Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old Mar 7, 2010 | 07:20 PM
  #41  
Skyace45's Avatar
Skyace45
Registered User
iTrader: (1)
 
Joined: Aug 2009
Posts: 11
Likes: 0
From: Bay Area
Default

Just got infected by xp security 2010 virus while checking out the diy section. Let me tell you, it's one tricky malware to remove. Nevertheless it's out of my comp. Hope the mods can clear it up.
Reply
Old Mar 7, 2010 | 07:40 PM
  #42  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

This has been reported and labeled as high priority. Today is Sunday so most likely it will not be resolved until Monday at the earliest.
Reply
Old Mar 7, 2010 | 07:42 PM
  #43  
Hraesvelg's Avatar
Hraesvelg
Got Uranium?
Premier Member
iTrader: (1)
 
Joined: Apr 2003
Posts: 35,723
Likes: 6
From: The Recliner of Rage
Default

It's JVanquish.
Reply
Old Mar 7, 2010 | 08:05 PM
  #44  
JEKL's Avatar
JEKL
New Member
iTrader: (24)
 
Joined: Dec 2008
Posts: 2,910
Likes: 0
From: Greensboro, NC
Default

Originally Posted by juju
If you are experiencing the fake windows antivirus, here's the removal instructions. I did this and it worked for me:

http://www.2-spyware.com/remove-antivirus-xp-2010.html
That is exactly what happened to me. It blocked me from accessing any websites at all. I used another computer and found those directions. The problem was I couldn't get to it from the infected computer and do a copy and paste to Notepad.

Here are the registry changes I had to make to remove it:

HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\secfile\shell\open\comman d "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_CLASSES_ROOT\secfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFO X.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFO X.EXE\shell\safemode\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLO RE.EXE\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\av.exe" /START "C:\Program Files\Internet Explorer\iexplore.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "AntiVirusOverride" = "1"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center "FirewallOverride" = "1"
Reply
Old Mar 7, 2010 | 08:15 PM
  #45  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Man, now, you guys got me all paranoid. I haven't seen anything that you've brought up on both my machines. But, I think I'm gonna run Malwarebytes anyways. Both machines are running FF+ABP+Kaspersky AV.

Last edited by Black Z Eddie; Mar 7, 2010 at 08:51 PM.
Reply
Old Mar 7, 2010 | 09:15 PM
  #46  
Silly Wabbit's Avatar
Silly Wabbit
Registered User
 
Joined: May 2009
Posts: 310
Likes: 2
From: SoCal
Default

got hit today too by some fake virus scanner.
Reply
Old Mar 8, 2010 | 12:26 AM
  #47  
Crom's Avatar
Crom
Registered User
iTrader: (47)
 
Joined: Sep 2004
Posts: 3,463
Likes: 2
From: Huntington Beach
Default

This blows...got my comp just now and I am running AVG pro...It installs that fake internet security crap....I think IB better make this a higher priority - def not cool at all. currently trying to remove using fix.reg and malwarebytes..

http://www.bleepingcomputer.com/viru...rus-vista-2010
Reply
Old Mar 8, 2010 | 01:45 AM
  #48  
terrasmak's Avatar
terrasmak
Super Moderator
MY350Z.COM
Premier Member
15 Year Member
Liked
Loved
Community Favorite
iTrader: (8)
 
Joined: Jan 2007
Posts: 29,119
Likes: 2,400
From: Sin City
Default

Ya i got popped with the Virus on friday morning. Got my computer up and running again today.
Reply
Old Mar 8, 2010 | 03:22 AM
  #49  
MDHRZ's Avatar
MDHRZ
Registered User
iTrader: (14)
 
Joined: Apr 2008
Posts: 4,026
Likes: 0
From: Southern MD
Default

Another good security practice is to NOT log on as a administrator for daily use. You should only be using an account with user permissions. Registry settings can't be changed under user permissions. Renaming the admin account and setting a password of 15 characters or more will also help.
Reply
Old Mar 8, 2010 | 05:52 AM
  #50  
buzzardmountain's Avatar
buzzardmountain
New Member
iTrader: (17)
 
Joined: Feb 2003
Posts: 9,898
Likes: 7
From: Flying Low....
Default

Good to see it's a high priority for most of the mods........
Reply
Old Mar 8, 2010 | 07:17 AM
  #51  
gregtotheb's Avatar
gregtotheb
Registered User
iTrader: (49)
 
Joined: Feb 2007
Posts: 1,758
Likes: 0
From: Pasadena, CA
Default

this bug was preventing me from installing any programs. just reformatted and installed avg, hopefully it keeps anything else OFF my comp.
Reply
Old Mar 8, 2010 | 07:22 AM
  #52  
BornSlippyZ's Avatar
BornSlippyZ
Registered User
iTrader: (1)
 
Joined: Dec 2006
Posts: 7,418
Likes: 2
From: Minnesota!
Default

This thing jack my 'puter up too. Got it all fixed now.
Reply
Old Mar 8, 2010 | 07:25 AM
  #53  
Entaille's Avatar
Entaille
New Member
iTrader: (16)
 
Joined: Sep 2008
Posts: 9,043
Likes: 21
From: WA
Default

Originally Posted by MDHRZ
Another good security practice is to NOT log on as a administrator for daily use. You should only be using an account with user permissions. Registry settings can't be changed under user permissions. Renaming the admin account and setting a password of 15 characters or more will also help.
while this is definitely best practice and something I recomend doing (really, how hard is it to shift right click something and run as the admin account when needed?), this will *not* prevent this particular infection from installing.

