Go ![]() | New ![]() | Find ![]() | Notify ![]() | Tools ![]() | Reply ![]() | |
Emeritus![]() ![]() |
Anyone know how i can get rid of this shit? _______________ -r0x | ||
|
| Emeritus |
hey i think i had something very similar; you mean it diverts your webpage to a search engine page? if so, a trojan[edit] it is... try Mid's instructions near the bottom of this thread.. hope that helps, i couldn't get anywhere with most of those spyware proggies and nort anti-virus.. | |||
|
Magistrate![]() |
| |||
|
Emeritus![]() ![]() |
lol okay i clicked him now what did that just do? Btw i love your creativity. _______________ -r0x | |||
|
Magistrate![]() |
That was a bitch to remove man( | |||
|
Emeritus![]() ![]() |
yeah dude im gonna need you to walk me through it if possible. il try to hop on earlier and catch ya. _______________ -r0x | |||
|
| Secretary |
Look guys this is a very fucked up virus that I am very very angry about. You will have to manually edit this shit out. The removal tool doesn't work worth shit. If you want a hand in removing this pest catch me on vent when I am on and I will talk you through. WinXP and WinME users disable that annoying System Restore Service on your computer before attempting to repair this. Once repaired please update your version of windows to the current date. There is a patch that corrects the hole in which this Trojan uses. But it must be manual patched before allowing the Microsoft patch to correct its error. DAMN YOU MICROSUCKS/MICROBLOWS Removal using the Trojan.Qhosts Removal Tool Symantec Security Response has developed a removal tool to clean the infections of Trojan.Qhosts. This is the easiest way to remove this threat and should be tried first. Manual Removal As an alternative to using the removal tool, you can manually remove this threat. The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines. Disable System Restore (Windows Me/XP). Update the virus definitions. Run a full system scan and delete all the files detected as Trojan.Qhosts. Reverse the changes that were made to the registry. Reverse the changes that were made to the Hosts file. For specific details on each of these steps, read the following instructions. 1. Disabling System Restore (Windows Me/XP) If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer. Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations. Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat. For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles: "How to disable or enable Windows Me System Restore" "How to turn off or turn on Windows XP System Restore" -------------------------------------------------------------------------------- Note: When you are completely finished with the removal procedure, and you are satisfied that the threat has been removed, you should reenable System Restore by following the instructions in the aforementioned documents. -------------------------------------------------------------------------------- For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder," Article ID: Q263455. 2. Updating the virus definitions Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions: Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate). Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater). The Intelligent Updater virus definitions are available: Read "How to update virus definition files using the Intelligent Updater" for detailed instructions. 3. Scanning for and deleting the infected files Start your Symantec antivirus program and make sure that it is configured to scan all the files. For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files." For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files." Run a full system scan. If any files are detected as infected with Trojan.Qhosts, click Delete. 4. Reversing the changes made to the registry -------------------------------------------------------------------------------- WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions. -------------------------------------------------------------------------------- Click Start, and then click Run. (The Run dialog box appears.) Type regedit Then click OK. (The Registry Editor opens.) Navigate to the key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\MSTCP In the right pane, delete the values: "EnableDNS"="1" "NameServer"=" "HostName"="host" "Domain"="mydomain.com" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings In the right pane, delete the values: "ProxyEnable"="0" "MigrateProxy"="0" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main In the right pane, delete the values: "Use Search Asst"="no" "Search Page"="http:/ /www.google.com" "Search Bar"="http:/ /www.google.com/ie" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL In the right pane, delete the values: ""="http:/ /www.google.com/keyword/%%s" "provider"="gogl" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search In the right pane, delete the value: "SearchAssistant"="http:/ /www.google.com/ie" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\Windows HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\Windows In the right pane, delete the value: "r0x"="your s0x" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters modify the value: "DataBasePath"="%SystemRoot%\help" to: "DataBasePath"="%SystemRoot%\System32\drivers\etc" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces For each subkey, Restore the value: "NameServer"=" NOTE: the default for many configurations is an empty string. Exit the registry Editor. 5. Reversing the changes made to the Hosts file All the computers will not have this file, and the location can vary. