Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Old 03-09-2010, 04:14 PM
  #101  
SlideFox
Registered User
 
SlideFox's Avatar
 
Join Date: Dec 2007
Location: Arizona
Posts: 4,470
Likes: 0
Received 5 Likes on 3 Posts
Default

I got it twice at home and once at work. I closed out of it, and ran webroot on my home PC. Haven't had any issues so far. IT at work was pissed. I played stupid.
Old 03-09-2010, 05:17 PM
  #102  
Diesel350
Registered User
iTrader: (6)
 
Diesel350's Avatar
 
Join Date: May 2003
Location: Tampa
Posts: 8,378
Likes: 0
Received 1 Like on 1 Post
Default

So I ran Malwarebytes and it did remove and quarantine a Fake Alert Trojan.
Old 03-09-2010, 05:22 PM
  #103  
03aeroZ
Registered User
iTrader: (11)
 
03aeroZ's Avatar
 
Join Date: Aug 2005
Location: monticello, illinois
Posts: 1,596
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Phreakdout
I too was hit yesterday. This fake antivirus program comes up and it looks just like a real Windows program. I can't seem to get rid of it.

Can ads be temporarily shut down till the source is found?

BTW: I am running Firefox on XP
I spent 4 days in safe mode trying to get rid of that one! Have fun.
Old 03-09-2010, 05:24 PM
  #104  
HeyItsDan
Registered User
iTrader: (18)
 
HeyItsDan's Avatar
 
Join Date: Oct 2008
Location: Rockville
Posts: 451
Likes: 0
Received 0 Likes on 0 Posts
Default

Got it on my work computer. Ran Malwarebytes and after scanning, I was able to remove it in about 45 min!
Old 03-09-2010, 09:31 PM
  #105  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

really????????? no official info? no apology? nothing?
Old 03-09-2010, 09:52 PM
  #106  
xDIEGOx
Registered User
 
xDIEGOx's Avatar
 
Join Date: Sep 2006
Location: San Diego, CA
Posts: 8,026
Likes: 0
Received 1 Like on 1 Post
Default

So this is why I got the "your computer has been infected" message.
Old 03-09-2010, 10:27 PM
  #107  
3hree5ive0ero
Retired Admin
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

They're trying to look for the malicious code but can't find anything. They haven't been able to duplicate it yet.

I was told that it could "be possible that perhaps someone has some sort of an image link in their signature or avatar that is attempting to execute some code."
Old 03-10-2010, 04:29 AM
  #108  
Driven1
Professional
iTrader: (2)
 
Driven1's Avatar
 
Join Date: Jan 2006
Location: Virginia
Posts: 4,398
Likes: 0
Received 0 Likes on 0 Posts
Default

^^Then wouldn't it be prudent to post a "warning" thread in a more visited and visible area to warn people they can't find it and this site indeed is passing malicious code?

It's not a signature....its a seemingly random occurrence and you can track it by some posts as people posted when they got it or flagged the thread/post.

It kind of seems like this is no big deal to them and they aren't really putting too much time into it...it was first reported on 2/26.....

If something doesn't happen soon I will be canceling my account and Im sure many members won't be back (most of them won't be able to get it off their pc).
Old 03-10-2010, 07:28 AM
  #109  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 3hree5ive0ero
They're trying to look for the malicious code but can't find anything. They haven't been able to duplicate it yet.

I was told that it could "be possible that perhaps someone has some sort of an image link in their signature or avatar that is attempting to execute some code."
of course that's possible. ANYTHING is possible. But, people have reported the exploit by simply coming to check PMs. If I were responsible for this site and I even remotely suspected avatars and/or signatures, I would, ummmm, turn them off!!! But I suspect they dont really think it's a single users avatar or sig.
Old 03-10-2010, 08:30 AM
  #110  
IIQuickSilverII
New Member
iTrader: (13)
 
IIQuickSilverII's Avatar
 
Join Date: Oct 2005
Location: Arizona -InP-
Posts: 14,613
Received 215 Likes on 184 Posts
Default

Originally Posted by JEKL
Good point. I added Comodo Firewall and MS Security Essentials too. What would you recommend for the browser?
if you really like scripts...flash... but at the same time you are really concerned about this... how about setting the settings to prompt anytime a website request one of this things to run....
I have set most of those setting to prompt see if i can track it when something weird tries to "play/self-install".....
Old 03-10-2010, 09:10 AM
  #111  
Entaille
New Member
iTrader: (16)
 
Entaille's Avatar
 
Join Date: Sep 2008
Location: WA
Posts: 9,043
Received 21 Likes on 16 Posts
Default

I've seen it triggered just browsing forum to sub forum, with no posting or sigs involved. They are not looking hard enough. : P
Old 03-10-2010, 09:16 AM
  #112  
JEKL
New Member
iTrader: (24)
 
JEKL's Avatar
 
Join Date: Dec 2008
Location: Greensboro, NC
Posts: 2,910
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 3hree5ive0ero
BTW, MC never owned this site. He became an admin back in the day because he used to contribute a lot to this forum (mostly Nismo stuff). Too bad when he was asked to step down, he deleted all the contributions he made.
Originally Posted by 3hree5ive0ero
I'm not blaming him for anything. I just think it's ridiculous that he did that. What if every single member here who no longer visits this site decided to erase all trace of their activity on here? How much info do you think we'd have?