I've seen this on a few machines at work and on one of my home pc's when my pal was using it.

also, while this has popped up three times for me, I've just closed my browser and it prevented the install.
Reply
Old Mar 8, 2010 | 07:36 AM
  #54  
JCat's Avatar
JCat
---------------
Premier Member
20 Year Member
Liked
Loved
Community Favorite
iTrader: (4)
 
Joined: Mar 2004
Posts: 3,996
Likes: 76
From: JC in Atlanta Georgia
Default

Caught the AV.exe here Friday 3/5/2010 at 3:57pm
Reply
Old Mar 8, 2010 | 08:42 AM
  #55  
35oZephyR's Avatar
35oZephyR
Registered User
iTrader: (4)
 
Joined: Apr 2003
Posts: 8,617
Likes: 1
From: san diego
Default

Got rocked twice! Is this still an issue?
Reply
Old Mar 8, 2010 | 09:18 AM
  #56  
GeauxLadyZ's Avatar
GeauxLadyZ
Registered User
iTrader: (9)
 
Joined: Mar 2008
Posts: 3,798
Likes: 3
From: Htown
Default

I got infected 3 times last week....IT fixed my comp and i went on My350 this morning at work and got it as soon as the My350Z page loaded....

This is rediculous!!!!!!!!!!!!!!!!! MODS PLEASE FIX!!!!

Ok guys i keep getting this like crazy, and i found out that when you go into task manager, the malware's id in task manager is AV.exe or something with AV.****.

If you end that process, you will be able to access everything (IE, Programs, etc) but it somehow is still blocking my Malwarebytes program so i cant remove it. Also, it is still running after you end this process because the icon for it is still in my tray on the start bar.

MODS, please fix this if you can, IT is getting pissed at me because they keep having to fix my CPU, lol.
Reply
Old Mar 8, 2010 | 09:24 AM
  #57  
Shift_SpecV's Avatar
Shift_SpecV
350Z-holic
Premier Member
iTrader: (3)
 
Joined: Dec 2005
Posts: 5,301
Likes: 0
From: H-town
Default

Mods/Admins can't do anything about it. Its all in the hands of IB staff. Believe me when I say that we are complaining as well. I gotten the phishing web twice already. 3ree5ive0ero already sent a High priority ticket to the IB staff yesterday. Hopefully it should be resolved soon.

Shift_SpecV
Reply
Old Mar 8, 2010 | 09:25 AM
  #58  
35oZephyR's Avatar
35oZephyR
Registered User
iTrader: (4)
 
Joined: Apr 2003
Posts: 8,617
Likes: 1
From: san diego
Default

Originally Posted by GeauxLadyZ
I got infected 3 times last week....IT fixed my comp and i went on My350 this morning at work and got it as soon as the My350Z page loaded....

This is rediculous!!!!!!!!!!!!!!!!! MODS PLEASE FIX!!!!

Ok guys i keep getting this like crazy, and i found out that when you go into task manager, the malware's id in task manager is AV.exe or something with AV.****.

If you end that process, you will be able to access everything (IE, Programs, etc) but it somehow is still blocking my Malwarebytes program so i cant remove it. Also, it is still running after you end this process because the icon for it is still in my tray on the start bar.

MODS, please fix this if you can, IT is getting pissed at me because they keep having to fix my CPU, lol.



^^^ shhhh....chill out homie.

You might get banned here quicker than this virus gets taken care of.
Reply
Old Mar 8, 2010 | 09:29 AM
  #59  
SOLO-350Z's Avatar
SOLO-350Z
'12 TL SH-AWD
Premier Member
iTrader: (26)
 
Joined: Feb 2004
Posts: 6,348
Likes: 1
From: Alamo
Default

Originally Posted by 3hree5ive0ero
I'll let IB know.


I don't know why some of you guys have this issue. I've been on this site for years and I've never had an issue.



BTW, MC never owned this site. He became an admin back in the day because he used to contribute a lot to this forum (mostly Nismo stuff). Too bad when he was asked to step down, he deleted all the contributions he made.
I don't blame MC for doing so either as it was his contributions. Nothing against this site or you, it just makes sense.
Reply
Old Mar 8, 2010 | 09:51 AM
  #60  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

Originally Posted by SOLO-350Z
I don't blame MC for doing so either as it was his contributions. Nothing against this site or you, it just makes sense.
I'm not blaming him for anything. I just think it's ridiculous that he did that. What if every single member here who no longer visits this site decided to erase all trace of their activity on here? How much info do you think we'd have?

Remember that in order for forums to exist, knowledge must be shared and retained.
Reply



All times are GMT -8. The time now is 06:39 AM.