yahoo messenger virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by jeo, Nov 22, 2006.

  1. jeo

    jeo Private E-2

    Hi, i accidentally clicked a link on yahoo messenger yesterday that send me to this website thecoolpics.net/ and bitsourceinteractive.com/portal/media/index.php and since then:
    1) other people on my messenger list has been receiving y.m. messages from me with those links, i.e. "the page cannot be displayed thec%6folpics.net/error.jpg Something was wrong !!! Check it again and tell me later. THanks"
    2) my y.m. status has changed to:
    :( the page cannot be displayed thec%6folpics.net/error.jpg Something was wrong !!! Check it again and tell me later. THanks
    screenshot of new windows
    etc. etc.
    3) my homepage changed by itself to
    thecoolpics.net/
    which links to bitsourceinteractive.com/portal/media/index.php
    or the other way around (it's a porn page)
    and upon openning internet tools, i can't change to a different homepage as the option to change homepage is not available.

    This is still happening although i've downloaded and run AVG and Search & Destroy and Ad-Aware

    Additionally, after running Pandaware anti-virus, it cleaned a bunch of viruses but said that it cannot clean hijacker.agent.a, and that my registry is unaccessible by the administrator. I actually don't know if the hijacker.agent.a is responsible for the y.m. mess.

    HELP!!!!

    Thanks
     
    Last edited by a moderator: Nov 22, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    To start the removals process and identify all the hijack malware components its best to run the below, then once all the requested logs are attached and if you still have infection one of our malware experts will be able to post some manual further removal instructions for you,


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. jeo

    jeo Private E-2

    Application.JS.ForcePopup.D virus removal?

    Hi, I ran Bullguard and it removed all viruses except this one:

    Application.JS.ForcePopup.D virus

    How do I remove it and could it be responsible for changing my YM Status and changing my internet homepage to a porn site (and I can't change back)?

    Thanks!

    -Jeo
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi, Please follow the above posted guide from post #2, and once the logs are attached our malware guys can assist you in removing the infection.
     
  5. jeo

    jeo Private E-2

    Hi, am attempting to finish everthing on " READ & RUN ME FIRST Before Asking for Support" but have run into a problem.

    Can't seem to run msconfig to check if it is controlling startups, since (this may probably sound really stupid) I seem to have lost "Run" on my computer.

    I know where it's supposed to be, but I can't find it now!
    I clicked Run, and there is no "run" below Help and support and Search.
    Am I just blind or something? what else can I do?

    -Jeo
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Possible a virus or malware could block you so try this to enter msconfig, goto the location below and msconfig is in their just double click its icon

    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries

    but do continue with the guide steps as if you cannot get to msconfig, we will be able to determine if msconfig is controlling your startups, so attach the logs and our malware guys can get to work on helping you remove the pests.
     
  7. jeo

    jeo Private E-2

    Hi Halo,

    Thanks so much for all your help.

    While waiting for your reply, my husband decided to skip msconfig.

    We had a resident trial version of Bullguard running and it kept blocking the creation of an Object1.exe and Object2.exe which originated from iexplore.exe (supposedly from the worm) when their "bad" website launched as the default home page. Bullguard blocked and documented this repeatedly, So he had the idea that the default bad home page had to be stopped first.

    Since IE6 options page had the set home page option grayed out (option disabled), we decided to use the button under Internet Options>Programs>Reset Web settings built into IE. That reset the default to www.msn.com. It reset the homepage but the set home page option was still disabled.

    Then we booted in Safe Mode with Networking as you suggested. We ran CCleaner, then Spybot S&D. Spybot fixed the bad registries that mutated Windows explorer, Internet Explorer and Windows.

    Then we ran Bullguard again and it cleaned out the xxxx.exe programs the worm creates using our files (with xxxx as the basename). Then we disabled System Restore and rebooted.

    We ran bullguard again, and it found another set of xxxx.exe files again plus a bad system restore file which was infected with the worm.

    After bullguard and spybot cleaned those out, we rebooted and things seem to have returned to normal. I got my "Run" back, and can log on to yahoo messenger again, and bullguard wasn't blocking multitudeds of .exe files. We are also now able to reset out homepage (not disabled anymore).

    So far so good, a second scan with bullguard after a reboot found nothing. :)

    We're running bullguard and spybot again overnight, just to check again. We're asking friends to report if they received spam from us with exe attachments and ask them not to open any exe attachments from us.

    I didn't find any logs from spybot, and the logs that are still recorded in Bullguard only recorded the logs from the last 4 scans we ran which were all clean. I'll attach the logs from bullguard and spybot and cclean as soon as I find it.

    Again, thanks so much for all the help!

    -jeo

    P.S. Bullguard and Spybot wasn't able to restore the Set Home Page option. My husband downloaded a VBscript from Doug Knox www.dougknox.com that restores this back to the original state.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds