So because I seriously lost my patience with having to wheel my shit
from one place to another, re-installing OS and 12 hours
reconfiguring, I wanna know what measures are sufficient to completely
purge all the agents of XP Antivirus 2008. I've done a System Restore
which appears to have resolved everything, but I can't afford having
Trojans behind my back while I'm doing scene releases for the public,
so I need to know: is a system restore enough?
Thanks.
| Thanks.
Malwarebytes Anti-Malware
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
--
Ignore posts made by the person called Leythos, he is a stalker who's been
obsessed with me for years ever since I spurned his advances towards me.
"Industrial One" <industr...@hotmail.com> wrote in message
news:d134a24d-3473-4c96...@u12g2000prd.googlegroups.com...
I just remembered I had a system snapshot from last week, and ignoring
all legit changes, there was only the folder with the desktop-
hijacking .bmp that System restore skipped, and your application
removed the folder+picture. However, it also did this:
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
{B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationAddress
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
{B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationMask
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
{B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationSeed
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
\DontAddDefaultGatewayDefault
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
\EnableIcmpRedirect
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
\EnableSecurityFilters
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
\UseDomainNameDevolution
Why?
| I just remembered I had a system snapshot from last week, and ignoring
| all legit changes, there was only the folder with the desktop-
| hijacking .bmp that System restore skipped, and your application
| removed the folder+picture. However, it also did this:
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
| {B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationAddress
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
| {B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationMask
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
| {B8CB87BB-64E5-4DA2-9363-E29B2C77B95A}\IpAutoconfigurationSeed
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
| \DontAddDefaultGatewayDefault
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
| \EnableIcmpRedirect
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
| \EnableSecurityFilters
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
| deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
| \UseDomainNameDevolution
| Why?
He can't explain. He didn't write it.
Butts plagiarized the code from RogueFix by Stuart Saunders at
http://www.internetinspiration.co.uk/roguefix.htm
and he also plagiarized the MVP Hosts file found at
http://www.mvps.org/winhelp2002/hosts.htm to produce that bastard child called "Remove-it"
which is a delibarate name modification of the legitaimte tool RemoveIT found at
http://www.incodesolutions.com/index2.html
--
Ignore posts made by the person called Leythos, he is a stalker who's been
obsessed with me for years ever since I spurned his advances towards me.
"Industrial One" <industr...@hotmail.com> wrote in message
news:32ec9145-b5ff-4645...@r35g2000prm.googlegroups.com...
--
Ignore posts made by the person called Leythos, he is a stalker who's been
obsessed with me for years ever since I spurned his advances towards me.
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:WMqdncmwNL9DfQ3V...@giganews.com...
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam9...@rrohio.com (remove 999 for proper email address)
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
And you can see that he was unable to explain your question also.
Butts has no direct knowledge of anything technical.
--
Ignore posts made by the person called Leythos, he is a stalker who's been
obsessed with me for years ever since I spurned his advances towards me.
"Leythos" <vo...@nowhere.lan> wrote in message
news:12174678...@news.usenet.com...
All 3 links are broken.
On Jul 30, 5:11 pm, "The Real Truth MVP" <to...@tpap.com> wrote:
> Remove-it has built into it the Winsock repair command that MS recommends to
> fix internet connection issues and removes altered LSP's. Resetting the
> Winsock using the netsh winsock command removes all the third-party LSPs and
> restores Winsock to factory default setting. Malware likes to add stuff to
> the TCP/IP stack. This fixes it.
I see.
On Jul 30, 5:33 pm, Leythos <v...@nowhere.lan> wrote:
> In article <2x6kk.18875$Ri....@flpi146.ffdc.sbc.com>, to...@tpap.com
> says...
>
> > Ignore posts made by the person called Leythos, he is a stalker who's been
> > obsessed with me for years ever since I spurned his advances towards me.
