Closed Thread
Results 1 to 12 of 12

Thread: MmMm - Help. Spyware/adware.

  1. #1
    b& Darknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant future
    Join Date
    Nov 2006
    Location
    The Best Country
    Posts
    4,086

    MmMm - Help. Spyware/adware.

    all started with "a.exe"
    Spybot.info dont trace much of it and I went to download adaware only to find that its also found a way to null all adaware software sites to 127.0.0.1?
    Anyone had this before? all adware/av progs cant update either.

  2. #2
    FWS Addict david432111 is just really nicedavid432111 is just really nicedavid432111 is just really nice
    Join Date
    Jul 2007
    Location
    Denmark
    Posts
    594
    Run an online scan. Google it.
    Don't really have anything to post here...

  3. #3
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    Rename your hosts file and renew your network config and try one of the online scanners.

    Or try downloading this one (the only difference with free and paid is automatic montoring, the free one is a great on demand scanner - run the update first then the quick scan)- http://www.malwarebytes.org/mbam.php
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

  4. #4
    Senior Member SC-Jon has disabled reputation SC-Jon's Avatar
    Join Date
    Feb 2005
    Location
    /dev/null
    Posts
    162
    Wow, I had that recently too.

    It's suppose to be an email virus, but I'm nto sure. A day later my registry hives were gone, and windows couldn't repair it. MBR was gone too, along with systemroot\windows\system32\config \software \SAM \system

    was all gone.

    a.exe is registered as the W32.Ahlem.A@mm worm which is transmitted via e-mail and attempts to install itself on your computer.
    Jonathan | Server Complete, LLC || VPS | Hybrid | Dedicated | Backup ||
    Virtualized to Perfection in multiple United States datacenters!
    55 Marietta (Atlanta, GA) || Latisys (Chicago, IL) || DataBank (Dallas, TX) || SVTIX (San Jose, CA)

  5. #5
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    Comes in as a load of things at the mo, there's a few new mutexes doing the rounds.

    Just don't bottle it It's not too bad and easy enough to get rid of as long as you don't ignore it too long. Owning the hosts file is a ----- that throws a lot of folk though.
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

  6. #6
    b& Darknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant future
    Join Date
    Nov 2006
    Location
    The Best Country
    Posts
    4,086
    I am most pissed off about the time its going to take.
    There is no entries in the host file that shouldnt be there.
    Since they block adaware im guessing it must do something so ima download it through a vps.
    Quote Originally Posted by david432111 View Post
    Run an online scan. Google it.
    if you knew this virus/worm you would have understood using google is almost impossible with it.

    EDIT:
    Adaware worked slightly, trying deckers now.
    Last edited by Darknight; August 22nd, 2008 at 22:42.

  7. #7
    b& Darknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant future
    Join Date
    Nov 2006
    Location
    The Best Country
    Posts
    4,086
    k, 2 more gone with avast a rootkit named sysrest.sys
    and a "other" win32ther lol.

    Now my only issue is the DNS thats been fuxerd and the google searchs that turns ever search result in to a ad when you click....

  8. #8
    Super Moderator hamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to all hamster's Avatar
    Join Date
    Jul 2007
    Location
    Singapore
    Posts
    2,634
    Since we're talking about spyware/adware, there's been this stupid portable thingy going around infecting each and every drive in the computer if you're infected. This thingy causes your drive to be un-openable by double clicking but you can right-click and open it from my computer though. Other file explorers still work.

    I dunno, but my entire school network has this thingy and they're all frantic over it. No one dares to plug in their thumbdrives into the school comps lol.

    Has anyone seen or head of this kinda thing before? There's no information on what it does so far.

  9. #9
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    Been looking at this one and I recon it's a varient of the recent Vundo strains, USB keys write disabled should be okay but anything else is dodgy.

    Grab a pack and burn it to CD/DVD on a non infected and hit the infected ones, although I had it on one system and Malwarebytes did the trick, just don't do any manual editting/deleting first, but use the log after scanning.
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

  10. #10
    Super Moderator hamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to allhamster is a name known to all hamster's Avatar
    Join Date
    Jul 2007
    Location
    Singapore
    Posts
    2,634
    It spreads like wildfire... one USB device plugs in, gets the thing, plugs into another PC, infects that PC and the cycle just keeps repeating with more and more people with more and more USB devices!

  11. #11
    b& Darknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant futureDarknight has a brilliant future
    Join Date
    Nov 2006
    Location
    The Best Country
    Posts
    4,086
    w00t, thanks for that link decker, it was by far the best program I tried.
    It removed other sections of the rootkit AVAST missed as well as fixed the DNS poising issue.
    It also found many other things that adaware 2008, spybot and avast missed.
    Thanks again.
    Decker > a.exe

  12. #12
    #anonymous Decker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond reputeDecker has a reputation beyond repute Decker's Avatar
    Join Date
    Dec 2003
    Location
    West Yorkshire, Englandshire
    Posts
    10,145
    glad it helped out, Malware is the best one I've found for ages, and it's quick, and best of all free
    /\__/\ We Do Not Forgive!
    (- o *) We Do Not Forget!
    (")_(") Expect Us!
    IT Help for everyone @ Scotia-IT.com - when it's finished

Closed Thread

Similar Threads

  1. A site on Adware/Spyware FAQ!
    By ExoWorks in forum Review my webdesign
    Replies: 4
    Last Post: March 6th, 2005, 09:57
  2. finding adware/spyware
    By jason in forum General Discussions
    Replies: 3
    Last Post: July 1st, 2002, 13:55
  3. Mmmm Noodles...
    By Haze in forum General Discussions
    Replies: 3
    Last Post: June 17th, 2002, 11:16
  4. Mmmm, music
    By roblev in forum General Discussions
    Replies: 21
    Last Post: February 11th, 2002, 22:48
  5. Mmmm
    By roblev in forum Test things out
    Replies: 30
    Last Post: September 19th, 2001, 18:29

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts