den: (bugger)
[personal profile] den
I let a kid on my system to "look for game cheats." As soon as I left the room he surfed for porn and something (not Gater or Kaza) installed on my system. There were a bunch of icons for porn, adult material, free music etc on my desktop.

But

Something has installed into my registry that kicks off a little thinky in my systray. It calls itself "Music Search Online" but clicking on it takes me to a hard-core porn site. I CAN'T GET RID OF IT!

Every time I boot windows something in the regsitry kicks off and creates a *random_name*.TPM file in the windws/temp dir, and runs THAT. I can't find the reg key! dammit! I really don't want to delete system.dat and user.dat and reload windows again. What a pain in the arse.

Any gurus out there?

actually, I might del the registry. It's badly bloated.

Before you do anything rash

Date: 3 Dec 2002 01:33 (UTC)
From: [identity profile] berin.livejournal.com
Try this: http://www.webattack.com/get/adaware.shtml

This should, if you can get it to install, scan your registry and HD and remove all the offending and offensive programs. I use it at work (well, *used* it at work) periodically to clean up after people who install stuff without asking.

Date: 3 Dec 2002 01:45 (UTC)
From: [identity profile] skipai.livejournal.com
If this has happened with 5 days or 5 reboots you could use scanreg /restore in dos and restore a old registry before this action occurred. I had mine set up for 99 days. Never know you know ;)

That or you could use and download ad-ware which could scan the registry and startup files to see where it's at.

Also, have a look in autoexec.bat, config.sys, win.ini, system.ini and startup list in msconfig. Type that in run command. Then you can go to system configuration.

Take a look in there for any entries that you know for certain shouldn't be in there and un-tick it. Then go into the registry and look for any instances that go to the path on the drive for a particular item, name of start up. You could get rid of the button thing by checking explorer settings. But I ain't in 98 right now so I can't give you the exact path in the registry to check.

Only other solution is to look in your history and see just where he had surfed to and see what would've been installed.

That or format and start again from scratch and don't let him near the computer again to do this.

Re: Before you do anything rash

Date: 3 Dec 2002 02:34 (UTC)
From: [identity profile] dewhitton.livejournal.com
Got it. use it. It's a very nifty proggy. It picked up 16 new files and reg keys and killed all but one of the adwares. It's this last one running in the systray I can't remove

Date: 3 Dec 2002 02:57 (UTC)
From: [identity profile] dewhitton.livejournal.com
Thanks Skip! You gave me a clue that let me track down the offending proggy! Ta mate.

salvation

Date: 3 Dec 2002 07:10 (UTC)
From: [identity profile] penpouring.livejournal.com
there is a great friend of mine named Greg who can fix you up - his email address is killjoy999@hotmail.com and he can fix anything - I've thanked him a few times on my journal - he's a tech from the early days and is gold-seal IBM certified for all the new stuff. I'd call him a hacker too but the word hack cannot be associated with this wizard. I will tell him that you will be emailing.....he will help you - I promise. Mention in your subject line - referred by Connie.

Date: 3 Dec 2002 09:24 (UTC)
From: [identity profile] mactavish.livejournal.com
Is it illegal in NSW to hunt the kid down and have him drawn and quartered?

Date: 3 Dec 2002 10:21 (UTC)
From: [identity profile] lizardling.livejournal.com
Break the kid's fingers. One does *not* go installing anything on someone else's computer without asking.

I hope you can get your computer back.

Re: salvation

Date: 3 Dec 2002 14:12 (UTC)
From: (Anonymous)
Well, thanks Pen, you flatter me, now I feel uncomfortable. I can't fix *everything*. But anyways, this one sounds like a real bugger. I couldn't find any info on it anywhere, and since Ad-aware didn't find it, you might want to try some of the other spy cleaners. It's unlikely unlikely they'll find anything, but sometimes they get stuff that Ad-aware misses. This is a good page to start:

http://www.spyware.co.uk/downloads.shtml

Here's another site, but their database didn't find anything:

http://www.spychecker.com/

Since you've already been tinkering around in the registry, you might want to check (although it sounds like you've already done this) all of the startup keys (including Run, Run- , RunOnce, RunServices, RunServicesOnce). Also get a good process checker, and look up everything you're unsure about. Start killing process one by one, and same with stuff in your start up keys. Even this trial and error might not get it. Like you said, it could be buried somewhere else.

