[Attention] Getting rid of the recent homepage virus menu

User Tag List

Page 1 of 2 12 LastLast
Results 1 to 15 of 21
  1. #1
    maclone's Avatar / Authenticator enabled
    Reputation
    2420
    Join Date
    Nov 2007
    Posts
    8,726
    Thanks G/R
    0/1029
    Trade Feedback
    0 (0%)
    Mentioned
    2 Post(s)
    Tagged
    0 Thread(s)

    [Attention] Getting rid of the recent homepage virus

    As you may know, MMOwned was hit by a recent attack.
    If you visited the homepage (http://mmowned.com/) in the past days, you may have been infected with a virus.

    How-to check for and/or remove the virus:

    It's preferred that this is all done while your internet is shut off.
    (Remove network cable or disable the connection in Control Panel.)
    1. Open RegEdit (Press [Win]+[R] to get the 'Run...' dialog, write "regedit.exe" and press enter.)
    2. Navigate to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\.
    3. Find the key that really doesn't belong there.
      Like the same exe name as the one you got infected with. Make note of the path, as you'll need to go there and delete the file.
      - It's likely to be in
      XP: C:\Documents and Settings\<Your UserName>\ ??? \System32\<ExeName>
      Vista/Win7: C:\Users\<Your UserName>\ ??? \System32\<ExeName>
    4. Delete the registry key and the EXE (you may need to end its task with taskmanager first.)
    5. Next, open msconfig ('Run...' dialog, -> "msconfig")
      Click on the 'Startup' tab and disable the 2 startup entries. (Delete them if you know how.)

    You should be free now.
    Last edited by maclone; 07-12-2010 at 09:02 AM.
    Zomfg. And no, don't ask. - Dombo did it.

    [Attention] Getting rid of the recent homepage virus
  2. #2
    Dombo's Avatar Banned
    Reputation
    622
    Join Date
    Nov 2008
    Posts
    1,421
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I wasn't infected, thanks for the tutorial though. (I also checked in HKEY_LOCAL_MACHINE, just to be sure)

  3. #3
    Allstar .ιllιlı.'s Avatar Banned
    Reputation
    284
    Join Date
    Jan 2009
    Posts
    481
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nothing suspicious here.

  4. #4
    Opirity's Avatar Contributor
    Reputation
    139
    Join Date
    Apr 2010
    Posts
    462
    Thanks G/R
    6/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    nothing here too

  5. #5
    Danne206's Avatar Contributor
    Reputation
    183
    Join Date
    Jan 2008
    Posts
    717
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I don't really find anything suspicious expect for a hidden temp folder ("6EF59C2EE3554AA8B18A3E19A7B8EDE9.TMP"). It was empty tho.
    When I got redirected, I got the "nothing found" message - was that just for fooling purposes or didn't it find anything?
    Dahnniel [DOT] s [AT] gmail [DOT] com

  6. #6
    Ravenheart's Avatar Nevermore
    Reputation
    355
    Join Date
    Oct 2007
    Posts
    549
    Thanks G/R
    3/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nothing here, but thanks for the tut

    Don't forget You're able to design your own universe.


  7. #7
    Sychotix's Avatar Moderator Authenticator enabled
    Reputation
    1421
    Join Date
    Apr 2006
    Posts
    3,942
    Thanks G/R
    285/572
    Trade Feedback
    1 (100%)
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)
    I pressed cancel I believe and its not there. Firefox ftw? (or maybe it was Bitdefender)

  8. #8
    Hewit's Avatar Member
    Reputation
    45
    Join Date
    Sep 2007
    Posts
    171
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    It was firefox


  9. #9
    -Ryuk-'s Avatar Elite User CoreCoins Purchaser Authenticator enabled
    Reputation
    529
    Join Date
    Nov 2009
    Posts
    1,028
    Thanks G/R
    38/51
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Using chrome, and wasnt infected.

    Thanks anyway
    |Leacher:11/2009|Donor:02/2010|Established Member:09/2010|Contributor:09/2010|Elite:08/2013|

  10. #10
    Sm00gel's Avatar Corporal
    Reputation
    4
    Join Date
    Dec 2009
    Posts
    33
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Uhh what was the virus exe name?

    I had a exe called svhost.exe and v3.exe in the folder you said.

    I havent been on MMOwned for a few weeks though:O
    Last edited by Sm00gel; 07-12-2010 at 01:08 PM.
    Code:
    https://www.mmowned.com/ap_ver8/inde...tes&uid=100000 - If you want to advertise on MMOwned

  11. #11
    Dombo's Avatar Banned
    Reputation
    622
    Join Date
    Nov 2008
    Posts
    1,421
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Sm00gel View Post
    I had a exe called svhost.exe and v3.exe in the folder you said.
    If you meant "svchost.exe" then there's no worry. Though v3.exe sounds very supsicious.

  12. #12
    Sm00gel's Avatar Corporal
    Reputation
    4
    Join Date
    Dec 2009
    Posts
    33
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Dombo View Post


    If you meant "svchost.exe" then there's no worry. Though v3.exe sounds very supsicious.
    I thought that. A few days/ a week ago I looked into the v3.exe quickly. It was causing outbound connections. I just assumed it was something to do with windows 7 as I just upgraded. It should be gone now though. deleted the files, and the registry.
    Them 2 files I said also don't have an icon. They also keep getting recreated every day (at least, I think. But they do update) and it says both of them files where created at the same time. :O
    And it was svhost, not svchost

    Edit: The 2 files I said are also having connections from the startup folder.
    Last edited by Sm00gel; 07-12-2010 at 01:28 PM.
    Code:
    https://www.mmowned.com/ap_ver8/inde...tes&uid=100000 - If you want to advertise on MMOwned

  13. #13
    Confidence's Avatar Contributor
    Reputation
    272
    Join Date
    Sep 2009
    Posts
    447
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks, however I was also unaffected.

  14. #14
    chance96283's Avatar Member
    Reputation
    1
    Join Date
    Sep 2008
    Posts
    14
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    I haven't found anything on my computer, thanks for telling us though, Im sure some people might have been infected and needed this tutorial. /Bows to maclone

  15. #15
    [LT]'s Avatar Active Member
    Reputation
    37
    Join Date
    Mar 2009
    Posts
    107
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks for letting us know about the attack but seems I was unaffected.
    https://www.mmowned.com/forums/world-of-warcraft/guides/264682-achievement-onyxias-lair-level-60-3-2-2-hunter.html

Page 1 of 2 12 LastLast

Similar Threads

  1. Get rid of the virus scanning rule in B&P
    By Cypher in forum Suggestions
    Replies: 2
    Last Post: 12-16-2009, 01:11 PM
  2. Get rid of the virus scanning rule in B&P
    By Cypher in forum Suggestions
    Replies: 1
    Last Post: 09-30-2009, 07:51 AM
  3. How do i get rid of the 'you cannot speak that language' thing
    By Thirsha in forum World of Warcraft Emulator Servers
    Replies: 8
    Last Post: 02-24-2008, 03:45 PM
  4. Get rid Of the Leechers On MMowned!!!
    By Gelormino in forum Suggestions
    Replies: 1
    Last Post: 11-24-2007, 12:11 AM
  5. Get rid of the nocopy.jpg images
    By jaymunee80 in forum Suggestions
    Replies: 2
    Last Post: 06-28-2006, 03:12 PM
All times are GMT -5. The time now is 12:53 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search