Why not register?


Post new topic Reply to topic  [ 15 posts ] 

All times are UTC [ DST ]

Author Message
PostPosted: Mon Sep 27, 2004 4:09 pm  Post subject: Why can't I see my 'Content.ie5' dir?
Reply with quote
User avatar
Offline

The Ancient One
Joined: Sun Feb 23, 2003 10:03 am
Posts: 5034
Location: Norway - Where the polar bears roam the streets
So bitdeffender tells me I've got a virus:
G:\Documents and Settings\John Doe\Local Settings\Temporary Internet Files\Content.IE5\A1JC14NM\bridge-c14[1].cab=>WinadX.dll=>(Upx) Infected Trojan.Downloader.Winupdt.A
G:\Documents and Settings\John Doe\Local Settings\Temporary Internet Files\Content.IE5\A1JC14NM\bridge-c14[1].cab=>WinadX.dll=>(Upx) Deleted
G:\Documents and Settings\John Doe\Local Settings\Temporary Internet Files\Content.IE5\A1JC14NM\bridge-c14[1].cab Update failed

Tremendously anying that it don't just delete the whole 'bridge' file! And when it finds this virus in my scheduled scan, it doesn't continue the scanning, until I've pressed 'delete' or something.

Anyway, when I then go to:
G:\Documents and Settings\John Doe\Local Settings\Temporary Internet Files\
there is no Content.IE5 direcotry there. I've got 'Hidden and system dirs' to be shown under 'folder options' so why can't I see it? I can get there in command-promt, but then I can't delete the damned file.

argh


Top
 Profile  
PostPosted: Mon Sep 27, 2004 6:01 pm  Post subject:
Reply with quote
User avatar
Offline

Servant Of The Dead Donkey
Joined: Tue Mar 16, 2004 9:42 am
Posts: 78
use the folder view in explorer to browse those directories

_________________
https://members.lycos.co.uk/hhahavatars/uploads/twistedtales1-00.jpg


Top
 Profile  
PostPosted: Mon Sep 27, 2004 6:40 pm  Post subject:
Reply with quote
User avatar
Offline

Site Admin
Joined: Sat Nov 02, 2002 1:35 am
Posts: 19779
Location: En España
can I ask why in the name of Greek buggery, in light of abuse, self-decimation and public ridicule your still using Internet Exploiter btw? :wink:

_________________
Mouse nipple for the win! Trackpoint or death!


Top
 Profile  
PostPosted: Mon Sep 27, 2004 8:51 pm  Post subject:
Reply with quote
User avatar
Offline

Servant Of The Dead Donkey
Joined: Tue Mar 16, 2004 9:42 am
Posts: 78
seems that this was downloaded and being installed through an activeX installer when your AV caught it .

check out my tutorial at the edonkey forum to cripple this "feature" of IE
http://forum.edonkey.com/viewtopic.php? ... highlight=

_________________
https://members.lycos.co.uk/hhahavatars/uploads/twistedtales1-00.jpg


Top
 Profile  
PostPosted: Mon Sep 27, 2004 10:17 pm  Post subject:
Reply with quote
User avatar
Offline

Dead But Dreaming
Joined: Wed Sep 15, 2004 2:08 pm
Posts: 309
Location: Hurricane Bait, USA
spudthedestroyer wrote:
can I ask why in the name of Greek buggery, in light of abuse, self-decimation and public ridicule your still using Internet Exploiter btw? :wink:


Firefox?


Top
 Profile  
PostPosted: Tue Sep 28, 2004 3:36 am  Post subject:
Reply with quote
User avatar
Offline

The Ancient One
Joined: Sun Feb 23, 2003 10:03 am
Posts: 5034
Location: Norway - Where the polar bears roam the streets
_ImAdV8_ wrote:
use the folder view in explorer to browse those directories


I'm trying, but they simply aren't there!! ???


spudthedestroyer wrote:
can I ask why in the name of Greek buggery, in light of abuse, self-decimation and public ridicule your still using Internet Exploiter btw? :wink:


Oh no... not that old discussion again. We've only had it like 4 times allready?


Top
 Profile  
PostPosted: Tue Sep 28, 2004 9:30 am  Post subject:
Reply with quote
a member of the recently deceased
Offline

a member of the recently deceased
Joined: Mon Jul 28, 2003 8:07 am
Posts: 2564
Location: Hell ___________________________ ------ Horror Dealer ------
sounds like the Jpeg worm?