>
> Do you really want to trust someone that was banned from posting
> directly to Microsoft Usenet servers, someone that has posted links to
> pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
That's cool, as long as it ain't them down-syndrome methhead hoes with
bouncy implants and thick bushes, as if an elephant stepped in her
snatch.
> Block list, and who provides a tool for your use that will block access
> to reputable anti-malware sites without telling you he's doing it?
After briefly skimming over the code, I didn't notice anything
suspicious. Hell, I don't need antimalware sites to protect myself. I
already got my leet kit of SYGate firewall, System shield which
closely monitors unsolicited ads/scripts and a helluva lot more. I
don't have 'em installed on this comp yet cuz it's new, and I never
thought that I'd have the misfortune of the FIRST cracked application
I ever download with this machine to be infected.
As for "Butts" or whoever stealing code. Is it provable that portions
of the source code from the original application matches the one on
Remove-It? And if Butts is his real name, then that's really fucking
sad.
| I see.
Yes it is Christopher Butts.
And yes, we have proven that he stolen stolen the code. Not just from RogueFix but from
several other peoples work for several utilities whhere Butts replaced the authors name
and directly replaced it with PCBUTTS1. It is a ver, very, sad state of affair.
http://www.temerc.com/forums/viewtopic.php?p=10862
"No good deed goes unpunished"
http://www.viruslist.com/en/weblog?calendar=2006-09
PCButts is a Pakistani. His full name is Pushya Cockupmai Butt.
Il mittente di questo messaggio|The sender address of this
non corrisponde ad un utente |message is not related to a real
reale ma all'indirizzo fittizio|person but to a fake address of an
di un sistema anonimizzatore |anonymous system
Per maggiori informazioni |For more info
https://www.mixmaster.it
Heheheh.
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
--
Been proven dozens of times, butts will include the updates that are in
the real program a few days after it's updated.
His Hosts file will also block access to reputable anti-malware sites
without telling the poor sucker that runs his hack tool.
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
--
Leythos - spam9...@rrohio.com (remove 999 to email me)
Public Service Warning: Learn about PCButts before you trust:
http://www.velocityreviews.com/forums/t513604-author-of-removeit.html
http://www.google.com/search?hl=en&q=pcbutts1+thief
--
Ignore posts made by the person called Leythos, he is a stalker who's been
obsessed with me for years ever since I spurned his advances towards me.
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:l7mdnVuSscovtQzV...@giganews.com...
You've missed the point entirely Butts, you look like a FOOL and
UNETHICAL HACK based on your OWN ACTION, OWN STATEMENTS, OWN ADMISSIONS,
and based on the content on your butts site and your stalking site.
It was never really about shutting you down, you're not that important
to anyone, it was about giving you enough rope to hang yourself and you
did a great job, all your impersonations, all your porn on that site,
stalking me with your sig lines and even a website in my name, all of
your lies, all the times you've had to change your name just to post to
MS groups.... You've shown anyone that cares to look just the kind of
person you really are - you have proven to be your own downfall and
worst enemy.
> Ignore posts made by the person called Leythos, he is a stalker who's been
> obsessed with me for years ever since I spurned his advances towards me.
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
--
> All that info about me and nothing can be done about it. You've posted
> my name address and phone number yet I'm still here, WOW I must be a
> god.
Not hardly. Your just a mentally disturbed individual with too much time on
his hands. And things have been done about you, with varying degrees of
success.
--
Regards,
Dustin Cook, Author of BugHunter
BugHunter - http://bughunter.it-mate.co.uk
MalwareBytes - http://www.malwarebytes.org
Congrats on scene releases, try to have better sources for known clean
software tho. :)
Well, whether he stole the app or not, it purged all traces of the
trojan and I didn't notice any malicious code in it. Besides, this
will never happen again, so it's the first and last time I'll be using
RemoveIt.
--
Ignore any posts made by the Stalker Leythos, he's still in love with me.
He started stalking me after I spurned his advances towards me.
