Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Monkey+Football
 
Icemaster's Avatar
 
Join Date: Apr 2003
Location: It aint a popularity contest
Posts: 4,785
Garage
Send a message via AIM to Icemaster
Did you run a hijackthis scan and dump the log before starting the cleaning? I'm kind of curious what shows up.

__________________
<Insert witty comment>

85 Targa Wong Chip Fabspeed M&K Bilsteins and a bunch of other stuff.
Old 08-20-2008, 05:15 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #21 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:
Originally Posted by Icemaster View Post
Did you run a hijackthis scan and dump the log before starting the cleaning? I'm kind of curious what shows up.
No, as that is not an authorized Mule tool. He fights me every time with his ccleaner, so since I got hit with the same thing as AZ_porschekid, I decided to follow Mules advice. And a waste of time it was, although if I was billing a client, I'd have made a killing.

I tired to reinfect my computer and run the appropriate Vundo/Winfixer script, but I could not. I was going to run the script.. If AZ_porschekid wants to forward the link he received, I'd be happy to reinfect my computer.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 05:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #22 (permalink)
Registered
 
syncroid's Avatar
 
Join Date: Jul 2005
Location: San Jose
Posts: 4,622
Dumb question....did I miss something here? I thought the original poster was the one with the virus problem. (AZ_porschekid) Slodave, how did it get on "your" computer?
__________________
Dan
2002 996 C4 Cab w/ Jake Raby 4.0
2024 Tacoma TRD Offroad 4x4
2003 Range Rover HSE
Old 08-20-2008, 05:27 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #23 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:
Originally Posted by syncroid View Post
Dumb question....did I miss something here? I thought the original poster was the one with the virus problem. (AZ_porschekid) Slodave, how did it get on "your" computer?
It's viral!!!

I'm not sure. I went to a website earlier and things started to pop up. I went back after cleaning (with both FF and IE7) and could not reinfect my laptop. Since it was the same thing, I decided to play...
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 05:31 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #24 (permalink)
Registered
 
syncroid's Avatar
 
Join Date: Jul 2005
Location: San Jose
Posts: 4,622
Very strange! Good luck and let us know how you get rid of it.
__________________
Dan
2002 996 C4 Cab w/ Jake Raby 4.0
2024 Tacoma TRD Offroad 4x4
2003 Range Rover HSE
Old 08-20-2008, 05:33 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #25 (permalink)
RETIRED
 
Joe Bob's Avatar
 
Join Date: Jul 1999
Location: BOULDER Colorado
Posts: 39,412
Garage
I learned a lot when mine had a directory error. Best to remove the HD, hook it up as a slave to another, move your files and do an O/S reinstall.

A914guy@aol.com is Rich Johnson in Texas. Someone is spoofing his address.
__________________
1983/3.6, backdate to long hood
2012 ML350 3.0 Turbo Diesel
Old 08-20-2008, 05:39 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #26 (permalink)
 
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:
Originally Posted by syncroid View Post
Very strange! Good luck and let us know how you get rid of it.
I already did... If you choose Mule's way, It'll take an hour or so and if you run ccleaner, it will do nothing except delete your history in FF and annoy you. The other program will clean Winfixer, but take an hour.

A faster way, is to follow the link I posted last night and run the VirtumundoBeGone program.

Remember, this is what I do for a living.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 05:41 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #27 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Here is the malwarebytes log:

Malwarebytes' Anti-Malware 1.25
Database version: 1062
Windows 5.1.2600 Service Pack 3

5:02:19 PM 8/20/2008
mbam-log-08-20-2008 (17-02-16).txt

Scan type: Full Scan (C:\|)
Objects scanned: 123225
Time elapsed: 42 minute(s), 45 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 23

Memory Processes Infected:
C:\WINDOWS\system32\lphcpd2j0e597.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

Memory Modules Infected:
C:\WINDOWS\system32\blphcpd2j0e597.scr (Trojan.FakeAlert) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\svchost.exe (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\lphcpd2j0e597 (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssl.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt15.tmp (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt6.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt7.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt8.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.tt9.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.ttA.tmp (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\Temp\.ttE.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\blphcpd2j0e597.scr (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\lphcpd2j0e597.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\phcpd2j0e597.bmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\help.txt (Stolen.Data) -> No action taken.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 05:46 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #28 (permalink)
Unfair and Unbalanced
 
Mule's Avatar
 
Join Date: Jul 2004
Location: From the misty mountains to the bayou country
Posts: 9,711
Quote:
Originally Posted by slodave View Post
Alright Mule, since I just got nailed with Winfixer - thanks those stupid political posts. I'll download ccleaner and give it a go...



EDIT: Norton Corporate came up and isolated a file. Hopefully it has not fixed the problem.
What the hell is that?
__________________
"SARAH'S INSIDE Obama's head!!!! He doesn't know whether to defacate or wind his watch!!!!" ~ Dennis Miller!
Old 08-20-2008, 06:26 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #29 (permalink)
Unfair and Unbalanced
 
Mule's Avatar
 
Join Date: Jul 2004
Location: From the misty mountains to the bayou country
Posts: 9,711
Quote:
Originally Posted by slodave View Post
The little bugger even disables Windows firewall...


You can see one of the randomly named files running under TM.


Malwarebytes did find winfixer... Took only 45 minutes though


Malwarebytes did get rid of Winfixer, but not 100%. I still have to get rid of a blank icon in my system tray. Now, had I run the Vundo fix I had posted last night, I would have been up and running with in minutes, not 45 minutes. Ccleaner still sucks and does nothing.