Top
 Profile  
PostPosted: Wed Sep 29, 2004 3:45 pm  Post subject:
Reply with quote
User avatar
Offline

Site Admin
Joined: Sat Nov 02, 2002 1:35 am
Posts: 19779
Location: En España
John_Doe wrote:
Oh no... not that old discussion again. We've only had it like 4 times allready?


lol, yeah but I get confused when people choose pain of pleasure. Seriously my brain hurts when such illogical choices arise.. its like "but... but... but..." then it implodes :lol:

_________________
Mouse nipple for the win! Trackpoint or death!


Top
 Profile  
PostPosted: Wed Sep 29, 2004 4:00 pm  Post subject:
Reply with quote
User avatar
Offline

The Devil, Probably
Joined: Mon Jun 09, 2003 1:04 pm
Posts: 2497
Location: In the darkest spot of your soul.
Hey Spud, I can help you to make sense of it: John loves horror in all its forms, :-)


Top
 Profile  
PostPosted: Wed Sep 29, 2004 4:39 pm  Post subject:
Reply with quote
User avatar
Offline

Site Admin
Joined: Sat Nov 02, 2002 1:35 am
Posts: 19779
Location: En España
lol, yeah that must be it... :lol: :mrgreen:

_________________
Mouse nipple for the win! Trackpoint or death!


Top
 Profile  
PostPosted: Thu Sep 30, 2004 4:11 am  Post subject:
Reply with quote
User avatar
Offline

The Ancient One
Joined: Sun Feb 23, 2003 10:03 am
Posts: 5034
Location: Norway - Where the polar bears roam the streets
ahh, go suck a fuck. :moon:

:roll:


Top
 Profile  
PostPosted: Thu Sep 30, 2004 9:45 pm  Post subject:
Reply with quote
User avatar
Offline

Site Admin
Joined: Sat Nov 02, 2002 1:35 am
Posts: 19779
Location: En España
now that we've had our fun, you should try a competant norton commander clone over explorer for these tasks, you'll see the real contents of the folder.

You could actually have just done a bat file now that I think of it:
Code:
del G:\Documents and Settings\John Doe\Local Settings\Temporary Internet Files\Content.IE5\A1JC14NM\bridge-c14[1].cab


Might do it :)

Of course this is all trivia since your an ie user and the same thing will be there next time you load it up :mrgreen:

_________________
Mouse nipple for the win! Trackpoint or death!


Top
 Profile  
PostPosted: Fri Oct 01, 2004 3:43 am  Post subject:
Reply with quote
User avatar
Offline

The Ancient One
Joined: Sun Feb 23, 2003 10:03 am
Posts: 5034
Location: Norway - Where the polar bears roam the streets
naah.. tried deleting it in dos, and it wouldn't let me. really strange.

Guess I should try in safe-mode, but I haven't restarted in a while, cause my mule is flying by.. =)


Top
 Profile  
PostPosted: Fri Oct 01, 2004 10:40 am  Post subject:
Reply with quote
User avatar
Offline

Servant Of The Dead Donkey
Joined: Tue Mar 16, 2004 9:42 am
Posts: 78
_ImAdV8_ wrote:
_________________________________
Virus/Trojan/Spyware - what to do??
_________________________________

check out this thread

get the HijackThis proggie , ad-aware and spybot and if that all dosent help , post the HijackThis log in that thread and on some of the security forums posted there

_________________________________
Online - PORTSCANNERS and Anti-Virus check
_________________________________
Symantic - portscan and AV
DSLReports/Broadband Reports - portscan - also a lot of other internet tools
[url=https://www.grc.com/x/ne.dll?bh0bkyd2]Gibson Research-ShieldsUp[/url] - portscan - and some tools
TrojanScan

there are quite a few others :wink:


note you cannot see that thread at FTi without being registered so im posting the info in the next post here

_________________
https://members.lycos.co.uk/hhahavatars/uploads/twistedtales1-00.jpg


Top
 Profile  
PostPosted: Fri Oct 01, 2004 10:44 am  Post subject:
Reply with quote
User avatar
Offline

Servant Of The Dead Donkey
Joined: Tue Mar 16, 2004 9:42 am
Posts: 78
_ImAdV8_ wrote:
maybe a version of the Blaster worm would do that , dont think the game would do that on its own , just a thought .

are you online when your not playing the demo , what are your specs , get this proggie and see what goes on at system start up http://download.com.com/3000-2144-10227352.html , post your results .

damn , that link is dead , does anyone have a direct download site for Hijackthis ? i gotta run to work :(
mtmartian wrote:



