YOU HAVE ALREADY CLICKED, it will disable you from using the start-Run command Or any registry editing command. Apart from this it will also disable your Task Manager or the ctrl+alt+delete function.





    Incase this has happened, please run Spybot Search and Destroy to remove the infection.

    It will add

    Code:
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    
    "Task Manager"="C:\\WINDOWS\\svhost32.exe"
    and

    Code:
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    
    "Svchost"="C:\\WINDOWS\\svhost.exe"
    To your start up procedure.



    Besides disabling the RUN command, Registry Editing tools and the Taskbar for an active user as well as for other users using the same system.



    Incase you want to re enable the run, regedit and task manager please post here. It involves editing the registry and can prove ill for people who dont know their way around the registry.

    Thanks.


    Thanks to Imageshack for Free Image Hosting

  2. #2
    Striker10 is offline Privileged Users
    Join Date
    Mar 2005
    Posts
    2,223
    yea man , my friend had his status message like that once(4-5 days back I think) , I clicked on it (ZoneAlarm asked me if I wanted to let one "project1" access the internet , I denied it but somehow my system got infected . So I quickly ran Spybot in safe mode cleared out some things and used Hijack-This to remove the start-up entries . this took me some time =@ and system was back to normal. and yes I removed him from my list LOL .

    I thought he did this purposely , now I will add him back
    AMD X2 4800+ | 2GB DDR-II | ASUS M2A-VM | 500GB+160+1TB,500GB EXT HDD | OPTIARC AD-7200 | 9600GT 512MB | CM 460 :cool2: | SS 933SN

  3. #3
    chic_magnet is offline Upgraded User
    Join Date
    Mar 2005
    Posts
    2,351
    yeah my stupid college friends wouldnt listen to that thier comp is infected. so i block em.. now everyone is katti with me, cause i blocked em for no apparent reason.. stupid fools.. ..
    At Home - Gigabyte MA78GM-S2HP | AMD 7750+ | 4 GB Corsair XMS RAM | 1.2TB | Sapphire 4850 1GB |PowerSafe 600Watts | Thermaltake Xaser III |LG GH22NS30|MX5021 - M-Audio 7.1

    On the Go - Cowon D2 24GB + Sennheiser CX 400

    [SIGPIC][/SIGPIC]

  4. #4
    FaH33m is online now Privileged Users
    Join Date
    Apr 2006
    Posts
    4,923
    man ..i have been getting the same msgs from all my friends in yahoo messenger for the past 4-5 days..in the starting i clicked on one of them and ALAS !!! my pc was infected and everything screwed up ..also it started infecting all my files on the pc ...and i had to do a format .as Zone alarm as well as avast could not repair the files.(only delete them).....



    GUYS -also note that if infected by such trojan/virus all u r administrative rights will also be gone..it had even disabled my anti virus and zone alarm..

    then u need to clean system in safe mode.

    i hope there is some sollution soon and this things stops..

    ALSO should i keep any other antispyware/stinger etc. along with zone alarm and avast ?any recommendations to keep PC completely away from such viruses/spyware/adware/trojans etc ?
    IEMs: UE TF10,RE-0 Cans: LA modded-Mogami-recabled Denon AH-D5000.

    Source: iPhone 4,Sansa Fuze,Audinst HUD-MX1


    Nikon D7000 + Tamron 17-50 F/2.8 + Nikkor 35mm F/1.8 + Nikkor 50mm F/1.8.

  5. #5
    XTerminator is offline Upgraded User
    Join Date
    Dec 2004
    Posts
    3,118
    I got infected dunno when....probably due to someone else using my comp...

    I generally use run and type notepad to open notepad...but the run command gave me an error that you donot have the right!!!



    I was shocked...tried again..and same problem...So i immediately disconnected from the internet, ran spybot s&d followed by Adaware SE. A total of 6 objects were removed. Then used Regcleaner to see the startup files, saw two suspecious entries, removed them from start up, booted into safe mode, removed the two files manually from the hdd, restarted, ran anti-virus, then checked for the entries for the Enable Run and Regedit from the internet and used a .reg file to fix the same. After that the comp has not given me any problems so far...but i am still on the alert as to what or how it came in.



