virus in my posts. help!!!

Discussion in 'General Chat' started by money_train, Jun 11, 2007.

  1. #1
    free mn_fuzkafree mn_fuzkathere is some virus in my posts.
    they are accompanied with
    soemthing like this. please help !! xx mn_fuzka xx xx mn_fuzka xx
     
    money_train, Jun 11, 2007 IP
  2. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #2
    free mn_fuzkanow this is what i mean.


    free mn_fuzkafree mn_fuzkat and this

    xx mn_fuzka xx xx mn_fuzka xx
    i am not sure how this is happening and how to recitify this.


    xx mn_fuzka xx
     
    money_train, Jun 11, 2007 IP
  3. karl turnbull

    karl turnbull Peon

    Messages:
    3,512
    Likes Received:
    482
    Best Answers:
    0
    Trophy Points:
    0
    #3
    lol tyhats a strange one m8 , not sure whats going on there my friend , until a mod comes the best thing for you to do is
    free mn_fuzkanow :D
     
    karl turnbull, Jun 12, 2007 IP
  4. ReadyToGo

    ReadyToGo Peon

    Messages:
    2,853
    Likes Received:
    78
    Best Answers:
    0
    Trophy Points:
    0
    #4
    You can "rectify" it by not doing it.
     
    ReadyToGo, Jun 12, 2007 IP
  5. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #5
    Your computer is affected by a spyware. This spyware has injected DLL into your network layer, and it's adding this fuzka stuff to any network packets you are sending.

    If you search your PC, you might find this dll in your PC: rsvp32_2.dll

    Download hijack this from here and post your log:

    http://www.spywareinfo.com/~merijn/programs.php

    Also, do not type in any sensitive information on your PC, as copies of your network traffic would have been forwarded to these spyware owners or who knows.
     
    NeoGen, Jun 12, 2007 IP
  6. Zerosleep

    Zerosleep Established User

    Messages:
    7,999
    Likes Received:
    559
    Best Answers:
    1
    Trophy Points:
    405
    #6
    Yea even my PC was affect by similar type of Spyware/Virus just difference was I used to get this : ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||

    Strange :p
    anyways as NeoGen said Download HiJack This and post the Log in this thread
     
    Zerosleep, Jun 12, 2007 IP
    NeoGen likes this.
  7. getjimmy

    getjimmy Prominent Member

    Messages:
    17,260
    Likes Received:
    1,005
    Best Answers:
    0
    Trophy Points:
    360
    #7
    And if u r still facing similar problem then its better to format ur system and reinstall OS.
     
    getjimmy, Jun 12, 2007 IP
  8. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #8
    free mn_fuzkathis is scary.
    i need to take action on this fast.
    but its only on DP that i get to see this.
    i dont see this happening on any other forum or anything.
    xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  9. sri

    sri Active Member

    Messages:
    917
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    70
    #9
    I know am not supposed to laugh...but am literally ROFLOL! :D

    mn_fuzka :p
     
    sri, Jun 12, 2007 IP
  10. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #10
    Have you used hijackthis or any other spyware remover software..

    Don't worry, it will soon start in other forums and your outgoing mails also, if you are not going to clean your machine
     
    NeoGen, Jun 12, 2007 IP
  11. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #11
    free mn_fuzka
    i dont think so.
    but may be i accidently clicked on one of the system doctor pop ups.
    i will look into this tonight.

    xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  12. uttoransen

    uttoransen Prominent Member

    Messages:
    8,227
    Likes Received:
    550
    Best Answers:
    0
    Trophy Points:
    320
    #12
    spyware! lol i would never talk about spwares and viruese agian:eek:

    anyways, i did not faced any problems, the posts are all right here:)
     
    uttoransen, Jun 12, 2007 IP
  13. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #13
    free mn_fuzkathanx for the help guys
    i have downloaded hijack this from
    http://www.spywareinfo.com/~merijn/programs.php

    i ran it and it gave a realy big log am not sure what it means.
    will try posting it here in a sec.
    also i found this file rsvp32_2.dll in windows/system32.
    please hlep me get rid of it.
    xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  14. Crazy_Zap

    Crazy_Zap Well-Known Member

    Messages:
    1,342
    Likes Received:
    305
    Best Answers:
    0
    Trophy Points:
    170
    #14
    Are you going to post your hjt log?

    free mn_fuzkafree mn_fuzkat
     
    Crazy_Zap, Jun 12, 2007 IP
  15. Crazy_Zap

    Crazy_Zap Well-Known Member

    Messages:
    1,342
    Likes Received:
    305
    Best Answers:
    0
    Trophy Points:
    170
    #15
    DAMN!!! I think I caught it now!!! :mad:

    free mn_fuzkafree mn_fuzkat :eek:
    xx mn_fuzka xx ;)
     
    Crazy_Zap, Jun 12, 2007 IP
  16. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #16
    free mn_fuzkatrying to but its a big file.
    now spliting it
    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 7:46:00 PM, on 12-Jun-07
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\AdobeR.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\DrvMon.exe
    C:\Program Files\WorldTime Clock\Clock.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Documents and Settings\Raghav Khanna\Desktop\HiJackThis_v2.exe xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  17. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #17
    free mn_fuzkafree mn_fuzkacontinued
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q304&bd=presario&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q304&bd=presario&pf=laptop
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0b95d3ef-7e72-45e5-9f47-02c4d6cabcea} - C:\WINDOWS\system32\dsuiALE.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {DEBEB52F-CFA6-4647-971F-3EDB75B63AFA} - C:\WINDOWS\system32\tmp2.tmp.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\AdobeR.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\vtronn.dll",realset
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DrvMon.exe] C:\WINDOWS\system32\DrvMon.exe
    O4 - HKCU\..\Run: [WorldTime Clock] C:\Program Files\WorldTime Clock\Clock.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [System] c:\windows\lsass.exe
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll
    O10 - Unknown file in Winsock LSP: rsvp32_2.dll xx mn_fuzka xx xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  18. money_train

    money_train Peon

    Messages:
    367
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #18
    free mn_fuzkaO14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q304&bd=presario&pf=laptop
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zan...fc36a816edcd:0be8363c48a33c637ca127220979e509
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DA408504-9C1E-4ABA-BF6F-0E6610BA015D}: NameServer = 202.164.32.82,202.164.51.21
    O20 - AppInit_DLLs: C:\WINDOWS\system32\win_5.dll
    O20 - Winlogon Notify: dsuiALE - C:\WINDOWS\SYSTEM32\dsuiALE.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe xx mn_fuzka xx
     
    money_train, Jun 12, 2007 IP
  19. qwestcommunications

    qwestcommunications Notable Member

    Messages:
    8,868
    Likes Received:
    172
    Best Answers:
    0
    Trophy Points:
    233
    #19
    Have you any antivirus software installed on your computer?
     
    qwestcommunications, Jun 12, 2007 IP
  20. NeoGen

    NeoGen Writer

    Messages:
    2,303
    Likes Received:
    301
    Best Answers:
    0
    Trophy Points:
    230
    #20
    What have you done with your PC???

    Okay, using hijack this select following entries:

    O10 - Unknown file in Winsock LSP: rsvp32_2.dll

    and repair/delete them.

    Remove/annihilate all traces of rsvp32_2.dll
     
    NeoGen, Jun 12, 2007 IP