Tom's Hardware > Forum > Old Man/Woman's Club > Other > You dumbass coders

You dumbass coders

Forum Old Man/Woman's Club : Other - You dumbass coders

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Well today I figured I’d share my method of removing “internetservice payload” caused by bzlob-e virus using virusheat Bullcarp. These coders are scum bags, ‘ because gomerpile says so’.
You need to use a winstock injection tool to view all files and services running in winstock (very risky task if the wrong file is deleted), hijack this 2.2 works well for this.
Remove anything that refers to files or registry entries you believe should not be running, if your experienced with xp files and dlls you’ll know what too look for.
The files you’d look for is internetservice, and a few other odd balls. I found the bzlob virus initially by using macAfee online virus scanner and Microsoft malicious removal tool (Microsoft tool did remove the bzlob-e virus) however I still had the payload of that virus to deal with and found internetservice process was not something I’d ever use or install on a childs computer. Also this internetservice did not show up in taskmanager process, internetservice did show up in sysinternals. I manually deleted the registry entry, and upon reboot this was in the registry again, if you try to remove the file windows will not allow you to delete it, even in safe mode ( it is hidden well, searching is useless when in safe mode).
I’d like to give my piss ass siht to the writers of your reversible BS. My daughter did not enjoy the porn site your sorry ass payload took her to.

------------------------------ WAITING FOR THE NEXT MOMENT TO STRIKE

 

Sponsored Links
Register or log in to remove.

Have you tried changing the "internetservice" service in "administrative tools" - "services" to disabled?
Then restart the computer.
See if you can remove the file the service links to.
Restart computer.
Remove registry entry.
Restart computer.
Then see if the service, file and registry entry have been removed.

I don't know if it will work, but that's what I would try.

------------------------------ Doctor Hooter
Boobs Boobs Boobs...who loves boobs?...I do I do

 

Reply to zpyrd

FIFSO
F*ck It Format Start Over

------------------------------ Now Featuring:
+10 GIMP Bonus|+5 Disturbing Pics Bonus|+5 Open source adulteration.|-3 basic fixed gag | +13 aimed at Jef |
+5 Null Points(+5 too much time -5 work too much = +5 Null) |...*** GIMPAGE!! ***...

Reply to lvdax

shes good to go now. lvdax I was able to use hijack to remove the codes and files.zpyrd I did not try that and if she is attacted again I will but hijack injection was able to remove the lines of code running in winstock service.


Message edited by gomerpile on 05-11-2008 at 10:48:16 AM
------------------------------ WAITING FOR THE NEXT MOMENT TO STRIKE

 

Reply to gomerpile

lvdax wrote :

FIFSO
F*ck It Format Start Over



+5 Best practice.

The only true way to ensure a system is sound once you have detected an infection.

Reply to audiovoodoo

I'd do that audivoodoo, except I use her drive to store info about 120 gig of stuff. I've run wireshark now for 24 hours recording, no IPs in or out so things are looking good. Today i'm getten a drive and it will be a fresh install

------------------------------ WAITING FOR THE NEXT MOMENT TO STRIKE

 

Reply to gomerpile

Tom's Hardware > Forum > Old Man/Woman's Club > Other > You dumbass coders
Go to:

There are 1175 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them