He said he would stop Stalking me If I stopped mentioning his name.
As you can see that does not work. He is a sick obsessive STALKER.
"Industrial One" <industr...@hotmail.com> wrote in message
news:03adc0ef-aeb8-404f...@c58g2000hsc.googlegroups.com...
| Well, whether he stole the app or not, it purged all traces of the
| trojan and I didn't notice any malicious code in it. Besides, this
| will never happen again, so it's the first and last time I'll be using
| RemoveIt.
Good. Don't use it again.
"He", Christopher Butts did plagiarize the code and it is ineffectual with the RootKit
that can accompany the non-viral malware infection.
I hope you did let it modify your Hosts file. If you did, you will find that it blocks
LEGITIMATE anti malware sites!
If you have the file; C:\WINDOWS\system32\drivers\ete\hosts that is greater than 1KB,
delete it.
If you want to have a legitimate Hosts files you can get the original MVP Hosts File where
Butts plagiarized that too but added blocking to legitimate sites and REMOVED the blocking
of PCBUTTS1.COM
Borrowed from Siljaline...
http://www.mvps.org/winhelp2002/hosts.htm
Download: hosts.zip (142 kb)
http://www.mvps.org/winhelp2002/hosts.zip
How To: Download and Extract the HOSTS file
http://www.mvps.org/winhelp2002/hosts2.htm
HOSTS File - Frequently Asked Questions
http://www.mvps.org/winhelp2002/hostsfaq.htm
> I hope you did let it modify your Hosts file.
I hope you did NOT let it modify your Hosts file. <g>
--
-bts
-Friends don't let friends drive Windows
| David H. Lipman wrote:
>> I hope you did let it modify your Hosts file.
| I hope you did NOT let it modify your Hosts file. <g>
Ooooops !
Thanx for the correction BTS.
| How do you feel about making the hosts file "read only"?
| --
| Ernie B.
| Communication: The art of moving an idea from one mind to another, hopefully
| without distortion.
It may help. It depends on if the utility changes the attributes or just deletes and
replaces the file instead of appending to it.
> David H. Lipman wrote:
>> From: "Beauregard T. Shagnasty" <a.non...@example.invalid>
>>| David H. Lipman wrote:
>>>> I hope you did let it modify your Hosts file.
>>
>>| I hope you did NOT let it modify your Hosts file. <g>
>>
>> Ooooops !
>>
>> Thanx for the correction BTS.
>
> How do you feel about making the hosts file "read only"?
If it makes you feel warm and fuzzy. <g>
(Do you think malicious software can't change that?)
Are you saying Leythos is gay like you ??????
--
Ignore any posts made by the Stalker Leythos, he's still in love with me.
He started stalking me after I spurned his advances towards me.
He said he would stop Stalking me If I stopped mentioning his name.
As you can see that does not work. He is a sick obsessive STALKER.
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:ntqdncz9lcMJeEfV...@giganews.com...
Do you really want to trust someone that was banned from posting
directly to Microsoft Usenet servers, someone that has posted links to
pornographic materials on HIS WEBSITE, who's website is in the MVP HOST
Block list, and who provides a tool for your use that will block access
to reputable anti-malware sites without telling you he's doing it?
And do you really want to trust someone that has had to change their
posting identity after being busted by MS as a fake MVP?
Stalking, even in usenet is a crime, there are enough pages from your
filthy site to prove you're stalking me in your posts, I have them
documented and certified authentic - it's your call now Stalker.
Do you really want to trust someone that was banned from posting
LOL, I can assure you I'm not gay like Butts1 appears to be, nor do I
need 20+ fake names to post under like Butts does.
On Sep 25, 1:12 am, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
wrote:
> From: "Industrial One" <industrial_...@hotmail.com>
>
> | Well, whether he stole the app or not, it purged all traces of the
> | trojan and I didn't notice any malicious code in it. Besides, this
> | will never happen again, so it's the first and last time I'll be using
> | RemoveIt.
