Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old Mar 8, 2010 | 08:21 PM
  #81  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

ad feeds should have been cut on Friday until they could track down the offender. heads should roll for this (or at least the ad network). 4 hours is understandable, 4 days can't be excused. It's happened to the biggest net properties, but it rarely goes on for more than a few minutes or hours at most. I hope IB demands some accountability from whomever approved these malicious ads. While I believe it's the ultimate responsibility for everyone to protect their own machines and practice safe browsing, this isnt the type of place you'd expect to have to sandbox your browser to visit.

I feel bad for anyone who had their work machine exploited. Again, ultimately, it's your responsibility for your own machine at work, but I bet alot of people have some explaining to do that they really shouldn't have had to worry about.
Reply
Old Mar 8, 2010 | 08:25 PM
  #82  
nismo*son's Avatar
nismo*son
Registered User
iTrader: (3)
 
Joined: Feb 2007
Posts: 402
Likes: 0
From: boston
Default

got the virus twice yesterday, both times when I was in the fitness section. Sent 2hr getting rid of it.
Reply
Old Mar 8, 2010 | 08:34 PM
  #83  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

Originally Posted by tware
ad feeds should have been cut on Friday until they could track down the offender. heads should roll for this (or at least the ad network). 4 hours is understandable, 4 days can't be excused. It's happened to the biggest net properties, but it rarely goes on for more than a few minutes or hours at most. I hope IB demands some accountability from whomever approved these malicious ads. While I believe it's the ultimate responsibility for everyone to protect their own machines and practice safe browsing, this isnt the type of place you'd expect to have to sandbox your browser to visit.

I feel bad for anyone who had their work machine exploited. Again, ultimately, it's your responsibility for your own machine at work, but I bet alot of people have some explaining to do that they really shouldn't have had to worry about.
Like I said before, if you get this on your PC at work, your IT department may be getting flag emails if you keep coming to the site and the restricted ad keeps popping up under the phishing or virus category. It looks like you are trying to access the malicious site. This could get you in BIG trouble, particulary if they confiscate your PC for forensics.
Reply
Old Mar 8, 2010 | 10:39 PM
  #84  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

I hope that people who are reporting repeat infections late today are really just seeing the same infection. It can't possibly be still lurking around... I'd really like to think that.

Out of respect for the site, I generally wouldn't visit with an Ad Blocker and noscript. But I'm not sure there's a safe option until we hear how this happened and how it should be prevented in the future.

I wonder if anyone got this will fully patched flash? no flash installed? I've been blocking flash (although it is installed) for weeks. a complete PITA, but I'm not sure when it will be safe to run Flash again.
Reply
Old Mar 9, 2010 | 04:01 AM
  #85  
Driven1's Avatar
Driven1
Professional
iTrader: (2)
 
Joined: Jan 2006
Posts: 4,397
Likes: 0
From: Virginia
Default

Originally Posted by tware
ad feeds should have been cut on Friday until they could track down the offender. heads should roll for this (or at least the ad network). 4 hours is understandable, 4 days can't be excused. It's happened to the biggest net properties, but it rarely goes on for more than a few minutes or hours at most. I hope IB demands some accountability from whomever approved these malicious ads. While I believe it's the ultimate responsibility for everyone to protect their own machines and practice safe browsing, this isnt the type of place you'd expect to have to sandbox your browser to visit.

I feel bad for anyone who had their work machine exploited. Again, ultimately, it's your responsibility for your own machine at work, but I bet alot of people have some explaining to do that they really shouldn't have had to worry about.
4days? Viruses thru the ads were reported back on Feb 26th in another thread I believe.

Honestly, it's kinda sad that until "bigger" names and mods entered into the equation nothing seemed to be getting done about it.

Even a warning would have been nice...instead of hiding a little thread in the "Feedback" section where maybe 20% of the people go?
Reply
Old Mar 9, 2010 | 05:41 AM
  #86  
Mike@Blackline's Avatar
Mike@Blackline
Banned
iTrader: (37)
 
Joined: Jul 2008
Posts: 3,525
Likes: 0
From: Charlotte / Raleigh, NC
Default

Originally Posted by LVZ053
same here, happen to me twice already. Stupid Vista defender.
ARE YOU SERIOUS? that is from this site? i got it randomly yesterday and if this site is the reason for this nearly-impossible-to-delete ****, then we'll put our vendorship on hold until its resolved. i spent hours yesterday trying to shake XP defender and cant. truly ridiculous that its coming from this site, whether its from an ad feed or whatever.

This computer sees 3 websites and 3 alone, so it probably is here.....*super face palm*
Reply
Old Mar 9, 2010 | 08:00 AM
  #87  
IIQuickSilverII's Avatar
IIQuickSilverII
New Member
iTrader: (13)
 
Joined: Oct 2005
Posts: 14,613
Likes: 215
From: Arizona -InP-
Default

yah getting rid of the stupid vista 2010 defender was a bit tricky on my other vista laptop at home, there is no simple "just install and run this program", i had to play with the registry manually, i wasnt sure the fix.reg was gonig to do it...... the one i am using now was well protected (win7)......still

this is BS and i hope to hear more from the staff on this.

Last edited by IIQuickSilverII; Mar 9, 2010 at 08:09 AM.
Reply
Old Mar 9, 2010 | 08:25 AM
  #88  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

seriously, I posted wayyyy up on the first page, this can be knocked out in a matter of minutes, if not seconds. Head over to the malwarebytes site, then contact us, then forums. Or use my links. down the page there are instructions to remove just about every infection out there right now. They tell you how to get Process Explorer to stop the process, then how to rename malwarebytes so it will run unseen by the other part of the rogue software. After that, youre one scan and reboot away from being rogue free. However, that wont stop you from being jacked again.....

