Low Caliber Club
Low Caliber Club
    Low Caliber Forum  Hop To Forum Categories  Red Carpet    Search engine virus?
Go
New
Find
Notify
Tools
Reply
  
Search engine virus?
 Login/Join
 
Emeritus
Picture of kyr0xx0r
AIM: Online Status For imsofakingl33t
posted
Anyone know how i can get rid of this shit? Thumbs Down

_______________
-r0x
 
Posts: 838 | Location: So, Cal | Registered: Thu June 26 2003Reply With QuoteReport This Post
Emeritus
Picture of Dante
posted Hide Post
hey i think i had something very similar; you mean it diverts your webpage to a search engine page? if so, a trojan[edit] it is...

try Mid's instructions near the bottom of this thread..

hope that helps, i couldn't get anywhere with most of those spyware proggies and nort anti-virus..

 
Posts: 1258 | Location: "Auslander" | Registered: Wed May 21 2003Reply With QuoteReport This Post
Magistrate
Picture of Manowar
MSN does not support status - click here for the profile.
posted Hide Post
Frown

(click the crying guy)
 
Posts: 2948 | Location: Michigan, USA | Registered: Fri January 17 2003Reply With QuoteReport This Post
Emeritus
Picture of kyr0xx0r
AIM: Online Status For imsofakingl33t
posted Hide Post
lol okay i clicked him now what did that just do?

Btw i love your creativity.

_______________
-r0x
 
Posts: 838 | Location: So, Cal | Registered: Thu June 26 2003Reply With QuoteReport This Post
Magistrate
Picture of Manowar
MSN does not support status - click here for the profile.
posted Hide Post
That was a bitch to remove man( Mad), let me know if you got rid of it. If not, I can walk you through it on Vent.

 
Posts: 2948 | Location: Michigan, USA | Registered: Fri January 17 2003Reply With QuoteReport This Post
Emeritus
Picture of kyr0xx0r
AIM: Online Status For imsofakingl33t
posted Hide Post
yeah dude im gonna need you to walk me through it if possible.
il try to hop on earlier and catch ya.

_______________
-r0x
 
Posts: 838 | Location: So, Cal | Registered: Thu June 26 2003Reply With QuoteReport This Post
Secretary
Picture of Midknight
posted Hide Post
Look guys this is a very fucked up virus that I am very very angry about.
You will have to manually edit this shit out. The removal tool doesn't work worth shit.
If you want a hand in removing this pest catch me on vent when I am on and I will talk you through.

WinXP and WinME users disable that annoying System Restore Service on your computer before attempting to repair this.

Once repaired please update your version of windows to the current date. There is a patch that corrects the hole in which this Trojan uses. But it must be manual patched before allowing the Microsoft patch to correct its error. DAMN YOU MICROSUCKS/MICROBLOWS


Removal using the Trojan.Qhosts Removal Tool
Symantec Security Response has developed a removal tool to clean the infections of Trojan.Qhosts. This is the easiest way to remove this threat and should be tried first.

Manual Removal
As an alternative to using the removal tool, you can manually remove this threat.

The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.


Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as Trojan.Qhosts.
Reverse the changes that were made to the registry.
Reverse the changes that were made to the Hosts file.

For specific details on each of these steps, read the following instructions.



1. Disabling System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer.

Windows prevents outside programs, including antivirus programs, from modifying System Restore. Therefore, antivirus programs or tools cannot remove threats in the System Restore folder. As a result, System Restore has the potential of restoring an infected file on your computer, even after you have cleaned the infected files from all the other locations.

Also, a virus scan may detect a threat in the System Restore folder even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles:
"How to disable or enable Windows Me System Restore"
"How to turn off or turn on Windows XP System Restore"

--------------------------------------------------------------------------------
Note: When you are completely finished with the removal procedure, and you are satisfied that the threat has been removed, you should reenable System Restore by following the instructions in the aforementioned documents.
--------------------------------------------------------------------------------

For additional information, and an alternative to disabling Windows Me System Restore, see the Microsoft Knowledge Base article, "Antivirus Tools Cannot Clean Infected Files in the _Restore Folder," Article ID: Q263455.

2. Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
Running LiveUpdate, which is the easiest way to obtain virus definitions: These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, refer to the Virus Definitions (LiveUpdate).
Downloading the definitions using the Intelligent Updater: The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, refer to the Virus Definitions (Intelligent Updater).

The Intelligent Updater virus definitions are available: Read "How to update virus definition files using the Intelligent Updater" for detailed instructions.

3. Scanning for and deleting the infected files
Start your Symantec antivirus program and make sure that it is configured to scan all the files.
For Norton AntiVirus consumer products: Read the document, "How to configure Norton AntiVirus to scan all files."
For Symantec AntiVirus Enterprise products: Read the document, "How to verify that a Symantec Corporate antivirus product is set to scan all files."
Run a full system scan.
If any files are detected as infected with Trojan.Qhosts, click Delete.

4. Reversing the changes made to the registry


--------------------------------------------------------------------------------
WARNING: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
--------------------------------------------------------------------------------

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)


Navigate to the key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\MSTCP


In the right pane, delete the values:

"EnableDNS"="1"
"NameServer"=""
"HostName"="host"
"Domain"="mydomain.com"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings


In the right pane, delete the values:

"ProxyEnable"="0"
"MigrateProxy"="0"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


In the right pane, delete the values:

"Use Search Asst"="no"
"Search Page"="http:/ /www.google.com"
"Search Bar"="http:/ /www.google.com/ie"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL


In the right pane, delete the values:

""="http:/ /www.google.com/keyword/%%s"
"provider"="gogl"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search


In the right pane, delete the value:

"SearchAssistant"="http:/ /www.google.com/ie"


Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\Windows

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\Windows


In the right pane, delete the value:

"r0x"="your s0x"

Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters

modify the value:

"DataBasePath"="%SystemRoot%\help"
to:
"DataBasePath"="%SystemRoot%\System32\drivers\etc"


Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces


For each subkey, Restore the value:

"NameServer"=""
NOTE: the default for many configurations is an empty string.

Exit the registry Editor.



5. Reversing the changes made to the Hosts file

All the computers will not have this file, and the location can vary. For example, if the file exists in Windows 98, it will usually be in C:\Windows; and in Windows 2000, it is in the C:\WINNT\SYSTEM32\DRIVERS\ETC folder. Also, there may be multiple copies of this file in different locations.

The most efficient way to locate the file is to search for it.

Follow the instructions for your operating system:
Windows 95/98/Me/NT/2000
Click Start, point to Find or Search, and then click Files or Folders.
Make sure that "Look in" is set to (CSmile and that "Include subfolders" is checked.
In the "Named" or "Search for..." box, type:

hosts


Click Find Now or Search Now.
For each one that you find, right-click it, and then click "Open With."
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
Look for the following lines and delete them, if found:

elite
www.google.akadns.net
www.google.com
google.com
www.altavista.com
altavista.com
search.yahoo.com
uk.search.yahoo.com
ca.search.yahoo.com
jp.search.yahoo.com
au.search.yahoo.com
de.search.yahoo.com
search.yahoo.co.jp
www.lycos.de
www.lycos.ca
www.lycos.jp
www.lycos.co.jp
alltheweb.com
web.ask.com
ask.com
www.ask.com
www.teoma.com
search.aol.com
www.looksmart.com
auto.search.msn.com
search.msn.com
ca.search.msn.com
fr.ca.search.msn.com
search.fr.msn.be
search.fr.msn.ch


Close Notepad and save your changes when prompted.


Windows XP
Click Start, and then click Search.
Click All files and folders.
In the "All or part of the file name" box, type:

hosts


Verify that "Look in" is set to "Local Hard Drives" or to (CSmile.
Click "More advanced options."
Check "Search system folders."
Check "Search subfolders."
Click Search.
Click Find Now or Search Now.
For each one that you find, right-click it, and then click "Open With."
Deselect the "Always use this program to open this program" check box.
Scroll through the list of programs and double-click Notepad.
Look for the following lines and delete them, if found:

elite
www.google.akadns.net
www.google.com
google.com
www.altavista.com
altavista.com
search.yahoo.com
uk.search.yahoo.com
ca.search.yahoo.com
jp.search.yahoo.com
au.search.yahoo.com
de.search.yahoo.com
search.yahoo.co.jp
www.lycos.de
www.lycos.ca
www.lycos.jp
www.lycos.co.jp
alltheweb.com
web.ask.com
ask.com
www.ask.com
www.teoma.com
search.aol.com
www.looksmart.com
auto.search.msn.com
search.msn.com
ca.search.msn.com
fr.ca.search.msn.com
search.fr.msn.be
search.fr.msn.ch


Close Notepad and save your changes when prompted.

Midknight
 
Posts: 1280 | Location: Edmonton | Registered: Sat January 18 2003Reply With QuoteReport This Post
Magistrate
Picture of Manowar
MSN does not support status - click here for the profile.
posted Hide Post
that's the text from the link. it's still not the easiest for people to read through and fix, so r0x might need a walk through.
 