>
> Good. Don't use it again.
> "He", Christopher Butts did plagiarize the code and it is ineffectual with the RootKit
> that can accompany the non-viral malware infection.
>
> I hope you did let it modify your Hosts file. If you did, you will find that it blocks
> LEGITIMATE anti malware sites!
>
> If you have the file; C:\WINDOWS\system32\drivers\ete\hosts that is greater than 1KB,
> delete it.
No such directory on my system.
On Sep 25, 12:52 am, "The Real Truth MVP" <to...@tpap.com> wrote:
> She and no it is not stolen.
She? I'm confused.
Leythos, you busted the BI a long time back with this particular text.
If someone reports it to your ISP, and if your ISP is responsible, it
will nuke your account.
Everyone agrees that Butts is a piece of shit liar and thief, but
stalking him and showing a total disregard for the customs of usenet is
not the way to solve the problem.
--
Rhonda Lea Kirk Fries
"You know you can indict a ham sandwich if you want to."
William J. Martini, Judge, United States District Court
>> If you have the file; C:\WINDOWS\system32\drivers\ete\hosts that is greater than 1KB,
>> delete it.
| No such directory on my system.
Sorry...
The folder is...
C:\WINDOWS\system32\drivers\etc
The file is; "hosts" in that folder.
Amen and amen! Done got Butts k-filed and hate to do the same for Leythos
but it gets a bit much re-reading Butts thru Leythos' reactive posts. K-file
him or ignore him but spare the rest of us..PLEASE!
Bud
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
"Industrial One" <industr...@hotmail.com> wrote in message
news:42949e25-95bd-43f4...@r38g2000prr.googlegroups.com...
> From: "Industrial One"
>| No such directory on my system.
> The folder is...
> C:\WINDOWS\system32\drivers\etc
Very likely is for most people running XP and above on a standard
install. However, it might be where this registry entry points to:
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DataBasePath
which normally contains:
%SystemRoot%\System32\drivers\etc
and on my system the variable %SystemRoot% translates to "D:\WINNT"!
Butts thinks he's a female porn star!
I also agree with you and Rhonda......and have started avoiding Leythos'
posts because the repetition is really annoying. There can't be anyone
left on this planet that doesn't know what an a$$hole Butts is.
Maybe.......just maybe.....if everyone ignores him, he will go away.
But that is a tall order.
Heather
And taking schlong up his well-used mangina reinforces his fantasy!
On Oct 20, 7:43 pm, "David H. Lipman" <DLipman~nosp...@Verizon.Net>
wrote:
> From: "Industrial One" <industrial_...@hotmail.com>
>
> >> If you have the file; C:\WINDOWS\system32\drivers\ete\hosts that is greater than 1KB,
> >> delete it.
>
> | No such directory on my system.
>
> Sorry...
>
> The folder is...
> C:\WINDOWS\system32\drivers\etc
>
> The file is; "hosts" in that folder.
Damn! Now I know why I couldn't access thebugs.ws lately. What
legitimate sites does... her program block -- besides my
aforementioned fav warez joint? But hell, even if there are legitimate
antispyware sites listed, it doesn't matter, as I already have
everything I need and have no use for visitting them sites.
On Oct 20, 9:28 pm, "The Real Truth MVP" <to...@tpap.com> wrote:
> She meaning me, I am female. They have me confused with someone else and
> they have you believing them.
I see. Whoever you are, thanks for the help -- whether you jacked that
app or not.
P.S. Isn't there a privkey/digital signature you can inscribe on your
applications to prove authenticity?
>> Sorry...
It is plagiarized software based upon a BAT file and you can't insert a publisher's
certificate in a BAT file.
He is Christopher Butts and is NOT a female.
