Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
2 users currently in General Chat: Ailure, Dark Vampriel | 1 guest
Acmlm's Board - I2 Archive - General Chat - "hey check out this" AIM virus thing on the loose, be carefull! | |
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
Alastor the Stylish
Hey! I made a cool game! It's called "I poisoned half the food, so if you eat you might die!" Have a taco.


Level: 114

Posts: 6306/7620
EXP: 16258468
For next: 51099

Since: 03-15-04
From: Oregon, US

Since last post: 2 hours
Last activity: 2 hours
Posted on 05-01-05 06:35 AM Link | Quote
Eh. I can't direct connect to DisruptiveIdiot because of it, I can't send files to HyperHacker because of it, same with Kefka... And with plenty of other people. But it works fine with AIM users and users of AIM clones. It's a problem that only comes up when talking to Trillian users.
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 4309/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 05-01-05 07:03 AM Link | Quote
Meep. Anyone for a mass DDoS on that IP?
On an unrelated note, TMCNet has a big ugly ad transition page, not to mention non-working (or just plain no) line breaks, and therefore sucks. (And interesting how it appears they tried to rip off Cnet. ) They even link to the page that supposedly gives you the virus without a warning. (I just get a 403 though. Seeing how I'm using Firefox and know a thing or two about not downloading and running random .COM files, I figured what the hell. )

BTW, Kyouji's right. Trillian's nice in that it protects you from these, but otherwise, it's utter crap. Problem is, the other clients are even crappier. I can't DC to a lot of people unless I'm the one to start the connection, and some people simply cannot send or recieve files to/from me. The real problem, though, is the 325786578659872 window bugs, because they're "too good" for standard windows.
Kefka
Indefinitely Unbanned
Level: 81

Posts: 3026/3392
EXP: 4826208
For next: 166641

Since: 03-15-04
From: Pomona, CALIFORNIA BABY!

Since last post: 4 hours
Last activity: 4 hours
Posted on 05-01-05 10:27 AM Link | Quote
Originally posted by Kyouji Craw
Eh. I can't direct connect to DisruptiveIdiot because of it, I can't send files to HyperHacker because of it, same with Kefka... And with plenty of other people. But it works fine with AIM users and users of AIM clones. It's a problem that only comes up when talking to Trillian users.


Hey, I can connect to YOU when I try. And I can connect to Trillian users. So, basically, Trillian > AIM. Yea.
Kirby PopStar

Bloober
Level: 33

Posts: 387/431
EXP: 218655
For next: 10524

Since: 03-15-04
From: Santa Clarita, CA

Since last post: 27 days
Last activity: 19 days
Posted on 05-01-05 10:57 AM Link | Quote
I got it this morning when NSNick's screen name apparently automaticly IMed me and sent it to me... AOL saved it and opened it automaticly. It's been wreaking havoc on my computer, and I don't know how to get it off! To those who got it and got rid of it, what do I do? It loaded lots of crap into my program files that I can't delete. One of the things automatically comes up when I restart my computer with "Hide PORN on your PC!!!", or something to that extent. It was really embarassing for my dad to use the computer and see that, and then me having to explain what happened. What the heck do I do?
Alastor the Stylish
Hey! I made a cool game! It's called "I poisoned half the food, so if you eat you might die!" Have a taco.


Level: 114

Posts: 6310/7620
EXP: 16258468
For next: 51099

Since: 03-15-04
From: Oregon, US

Since last post: 2 hours
Last activity: 2 hours
Posted on 05-01-05 12:30 PM Link | Quote
Open the comp in safe mode and get rid of every unusual executable file from 4/23/05, PARTICULARLY those from at 9:07 AM. Perhaps, however, it assigns a random date for these files, so also be on the lookout for things that have a really strange date you just know isn't right that are located in C:/WINDOWS/SYSTEM32. Also get rid of the stuff it put on there from the day you got it, though you'll likely have to shut down their processes first (Ctrl+Alt+Del > Processes > select, End Process).

Note that svchost.exe is not a process that you should be able to end your own if you don't have administrative access, and it should not be located in C:/WINDOWS/, it should be in C:/WINDOWS/SYSTEM32 so if you find in the standard Windows folder, get rid of it. Heh. This is what happened to me, I didn't recognize that until I talked to HyperHacker about it which is why it kept coming back - it was disguised as that particular system file.

Note that this assumes you have Windows XP, as I do.

However, unlike you, I managed to get rid of a fair portion of its files before restarting and prevent most of the other ones from popping up again through msconfig, so I'm not really certain if this will solve things for you (though I should hope it does.)


(edited by Kyouji Craw on 04-30-05 07:30 PM)
(edited by Kyouji Craw on 04-30-05 07:32 PM)
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 4317/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 05-02-05 03:55 AM Link | Quote
Yes, you need to nuke \Windows\svchost.exe. The real svchost is in \WIndows\System32. Of course that's just from what Kyouji said... It could very well have random names or something nasty like that.
Alastor the Stylish
Hey! I made a cool game! It's called "I poisoned half the food, so if you eat you might die!" Have a taco.


Level: 114

Posts: 6323/7620
EXP: 16258468
For next: 51099

Since: 03-15-04
From: Oregon, US

Since last post: 2 hours
Last activity: 2 hours
Posted on 05-02-05 01:11 PM Link | Quote
"omg check this out!"

"this" links to http://jon.xavia.org/aim.com. New variant going 'round, I'm afraid.
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - General Chat - "hey check out this" AIM virus thing on the loose, be carefull! | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.011 seconds.