Frustrating, I know.

Since I don't have it, I can't play with it, if you find a copy let me know. Maybe I'll get brave and do some self-experimenting (self-mutilation?), as my system is really clean and I'd recognize anything new right away (maybe). Good luck!

Re: salvation

Date: 3 Dec 2002 14:43 (UTC)
From: [identity profile] dewhitton.livejournal.com
AdAware, Spychecker and OptOut didn't pick up the program, but I found it! In /winapps there was a small exe called emylthro.exe which had a date that matched the day I started having problems. This is how I reckon it worked:

When windows is started emylthro.exe is executed and resides in mem. All it does is set the homepage on IE to a porn site, and create in /windows/temp a .tmp file with a random name like hxvc7391.TMP They were always llllnnn.TMP Emylthro.exe stayed resident in mem but did nothing after it executed the .TMP. This .tmp created an icon in the systray called Music Search Online, but actually linked to a hard-core porn site. I connected once to see where it took me, but hit the LOCK switch on ZoneAlarm as soon as it started asking to upload some more s/ware. I set the firewall to deny the Music Search Online access to all networks. Proxomitron killed all the popups and ads so I don't know how many there were, but I expect the site is popoup central.

anyway. That's the story. Time to run regclean. Again.

Date: 3 Dec 2002 14:54 (UTC)
From: [identity profile] dewhitton.livejournal.com
He's lost access to all the PCs in the house. Now he can't get on the 'net OR play the games I have that he doesn't.

Date: 3 Dec 2002 14:55 (UTC)
From: [identity profile] dewhitton.livejournal.com
I've done worse. Much, much worse.

I told his mum exactly what he was doing: looking for lesbian porn on the internet.

Re: salvation

Date: 3 Dec 2002 15:02 (UTC)
From: [identity profile] dewhitton.livejournal.com
He posted here, and I've replied. I found the pesky little thing last night and KILLED IT GOOD.

by the way...

Date: 3 Dec 2002 15:13 (UTC)
From: [identity profile] dewhitton.livejournal.com
Thanks for the heads-up. Its registry key in in Run. Looks like it was written to stop searches for things running in stealth mode, except I don't do MatchByCase searches. This is the reg entry:

oushfa "C:\WINDOWS\APPLIC~1\emylthro.exe-QuieT"

Unfortunately I killed it all last night so I have nothing to send you.


another useful tip

Date: 1 Jan 2003 07:44 (UTC)
From: (Anonymous)
otcrdnoa.exe is a little program in the application data folder that, sure enough, is the music search online. thought it might help some people because mine wasn't called emylthro... :P

Re: another useful tip

Date: 5 Jan 2003 20:21 (UTC)
From: (Anonymous)
Hey-

This little guy frustrated me for a couple days, but this is what I got on it. I think it randomly assigns itself a label, because for me it was listed as jhieklnq.exe. I found it nested under C:\Documents And Settings\{Your User Name Here}\Application Data. That is for anyone using Windows XP. It seems to have hidden itself from a standard windows search, because I even copied and pasted that title directly, and windows failed to find it. I found it by going through msconfig in the startup tab. The only thing similar to the other ones posted here is that it had "-Quiet" at the end of the title, which I used to confirm its presence. And no, I wasn't looking for any kind of porn. It came from an mp3 album website in which I carelessly let it in thinking it was an unremarkable plug-in... I should have known better. I hope this info helped.

Profile

den: (Default)
den

April 2023

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526 272829
30      

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated 31 December 2025 03:43
Powered by Dreamwidth Studios