»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 02-15-2004, 06:47 PM   #1 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lincoln, Nebraska
Posts: 1,444
narayan is on a distinguished road
Outdoors virus trouble

I was fortunate enough to get this suck virus that turns my PC into a porn server. xxxload.exe and save.exe are my culprits and I cannot find these anywhere to fix them. Symantec's site is no help. ZA has given me a path to these files, but they are not where ZA says. The only symptom I had of these is very slow surfing. Don't feel like formatting. Has anyone heard of this?

narayan is offline   Reply With Quote
Old 02-15-2004, 06:52 PM   #2 (permalink)
Registered User
 
Join Date: Dec 2003
Posts: 1,045
HeadBand is on a distinguished road
get adaware and spybot and run them also you might try the online virus scan at www.antivirus.com and also avg
HeadBand is offline   Reply With Quote
Old 02-15-2004, 06:55 PM   #3 (permalink)
Registered User
 
jannybean2002's Avatar
 
Join Date: Feb 2003
Location: Bolton. UK
Posts: 149
jannybean2002 is on a distinguished road
Send a message via Yahoo to jannybean2002
you could try www.trendmicro.com
run the house call virus scan..........its free
__________________
janny
jannybean2002 is offline   Reply With Quote
Old 02-15-2004, 08:00 PM   #4 (permalink)
Registered User
 
Dax_Brandy's Avatar
 
Join Date: Oct 2001
Location: Manila, Phil
Posts: 1,258
Dax_Brandy is on a distinguished road
Send a message via Yahoo to Dax_Brandy
Adaware 6 could be helpful. http://www.lavasoftusa.com/
Dax_Brandy is offline   Reply With Quote
Old 02-16-2004, 01:23 AM   #5 (permalink)
Junior Member
 
Join Date: Jan 2004
Posts: 0
whitebeard21 is on a distinguished road
http://www.computing.net/security/ww...orum/9672.html

You have one of the most insidious worms to hit the net. Some versions self install when you delete a popunder.
I am Posting the info because of the extreme slowdown this causes to your pc, If you are here why wait 10 minutes for another page to load.

drop down to solution # 4

Name: The Helper
Date: February 14, 2004 at 10:44:15 Pacific
Homepage: HIJACKTHIS! DOWNLOAD
Subject: HEEELP!! Hijacked by MagicSearch.ws

Reply:
Ok, I picked up this hijacker today.
To remove it, you need to download a free software application HijackThis! from Download.com (Click my homepage link, it should take you to the download page for it on download.com and bypass the trojan).

When you have this software and you have run it click the scan button at the bottom of the window. The listbox should then fill up with crap. Tick everything and click the Fix Checked button. When it is done, wait 20 seconds and click scan again. The listbox will fill up again with stuff all with the .magicsearch.ws URL in it. This time, press CTRL and ALT and DELETE (or DEL) at the same time and go to the processes tab in Windows XP. Look for a file in that list called directx.exe or some executable file that isn't meant to be there running from you're user account. Click it and click end task. You have closed the secret file that is putting the entries back into the listbox. Go back to HijackThis! and check all of the lines and click Fix Checked again. Wait 20 seconds and click Scan. There, all gone!

Now to make sure that our little twat friend that puts the entries back dosn't come back. Click start, My Computer. Double Click you're main hard drive and go to Program Files and in there go into a folder named Common Files. In the Common Files directory, there should be a folder called Services. Delete that. If you recieve an access denied error, look at the filename in the error box and press CTRL + ALT + DEL again and close it's a**(edit).

When that Services folder is deleted and when you press scan in HijackThis! and nothing appears, CONGRATULATIONS! YOU HAVE KICKED THE PIECE OF CRAP MAGICSEARCH.WS IS OFF YOUR SYSTEM!

Last edited by whitebeard21; 02-16-2004 at 01:38 AM.
whitebeard21 is offline   Reply With Quote
Old 02-19-2004, 04:03 PM   #6 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lincoln, Nebraska
Posts: 1,444
narayan is on a distinguished road
Thanks for the replys. AdAware didn't work, HijackThis didn't work. Spybot didn't work. Will try Trendmicro.com tonight. I;'m beginning to lose my patients with this. I am able to type about 10 words before they even appear in the box. Neat.

Thanks again, I'll let you know.
narayan is offline   Reply With Quote
Old 02-23-2004, 05:27 AM   #7 (permalink)
Junior Member
 
Join Date: Jan 2004
Posts: 0
whitebeard21 is on a distinguished road
Naryan this is what you have, the site with the removal tools is under a constant dos attack but this link will give you the latest links to a removal tool.

I'm not Mike, but I copied this brief description from Merijn's page and thought it might help you:
"The latest and greatest nuisance on the Internet, the browser hijacker that won't stop, the trojan from hell... name it what you want, but fact is that a company naming itself 'Coolwebsearch' (CWS) is producing a quickly growing strain of trojans that exploit a hole in the Microsoft Java VM, and change your homepage.

And by changing your homepage, I mean lodge itself onto your system in almost two dozen different ways, change your start page, search page, search assistant, redirecting you to porn sites from other porn sites or even search engines, popping up porn ads and sometimes even carrying a payload."

http://www.lurkhere.com/forum600.html then scroll >spies>CoolWebShredder - Latest Update Pages 1 | 2
Please Post the Most Recent CoolWebShredder Update Here
whitebeard21 is offline   Reply With Quote
Old 02-24-2004, 09:38 AM   #8 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lincoln, Nebraska
Posts: 1,444
narayan is on a distinguished road
FINALLY!! I think it's gone. at least for now. Whitebeard, I didn't get a chance to try your link before a friend told me about PestPatrol. THink I'm gonna go there now just to see what I can find out. Thanks to all. I learned a little today.
narayan is offline   Reply With Quote
Old 02-24-2004, 11:32 PM   #9 (permalink)
Junior Member
 
Join Date: Jan 2004
Posts: 0
whitebeard21 is on a distinguished road
I got that thing when my granddaughter was dl some music. It drove me nuts for a week. It seems to be a Russian site bouncing between Samoa, Singapore, Macao and who knows where else.
whitebeard21 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 05:56 PM.