Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Old 03-10-2010, 04:48 PM
  #141  
Driven1
Professional
iTrader: (2)
 
Driven1's Avatar
 
Join Date: Jan 2006
Location: Virginia
Posts: 4,398
Likes: 0
Received 0 Likes on 0 Posts
Default

It crashed Firefox on my Mac 2 times fyi.

Its just easier for me to clean up

But people seem to be doing well with FF+adblock plus.
Old 03-10-2010, 04:53 PM
  #142  
JEKL
New Member
iTrader: (24)
 
JEKL's Avatar
 
Join Date: Dec 2008
Location: Greensboro, NC
Posts: 2,910
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by phreaktor
Can we compile a list of the threads that this has come up in with specific page numbers? I want to cross reference them for correlating usernames.
The first time I got it was in the Lucky Kid Gets Camaro SS For 16th Birthday thread, but it has since been merged with the Official Internet Video Thread.

I can't remember where I was the second time.
Old 03-10-2010, 04:55 PM
  #143  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

The only time AVG flagged it was when I went to bassholics thread bout his girl leaving with his phone. The thread was deleted or moved to QP. Since then, no flags on Win 7 64bit at home. At work one of the ads had our "Website blocked" page in it. Nothing else. This was an ad at the top of the page though- not in a thread.

Last edited by phreaktor; 03-10-2010 at 05:06 PM.
Old 03-10-2010, 05:22 PM
  #144  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Is this site hosted by Internet Brands or someone else? Also, there is no info on www.vbulletin.com forums regarding this. I'll check some of the "grey-hat" vbulletin forums.

Originally Posted by buzzardmountain
Good to see it's a high priority for most of the mods........
I'm pretty sure the mods are forum moderators, not IT security technicians.

Last edited by phreaktor; 03-10-2010 at 05:27 PM.
Old 03-10-2010, 06:02 PM
  #145  
akks350z
Registered User
iTrader: (26)
 
akks350z's Avatar
 
Join Date: Jan 2007
Location: South Jersey
Posts: 629
Likes: 0
Received 0 Likes on 0 Posts
Default

possibly my ***...im 1000% sure its from this site this bs vista security 2010 scam/virus...i recovered my entire computer and then only went on this site and bam i got it again...mods please pm me when this virus is gone from this site...im not recovering my entire system again until it is...at least this time i can still surf around but annoying warning and danger pop ups still every 3 mins...
Old 03-10-2010, 06:12 PM
  #146  
PikesPeakZ
New Member
iTrader: (12)
 
PikesPeakZ's Avatar
 
Join Date: Apr 2006
Location: Roseville,Ca
Posts: 2,773
Received 3 Likes on 1 Post
Default

Wow I'v been browsing this forum with no problems the past few weeks at home and work without even knowing anything like this was going on until I saw the warning when I just got on the site.

Mac and Safari FTMFW

It sucks, it looks like a lot of people here have been screwed. Fookin virus writers are retarded.
Old 03-10-2010, 06:32 PM
  #147  
MDHRZ
Registered User
iTrader: (14)
 
MDHRZ's Avatar
 
Join Date: Apr 2008
Location: Southern MD
Posts: 4,026
Likes: 0
Received 0 Likes on 0 Posts
Default

Do the advertisements come from ad.doubleclick.net and doubleclick.net? I have a pretty good feeling that's where the problem is.
Old 03-10-2010, 06:40 PM
  #148  
MDHRZ
Registered User
iTrader: (14)
 
MDHRZ's Avatar
 
Join Date: Apr 2008
Location: Southern MD
Posts: 4,026
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by phreaktor
I'm pretty sure the mods are forum moderators, not IT security technicians.
True, but IB IT security sure seems lazy lol. After the moderator board glitch and now this. Somebody isn't doing their job.
Old 03-10-2010, 07:56 PM
  #149  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by dikspiel
I work in IT and I fixed it in 20mins. Most of the 20mins was done scanning. Sounds like your sister's boyfriend is teh sux.
Well, yeah, you can scan/remove it in 20 mins and hope you dont still have a well hidden rootkit. I personally wouldnt go back to online banking on any PC thats had any of this newer malware entrenched like that until I've blown out the whole partition and MBR and started over. Even with a recent drive image, thats gonna take more than a few minutes.

Actually, since this targets some tools we usually use and does its best to keep you offline, I wouldn't be surprised if it took longer than 20 mins to figure out how to stop it with Process Explorer, find an offline update file for malwarebytes or similar, then start cleaning it.

I tend to think I know my **** with this stuff, but each new batch of these things just gets more and more devious. Takes alittle diggin to really figure out what they've done, and decide if a simple scan is good enough.
Old 03-10-2010, 08:45 PM
  #150  
Tian
Registered User
 
Tian's Avatar
 
Join Date: Oct 2006
Location: South FL
Posts: 199
Likes: 0
Received 0 Likes on 0 Posts
Default

It's showing up on G35Driver as well.
http://g35driver.com/forums/lounge-o...iver-also.html
Old 03-10-2010, 09:15 PM
  #151  
Hraesvelg
Got Uranium?
iTrader: (1)
 
Hraesvelg's Avatar
 
Join Date: Apr 2003
Location: The Recliner of Rage
Posts: 35,723
Received 6 Likes on 4 Posts
Default

Damn... I opened my350z and didn't expect the warning screen. I thought I got banned again.
Old 03-10-2010, 09:24 PM
  #152  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Originally Posted by Tian
It's showing up on G35Driver as well.
http://g35driver.com/forums/lounge-o...iver-also.html
This is an important statement. Are other IB owned sites having issues? Or is it related to a specfic advertiser that has been exploited? If it's just G35driver and here, we have narrowed it down a LOT. Also can someone PM the link that the virus redirects to?


