Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Virus/Malware JambanMu.com and Flash.10.exe, need help in removing this malware

views
     
TSfarique
post Oct 3 2007, 10:20 PM, updated 18y ago

8_8
*******
Senior Member
2,147 posts

Joined: Mar 2005
Hello, this problem is not from my PC. Its from a laptop installed with Windows Vista Ultimate. Each time it boots up, there will be warning saying that JambanMu.com could not be find or Flash.10.exe can not be executed because the file is not there.

So, I ran Hijackthis and here is the scan log.

» Click to show Spoiler - click again to hide... «


could anyone pin point which entry shall I fix? notworthy.gif

Thanks.
TSfarique
post Oct 3 2007, 10:39 PM

8_8
*******
Senior Member
2,147 posts

Joined: Mar 2005
nvm.. the problem solved. tongue.gif

For those who are having the same problem with me, you can just download this KillFlash.10.exe and run it. It works well. thumbup.gif

Kudos, to the programmer for this program. biggrin.gif
lamely_named
post Oct 4 2007, 10:25 AM

I got younger. ROLLZ.
******
Senior Member
1,931 posts

Joined: Jan 2003
From: Human Mixbreeding Farm

why is everyone getting jambanmu.com recently?

is this a virus that spread through a local malaysian porn site?

you naughty.


edan1979
post Oct 4 2007, 10:31 AM

*GruMpy_MoDe*
*******
Senior Member
5,512 posts

Joined: Jun 2006
From: On Earth.



they went to free toilet maybe...

yup i saw lots of it recently... even in my office pc... donno where it came from... just pop up...
lamely_named
post Oct 4 2007, 10:48 AM

I got younger. ROLLZ.
******
Senior Member
1,931 posts

Joined: Jan 2003
From: Human Mixbreeding Farm

http://www.pandasecurity.com/homeusers/sec...da=particulares

according to panda security. "It spreads via mapped drive".

hahhaha, another USB thumbdrive virus.

you guyz been sharing porn through thumbdrive is it?

hehe.


AzkA
post Oct 4 2007, 11:19 AM

sep netok
*****
Senior Member
811 posts

Joined: Sep 2006
From: somewhere i belong
QUOTE(lamely_named @ Oct 4 2007, 10:25 AM)
why is everyone getting jambanmu.com recently?

is this a virus that spread through a local malaysian porn site?

you naughty.
*
jambanmu.com generate some file internet explorer in partion that install window,so who infected this virus should read the message..maybe local people created this virus wink.gif
shiinkuro31
post Oct 4 2007, 01:17 PM

Chef of Straw Hat Pirates
******
Senior Member
1,259 posts

Joined: Feb 2005
From: North Blue



QUOTE(farique @ Oct 3 2007, 10:39 PM)
nvm.. the problem solved. tongue.gif

For those who are having the same problem with me, you can just download this KillFlash.10.exe and run it. It works well. thumbup.gif

Kudos, to the programmer for this program. biggrin.gif
*
is this the one which created a flash icon, folder option got hide, msconfig n regedit cant be accesed?????
rich8833
post Oct 4 2007, 04:53 PM

Look at my stars!
*******
Senior Member
2,194 posts

Joined: Nov 2006
From: Beach Town



QUOTE(farique @ Oct 3 2007, 10:39 PM)
nvm.. the problem solved. tongue.gif

For those who are having the same problem with me, you can just download this KillFlash.10.exe and run it. It works well. thumbup.gif

Kudos, to the programmer for this program. biggrin.gif
*
for those who cannot unzip the above, can download from here.


spayre
post Oct 4 2007, 07:51 PM

hush puppy
******
Senior Member
1,251 posts

Joined: Jan 2003
according to word on the street, the jambanmu virus was created by indonesian.. not malaysian... tongue.gif
AzkA
post Oct 4 2007, 09:46 PM

sep netok
*****
Senior Member
811 posts

Joined: Sep 2006
From: somewhere i belong
QUOTE(spayre @ Oct 4 2007, 07:51 PM)
according to word on the street, the jambanmu virus was created by indonesian.. not malaysian...  tongue.gif
*
created from indonesian....very fast spread..anyone know the purpose this virus? hmm.gif
k!nex
post Oct 4 2007, 10:42 PM

Restless stars
*******
Senior Member
3,389 posts

Joined: Mar 2007
From: KL


is it like brontok???same thing pops up a stupid green colour disgusting screensaver??den got disable folder options and stuff??
another 'good job' from indonesians again...sick of them.
duncan880409
post Oct 4 2007, 10:49 PM

Like Working in My Lab ^^
*******
Senior Member
3,700 posts

Joined: May 2007
From: KT/UTM Skudai



ya, wat i can know, brontok n jamban is from info, thier purpose i really dunno, if somebody can share tis?>

fantagero
post Nov 16 2007, 03:28 AM

[ToFish4RepliesLikeYours]
*******
Senior Member
2,723 posts

Joined: Jan 2006
From: Pekopon Planet ~~~



if u guys noticed. after infected by jamban mu.. u can see at my computer propeties.. the computer registered to changed.. anyone knows how to change it ?? registry maybe??
sani154ta
post Nov 16 2007, 04:57 AM

