After another 2 hours and 15 minutes of networking troubleshooting the computer is back at its owners and they are surfing the Internet. A 3 hour job took 17.25 hours!
Day: April 3, 2005
A different path
Sometimes I wonder what it would be like to be one of those people that gets into the office at 7:59am, has a 30 minute lunch brought in a sack and eats in the breakroom, leaves the office at 5:01pm, and doesn’t interupt family for work nor work for family; each would get left at its respective door.
World’s Coolest Dad
I hope that one day I can be as cool as this dad [should be work safe..only possible offensiveness is the word “blowjob” in the audio]
Progress!
I may have woken at 5:30 this morning. The clock times I remember on the cable box were 3:30 and 4:30 but the wife says it adjusted after I was up.
My computer repair is going well. If you know someone in Knoxville that needs a computer repaired, refer them to my via SIDesigns.com please.
I’m simultaneously fixing issues in the website that I am frantically trying to see released.
Local Blingo Winner!
Computer Repair
I have a machine to add memory to, de-virus and otherwise cleanup.
- First problem, I can’t get a signal to the monitor. Did the video card die? Ah! Monitor cable wasn’t plugged in all the way.
- Installed memory is a 128MB DIMM. Must check with Gateway TS to see what memory is allowed. Wow! Have to hand it to gateway. Surfing their support site for documentation is a breeze.
- 256 MB of memory installed. The memory doesn’t have to be identically paired but I believe it best to put the larger DIMM in slot 1 so the 128MB DIMM was moved to slot 2.
- Checking Add/Remove programs
- Removed ViewPoint and ViewPoint Manager
- Removed Diet Kaza
- Removed KaZaA Lite–nix–uninstall file unavailable
- Uninstalled MediaLoads
- Uninstalled Morpheus–nix–uninstall file unavailable
- Running Spybot and Adaware
- Received new definitions.
- Running Norton Antivirus Liveupdate – Subscription expires on the 27th, must advise.
- Last full system scan was 1/11/2005. Scanning now.
- Spybot issues:
- Avenue A, Inc.
- Advertising.com
- Callinghome.biz
- FastClick
- HitBox
- MoeMonkey
- SurfSideKick
Repairing…
- Spybot S&D fixed all but Callinghome.biz and will attempt that on reboot. Time to start researching a manual removal.
- Adaware found 215 problems. I won’t list all those but it does show that sixty pop six (\\windows\sixtypopsix.exe) is by a company called MediaMotor aka Roings LTD “a leader in targeted marketing” (their AIM is roingsmaster)
Operates in stealth. Downloads additional trojan downloaders and malware.
Some of the names include:
- exdgen
- Mediamotor
- e2give
- Ebates MoneyMaker (see also and manual removal instructions)
- ImIServer IEPlugin
- Roings aka MediaMotor
- popuppers.com aka MediaMotor
- Prutect
- IBIS Toolbar
- 180 Solutions
- Clear Search
- EzuLa
- MemoryMeter
You can right-click in adaware to select all. Also be sure to look under the "negligible objects" tab. Cleaning all issues.
- Done. Waiting for virus scan to complete.
- Virus scan complete. Symantec reports no viruses. Rebooting.
- Of 9.7 gb only 421 mb of harddrive remain. Must fix that.
- Spybot runs on boot. Results:
- Callinghome.biz
- AbetterInternet
Fixed!
- unplugged Internet connection to prevent new trojans
- Used Partition Magic to remove the unused 3GB partition and combine it with the 9.7gb partition
- Partition Magic failed. Trying again with one step at a time. Deleting Logical partition within Extended partition. Success.
- Deleting Extended partition. Success.
- Resizing primary partition for the full 13gb. Boom.
- Restarting computer.
- Partition Magic blew up again. Let’s try in safe mode.
- Giving up on Partition Magic.
- Re-created 3gb extended partition.
- Deleting temporary files and Windows uninstall information for antique updates
- Rechecking with Spybot SND. Reports clean.
- Rechecking with Adaware. Reports 10 objects.
- 2 tracking cookies (http://landing.domainsponsor.com/ and http://domainsponsor.com – considering no browser has been opened since the cache was dumped this is interesting)
- A0079949.exe related to Win32.TrojanDownloader.Agent.Ay
- MediaMotor
- Prutect
- ClearSearch
- Installing VX2 cleaner plugin for Adaware
- Checking for VX2 issues. Reports clean.
- Checking CWShredder. Reports clean.
- Reboot.
- Running Spybot SND. Reports clean.
- Running Adaware. Reports clean.
- HijackThis found:
- wsxsvc
- Ebates_MoeMoneyMaker under program files
- some other questionables
- reboot
- Removing Morpheus Gone.
- Manually checking registry. Mainly looking under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ (Run, Run-, RunOnce, RunOnceEx) and HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ (Run Run- RunOnce) Found newdotnet parasite
- Removed references to morpheus and kazaa within registry and program files.
- reboot.
- Reconnecting Internet connection.
- Checking HijackThis
- Task Manager won’t come up via cmtl-alt-del or right clicking the taskbar. Troublesome. Ah! A registry hack to enable/disable the Task Manager.
- HijackThis reports clean.
- Final virus scan with TrendMicro’s HousecallFound:
- TROJ_UR.A – \\windows\system32\sysdrc.dll
- TROJ_SMALL.AJM – \\windows\memmupdaterV2.exe
- TROJ_SMALL.ABT – \\windows\pi1_25.exe
- WORM_KLEZ.H – \Program Files\EarthLink 5.0\emailaddr@mindspring.com\mailbox\003.msf “OffersData(7).pif”
- TROJ_UR.A – \\Documents and Settings\User C\Local Settings\TEMP\ICD8.tmp\sysdrc.dll
- TROJ_DROP.A – \\Documents and Settings\User C\Local Settings\TEMP\iF5.tmp
- TROJ_SMALL.ABT – \\Documents and Settings\User C\Local Settings\Temporary Internet Files\Content.IE5\7PBF500\pi1_25(1).exe
- EXPL_IFRAMEBO.A – \\Documents and Settings\User C\Local Settings\Temporary Internet Files\Content.IE5\7PBF500\counter(1).js
- EXPL_IFRAMEBO.A – \\Documents and Settings\User C\Local Settings\Temporary Internet Files\Content.IE5\1RXAFK7L\counter(1).js
- TROJ_SMALL.UX – \\Documents and Settings\mb user\My Documents\backit\gmz\Tiberium Sun\TiberiumSunRAR.zip *Layer2 cctibsun\RAZOR.EXE*
- One final Spybot S&D. Clean with the exception of 3 tracking cookies (no big deal).
- One final Adaware. Clean with the exception of 4 tracking cookies (no big deal).
- Norton Antivirus caught:
I did a preliminary cleaning that lasted 3 hours earlier in the week. Today’s cleaning started at 7am and ended at 7pm.
Beautiful Morning!
I rose at 4:30 and while walking the dog
just had to stare at the sky.
The air was crisp and quiet.
The horizon was painted in soft clouds
barely visible through the still leafless, skeltons of trees
yet above the canopy of trees the majority of the sky was purple and cloudless
showing off the stars with absolute clarity.
The moon hung low still in the clouds
as not to diminish the brightness of the stars with its own light.
I could have stared at that sky for hours.