Here is an article published on him in a Swiss online publication service.
http://translate.google.co.uk/translate?u=http%3A%2F%2Fwww.tagesanzeiger.ch%2Fdigital%2FSoftwaredieb-zensiert-Schweizer-PCMagazin%2Fstory%2F27917275&sl=de&tl=en&hl=en&ie=UTF-8
Some more reading...
http://blog.malwareteks.com/pcbutts1-the-saga-continues/
What Kaspersky has to say about him...
http://www.viruslist.com/en/weblog?weblogid=197597102
And more...
http://www.bleepingcomputer.com/securityblog/2006/09/07/pcbutts1what-a-royal-pain-in-the-butt/
http://www.besttechie.net/2006/09/07/pcbutts1-back-at-it/
http://temerc.blogspot.com/2006/09/pcbutts-internet-software-theif.html
What he said.
Note to David: Two of the links are no good: bleepingcomputer.com,
temerc.blogspot.com. I'm not sure what's going on with the google
translator, but my browser didn't like the original page (crashed) or
the translation (wouldn't load).
| Note to David: Two of the links are no good: bleepingcomputer.com,
| temerc.blogspot.com. I'm not sure what's going on with the google
| translator, but my browser didn't like the original page (crashed) or
| the translation (wouldn't load).
| --
| Rhonda Lea Kirk Fries
| "You know you can indict a ham sandwich if you want to."
| William J. Martini, Judge, United States District Court
Hi Rohda:
Did you remarry ?
Anyway, some links fade away but the Google Translation page loads fine for me.
Married in May; moved to Texas in September. My daughter is still in New
Jersey, so I'll be back up there in March when her baby is due.
Lots of stuff going on this last year--all of it good.
Hope you're well.
> Anyway, some links fade away but the Google Translation page loads
> fine for me.
I tried it again, and it worked. Something must've been going on with
the original page when I first tried it or else there was something
funky in my browser.
Great article, not that it will stop Butts. I do think, however, that
posting these links, perhaps in the form of a periodic FAQ, would be
better than responding to his every post with a canned and relatively
non-substantive rant.
Perhaps if such a suggestion comes from you, it will go over better.
>> Hi Rohda:
>> Did you remarry ?
| Hope you're well.
C O N G R A T U L A T I O N S Rhonda !
I am very happy to hear that you were recently married :-)
Also, Congrats to your daughter. May you and your daughter be blessed with a beuatiful
and healthy grandchild.
I agree that the consistent postings and reposting by Leythos are troublesome to many.
The problem is too many newbies for for his sh1t.
As for the idea periodic FAQ...
The problem there is that people tend to NOT read prior posts before they make their own
posts. The suggestion does however have it merits.
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
"Rhonda Lea Kirk Fries" <ni...@databasix.com> wrote in message
news:gdq89o$kv0$1...@blackhelicopter.databasix.com...
Is that why Kadipshit Man slashed his wrists ?
Me too. My husband is a wonderful guy (even if he is one of those darned
kookologists).
> Also, Congrats to your daughter. May you and your daughter be
> blessed with a beuatiful and healthy grandchild.
It's a boy, says the sonogram, and all requisite parts are included.
> I agree that the consistent postings and reposting by Leythos are
> troublesome to many. The problem is too many newbies for for his sh1t.
>
> As for the idea periodic FAQ...
> The problem there is that people tend to NOT read prior posts before
> they make their own posts. The suggestion does however have it
> merits.
Too bad Butts has no merits at all, eh?
>>>> Hi Rohda:
>>>> Did you remarry ?
>>> Hope you're well.
I'll drink to that !
--
The Real Truth http://pcbutts1-therealtruth.blogspot.com/
"Rhonda Lea Kirk Fries" <ni...@databasix.com> wrote in message
news:gemuq6$cle$1...@blackhelicopter.databasix.com...
If you suck my cock there will be a peace of me
in your gob, you illiterate poofter!
Oohh... this just gets better and better. I love the open discussions,
man!
P.S. I just noticed that everyone who cussed at PCButts got their GG
accounts nuked. How is that possible?