Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old 03-07-2010, 07:20 PM
  #41  
Skyace45
Registered User
iTrader: (1)
 
Skyace45's Avatar
 
Join Date: Aug 2009
Location: Bay Area
Posts: 11
Likes: 0
Received 0 Likes on 0 Posts
Default

Just got infected by xp security 2010 virus while checking out the diy section. Let me tell you, it's one tricky malware to remove. Nevertheless it's out of my comp. Hope the mods can clear it up.
Old 03-07-2010, 07:40 PM
  #42  
3hree5ive0ero
Retired Admin
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

This has been reported and labeled as high priority. Today is Sunday so most likely it will not be resolved until Monday at the earliest.
Old 03-07-2010, 07:42 PM
  #43  
Hraesvelg
Got Uranium?
iTrader: (1)
 
Hraesvelg's Avatar
 
Join Date: Apr 2003
Location: The Recliner of Rage
Posts: 35,723
Received 6 Likes on 4 Posts
Default

It's JVanquish.
Old 03-07-2010, 08:05 PM
  #44  
JEKL
New Member
iTrader: (24)
 
JEKL's Avatar
 
Join Date: Dec 2008
Location: Greensboro, NC
Posts: 2,910
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by juju
If you are experiencing the fake windows antivirus, here's the removal instructions. I did this and it worked for me:

http://www.2-spyware.com/remove-antivirus-xp-2010.html
That is exactly what happened to me. It blocked me from accessing any websites at all. I used another computer and found those directions. The problem was I couldn't get to it from the infected computer and do a copy and paste to Notepad.

Here are the registry changes I had to make to remove it:

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\comman d "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFO X.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFO X.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLO RE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Old 03-07-2010, 08:15 PM
  #45  
Black Z Eddie
New Member
 
Black Z Eddie's Avatar
 
Join Date: Jun 2007
Location: San Pedro
Posts: 947
Received 9 Likes on 3 Posts
Default

Man, now, you guys got me all paranoid. I haven't seen anything that you've brought up on both my machines. But, I think I'm gonna run Malwarebytes anyways. Both machines are running FF+ABP+Kaspersky AV.

Last edited by Black Z Eddie; 03-07-2010 at 08:51 PM.
Old 03-07-2010, 09:15 PM
  #46  
Silly Wabbit
Registered User
 
Silly Wabbit's Avatar
 
Join Date: May 2009
Location: SoCal
Posts: 310
Likes: 0
Received 2 Likes on 2 Posts
Default

got hit today too by some fake virus scanner.
Old 03-08-2010, 12:26 AM
  #47  
Crom
Registered User
iTrader: (47)
 
Crom's Avatar
 
Join Date: Sep 2004
Location: Huntington Beach
Posts: 3,463
Likes: 0
Received 2 Likes on 2 Posts
Default

This blows...got my comp just now and I am running AVG pro...It installs that fake internet security crap....I think IB better make this a higher priority - def not cool at all. currently trying to remove using fix.reg and malwarebytes..

http://www.bleepingcomputer.com/viru...rus-vista-2010
Old 03-08-2010, 01:45 AM
  #48  
terrasmak
Super Moderator
MY350Z.COM
iTrader: (8)
 
terrasmak's Avatar
 
Join Date: Jan 2007
Location: Sin City
Posts: 28,637
Received 2,283 Likes on 1,645 Posts
Default

Ya i got popped with the Virus on friday morning. Got my computer up and running again today.
Old 03-08-2010, 03:22 AM
  #49  
MDHRZ
Registered User
iTrader: (14)
 
MDHRZ's Avatar
 
Join Date: Apr 2008
Location: Southern MD
Posts: 4,026
Likes: 0
Received 0 Likes on 0 Posts
Default

Another good security practice is to NOT log on as a administrator for daily use. You should only be using an account with user permissions. Registry settings can't be changed under user permissions. Renaming the admin account and setting a password of 15 characters or more will also help.
Old 03-08-2010, 05:52 AM
  #50  
buzzardmountain
New Member
iTrader: (17)
 
buzzardmountain's Avatar
 
Join Date: Feb 2003
Location: Flying Low....
Posts: 9,898
Likes: 0
Received 7 Likes on 4 Posts
Default

Good to see it's a high priority for most of the mods........
Old 03-08-2010, 07:17 AM
  #51  
gregtotheb
Registered User
iTrader: (49)
 
gregtotheb's Avatar
 
Join Date: Feb 2007
Location: Pasadena, CA
Posts: 1,759
Likes: 0
Received 0 Likes on 0 Posts
Default

this bug was preventing me from installing any programs. just reformatted and installed avg, hopefully it keeps anything else OFF my comp.
Old 03-08-2010, 07:22 AM
  #52  
BornSlippyZ
Registered User
iTrader: (1)
 
BornSlippyZ's Avatar
 
Join Date: Dec 2006
Location: Minnesota!
Posts: 7,419
Likes: 0
Received 2 Likes on 2 Posts
Default

This thing jack my 'puter up too. Got it all fixed now.
Old 03-08-2010, 07:25 AM
  #53  
Entaille
New Member
iTrader: (16)
 
Entaille's Avatar
 
Join Date: Sep 2008
Location: WA
Posts: 9,043
Received 21 Likes on 16 Posts
Default

Originally Posted by MDHRZ
Another good security practice is to NOT log on as a administrator for daily use. You should only be using an account with user permissions. Registry settings can't be changed under user permissions. Renaming the admin account and setting a password of 15 characters or more will also help.
while this is definitely best practice and something I recomend doing (really, how hard is it to shift right click something and run as the admin account when needed?), this will *not* prevent this particular infection from installing.

I've seen this on a few machines at work and on one of my home pc's when my pal was using it.

also, while this has popped up three times for me, I've just closed my browser and it prevented the install.
Old 03-08-2010, 07:36 AM
  #54  
JCat
---------------
iTrader: (4)
 
JCat's Avatar
 
Join Date: Mar 2004
Location: JC in Atlanta Georgia
Posts: 3,985
Received 73 Likes on 48 Posts
Default

Caught the AV.exe here Friday 3/5/2010 at 3:57pm
Old 03-08-2010, 08:42 AM
  #55  
35oZephyR
Registered User
iTrader: (4)
 
35oZephyR's Avatar
 
Join Date: Apr 2003
Location: san diego
Posts: 8,617
Likes: 0
Received 1 Like on 1 Post
Default

Got rocked twice! Is this still an issue?
Old 03-08-2010, 09:18 AM
  #56  
GeauxLadyZ
Registered User
iTrader: (9)
 
GeauxLadyZ's Avatar
 
Join Date: Mar 2008
Location: Htown
Posts: 3,798
Likes: 0
Received 3 Likes on 3 Posts
Default

I got infected 3 times last week....IT fixed my comp and i went on My350 this morning at work and got it as soon as the My350Z page loaded....

This is rediculous!!!!!!!!!!!!!!!!! MODS PLEASE FIX!!!!

Ok guys i keep getting this like crazy, and i found out that when you go into task manager, the malware's id in task manager is AV.exe or something with AV.****.

If you end that process, you will be able to access everything (IE, Programs, etc) but it somehow is still blocking my Malwarebytes program so i cant remove it. Also, it is still running after you end this process because the icon for it is still in my tray on the start bar.

MODS, please fix this if you can, IT is getting pissed at me because they keep having to fix my CPU, lol.
Old 03-08-2010, 09:24 AM
  #57  
Shift_SpecV
350Z-holic
iTrader: (3)
 
Shift_SpecV's Avatar
 
Join Date: Dec 2005
Location: H-town
Posts: 5,301
Likes: 0
Received 0 Likes on 0 Posts
Default

Mods/Admins can't do anything about it. Its all in the hands of IB staff. Believe me when I say that we are complaining as well. I gotten the phishing web twice already. 3ree5ive0ero already sent a High priority ticket to the IB staff yesterday. Hopefully it should be resolved soon.

Shift_SpecV
Old 03-08-2010, 09:25 AM
  #58  
35oZephyR
Registered User
iTrader: (4)
 
35oZephyR's Avatar
 
Join Date: Apr 2003
Location: san diego
Posts: 8,617
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by GeauxLadyZ
I got infected 3 times last week....IT fixed my comp and i went on My350 this morning at work and got it as soon as the My350Z page loaded....

This is rediculous!!!!!!!!!!!!!!!!! MODS PLEASE FIX!!!!

Ok guys i keep getting this like crazy, and i found out that when you go into task manager, the malware's id in task manager is AV.exe or something with AV.****.

If you end that process, you will be able to access everything (IE, Programs, etc) but it somehow is still blocking my Malwarebytes program so i cant remove it. Also, it is still running after you end this process because the icon for it is still in my tray on the start bar.

MODS, please fix this if you can, IT is getting pissed at me because they keep having to fix my CPU, lol.



^^^ shhhh....chill out homie.

You might get banned here quicker than this virus gets taken care of.
Old 03-08-2010, 09:29 AM
  #59  
SOLO-350Z
'12 TL SH-AWD
iTrader: (26)
 
SOLO-350Z's Avatar
 
Join Date: Feb 2004
Location: Alamo
Posts: 6,348
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by 3hree5ive0ero
I'll let IB know.


I don't know why some of you guys have this issue. I've been on this site for years and I've never had an issue.



BTW, MC never owned this site. He became an admin back in the day because he used to contribute a lot to this forum (mostly Nismo stuff). Too bad when he was asked to step down, he deleted all the contributions he made.
I don't blame MC for doing so either as it was his contributions. Nothing against this site or you, it just makes sense.
Old 03-08-2010, 09:51 AM
  #60  
3hree5ive0ero
Retired Admin
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

Originally Posted by SOLO-350Z
I don't blame MC for doing so either as it was his contributions. Nothing against this site or you, it just makes sense.
I'm not blaming him for anything. I just think it's ridiculous that he did that. What if every single member here who no longer visits this site decided to erase all trace of their activity on here? How much info do you think we'd have?

Remember that in order for forums to exist, knowledge must be shared and retained.


Quick Reply: Virus and keyloggers on my350z



All times are GMT -8. The time now is 05:05 AM.