Remember that in order for forums to exist, knowledge must be shared and retained.
So he was pushed out of his position on a forum that he contributed a lot to and decided to take all his information with him?

Sounds about right to me.
Old 03-10-2010, 09:19 AM
  #113  
JEKL
New Member
iTrader: (24)
 
JEKL's Avatar
 
Join Date: Dec 2008
Location: Greensboro, NC
Posts: 2,910
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by tware
"What would you recommend for the browser?"
My recommendation would make the internet suck for a few days until you manually whitelisted all the trusted scripts. And vids dont load until I click on the box and allow them to run. FF with noscript and ABP add ons for me. My wife is not exactly tech savy but within a few minutes, she was figuring out how to whitelist scripts with noscript. If you go to ebay or paypal, and 1/2 the page is blank, youre missing a script. You right click on the little noscript S in the bottom corner and "allow ebay.com" or "allow my350z" and so forth.
Originally Posted by MDHRZ
Firefox, then install NoScript and Ad Block Plus.
Originally Posted by IIQuickSilverII
if you really like scripts...flash... but at the same time you are really concerned about this... how about setting the settings to prompt anytime a website request one of this things to run....
I have set most of those setting to prompt see if i can track it when something weird tries to "play/self-install".....
Thanks guys. I need to educate myself more on configuring my browser so this doesn't keep happening.
Old 03-10-2010, 09:20 AM
  #114  
bryan@Z1
Vendor - Former Vendor
iTrader: (23)
 
bryan@Z1's Avatar
 
Join Date: Jan 2008
Location: Carrollton, GA
Posts: 2,890
Likes: 0
Received 3 Likes on 3 Posts
Default

Spybot took care of it me. My PC at work got hit by this on Monday.
Old 03-10-2010, 09:22 AM
  #115  
blasian
Registered User
iTrader: (29)
 
blasian's Avatar
 
Join Date: Apr 2005
Location: Get out my way pimpin, LA
Posts: 33,731
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by bryan@Z1
Spybot took care of it me. My PC at work got hit by this on Monday.
John need me to fix his laptop again?
Old 03-10-2010, 09:25 AM
  #116  
bamyi
Registered User
iTrader: (2)
 
bamyi's Avatar
 
Join Date: Aug 2004
Location: Denver, CA
Posts: 3,789
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Hraesvelg
It's JVanquish.
I too blame everything on him.
Old 03-10-2010, 09:51 AM
  #117  
IllumEstVeritas
Registered User
 
IllumEstVeritas's Avatar
 
Join Date: Feb 2004
Location: Cali
Posts: 6,395
Likes: 0
Received 2 Likes on 2 Posts
Default

Maybe I got it from here - it was a nightmare to remove all that. I had something else though b/c it would let me install malwarebytes, my search was always redirected on yahoo/google. Nasty Nasty - had to remove all extensions and redo before it would allow any anti-virus to be run. =\
Old 03-10-2010, 09:55 AM
  #118  
Divergent13
Registered User
 
Divergent13's Avatar
 
Join Date: Feb 2007
Location: Northwest
Posts: 6,573
Likes: 0
Received 0 Likes on 0 Posts
Default

And here I was thinking it was all the **** sites I was visiting. A good tip from the guy who said to block all flash and all advertisements... one of them must be able to exploit some kind of vulnerability in FireFox to get on the PC. One thing that would be interesting is if Chrome-only users have experienced the virus or not...

Can any Chrome-only users chime in?
Old 03-10-2010, 09:58 AM
  #119  
Entaille
New Member
iTrader: (16)
 
Entaille's Avatar
 
Join Date: Sep 2008
Location: WA
Posts: 9,043
Received 21 Likes on 16 Posts
Default

another helpful tip, people should be keeping their adobe readers, java, flash players etc fully up to date. flash player and reader are getting pounded by all sorts of nasty things lately.
Old 03-10-2010, 10:02 AM
  #120  
Black Z Eddie
New Member
 
Black Z Eddie's Avatar
 
Join Date: Jun 2007
Location: San Pedro
Posts: 947
Received 9 Likes on 3 Posts
Default

Originally Posted by Entaille
I've seen it triggered just browsing forum to sub forum, with no posting or sigs involved. They are not looking hard enough. : P
Maybe they too are using Firefox + ABP.

On a serious note, I almost wanna install virtual pc and maybe run a screen capture app that way can check out frame by frame to see about when/where it happens.

Thread Tools
Search this Thread
Quick Reply: Virus and keyloggers on my350z



All times are GMT -8. The time now is 05:48 PM.