    When I recieved this message from my friend...and instantly knew it was the root cause.


    Thanks to Imageshack for Free Image Hosting

  6. #6
    FaH33m is online now Privileged Users
    Join Date
    Apr 2006
    Posts
    4,923
    actly we cant blame our frnds...cauz i asked few of my frnds if they had sent me such msgs all of them said NO ! and it is being sent automatically...from their name.to their contact list.
    IEMs: UE TF10,RE-0 Cans: LA modded-Mogami-recabled Denon AH-D5000.

    Source: iPhone 4,Sansa Fuze,Audinst HUD-MX1


    Nikon D7000 + Tamron 17-50 F/2.8 + Nikkor 35mm F/1.8 + Nikkor 50mm F/1.8.

  7. #7
    XTerminator is offline Upgraded User
    Join Date
    Dec 2004
    Posts
    3,118
    Yep...so it is.



    So you cannot blame anyone for this but u have to be careful yourself.

    Thats all.


    Thanks to Imageshack for Free Image Hosting

  8. #8
    pisen is offline Privileged Users
    Join Date
    May 2006
    Posts
    335
    well this virus has infected many friends of mine too, not from my PC but still their messages can be really irritating and tempting

  9. #9
    ComradE_BeaN is offline Upgraded User
    Join Date
    Feb 2006
    Posts
    2,428
    NOD32 caught it:hap2:....happened from 2 frnds..
    "If you want to use a hard drive in the vertical position, you must first reformat it in the vertical position!"

  10. #10
    greenhorn is offline Privileged Users
    Join Date
    Dec 2005
    Posts
    5,206
    happens if you have IE set as default... at least this helped me get a few more n00bs to convert to Firefox
    Turbo lag:@ But when it comes it :jumpy:COMES

  11. #11
    iosoft is offline Upgraded User
    Join Date
    Dec 2005
    Posts
    1,272
    Yes, I also got this type of messages. It was actually sent from a local friend's a/c. didn't clicked as the address was too odd.



    Thanks for the warning.
    Signature Removed.

    No Referral Links allowed.

  12. #12
    greenhorn is offline Privileged Users
    Join Date
    Dec 2005
    Posts
    5,206
    shouldnt be a problem if you're on firefox, especially if you have noscript installed.



    damn thing changes your IE home page to one of its own, which is filled with google ads for some rare form of cancer, which is a high priced ad word.



    btw, besides spamming links, it changes the status messages of infected users and puts the links in there too
    Turbo lag:@ But when it comes it :jumpy:COMES

  13. #13
    Quad Master is offline Upgraded User
    Join Date
    Apr 2005
    Posts
    5,359
    Thanks for sharing the info.



    Desktop: Gigabyte EP45-UD3P | C2D E8400 | Noctua NH-U12P | ATI 4850HD | Corsair TX750 | Xonar D2X | MX5021 | MX518 | Benq E2200HD | ZB01

    Gaming n Entertainment : Sony 3D LED KDL-HX800 40' | Sony 3D BluRay | Sony PS3 Slim 3.41

    Mobility : Sony VAIO VPCEB26FG-B | Samsung Galaxy S2


 

 

Similar Threads

  1. Replies: 5
    Last Post: 16-07-06, 12:16 AM
  2. Replies: 10
    Last Post: 04-07-06, 10:20 AM
  3. New worm spoofs Google, Yahoo and MSN sites
    By vishalk in forum Internet Talk
    Replies: 0
    Last Post: 03-10-05, 12:51 AM
  4. Adware/Spyawre/Trojan Cleaner with Active Monitoring.
    By gizmoholic in forum Applications
    Replies: 8
    Last Post: 13-09-05, 08:04 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
All times are GMT +5.5. The time now is 12:04 AM. Powered by vBulletin® Version 4.1.12
Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.
Content Relevant URLs by vBSEO 3.6.0 PL2