Well today I figured I’d share my method of removing “internetservice payload” caused by bzlob-e virus using virusheat Bullcarp. These coders are scum bags, ‘ because gomerpile says so’.
You need to use a winstock injection tool to view all files and services running in winstock (very risky task if the wrong file is deleted), hijack this 2.2 works well for this.
Remove anything that refers to files or registry entries you believe should not be running, if your experienced with xp files and dlls you’ll know what too look for.
The files you’d look for is internetservice, and a few other odd balls. I found the bzlob virus initially by using macAfee online virus scanner and Microsoft malicious removal tool (Microsoft tool did remove the bzlob-e virus) however I still had the payload of that virus to deal with and found internetservice process was not something I’d ever use or install on a childs computer. Also this internetservice did not show up in taskmanager process, internetservice did show up in sysinternals. I manually deleted the registry entry, and upon reboot this was in the registry again, if you try to remove the file windows will not allow you to delete it, even in safe mode ( it is hidden well, searching is useless when in safe mode).
I’d like to give my piss ass siht to the writers of your reversible BS. My daughter did not enjoy the porn site your sorry ass payload took her to.
------------------------------WAITING FOR THE NEXT MOMENT TO STRIKE
Have you tried changing the "internetservice" service in "administrative tools" - "services" to disabled?
Then restart the computer.
See if you can remove the file the service links to.
Restart computer.
Remove registry entry.
Restart computer.
Then see if the service, file and registry entry have been removed.
I don't know if it will work, but that's what I would try.
------------------------------Doctor Hooter
Boobs Boobs Boobs...who loves boobs?...I do I do
Reply to zpyrd
------------------------------Now Featuring:
+10 GIMP Bonus|+5 Disturbing Pics Bonus|+5 Open source adulteration.|-3 basic fixed gag | +13 aimed at Jef |
+5 Null Points(+5 too much time -5 work too much = +5 Null) |...*** GIMPAGE!! ***...
shes good to go now. lvdax I was able to use hijack to remove the codes and files.zpyrd I did not try that and if she is attacted again I will but hijack injection was able to remove the lines of code running in winstock service.
Message edited by gomerpile on 05-11-2008 at 10:48:16 AM
------------------------------WAITING FOR THE NEXT MOMENT TO STRIKE
Reply to gomerpile
I'd do that audivoodoo, except I use her drive to store info about 120 gig of stuff. I've run wireshark now for 24 hours recording, no IPs in or out so things are looking good. Today i'm getten a drive and it will be a fresh install
------------------------------WAITING FOR THE NEXT MOMENT TO STRIKE
Reply to gomerpile
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.