Posts: 2948 | Location: Michigan, USA | Registered: Fri January 17 2003Reply With QuoteReport This Post
Secretary
Picture of Midknight
posted Hide Post
Well here goes nothing. I have dropped it down a couple notches for a better understanding.

Go into My Computer and click on the C: Drive. Now go to the tools button at the top of the window and go to Folder Options. Once in Folder Options go to the View Tab and find the setting to show all hidden folders and files. Click that radio button and then click the button at the top to all changes to all folders and files. Click the ok at the bottom of the window and on your C: Drive there will be a Folder called Bdtmp. Delete that MOFO of a folder. Ok you just deleted the folder and files that start that nasty trojan up. Now carry on with the manual deletion of the Trojan.


First off disable your System Restore Service.

Click Start.
Right-click My Computer, and then click Properties.
Click the System Restore tab.
Select "Turn off System Restore" or "Turn off System Restore on all drives" check box.
Click Ok.

Secondly update your virus definitions off of the corporations website (Symantec (Norton), Mcafee, F-Prot, whatever).

Thridly you must edit your computers registry. I can't stress how important it is to be very careful while doing this. Please double or even triple check the path before altering the entry.

Click Start, and then click Run.
Type regedit

Then click OK.

Ok you will get a window with five folders and my computer as the root to the tree of folders.

Click the plus signs to expand the folder to view its content.

Follow the folder structure to this path:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\MSTCP

Thats the HKEY_LOCAL_MACHINE -->SYSTEM --> CurrentControlSet --> Services -->VxD -->MSTCP

Click the MSTCP folder. On the right side there will be a (Default) REG_SZ (value not set) and a Hostname REG_SZ Administrator

If there are these things in that right pane delete them.

"EnableDNS"="1"
"NameServer"=""
"HostName"="host"
"Domain"="mydomain.com"

By clicking the Name and hitting delete. ONLY DELETE THESE IF THEY ARE IN THERE. If these aren't in the folder continue on by further checking the other folders.

Then go back on the left pane where there is the tree of folders and go back to the way it was with five folders and my computer at the top.

Then do the same thing to these registry keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings


In the right pane, delete the values:

"ProxyEnable"="0"
"MigrateProxy"="0"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main


In the right pane, delete the values:

"Use Search Asst"="no"
"Search Page"="http:/ /www.google.com"
"Search Bar"="http:/ /www.google.com/ie"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL


In the right pane, delete the values:

""="http:/ /www.google.com/keyword/%%s"
"provider"="gogl"


Navigate to the key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search


In the right pane, delete the value:

"SearchAssistant"="http:/ /www.google.com/ie"


Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\Windows

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\Windows


In the right pane, delete the value:

"r0x"="your s0x"

Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters

modify the value:

"DataBasePath"="%SystemRoot%\help"
to:
"DataBasePath"="%SystemRoot%\System32\drivers\etc"


Navigate to the keys:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces


For each subkey, Restore the value:

"NameServer"=""
NOTE: the default for many configurations is an empty string.

Exit the registry Editor.



Click Start. Go to Search. Then select Files and Folders. In the search field type hosts. Make sure the search is looking at the C: Drive and not just one folder. Click Search. the Search will find a few files probably. There will be one if not two or more files called hosts. What you do is right click the file and goto Open With... Then select Notepad to open the file with. Once the file comes up look for this stuff:

elite
www.google.akadns.net
www.google.com
google.com
www.altavista.com
altavista.com
search.yahoo.com
uk.search.yahoo.com
ca.search.yahoo.com
jp.search.yahoo.com
au.search.yahoo.com
de.search.yahoo.com
search.yahoo.co.jp
www.lycos.de
www.lycos.ca
www.lycos.jp
www.lycos.co.jp
alltheweb.com
web.ask.com
ask.com
www.ask.com
www.teoma.com
search.aol.com
www.looksmart.com
auto.search.msn.com
search.msn.com
ca.search.msn.com
fr.ca.search.msn.com
search.fr.msn.be
search.fr.msn.ch

Delete all of this things but make sure not to delete anything else in this file just those. Then close notepad and save changes. Don't rename or give the file any other extensions just save changes.

Then there you go you have just accomplished something that Norton Specialists can't even delete with a program designed to eliminate such threats.


Have any questions grab me on vent or through a quick message in this post. I should be able to get back to you within a days time.

Midknight
 
Posts: 1280 | Location: Edmonton | Registered: Sat January 18 2003Reply With QuoteReport This Post
  Powered by Social Strata  
 

    Low Caliber Forum  Hop To Forum Categories  Red Carpet    Search engine virus?

© Low Caliber Club 2002-4
Gallery | Chat | Archive | Tutorials | Red Carpet

Constitution

Members

Forum

Stats

Wiki