Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old Mar 9, 2010 | 04:14 PM
  #101  
SlideFox's Avatar
SlideFox
Registered User
 
Joined: Dec 2007
Posts: 4,470
Likes: 5
From: Arizona
Default

I got it twice at home and once at work. I closed out of it, and ran webroot on my home PC. Haven't had any issues so far. IT at work was pissed. I played stupid.
Reply
Old Mar 9, 2010 | 05:17 PM
  #102  
Diesel350's Avatar
Diesel350
Registered User
iTrader: (6)
 
Joined: May 2003
Posts: 8,378
Likes: 1
From: Tampa
Default

So I ran Malwarebytes and it did remove and quarantine a Fake Alert Trojan.
Reply
Old Mar 9, 2010 | 05:22 PM
  #103  
03aeroZ's Avatar
03aeroZ
Registered User
iTrader: (11)
 
Joined: Aug 2005
Posts: 1,596
Likes: 0
From: monticello, illinois
Default

Originally Posted by Phreakdout
I too was hit yesterday. This fake antivirus program comes up and it looks just like a real Windows program. I can't seem to get rid of it.

Can ads be temporarily shut down till the source is found?

BTW: I am running Firefox on XP
I spent 4 days in safe mode trying to get rid of that one! Have fun.
Reply
Old Mar 9, 2010 | 05:24 PM
  #104  
HeyItsDan's Avatar
HeyItsDan
Registered User
iTrader: (18)
 
Joined: Oct 2008
Posts: 451
Likes: 0
From: Rockville
Default

Got it on my work computer. Ran Malwarebytes and after scanning, I was able to remove it in about 45 min!
Reply
Old Mar 9, 2010 | 09:31 PM
  #105  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

really????????? no official info? no apology? nothing?
Reply
Old Mar 9, 2010 | 09:52 PM
  #106  
xDIEGOx's Avatar
xDIEGOx
Registered User
 
Joined: Sep 2006
Posts: 8,026
Likes: 1
From: San Diego, CA
Default

So this is why I got the "your computer has been infected" message.
Reply
Old Mar 9, 2010 | 10:27 PM
  #107  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

They're trying to look for the malicious code but can't find anything. They haven't been able to duplicate it yet.

I was told that it could "be possible that perhaps someone has some sort of an image link in their signature or avatar that is attempting to execute some code."
Reply
Old Mar 10, 2010 | 04:29 AM
  #108  
Driven1's Avatar
Driven1
Professional
iTrader: (2)
 
Joined: Jan 2006
Posts: 4,397
Likes: 0
From: Virginia
Default

^^Then wouldn't it be prudent to post a "warning" thread in a more visited and visible area to warn people they can't find it and this site indeed is passing malicious code?

It's not a signature....its a seemingly random occurrence and you can track it by some posts as people posted when they got it or flagged the thread/post.

It kind of seems like this is no big deal to them and they aren't really putting too much time into it...it was first reported on 2/26.....

If something doesn't happen soon I will be canceling my account and Im sure many members won't be back (most of them won't be able to get it off their pc).
Reply
Old Mar 10, 2010 | 07:28 AM
  #109  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by 3hree5ive0ero
They're trying to look for the malicious code but can't find anything. They haven't been able to duplicate it yet.

I was told that it could "be possible that perhaps someone has some sort of an image link in their signature or avatar that is attempting to execute some code."
of course that's possible. ANYTHING is possible. But, people have reported the exploit by simply coming to check PMs. If I were responsible for this site and I even remotely suspected avatars and/or signatures, I would, ummmm, turn them off!!! But I suspect they dont really think it's a single users avatar or sig.
Reply
Old Mar 10, 2010 | 08:30 AM
  #110  
IIQuickSilverII's Avatar
IIQuickSilverII
New Member
iTrader: (13)
 
Joined: Oct 2005
Posts: 14,613
Likes: 215
From: Arizona -InP-
Default

Originally Posted by JEKL
Good point. I added Comodo Firewall and MS Security Essentials too. What would you recommend for the browser?
if you really like scripts...flash... but at the same time you are really concerned about this... how about setting the settings to prompt anytime a website request one of this things to run....
I have set most of those setting to prompt see if i can track it when something weird tries to "play/self-install".....
Reply
Old Mar 10, 2010 | 09:10 AM
  #111  
Entaille's Avatar
Entaille
New Member
iTrader: (16)
 
Joined: Sep 2008
Posts: 9,043
Likes: 21
From: WA
Default

I've seen it triggered just browsing forum to sub forum, with no posting or sigs involved. They are not looking hard enough. : P
Reply
Old Mar 10, 2010 | 09:16 AM
  #112  
JEKL's Avatar
JEKL
New Member
iTrader: (24)
 
Joined: Dec 2008
Posts: 2,910
Likes: 0
From: Greensboro, NC
Default

Originally Posted by 3hree5ive0ero
BTW, MC never owned this site. He became an admin back in the day because he used to contribute a lot to this forum (mostly Nismo stuff). Too bad when he was asked to step down, he deleted all the contributions he made.
Originally Posted by 3hree5ive0ero
I'm not blaming him for anything. I just think it's ridiculous that he did that. What if every single member here who no longer visits this site decided to erase all trace of their activity on here? How much info do you think we'd have?

