Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old Mar 8, 2010 | 09:56 AM
  #61  
Entaille's Avatar
Entaille
New Member
iTrader: (16)
 
Joined: Sep 2008
Posts: 9,043
Likes: 21
From: WA
Default

Geaux, if you google the name of the fake av program that is running you'll come across a link with a walkthrough that also contains a fixexe.reg file - basically alters the registry entry that is preventing you from opening any .exe files.

alternatively you can boot your pc into safemode and run malwarebytes.
Reply
Old Mar 8, 2010 | 10:30 AM
  #62  
Hraesvelg's Avatar
Hraesvelg
Got Uranium?
Premier Member
iTrader: (1)
 
Joined: Apr 2003
Posts: 35,723
Likes: 6
From: The Recliner of Rage
Default

Originally Posted by 3hree5ive0ero
I'm not blaming him for anything. I just think it's ridiculous that he did that. What if every single member here who no longer visits this site decided to erase all trace of their activity on here? How much info do you think we'd have?

Remember that in order for forums to exist, knowledge must be shared and retained.
If he was happy with y'all that wouldn't have happened. In order for a forum to exist you need to keep members around.
Reply
Old Mar 8, 2010 | 10:41 AM
  #63  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Just imagine if this malware was in stealth mode collecting personal data and/or using your machine as a server to distribute more crap. Given this latest outbreak, a lot of people would have been unaware.
Reply
Old Mar 8, 2010 | 10:41 AM
  #64  
JCat's Avatar
JCat
---------------
Premier Member
20 Year Member
Liked
Loved
Community Favorite
iTrader: (4)
 
Joined: Mar 2004
Posts: 3,996
Likes: 76
From: JC in Atlanta Georgia
Default

.
Most users ever online was 4,862, 10-06-2008 at 01:27 PM.
.
Reply
Old Mar 8, 2010 | 10:44 AM
  #65  
IB Adrian's Avatar
IB Adrian
IB Staff
iTrader: (1)
 
Joined: Apr 2008
Posts: 756
Likes: 0
From: Across from the neighbours
Default

<test> update insert union embed
Reply
Old Mar 8, 2010 | 10:45 AM
  #66  
IB Adrian's Avatar
IB Adrian
IB Staff
iTrader: (1)
 
Joined: Apr 2008
Posts: 756
Likes: 0
From: Across from the neighbours
Default

update insert union embed
Reply
Old Mar 8, 2010 | 10:47 AM
  #67  
Hraesvelg's Avatar
Hraesvelg
Got Uranium?
Premier Member
iTrader: (1)
 
Joined: Apr 2003
Posts: 35,723
Likes: 6
From: The Recliner of Rage
Default

I sense a disturbance in the Matrix....
Reply
Old Mar 8, 2010 | 10:49 AM
  #68  
MDHRZ's Avatar
MDHRZ
Registered User
iTrader: (14)
 
Joined: Apr 2008
Posts: 4,026
Likes: 0
From: Southern MD
Default

Neo?
Reply
Old Mar 8, 2010 | 10:50 AM
  #69  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

Good, Adrian's here.
Reply
Old Mar 8, 2010 | 11:00 AM
  #70  
Hraesvelg's Avatar
Hraesvelg
Got Uranium?
Premier Member
iTrader: (1)
 
Joined: Apr 2003
Posts: 35,723
Likes: 6
From: The Recliner of Rage
Default

Reply
Old Mar 8, 2010 | 11:00 AM
  #71  
Overlord#1's Avatar
Overlord#1
Registered User
iTrader: (1)
 
Joined: Oct 2007
Posts: 5,215
Likes: 5
From: Denver,Colorado
Default

Too late for me, this virus royally fcked my computer. My work computer is getting nuked tonight, re setting up chit the rest of the week.
Reply
Old Mar 8, 2010 | 11:02 AM
  #72  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

+1. This pwnd my personal laptop and my brand new netbook (just freshly taken out of sealed box today). FML. At least, I cleaned them up and they both work now.
Reply
Old Mar 8, 2010 | 11:10 AM
  #73  
buzzardmountain's Avatar
buzzardmountain
New Member
iTrader: (17)
 
Joined: Feb 2003
Posts: 9,898
Likes: 7
From: Flying Low....
Default

Originally Posted by 3hree5ive0ero
+1. This pwnd my personal laptop and my brand new netbook (just freshly taken out of sealed box today). FML. At least, I cleaned them up and they both work now.
It's probably not the site........
Reply
Old Mar 8, 2010 | 11:10 AM
  #74  
Hraesvelg's Avatar
Hraesvelg
Got Uranium?
Premier Member
iTrader: (1)
 
Joined: Apr 2003
Posts: 35,723
Likes: 6
From: The Recliner of Rage
Default

I've just had pop ups and other windows open to another site. No degradation in performance though.
Reply
Old Mar 8, 2010 | 11:30 AM
  #75  
FRESH Z's Avatar
FRESH Z
Registered User
iTrader: (10)
 
Joined: Sep 2006
Posts: 1,155
Likes: 0
From: SoCal
Default

Im glad i wasnt the only one!