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and in Windows 2000, it is in the C:\WINNT\SYSTEM32\DRIVERS\ETC folder. Also, there may be multiple copies of this file in different locations. The most efficient way to locate the file is to search for it. Follow the instructions for your operating system: Windows 95/98/Me/NT/2000 Click Start, point to Find or Search, and then click Files or Folders. Make sure that "Look in" is set to (C In the "Named" or "Search for..." box, type: hosts Click Find Now or Search Now. For each one that you find, right-click it, and then click "Open With." Deselect the "Always use this program to open this program" check box. Scroll through the list of programs and double-click Notepad. Look for the following lines and delete them, if found: Close Notepad and save your changes when prompted. Windows XP Click Start, and then click Search. Click All files and folders. In the "All or part of the file name" box, type: hosts Verify that "Look in" is set to "Local Hard Drives" or to (C Click "More advanced options." Check "Search system folders." Check "Search subfolders." Click Search. Click Find Now or Search Now. For each one that you find, right-click it, and then click "Open With." Deselect the "Always use this program to open this program" check box. Scroll through the list of programs and double-click Notepad. Look for the following lines and delete them, if found: Close Notepad and save your changes when prompted. Midknight | |||
|
Magistrate![]() |
that's the text from the link. it's still not the easiest for people to read through and fix, so r0x might need a walk through. | |||
|
| Secretary |
Well here goes nothing. I have dropped it down a couple notches for a better understanding. Go into My Computer and click on the C: Drive. Now go to the tools button at the top of the window and go to Folder Options. Once in Folder Options go to the View Tab and find the setting to show all hidden folders and files. Click that radio button and then click the button at the top to all changes to all folders and files. Click the ok at the bottom of the window and on your C: Drive there will be a Folder called Bdtmp. Delete that MOFO of a folder. Ok you just deleted the folder and files that start that nasty trojan up. Now carry on with the manual deletion of the Trojan. First off disable your System Restore Service. Click Start. Right-click My Computer, and then click Properties. Click the System Restore tab. Select "Turn off System Restore" or "Turn off System Restore on all drives" check box. Click Ok. Secondly update your virus definitions off of the corporations website (Symantec (Norton), Mcafee, F-Prot, whatever). Thridly you must edit your computers registry. I can't stress how important it is to be very careful while doing this. Please double or even triple check the path before altering the entry. Click Start, and then click Run. Type regedit Then click OK. Ok you will get a window with five folders and my computer as the root to the tree of folders. Click the plus signs to expand the folder to view its content. Follow the folder structure to this path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\MSTCP Thats the HKEY_LOCAL_MACHINE -->SYSTEM --> CurrentControlSet --> Services -->VxD -->MSTCP Click the MSTCP folder. On the right side there will be a (Default) REG_SZ (value not set) and a Hostname REG_SZ Administrator If there are these things in that right pane delete them. "EnableDNS"="1" "NameServer"="" "HostName"="host" "Domain"="mydomain.com" By clicking the Name and hitting delete. ONLY DELETE THESE IF THEY ARE IN THERE. If these aren't in the folder continue on by further checking the other folders. Then go back on the left pane where there is the tree of folders and go back to the way it was with five folders and my computer at the top. Then do the same thing to these registry keys: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings In the right pane, delete the values: "ProxyEnable"="0" "MigrateProxy"="0" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main In the right pane, delete the values: "Use Search Asst"="no" "Search Page"="http:/ /www.google.com" "Search Bar"="http:/ /www.google.com/ie" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL In the right pane, delete the values: ""="http:/ /www.google.com/keyword/%%s" "provider"="gogl" Navigate to the key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search In the right pane, delete the value: "SearchAssistant"="http:/ /www.google.com/ie" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\Windows HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\Windows In the right pane, delete the value: "r0x"="your s0x" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters modify the value: "DataBasePath"="%SystemRoot%\help" to: "DataBasePath"="%SystemRoot%\System32\drivers\etc" Navigate to the keys: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces For each subkey, Restore the value: "NameServer"="" NOTE: the default for many configurations is an empty string. Exit the registry Editor. Click Start. Go to Search. Then select Files and Folders. In the search field type hosts. Make sure the search is looking at the C: Drive and not just one folder. Click Search. the Search will find a few files probably. There will be one if not two or more files called hosts. What you do is right click the file and goto Open With... Then select Notepad to open the file with. Once the file comes up look for this stuff: Delete all of this things but make sure not to delete anything else in this file just those. Then close notepad and save changes. Don't rename or give the file any other extensions just save changes. Then there you go you have just accomplished something that Norton Specialists can't even delete with a program designed to eliminate such threats. Have any questions grab me on vent or through a quick message in this post. I should be able to get back to you within a days time. Midknight | |||
|
| Powered by Social Strata |
| Please Wait. Your request is being processed... |
|
© Low Caliber Club 2002-4



