May 16, 2006

Cut/Copy Denied? R u Infected?

How does it sound like? If you have worked with anything on your computer or done any of your projects yourself, you would be knowing how important CUT-COPY-PASTE Operations are. Well, I donno about you guys, but I certainly use them a lot, actually the shortcuts (lol). What if a user like me or anybody else, is denied of CUT-COPY-PASTE, I dont know how we will live...

Well it is close to a nightmare, and it is also the reality. My comp has denied me of the three most essential operations a computer operator requires.

It all began when I downloaded a software, i mean that was supposed to be a software. But when i executed the setup file, it turned out to be a malware/spyware.

I quickly uninstalled it, but then realised that it was not installed, but who the hell cares. But a while later, I was trying and copying something from Firefox to Word. I simply pressed CTRL+A, CTRL+C, and then could not paste a single letter in Word. Damn. I was shocked for a moment, but then i thought that there is something wrong with my systems Clipboard. I typed some junk,copied it, and then pasted it in word. That worked absolutely fine. That means something was wrong with firefox. Tried it with Opera, Maxthon, and even IE. All were infected. Then I realised that, that small advertisement was the fault.
Scanned all of the the bug reports on firefox but cudnt find anything.

I tried renaming firefox.exe to something like firefoxx.exe, and voila, COPY/PASTE was back. But this was not a FIX, it was just J-Method. You know what means.

Today, i looked and found that nothing was wrong with firefox, it was the malware that was causing it.
Whenever any application is loaded, the malware gets loaded with it. But it only denies copy/paste to certain targetted applications. Actually, it is designed to show ads on these browsers, but due to a bug in the malware/adware, it causes the copy/paste to be denied. WTF...
**The malware does *not* appear as a process and does not affect any files in
the Mozilla directories or Firefox program folder directly.*** This has been
hard for certain people to grasp! This is why when you uninstall and completely
remove Firefox and reinstall it, the problem still persists!

The malware comes in two parts. A nasty .dll file called pushow**.dll where **
is any random number and a windows registry entry for the string
'AppInit_DLLs'. This particular string 'helpfully' ensures the .dll file is
"loaded by each Microsoft Windows-based application that is running in the
current log on session". I pulled that quote straight off the microsoft website
- http://support.microsoft.com/default.aspx?scid=kb;en-us;197571

(I know for a fact that this malware affects Opera and IE too but I'll just
refer to Firefox to make it easier)

Ok, here is what you need to do to remove the Avertisemen.com malware: -

    Important! Close all Firefox, Opera and Internet Explorer windows.
  1. Click Start > Run…

  2. Type “regedit.exe” and press OK.

  3. Get to the following location in the registry: -
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

  4. In the pane on the right-hand side of regedit you should see a String called “AppInit_DLLs” with a value of “pushow**.dll” where ** is some random number.

  5. Right-click on this String and click Delete.

  6. Click Start > Run…

  7. Type “C:\windows\system32\” and press OK.

  8. Click on the Search toolbar button in the explorer window that just appeared.

  9. Click “All files and folders” on the search panel that has appeared on the left hand side of the window.

  10. Where it says “All or part of the file name:” enter “pushow*.dll” and click Search.


Once the search has finished select the pushow**.dll file (there will be multiple copies if you ran the setup file more than once). Delete the file or files.
Start Firefox and feel really good at being able to cut and paste properly again :)
Firefox is a great piece of open source software. It seems it wasn't a bug after all but a piece of malware that affected most major web browsers. If anything, Firefox was the only browser that flagged up any problems and I doubt I would have worked it out otherwise… Hopefully this will have fixed your problem. At the end, A big thumbs up to firefox and open source. \m/

1 Comments:

Anonymous Anonymous said...

hey man
interesting piece of info there


open souce rocks man

\m/

9:53 AM, May 18, 2006  

Post a Comment

<< Home