My roommate got pooned by 00mpa l00mpa

Maluno

Senior member
Mar 28, 2005
697
0
0
I just got back from class, and I found my roommate sitting at his Windows XP-based computer listening to the oompa loompa song. I wouldn't have said anything about it, (with him, it wouldn't be something out of the ordinary anyway), but it just kept looping the first verse over and over again. Finally, he told me that he had gotten a virus, which was causing the looping of the first verse in the background. Ok, I'm not going to get into an argument about the classifications of different types of malware here, as I really don't have the desire to do so---- so call it what you will, a virus, trojan, worm, spyware, or whatever; I accept no responsibility for the accuracy of my statement labeling it a virus, as it probably belongs in some other category of malware.

No details about how he got the lovely piece of software, (I'm not going to go there, though I assume it is from the usual venue associated with prurient web-browsing in the exploit-prone Internet Explorer browser), but I will explain the symptoms in the hopes that someone has information about it.

About once every minute a small message box pops up, which reads, "teh 00mpa l00mpa 0wns yu0!!!1", and the song just continually plays in the background.
-----------------------------------------------------------------------------------------
I did some research, but the only reference to malware related to oompa loompas was one from early 2006 which spread on Mac OS X. Although he was running Norton Antivirus, Corporate Ed., (required by our college network policy), he did not have any anti-spyware tools installed on his pc. He did have all the latest windows updates and vulnerability patches, though, AFAIK. Right now, I'm installing Spybot SD, in hopes that it will clean the problem up, and then afterwords I will try to do a few things manually, (ie. checking "run on startup" reg entries, check all running processes for things I don't recognize, etc), before doing a full Norton scan. If that doesn't clean up his problem, I hope someone else will have more information to help me out, or else I will be shooting in the dark; just trying various anti-spyware tools in search of a solution.

Anyway, I am fairly confident that I will be able to clean up his problem, but I thought that the situation was humorous enough to warrant a thread. Maybe someone else will find this as funny as I did. There is something strangely satisfying about seeing someone getting pwnt by an 00mpa l00mpa over and over again.
-----------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------

UPDATE: It gets more serious:


Spybot SD found 137 problems, and fixed 135 immediately, and had to run on startup to fix the other two, but everything looked clean from there. I updated Norton virus definitions, (which I found out hadn't been done since 1/27/07!!), and selected a full system scan.

Here's where the problem is: Everytime I start a scan, the scanning window comes up, and it scans for a second, then it suddenly stops, and says, "completed" in the status square, while the number of files scanned, (listed in the bottom left corner), remains at zero. The total time elapsed remains at :01 seconds. EVERY TIME, no matter what scan type I choose.

The music is still playing, BTW, and the 00mpa l00mpa messages are still pwning him, (and me as well, as I am forced to deal with the issue now). I'm thinking about doing a few more things and then just telling him to take it down to our college's IT service support techs, although that would most definitely be an embarrassing trip for him, given the nature of the issue. Plus, I am nearly positive that they would take at the very LEAST a few days to fix the pc, probably by resorting to doing a reformat after a lot of screwing around.

In the meantime, I don't want to have to lend the use of my computer for his convenience. He is a WoW player too, so I hope he doesn't go through withdrawal while his PC is down.

Ah, the irony of justice.
 

Maluno

Senior member
Mar 28, 2005
697
0
0
Originally posted by: calvinbiss
RE...format

What... you want more paragraphs??

EDIT: Oh, nevermind, I'm a moron, you meant reformat his HD, I thought you were referring to the format of my post. Yes, I realize that is the only guaranteed solution, but in his case, it isn't that easy, and it would end up being a hassle for me, plus I don't think he would go for that. Heck, I don't even know whether he has the recovery disks that came with his HP.
 

CityShrimp

Member
Dec 14, 2006
177
0
0
Originally posted by: cRazYdood
Yet another instance of why I believe Norton corporate is trash.

Ya. Norton Antivirus never prevented any virus for me
Funny thing was the last time I got a worm, Norton couldn't find it when I did a full system scan. But when I found the worm with Ad-aware, Norton pops up and basically says "oh ya, I found a worm now. i knew it was here all the time. that other program your using wasn't the one who found it. it's all me!"

F-ing ridiculous.
 

Maluno

Senior member
Mar 28, 2005
697
0
0
The point is, guys, that our Network administrators REQUIRE that we have Norton corp. ed., we have no choice in what we use on the network. If we don't have Norton installed, or if we don't have all of the latest windows vulnerability patches installed, then the application that they use to register our computers on the network will detect it, and we can't get on. I personally wouldn't touch Symantec's bloated crap with a ten foot pole, if it was up to my personal preference. Unfortunately, Norton is probably the best known AV company, and whoever administrates our network felt that it would be a good choice for the job.
 

GDaddy

Senior member
Mar 30, 2006
331
0
0
to get rid of it, delete as much of the program as you can, disable Run Once, make sure nothing is loading in msconfig, restart, delete some more, make sure Run Once is still disabled, restart, redo your spybot and nortons, and you should be ok.

I have run into nothing that i can't kill or at least disable enough not to be effective, with alillte digging, time and applied knowledge you should be able to get rid of anything that is put on your computer without formatting. Granted some are alot more difficult then others, the worst is when they "sense" you trying to disable them and they restart the "install" process as you trying to kill it.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |