Search Members Help

» Welcome Guest
[ Log In :: Register ]

Page 1 of 212>>

[ Track This Topic :: Email This Topic :: Print this topic ]

reply to topic new topic new poll
Topic: Er. Winoldap? Halp!< Next Oldest | Next Newest >
 Post Number: 1
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Mar. 19 2001,02:44  Skip to the next post in this topic. Ignore posts   QUOTE

Okay, I'm not sure if this is a malicious program or what, but I though you guys would be the best place to ask.

The last coupla days, whenver i've tried to end windows, it's said there's a dos program running called NET, and occasionally one called PING. Well, trying to figure out where these are coming from, I found programs running after a clean boot -- winoldap and ping. I don't know wtf these things are besides dos programs. Now, I few days ago i found a .vbm (visual basic, i assume) file called "(kamasutra)" something or other in one of my directories...no clue wtf it was.
Now, while trying to figure out what this winoldap thing was, i checked the registry. Under local user, and down to explorer, I found the culprits in a folder called "Doc Find Spec MRU." Inside was the following:
a "'"
b "directx.*"
c "dx*.*"
d "kamasutra*.*"
e "winoldap*.*"
MRUList "eadcb"

Does anyone have any idea what this crap is? I've gone through everything under the startup tab of msconfig, but i can't seem to lock it down. I hope this has nothing to do with the general protection fault my other computer decided to have. Any help is GREATLY appreciated.

Offline
Top of Page Profile Contact Info 
 Post Number: 2
SimplyModest Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 174
Joined: May 2000
PostIcon Posted on: Mar. 19 2001,04:49 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by Frosty:

The last coupla days, whenver i've tried to end windows, it's said there's a dos program running called NET, and occasionally one called PING. Well, trying to figure out where these are coming from, I found programs running after a clean boot -- winoldap and ping. I don't know wtf these things are besides dos programs. Now, I few days ago i found a .vbm (visual basic, i assume) file called "(kamasutra)" something or other in one of my directories...no clue wtf it was.
Now, while trying to figure out what this winoldap thing was, i checked the registry. Under local user, and down to explorer, I found the culprits in a folder called "Doc Find Spec MRU." Inside was the following:
a "'"
b "directx.*"
c "dx*.*"
d "kamasutra*.*"
e "winoldap*.*"
MRUList "eadcb"

Does anyone have any idea what this crap is? I've gone through everything under the startup tab of msconfig, but i can't seem to lock it down. I hope this has nothing to do with the general protection fault my other computer decided to have. Any help is GREATLY appreciated.



get a virus scanner.. and taht will take care of it..

most new virus' are actually VBScripts.. (my parents had one called network.).. but norton or mcafee took care of it.. no problem..

you should look into that kinda soonish.

Offline
Top of Page Profile Contact Info 
 Post Number: 3
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Mar. 19 2001,18:32 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Modest -- I'm buying Norton today, i think.

As for the rest of it...CatKnight, that's exactly what i was thinking, is that whatever it is may just ping out over and over and over to tell someone "This machine is ready to be hacked, yo" Anyway, it's good to know that the list is only shit i've searched for. Was kinda wondering what the hell anything related to kamasutra would have to do with windows...hrm. Hopefully it's just a malfunction.

Offline
Top of Page Profile Contact Info 
 Post Number: 4
kornalldaway Search for posts by this member.
1337 like alan turing
Avatar



Group: Members
Posts: 297
Joined: Jan. 2001
PostIcon Posted on: Mar. 19 2001,20:52 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

i would sudgest u open VBS file with notepad and read what it does, if u didn't already delete it, it's not too hard to understand VB.
also if u open it with notepad and save it as a text file, u can send it to me.
i used to collect VBS type viruses and i'll be able to tell u if it's a virus or not and what it does.
and as mentioned by people above antivirus will help greatly

------------------
"Me fail English? That's unpossible!"
- Ralph Whigham

Offline
Top of Page Profile Contact Info 
 Post Number: 5
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Mar. 20 2001,02:15 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

I was trying to do so when i first found it, but i think i accidentally ran it. Either way, it disappeared. That was probly the dumbest thing i've ever done with a computer.
Offline
Top of Page Profile Contact Info 
 Post Number: 6
Observer Search for posts by this member.
I once watched, but I have left.
Avatar



Group: Members
Posts: 912
Joined: May 2000
PostIcon Posted on: Mar. 20 2001,05:22 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Winoldap is just a DOS virtual environment for running old DOS programs like Ping.

Doc Spec MRU is just a history of files you have searched for.

Where you should be looking in the registry for malicious programs is under
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

...and your startup folder, of course.

------------------
A good programmer is someone who looks both ways on a one-way street

Offline
Top of Page Profile Contact Info 
 Post Number: 7
CatKnight Search for posts by this member.
Jedi Republican
Avatar



Group: Members
Posts: 3807
Joined: Dec. 2000
PostIcon Posted on: Mar. 20 2001,05:37 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

hey maybe whoever made the virus made it run ping so the virus maker would know when he was online? hmm...

anyway kamasutra is that hindu book of all all the different sex positions. hehe

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 8
blanalex Search for posts by this member.
DetVet
Avatar



Group: Members
Posts: 202
Joined: Nov. 2000
PostIcon Posted on: Mar. 20 2001,21:00 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by Observer:
Winoldap is just a DOS virtual environment for running old DOS programs like Ping.

Doc Spec MRU is just a history of files you have searched for.

Where you [b]should be looking in the registry for malicious programs is under
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

...and your startup folder, of course.
[/B]


check also for the lines load= and run= near the top of system.ini or win.ini (can't remember which one)

------------------
#define QUESTION (2b)| |!(2b)

Offline
Top of Page Profile Contact Info 
 Post Number: 9
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Mar. 20 2001,23:17 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Phew. Okay, I cleaned the worm out..apparently it wasn't too dangerous, luckily. Anyhow, thanks for your help everyone, at least i've got a little more info about what to look for in the future and a bit more registry knowledge so my previously searched for files don't freak me out. :-D
Offline
Top of Page Profile Contact Info 
 Post Number: 10
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Mar. 21 2001,05:33 Skip to the previous post in this topic.  Ignore posts   QUOTE

Well shit. It is a virus, VBS/Pica.worm.gen...I thought that goddamn thing looked suspicious.

[Edit -- Virus name]

This message has been edited by Frosty on March 21, 2001 at 12:34 PM

Offline
Top of Page Profile Contact Info 
10 replies since Mar. 19 2001,02:44 < Next Oldest | Next Newest >

[ Track This Topic :: Email This Topic :: Print this topic ]


Page 1 of 212>>
reply to topic new topic new poll

» Quick Reply Er. Winoldap? Halp!
iB Code Buttons
You are posting as:

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code