_ImAdV8_ wrote:
wow , you got a lot of crap on your hard drive , here is my entire post at Fileheaven about this subject and what you can do with your Hijackthis.log file , im not gonna have a lot of time tonight to do all this work :( , but maybe you can get some answers before i can get back to you on this
Quote:
@Hawkke ,
dont know about the trojan you bumped into , a good rule of thumb is to physically write down what the AV program pop's up , that goes for windows errors too
then type it into http://www.google.com between "quotes" , most likely , you arent the first person to have the problem .

from my research i dont know when the Trend Micro online scanner definitions were last updated , and BRIDGE.DLL is more often a Spyware , sometimes trojan related to trojans .

if you cannot find it , read you AV logs , maybe it has been deleted , or is quarantened .

http://www.computing.net/windowsxp/wwwb ... 03347.html
http://miataru.computing.net/windowsme/ ... 42327.html

____________________________________________

you can check out all your running processes with Google :
example the first hit for SMSS.EXE :

http://www.liutilities.com/products/win ... rary/smss/
a good site for a brief description of the process , change the last part of the URL for each process

<formula>http://www.liutilities.com/products/wintaskspro/processlibrary/ (process -extension)
</formula>

more info on Bridge.dll:
http://www.sysinfo.org/startuplist.php? ... =100&type=
what the "X" means (Definitely not required - typically viruses, spyware, adware and "resource hogs"):
http://www.sysinfo.org/startupinfo.php
____________________________________________

some possible problems i did detect:

1) Q: do you want your homepage in Internet Explorer to be "www.mail.com" ?

if not it might be a browser hijack , maybe by this next curiosity?

2)
Code:
C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe
C:\Program Files\BulletProofSoft.com\SpywareRemover\E05A4BD2.DLL
O4 - HKCU\..\Run: [SPYWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
just dont jive well with me , did you install this program on purpose , or was it acquired via a web page ?

possibly called SpywareRemover of Spywatch , this might be the cause of some of your woes , if you have any that is .

info:
http://www.windowsstartup.com/wso/brows ... 75&end=300
a rating means , its up to the user , whether to run it or not
http://www.newbie.org/help/messages/23135.html <-read this one

<opinion> recomendations:

get , install and run Spybot:search and destroy and ad-aware , update the definitions and scan

get rid of spywatch - which is a pay for prggie that steals old Spybot definitions , and has an odd history </opinion>

_______________________________________

also post your log at these forums for furthur opinions:

http://www.newbie.org
http://computercops.biz/forums.html
http://help.lockergnome.com/index.php?showforum=50
http://www.opentechsupport.net/forums/
http://www.annoyances.org/
http://www.softwaretipsandtricks.com/fo ... 083dd7622a
http://www.help2go.com/forum1.html
____________________________________________
also set your IE to "prompt" for Active scripting here

**************************************************************

@Sir_Boagalott

sorry its taking so long to get back to you on this , but i havent analyzed everything you have running , and boy there is a ton of stuff , i would suggest that you dont run it all on start up , that AV , as someone agrees here , seems like a tremendous resource hog . i would definately dump the "getright" also

get rid of "StartupMonitor.exe" , you have "hacker eliminator" which does exactly the same thing , if not more.

but i have to be honest , im completely stumped as far as a trojan on your machine , too many running processes , but no trojan as far as i can tell , post the LOG in the other forums i posted above , and give it a shot , maybe you are having some other type of problem , software conflicts or hardware (hard disk) problems . i would get rid of diskkeeper if its a warez version , i previously had a problem with that , lost a lot of files . maybe time for a re-format/re-install

also check out http://www.pcpitstop.com (as Hawkke did) , and see what the reccomend

NOTE: be warned that i am not an expert , and niether is anyone else at any of those forums , so be careful about what you delete

PS.you guys really put me to work this time :)
Image
hope this is of some help till i get some more time for you



welll thats about all of the info , hope it helps , did this cut and paste really fast (from a few threads) , cause i have to run to work , sorry if its a bit messy

_________________
https://members.lycos.co.uk/hhahavatars/uploads/twistedtales1-00.jpg


Top
 Profile  
Display posts from previous:  Sort by  

All times are UTC [ DST ]

Post new topic Reply to topic  [ 15 posts ] 


Who is online

Users browsing this forum: No registered users and 2 guests


Moderator: Help Mods

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Frontpage / Forums / Scifi


What's blood for, if not for shedding?