New Member
*
Junior Member
17 posts

Joined: Dec 2005

hahaha the virus name is kinda funny.... jamban......
cipherz6
post Nov 16 2007, 09:32 AM

Getting Started
**
Junior Member
104 posts

Joined: May 2007
From: Shah Alam, Selangor


QUOTE(duncan880409 @ Oct 4 2007, 10:49 PM)
ya, wat i can know, brontok n jamban is from info, thier purpose i really dunno, if somebody can share tis?>
*
Brontok (the name) came from a certain Indonesia's dialect. Translated into Bahasa Melayu, it means, Berontak @ Memberontak;

In English; Rebel, Rebellious (I guess)


"Brontok Virus came from Indonesia. It arrives as an attachment of e-mail named kangen.exe. When Brontok is first run, it copies itself to the user's application data directory. It then sets itself to start up with Windows, by creating a registry entry in the HKLM\Software\Microsoft\Windows\CurrentVersion\Run registry key. It disables the Windows Registry Editor and modifies Windows Explorer settings. It removes the option of "Folder Options" in the Tools menu so that the hidden files, where it is concealed, are not easily accessible to the user. It also turns off Windows firewall. In some variants, when a window is found containing certain strings in the window title, the computer reboots. Using its own mailing engine, it sends itself to email addresses it finds on the computer, even faking the own user's email address as the sender. The computer also restarts when trying to open MS Dos in Windows and Downloading Files from the Internet. It also pop ups an Internet browser which is located in the my pictures folder."


Hidden Message in Indonesian (and some broken English). When translated, this reads:

"[By: H [REMOVED] Community] -- stop the collapse in this country --
1. Try the Hoodlums, the Smugglers, the Bribers, the gamblers, & drugs
Port (Send to "Nusakambangan") --
2.Stop Free Sex, Abortion, & Prostitution
3.Stop (sea and river pollution), forest burning, & wild hunting.
4.SAY NO TO DRUGS!!! - THE END IS NEAR -

Inspired by: (Spizaetus Cirrhatus) that is almost extinct [By: H [REMOVED] unity --"


From Wikipedia Check it for more info



Before this Brontok, now jamban, Indonesian now days really maju lah
laugh.gif

This post has been edited by cipherz6: Nov 16 2007, 09:41 AM
hafiez
post Nov 16 2007, 10:35 AM

Look at all my stars!!
*******
Senior Member
2,980 posts

Joined: Jan 2007
From: Mount Chiliad



the purpose is simple i guess. to make other people suffer because of certain important program being disable. and they (who the sick developer) think that they're really brilliant because a lot of people suffer because of them. well, famous because of the virus. have you all heard surat utk edelin virus? the joke program.

This post has been edited by hafiez: Nov 16 2007, 10:36 AM
cipherz6
post Nov 16 2007, 10:38 AM

Getting Started
**
Junior Member
104 posts

Joined: May 2007
From: Shah Alam, Selangor


QUOTE(hafiez @ Nov 16 2007, 10:35 AM)
the purpose is simple i guess. to make other people suffer because of certain important program being disable. and they (who the sick developer) think that they're really brilliant because a lot of people suffer because of them. well, famous because of the virus. have you all heard surat utk edelin virus? the joke program.
*
surat utk edelin virus? care to story a lil bit.. wanna know smile.gif

hafiez
post Nov 16 2007, 10:43 AM

Look at all my stars!!
*******
Senior Member
2,980 posts

Joined: Jan 2007
From: Mount Chiliad



rumors said that this guy who are playing with his shadow. in love with this one gurl (but edelin didnt layan him or sumthing), who is my class mate. this guy maybe too shy to f2f with edelin, so he create a joke program named after that virus. well, its not a virus i guess. just a joke program. in that notepad said, i love you or sumthing. i didnt remember. i only opened the notepad once and showed to edelin. she's so piss off. but she just forget about it. nothing can do. the funny part is, she apologize to everybody who get infected by that virus. i mean, in our college la.

btw, u r from shah alam rite? u r student from UiTM? i can say that 90% of the student in our college infected by this virus. hmm.. funny virus.

This post has been edited by hafiez: Nov 16 2007, 10:44 AM
fantagero
post Nov 16 2007, 11:57 AM

[ToFish4RepliesLikeYours]
*******
Senior Member
2,723 posts

Joined: Jan 2006
From: Pekopon Planet ~~~



anyone knows how to solve my prob?
hafiez
post Nov 16 2007, 11:59 AM

Look at all my stars!!
*******
Senior Member
2,980 posts

Joined: Jan 2007
From: Mount Chiliad



QUOTE(fantagero @ Nov 16 2007, 11:57 AM)
anyone knows how to solve my prob?
*
try this..

http://www.astahost.com/info.php/how-chang...n-xp_t2311.html

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0195sec    0.60    5 queries    GZIP Disabled
Time is now: 11th December 2025 - 01:09 PM