This is getting deeper than I thought. I may have to browse the black hat forums.


Old 03-10-2010, 09:26 PM
  #153  
Hraesvelg
Got Uranium?
iTrader: (1)
 
Hraesvelg's Avatar
 
Join Date: Apr 2003
Location: The Recliner of Rage
Posts: 35,723
Received 6 Likes on 4 Posts
Default

Originally Posted by phreaktor
This is getting deeper than I thought. I may have to browse the black hat forums.


http://www.youtube.com/watch?v=y8Kyi0WNg40
Old 03-10-2010, 09:27 PM
  #154  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

LOL^ Is ICQ still like it used to be?
Old 03-10-2010, 09:29 PM
  #155  
billsrcursed
Registered User
 
billsrcursed's Avatar
 
Join Date: Sep 2008
Location: Orlando, FL
Posts: 671
Likes: 0
Received 0 Likes on 0 Posts
Default

Not sure if this is any way related, but my work has gone through this security upgrade because of an aggressive virus that is being spread throughout the building. I haven't seen anything on my PC to make me think I got anything here, but now I wonder.... anyone think it could be tied in?

*is PC retarded*
Old 03-10-2010, 09:55 PM
  #156  
Hraesvelg
Got Uranium?
iTrader: (1)
 
Hraesvelg's Avatar
 
Join Date: Apr 2003
Location: The Recliner of Rage
Posts: 35,723
Received 6 Likes on 4 Posts
Default

Originally Posted by phreaktor
LOL^ Is ICQ still like it used to be?
I probably haven't logged onto ICQ for 8 years.
Old 03-10-2010, 10:54 PM
  #157  
OCMan
Registered User
 
OCMan's Avatar
 
Join Date: Dec 2008
Location: Irvine, Ca
Posts: 794
Likes: 0
Received 0 Likes on 0 Posts
Default

i got the nasty virus from my350z 2 days ago. It's a fake antivirus program called Vista Antivirus Pro. Weird thing is that my mcafee antivirus program didn't stop it from attacking my pc. I found out later on that somehow i have windows firewall off...not sure if that would've made a difference. I then did a full scan w/ Mcafee but it couldn't find shiiit.

I downloaded Windows Security Essential from Microsoft and it was able to detect and removed the virus. For those w/ genuine windows, you should be able to download it for free.
Old 03-11-2010, 02:01 AM
  #158  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Btw when my 2nd PC at work (which is XP and not networked) was infected, it came from my flashdrive somehow. There were the shortcuts that said "pictures", "videos", and two others. I never clicked them- I just deleted them off the flash drive. I did get 3 icons on my desktop of **** picswith sites listed as the names. Malwarebyte took care of it in Safe Mode.

Just be aware it can spread to flashdrives as well. It was called taoubex.exe I think.

Last edited by phreaktor; 03-11-2010 at 02:02 AM.
Old 03-11-2010, 03:14 AM
  #159  
midz350
New Member
iTrader: (4)
 
midz350's Avatar
 
Join Date: Aug 2007
Location: around.
Posts: 4,054
Received 24 Likes on 21 Posts
Default

Originally Posted by phreaktor
Btw when my 2nd PC at work (which is XP and not networked) was infected, it came from my flashdrive somehow. There were the shortcuts that said "pictures", "videos", and two others. I never clicked them- I just deleted them off the flash drive. I did get 3 icons on my desktop of **** picswith sites listed as the names. Malwarebyte took care of it in Safe Mode.

Just be aware it can spread to flashdrives as well. It was called taoubex.exe I think.
I just fixed my friends computer. (he has never been here or G35Driver) the fake antivirus name was (Dr guard) and it did exactly what everyone describing. I used (Spyware Doctor) to remove it.

A direct link to download :

Spyware Doctor
Old 03-11-2010, 09:57 AM
  #160  
Tian
Registered User
 
Tian's Avatar
 
Join Date: Oct 2006
Location: South FL
Posts: 199
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by phreaktor
Btw when my 2nd PC at work (which is XP and not networked) was infected, it came from my flashdrive somehow. There were the shortcuts that said "pictures", "videos", and two others. I never clicked them- I just deleted them off the flash drive. I did get 3 icons on my desktop of **** picswith sites listed as the names. Malwarebyte took care of it in Safe Mode.

Just be aware it can spread to flashdrives as well. It was called taoubex.exe I think.
Does this include my ext hard drive?

Thread Tools
Search this Thread
Quick Reply: Virus and keyloggers on my350z



All times are GMT -8. The time now is 01:57 AM.