BTW, I started this at 3:30 and ended at about 5:10.
So if I understand you CORRECTLY, anybody capable of doing a simple download and install can fix the problem WITHOUT the ridiculous complexity of running hijack this and posting the results, then waiting for some propellerhead to interpret them and devise some mystical fix. Would that be correct? If he ran Malwarebytes & Ccleaner last night he would have been done in how long did you say?

PS: Norton is for folks that don't know any better.
__________________
"SARAH'S INSIDE Obama's head!!!! He doesn't know whether to defacate or wind his watch!!!!" ~ Dennis Miller!
Old 08-20-2008, 06:34 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #30 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
And had he run VirtumundoBeGone, he would have been done in less than 10 minutes and his computer would not be screwed up from ccleaner. Again, you don't do this for a living, you spout the same lame program.

I'll say it again and again and again, ccleaner DOES NOT DO ANYTHING! In fact, it will cause more problems.

Norton corporate is a in a different category from the rest of Norton end user programs, but you would not know that. STFU!
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 06:55 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #31 (permalink)
....
 
Arizona_928's Avatar
 
Join Date: Feb 2008
Posts: 18,664
mike it's "A911GUY"

it seems to be trying to copy microsoft, by saying Windows anti virus, even going as far as adding a fake copy of the windows firewall icon... have to say it's pretty well made, doesn't look like anything you have on yours. infact very different. almost like a ligit windows update... but way different..

i'm kinda hesitant to do a system restore, because i updated it when i first got the computer. but i'll try some anti virus stuff posted, then go from their...

thanks for the replys!
__________________
dolor et pavor

Copyright
Old 08-20-2008, 06:57 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #32 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Quote:
Originally Posted by Mule View Post
What the hell is that?
One more thing, if you actually work on computers, you would have seen this before.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 06:57 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #33 (permalink)
Unfair and Unbalanced
 
Mule's Avatar
 
Join Date: Jul 2004
Location: From the misty mountains to the bayou country
Posts: 9,711
Quote:
Originally Posted by slodave View Post
And had he run VirtumundoBeGone, he would have been done in less than 10 minutes and his computer would not be screwed up from ccleaner. Again, you don't do this for a living, you spout the same lame program.

I'll say it again and again and again, ccleaner DOES NOT DO ANYTHING! In fact, it will cause more problems.

Norton corporate is a in a different category from the rest of Norton end user programs, but you would not know that. STFU!
Getting a little tense there huh Bevis? Norton is STILL for fools. Did you have it off when you got your INFECTION?
__________________
"SARAH'S INSIDE Obama's head!!!! He doesn't know whether to defacate or wind his watch!!!!" ~ Dennis Miller!
Old 08-20-2008, 07:40 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #34 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
I don't like Norton nor do I recommend the products, other than corporate for corporate environments. No AV program is 100% and I've seen them all infected at one time or another. For me, Panda's free online scanner has been the best. When all other programs fail, it usually will get rid of the issue.

I use corporate because it's free and never will expire.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 08-20-2008, 08:08 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #35 (permalink)
Unfair and Unbalanced
 
Mule's Avatar
 
Join Date: Jul 2004
Location: From the misty mountains to the bayou country
Posts: 9,711
And it still sucks in comparison to numerous FREE products. But you go Bevis.
__________________
"SARAH'S INSIDE Obama's head!!!! He doesn't know whether to defacate or wind his watch!!!!" ~ Dennis Miller!
Old 08-21-2008, 06:27 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #36 (permalink)
Registered
 
Join Date: May 2001
Location: Madison, WI
Posts: 282
Garage
I really can't believe you all missed it..

I'd say the source of the original problem came from the subject of this thread.

Pelican Porn????
__________________
84 944
Old 08-21-2008, 06:58 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #37 (permalink)
Custom User Title
 
rammstein's Avatar
 
Join Date: Oct 2002
Location: Miami
Posts: 4,294
Slodave helped me with a similar problem a few months back, and sent me some cool diagnositc stuff free. He knows his stuff.
Old 08-21-2008, 09:00 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #38 (permalink)
Monkey+Football
 
Icemaster's Avatar
 
Join Date: Apr 2003
Location: It aint a popularity contest
Posts: 4,785
Garage
Send a message via AIM to Icemaster
Quote:
Originally Posted by Mule View Post
So if I understand you CORRECTLY, anybody capable of doing a simple download and install can fix the problem WITHOUT the ridiculous complexity of running hijack this and posting the results, then waiting for some propellerhead to interpret them and devise some mystical fix. Would that be correct? If he ran Malwarebytes & Ccleaner last night he would have been done in how long did you say?

PS: Norton is for folks that don't know any better.
Sounding intimidated there donkeyboy.

Come back when you know what youre talking about ya noob.
__________________
<Insert witty comment>

85 Targa Wong Chip Fabspeed M&K Bilsteins and a bunch of other stuff.
Old 08-21-2008, 03:51 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #39 (permalink)
Unfair and Unbalanced
 
Mule's Avatar
 
Join Date: Jul 2004
Location: From the misty mountains to the bayou country
Posts: 9,711
Quote:
Originally Posted by Icemaster View Post
Sounding intimidated there donkeyboy.

Come back when you know what youre talking about ya noob.
Let me guess, your solution is encoded in that message?

__________________
"SARAH'S INSIDE Obama's head!!!! He doesn't know whether to defacate or wind his watch!!!!" ~ Dennis Miller!
Old 08-21-2008, 05:03 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #40 (permalink)
Reply


 


All times are GMT -8. The time now is 08:03 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.