A 2010 antivirus spyware keeps on coming on everytime i visit this site... i finally got rid of it with anti-malware... but still comes back on when i visit my350z!
Reply
Old Mar 8, 2010 | 11:33 AM
  #76  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

Originally Posted by buzzardmountain
It's probably not the site........
I swear I wasn't watching **** on my brand new netbook.

It had to be. My netbook's internet connection, after setting up the OS, was tested using google.com and my350z.com. After a minute or so of browsing the forum (and no other site), I had caught the virus (my fault, though, since I hadn't yet set up the anti-virus on it yet). As for the laptop, I had the anti-virus deactivated temporarily since this past Sunday.
Reply
Old Mar 8, 2010 | 01:15 PM
  #77  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

My work server is blocking certain ads and labeling them as restricted sites now. I hope this doesn't flag someone in IT to come down here and seize this PC. Every time I open an page with one of the blocked ads on it, it's like I am trying to visit a restricted site.

Last edited by phreaktor; Mar 8, 2010 at 01:16 PM.
Reply
Old Mar 8, 2010 | 03:03 PM
  #78  
juju's Avatar
juju
Registered User
 
Joined: Apr 2009
Posts: 1,350
Likes: 0
From: Atlanta, GA
Default

I'm willing to bet that a handful of members are stuck without internet right now. This thing locked me out of Firefox when it was infected.

I had to look up the removal instructions on my iPhone while doing everything by hand on the laptop. Not fun.

I think it just tried to infect me again, but AVG caught it this time. Whatever is causing it is still here.
Reply
Old Mar 8, 2010 | 03:04 PM
  #79  
juju's Avatar
juju
Registered User
 
Joined: Apr 2009
Posts: 1,350
Likes: 0
From: Atlanta, GA
Default

I'm willing to bet that a handful of members are stuck without internet right now. This thing locked me out of Firefox when it was infected.

I had to look up the removal instructions on my iPhone while doing everything by hand on the laptop. Not fun.

I think it just tried to infect me again, but AVG caught it this time. Whatever is causing it is still here.

Last edited by juju; Mar 8, 2010 at 03:05 PM.
Reply
Old Mar 8, 2010 | 04:31 PM
  #80  
GeauxLadyZ's Avatar
GeauxLadyZ
Registered User
iTrader: (9)
 
Joined: Mar 2008
Posts: 3,798
Likes: 3
From: Htown
Default

Originally Posted by Shift_SpecV
Mods/Admins can't do anything about it. Its all in the hands of IB staff. Believe me when I say that we are complaining as well. I gotten the phishing web twice already. 3ree5ive0ero already sent a High priority ticket to the IB staff yesterday. Hopefully it should be resolved soon.

Shift_SpecV
Sorry Mods, unaware of what abilities you guys actually have. Thanks for putting in the complaints, though.

So far so good. Im on my personal laptop now that has a blocker so im safe, but so far no block notifies, so it would appear this problem is fixed....

Originally Posted by 35oZephyR
^^^ shhhh....chill out homie.

You might get banned here quicker than this virus gets taken care of.
Ya ya, written in frustration. Thats gotto be the worst spyware ive ever come accross...the little bisch really does some effin damage and seems worse than the average.

I was afraid my work IT would deem the site as unsafe, and block it. Once blocked, it cant be unblocked, and my job would become much more boring in downtime.

Originally Posted by Entaille
Geaux, if you google the name of the fake av program that is running you'll come across a link with a walkthrough that also contains a fixexe.reg file - basically alters the registry entry that is preventing you from opening any .exe files.

alternatively you can boot your pc into safemode and run malwarebytes.
Yes sir, i went on the earlier pages and followed that link with the instructions. It worked like a charm. I have some admin rights on my work PC but i cant boot in safe mode, among some other things. I CAN install programs and change registry, though. After seeing that it could be undone, i dont understand how so many ppls comps on here got so f'ed up they had to wipe drive, or reinstall windows, or etc.

Was this thing infecting everybody differently or something? The first time it blocked my Rundll32.exe in registry, but i fixed. Second time wasnt as bad, and third even less. Weird.

Thanks, though, brosef. Hope this is fixed for good!

Last edited by GeauxLadyZ; Mar 8, 2010 at 04:37 PM.
Reply



All times are GMT -8. The time now is 07:25 PM.