Remember that in order for forums to exist, knowledge must be shared and retained.
So he was pushed out of his position on a forum that he contributed a lot to and decided to take all his information with him?

Sounds about right to me.
Reply
Old Mar 10, 2010 | 09:19 AM
  #113  
JEKL's Avatar
JEKL
New Member
iTrader: (24)
 
Joined: Dec 2008
Posts: 2,910
Likes: 0
From: Greensboro, NC
Default

Originally Posted by tware
"What would you recommend for the browser?"
My recommendation would make the internet suck for a few days until you manually whitelisted all the trusted scripts. And vids dont load until I click on the box and allow them to run. FF with noscript and ABP add ons for me. My wife is not exactly tech savy but within a few minutes, she was figuring out how to whitelist scripts with noscript. If you go to ebay or paypal, and 1/2 the page is blank, youre missing a script. You right click on the little noscript S in the bottom corner and "allow ebay.com" or "allow my350z" and so forth.
Originally Posted by MDHRZ
Firefox, then install NoScript and Ad Block Plus.
Originally Posted by IIQuickSilverII
if you really like scripts...flash... but at the same time you are really concerned about this... how about setting the settings to prompt anytime a website request one of this things to run....
I have set most of those setting to prompt see if i can track it when something weird tries to "play/self-install".....
Thanks guys. I need to educate myself more on configuring my browser so this doesn't keep happening.
Reply
Old Mar 10, 2010 | 09:20 AM
  #114  
bryan@Z1's Avatar
bryan@Z1
Vendor - Former Vendor
iTrader: (23)
 
Joined: Jan 2008
Posts: 2,890
Likes: 3
From: Carrollton, GA
Default

Spybot took care of it me. My PC at work got hit by this on Monday.
Reply
Old Mar 10, 2010 | 09:22 AM
  #115  
blasian's Avatar
blasian
New Member
iTrader: (29)
 
Joined: Apr 2005
Posts: 33,731
Likes: 1
From: Get out my way pimpin, LA
Default

Originally Posted by bryan@Z1
Spybot took care of it me. My PC at work got hit by this on Monday.
John need me to fix his laptop again?
Reply
Old Mar 10, 2010 | 09:25 AM
  #116  
bamyi's Avatar
bamyi
Registered User
iTrader: (2)
 
Joined: Aug 2004
Posts: 3,789
Likes: 0
From: Denver, CA
Default

Originally Posted by Hraesvelg
It's JVanquish.
I too blame everything on him.
Reply
Old Mar 10, 2010 | 09:51 AM
  #117  
IllumEstVeritas's Avatar
IllumEstVeritas
Registered User
 
Joined: Feb 2004
Posts: 6,395
Likes: 2
From: Cali
Default

Maybe I got it from here - it was a nightmare to remove all that. I had something else though b/c it would let me install malwarebytes, my search was always redirected on yahoo/google. Nasty Nasty - had to remove all extensions and redo before it would allow any anti-virus to be run. =\
Reply
Old Mar 10, 2010 | 09:55 AM
  #118  
Divergent13's Avatar
Divergent13
Registered User
 
Joined: Feb 2007
Posts: 6,573
Likes: 0
From: Northwest
Default

And here I was thinking it was all the **** sites I was visiting. A good tip from the guy who said to block all flash and all advertisements... one of them must be able to exploit some kind of vulnerability in FireFox to get on the PC. One thing that would be interesting is if Chrome-only users have experienced the virus or not...

Can any Chrome-only users chime in?
Reply
Old Mar 10, 2010 | 09:58 AM
  #119  
Entaille's Avatar
Entaille
New Member
iTrader: (16)
 
Joined: Sep 2008
Posts: 9,043
Likes: 21
From: WA
Default

another helpful tip, people should be keeping their adobe readers, java, flash players etc fully up to date. flash player and reader are getting pounded by all sorts of nasty things lately.
Reply
Old Mar 10, 2010 | 10:02 AM
  #120  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Originally Posted by Entaille
I've seen it triggered just browsing forum to sub forum, with no posting or sigs involved. They are not looking hard enough. : P
Maybe they too are using Firefox + ABP.

On a serious note, I almost wanna install virtual pc and maybe run a screen capture app that way can check out frame by frame to see about when/where it happens.
Reply



All times are GMT -8. The time now is 10:20 AM.