Jump to content
[[Template core/front/custom/_customHeader is throwing an error. This theme may be out of date. Run the support tool in the AdminCP to restore the default theme.]]

Whitesmoke Virus


keggerz
 Share

Recommended Posts

anyone know anything about this thing? My LT was acting weird and then the next thing I know I have this Whitesmoke software and toolbar downloaded on my LT....I didn't initiate it or allow it....did a quick google search and can't really find anything...doing a scan now...part that sucks is that for the most part the only sites I have been on today is here, MFL, cbssportsline.com

Link to comment
Share on other sites

this dirty MF'r...ran hijackthis and when I try to put the log into a reader it kills the connection...try to email myself the log it kills the connection....try to PM myself the log it kills the connection (PM myself the word test it works)

 

now need to try and run the log file from another PC(why I posted it here)

Edited by keggerz
Link to comment
Share on other sites

All I can find out about Whitesmoke is it is a translation toolbar/reader. I have a feeling the virus/malware is spoofing Whitesmoke.

Boot into safe mode and do a scan.

Better yet try and do a restore, but go into safe mode first.

Link to comment
Share on other sites

All I can find out about Whitesmoke is it is a translation toolbar/reader. I have a feeling the virus/malware is spoofing Whitesmoke.

Boot into safe mode and do a scan.

Better yet try and do a restore, but go into safe mode first.

I am in the middle of a full system scan right now....Fn thing is doing re-directs now too and FF wont even open up...IE is all that is working now

Link to comment
Share on other sites

I am in the middle of a full system scan right now....Fn thing is doing re-directs now too and FF wont even open up...IE is all that is working now

 

I did find a few other people w/ a similar problem, but no resolve. Sorry.

Did you try the 'restore' yet? Prolly won't work as this seems like a smart one that's flying under the radar.

Link to comment
Share on other sites

I did find a few other people w/ a similar problem, but no resolve. Sorry.

Did you try the 'restore' yet? Prolly won't work as this seems like a smart one that's flying under the radar.

i basically went thru the hijack this line by line to see what wasnt letting it parse for the log analyzer...found this as the culprit but I dont know what it is.

 

http://w w w.Xupdate.Xmicrosoft.Xcom/XwindowsXupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194652676296

 

I had to put in the spaces between the www and added all the RED X's to be able to post the link but that is what was keeping HJT from being able to parse...actually if you take out the spaces and the red X's and cut and paste it into the google search it will most likley give you a response like it is not connected to the internet

 

this is what the entire string looks like in HJT(or course still take out the Red Xs and the spaces between www)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://w w w.Xupdate.Xmicrosoft.Xcom/XwindowsXupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194652676296

Edited by keggerz
Link to comment
Share on other sites

i basically went thru the hijack this line by line to see what wasnt letting it parse for the log analyzer...found this as the culprit but I dont know what it is.

 

http://w w w.Xupdate.Xmicrosoft.Xcom/XwindowsXupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194652676296

 

I had to put in the spaces between the www and added all the RED X's to be able to post the link but that is what was keeping HJT from being able to parse...actually if you take out the spaces and the red X's and cut and paste it into the google search it will most likley give you a response like it is not connected to the internet

 

this is what the entire string looks like in HJT(or course still take out the Red Xs and the spaces between www)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://w w w.Xupdate.Xmicrosoft.Xcom/XwindowsXupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194652676296

So where are you?

Link to comment
Share on other sites

So where are you?

did a system restore in safe mode....can now open firefox...initially didn't get any redirects but have now gotten some...also did full system scan with MS Security Essentials and it didn't find anything...but I know it is still there in some capacity anyway

 

at this point I am not even sure what to try next...actually going to run malwarebytes next and go from there

Edited by keggerz
Link to comment
Share on other sites

did a system restore in safe mode....can now open firefox...initially didn't get any redirects but have now gotten some...also did full system scan with MS Security Essentials and it didn't find anything...but I know it is still there in some capacity anyway

 

at this point I am not even sure what to try next...actually going to run malwarebytes next and go from there

 

Can't hurt, but this sounds like a new one. If you can, give it a few days and re-google. Sorry i couldn't help more.

C'mon Redrum...................where are you?

Link to comment
Share on other sites

Can't hurt, but this sounds like a new one. If you can, give it a few days and re-google. Sorry i couldn't help more.

C'mon Redrum...................where are you?

would like to give it a few days but not sure that I can...I use Contribute to write my weekly huddle article on and I only have it on that laptop...I am not sure if it will effect my being able to use it since it does access the huddle thru the net and that is how I download my weekly template and then re-upload it to the site...fingers crossed because i normally only have to have 2 teams written by Wed. if there is a Thurs game...but this week there are 3 Thurs games so I wanted to have all 6 teams written up by Tues nite so they would be accessible for Wed. AM...again fingers crossed.

Link to comment
Share on other sites

Make sure your proxy wasn't enabled, it's pretty basic, google it.

just checked FF and it is set like this "use system proxy settings"

 

In IE the "use a proxy server for you LAN" box is NOT checked and the auto detect and auto configure boxes aren't checked either

 

:wacko: now what?

Edited by keggerz
Link to comment
Share on other sites

In IE the "use a proxy server for you LAN" box is NOT checked and the auto detect and auto configure boxes aren't checked either

 

Check that one, leave the other two unchecked.

 

You need to download these on another machine, copy to flash drive or cd, then boot your other machine into safe WITH NETWORKING, run in this order:

 

Disable system restore

 

CCleaner, remove all temp files http://download.cnet.com/ccleaner/

 

Copy to desktop, run Combo fix, let it update and do whatever it suggests: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

Malwarebytes, update, then full scan

 

Where are you now?

Link to comment
Share on other sites

Check that one, leave the other two unchecked.

 

You need to download these on another machine, copy to flash drive or cd, then boot your other machine into safe WITH NETWORKING, run in this order:

 

Disable system restore

 

CCleaner, remove all temp files http://download.cnet.com/ccleaner/

 

Copy to desktop, run Combo fix, let it update and do whatever it suggests: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

Malwarebytes, update, then full scan

 

Where are you now?

almost 3 hours into another malware bytes scan (updated it this time)...forgot my flash drive at home so won't be able to do anything else until I get home around 5.

 

as for checking AUTO DETECT in IE what do i do for FireFox? I assume that I check "Auot-Detect proxy settings for this network" other options are:

No Proxy

Use System proxy settings (which is currently checked)

Manual proxy configurations

Automatic proxy configuration URL:

 

Thanks!

Link to comment
Share on other sites

C'mon Redrum...................where are you?

 

He is busy trying to prove that Barack Obama created the computer virus to destroy the world . . . . and then show a link that says the anti-virus manufacturers all donate to his campaign, creating a sinister synergy that is designed to generate support for the New World Order and an all-world currency under the control of the Un . . . aww forget it . . . .

Link to comment
Share on other sites

He is busy trying to prove that Barack Obama created the computer :wacko: virus to destroy the world . . . . and then show a link that says the anti-virus manufacturers all donate to his campaign, creating a sinister synergy that :tup: is designed to generate support for the New World Order and an all-world currency under the control of the Un . . . aww forget it . . . . :tup::lol:

 

fixed.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information