About sick of about

Discussion in 'Technology' started by ucicare, Dec 1, 2005.

  1. ucicare

    ucicare Active Member

    Messages:
    5,606
    Help please.

    I have aquired an About web hijacker.

    I downloaded Aboutbuster, which has worked well in the past. Somehow this one is disabling the Aboutbuster and will not let it run.

    I rebooted in safe mode, and ran About Buster from a floppy. It worked that way, and found the infection.

    The problem is the infect came right back. It appears that the file is hidden somewhere and recreates itself.

    This SUCKS.

    Suggestions short of reformat c:?


    Barry
     
  2. ucicare

    ucicare Active Member

    Messages:
    5,606
    Hummmm...


    Spy Ferret and Spy Sweeper can't find it.

    It only pops up when I open Fugly.com

    It only opens ever third time I open Fugly.com.

    I tried about 100 other website, no problem.


    Hummm......


    Barry
     
  3. ucicare

    ucicare Active Member

    Messages:
    5,606
    I refresh the page at fugly.com three times = about:blank

    No other site is effected

    HARLAN?

    DWAINE?

    JEFF?

    Is anybody home?????

    Barry
     
  4. Dwaine Scum

    Dwaine Scum New Member

    Messages:
    11,130
    have you tried your anti-virsu AVG insafe mode?
     
  5. pimpchichi

    pimpchichi Active Member

    Messages:
    7,211
    i found that the most effective way of combating the multitude of intrusive shit that sneaks onto my pc whilst browsing fugly was to stop browsing fugly
     
  6. ucicare

    ucicare Active Member

    Messages:
    5,606

    Word.

    But I am like a crack whore to this non sense.

    I need rehab.

    Barry
     
  7. lucyharper

    lucyharper Guest

  8. pimpchichi

    pimpchichi Active Member

    Messages:
    7,211
    use opera fatjack
     
  9. ucicare

    ucicare Active Member

    Messages:
    5,606
    I feel so violated.

    Does anyone know of a good therapist?


    Barry
     
  10. lucyharper

    lucyharper Guest

    Go here :arrow: Rebecca of Sunnybrook Farm
     
  11. Joeslogic

    Joeslogic Active Member

    Messages:
    8,426
    Barry, I use HijackThis all the time myself as well as in my job.

    If the nasty little sucker is affecting only fugly.com then why dont you search your registry for any reference to fugly? Also ping fugly to get the ip address and search for any reference to the ip.

    Thinking... :?

    Oh here is where to get HiJackThis http://www.tomcoyote.org/hjt/

    Also whats in your host file have you looked?

    What is your os?

    Gimme a screen shot of all the processes listed in task list
    Gimme a text file of hijackthis results
    and gimme a list of all your non microsoft services (msconfig from run menu) as well as everything on your startup. (Same utility)

    I'll see what I can find.

    If you do not understand send me a message. I clean up systems all the time in my job.
     
  12. ucicare

    ucicare Active Member

    Messages:
    5,606
    Fugly is hot on the trail Joe.....

    I do not think the bug is on my machine. It appears to be the web link produced by the search engine.

    Barry
     
  13. TheGrimJesus

    TheGrimJesus New Member

    Messages:
    3,893
    Barry Hit Control Alt Delete, Then sort by user. Then I want you to close everything except exploer.exe and Taskmgr.exe.

    after doing this the web highjacker will start it exe as soon as you close it as a different name. Post that name here and I will tell you how to kill it.
     
  14. ucicare

    ucicare Active Member

    Messages:
    5,606
    It is not produciing anything. No exe file is running. It only opens with a certain weblink.

    I think Fugly got it fixed. It is not happening now.

    Barry
     
  15. TheGrimJesus

    TheGrimJesus New Member

    Messages:
    3,893
    Hummm strange, Most highjackers have an exe.
     
  16. ucicare

    ucicare Active Member

    Messages:
    5,606
    Yes, very strange. I talked to Fugly by phone about it. He was pretty upset.

    He said that others were having the same problem, and he was pretty pissed at somebody. Obviously he got it fixed.

    Good job J.

    Barry
     
  17. Joeslogic

    Joeslogic Active Member

    Messages:
    8,426
    Well so long as its fixed. Good way to smoke out one of those random generated type of .exe though Grim I'll save that away for later.
     
  18. TheGrimJesus

    TheGrimJesus New Member

    Messages:
    3,893
    Well after you sniff it out, Search for it thru the start menu, It will make a copy of itself in the root folder. Then you have the name of the program.

    Then just go into regedit an remove anything with that folder and exe name.
     
  19. Joeslogic

    Joeslogic Active Member

    Messages:
    8,426
    Right but be careful with the ones that spoof a similar legitimate windows file name.

    Really though it never dawned on me to force a random file name .exe to stop so that when it regenerates to annotate the new name.
     

Share This Page