Just to come back to see this thread, I'm running Firefox, with noscript blocking flash and ADP ad blocker add-on.... and I'm in a sandboxed browser thru Kaspersky's Run Safe. But free sandboxie would have also worked.
Reply
Old Mar 9, 2010 | 09:01 AM
  #89  
JEKL's Avatar
JEKL
New Member
iTrader: (24)
 
Joined: Dec 2008
Posts: 2,910
Likes: 0
From: Greensboro, NC
Default

AVG just saved my butt while surfing this site! Thanks for recommending it to me.
Reply
Old Mar 9, 2010 | 09:07 AM
  #90  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by JEKL
AVG just saved my butt while surfing this site! Thanks for recommending it to me.
I would consider that a failure of sorts. It tried to execute, which probably means malicious code managed to wiggle into your temp storage. You got lucky. Don't leave it up to your AV to protect you. Lock down your browser.

Last edited by tware; Mar 9, 2010 at 09:13 AM.
Reply
Old Mar 9, 2010 | 09:11 AM
  #91  
JEKL's Avatar
JEKL
New Member
iTrader: (24)
 
Joined: Dec 2008
Posts: 2,910
Likes: 0
From: Greensboro, NC
Default

Originally Posted by tware
I would consider that a failure of sorts. It tried to execute, which probably means malicious code managed wiggle into your temp storage. You got lucky. Don't leave it up to your AV to protect you. Lock down your browser.
Good point. I added Comodo Firewall and MS Security Essentials too. What would you recommend for the browser?
Reply
Old Mar 9, 2010 | 10:18 AM
  #92  
sweettalker's Avatar
sweettalker
Banned
iTrader: (24)
 
Joined: Dec 2005
Posts: 106
Likes: 0
From: LA, CA
Default

I got it 3 times already. I had no idea it was from this site. HOW SAD no one is doing anything about it. I found an easy solution tho. It leeches on to your registery files so all you have to do is fix the registery files into the original default mode. There's no reset button so you have to download a file called FixExe.reg it's small file. You just download it and double click it and it does everything by itself. Viola. back to normal. Those xp antivirus 2010 or other similar named ones are VERY annoying. MAKE SURE you Run it in safemode to get to the website so it won't block you. Or download the file from another comp and transfer it using usb drive or something. That malware site the guy above me said has that file too.
Reply
Old Mar 9, 2010 | 10:19 AM
  #93  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

"What would you recommend for the browser?"
My recommendation would make the internet suck for a few days until you manually whitelisted all the trusted scripts. And vids dont load until I click on the box and allow them to run. FF with noscript and ABP add ons for me. My wife is not exactly tech savy but within a few minutes, she was figuring out how to whitelist scripts with noscript. If you go to ebay or paypal, and 1/2 the page is blank, youre missing a script. You right click on the little noscript S in the bottom corner and "allow ebay.com" or "allow my350z" and so forth.
Reply
Old Mar 9, 2010 | 10:20 AM
  #94  
MDHRZ's Avatar
MDHRZ
Registered User
iTrader: (14)
 
Joined: Apr 2008
Posts: 4,026
Likes: 0
From: Southern MD
Default

Originally Posted by JEKL
Good point. I added Comodo Firewall and MS Security Essentials too. What would you recommend for the browser?
Firefox, then install NoScript and Ad Block Plus.
Reply
Old Mar 9, 2010 | 10:22 AM
  #95  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

btw, the most nefarious thing is the next version of this actually mimics legit AV.. I mean, down to the logos.. not only do you not know it's disabled your real AV, but when you 'renew', which pops up right away, they are actually getting your info. F'n evil... so keep an eye on that. The fakes are easy to spot if youre paying attention.
Reply
Old Mar 9, 2010 | 10:40 AM
  #96  
klenkart's Avatar
klenkart
Registered User
iTrader: (1)
 
Joined: Nov 2009
Posts: 69
Likes: 0
From: Chicago il
Default

My computer was fine until yesterday. I went into the classified exhaust section and the vista thing started popping up. I tried the removal steps but I couldn't get it to work.
Reply
Old Mar 9, 2010 | 12:26 PM
  #97  
HyperKnight's Avatar
HyperKnight
Stulax makes me cream
20 Year Member
Liked
Loved
Community Favorite
iTrader: (1)
 
Joined: Oct 2002
Posts: 16,401
Likes: 631
From: Fort Worth, Texas
Default

Do a System Restore if you have a recent one. My computer makes one every night while I'm asleep.
Reply
Old Mar 9, 2010 | 03:33 PM
  #98  
Diesel350's Avatar
Diesel350
Registered User
iTrader: (6)
 
Joined: May 2003
Posts: 8,378
Likes: 1
From: Tampa
Default

Argh, I got this popped up a few minutes ago. AVG says it blocked it but not sure if anything go through. System seems to be running fine
Reply
Old Mar 9, 2010 | 03:36 PM
  #99  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Originally Posted by Diesel350
Argh, I got this popped up a few minutes ago. AVG says it blocked it but not sure if anything go through. System seems to be running fine
I'd run Malwarebytes just to be on the safe side.
Reply
Old Mar 9, 2010 | 03:37 PM
  #100  
Diesel350's Avatar
Diesel350
Registered User
iTrader: (6)
 
Joined: May 2003
Posts: 8,378
Likes: 1
From: Tampa
Default

Originally Posted by Black Z Eddie
I'd run Malwarebytes just to be on the safe side.
Thanks doing that now.
Reply



All times are GMT -8. The time now is 02:47 AM.