Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

my350z Phishing Virus

Thread Tools
 
Search this Thread
 
Old 02-26-2010 | 05:19 AM
  #1  
3FIDDYZED's Avatar
3FIDDYZED
Thread Starter
Registered User
iTrader: (2)
 
Joined: Jul 2007
Posts: 569
Likes: 0
From: London, UK
Default my350z Phishing Virus

I seem to be getting hit by a URL based phishing virus everytime I come on my350z.

Dosnt happen when I am on any other sites apart for this one.

Appears to be a malware that loads up as a webpage and is something like "Antispyware 2010" and a popup then appears

Have managed to get rid by hitting "x" on the popups rather than the "ok" or "cancel" buttons

Anyone else had the same? Its generally when I use a previous saved item in my history and then click on the next page or "view new posts"
Old 02-26-2010 | 05:38 AM
  #2  
06blueZ's Avatar
06blueZ
Registered User
iTrader: (10)
 
Joined: Jan 2006
Posts: 899
Likes: 0
From: St. Louis
Default

you're going to have to do more than just x'ing out of those screens, you need to update registry settings and delete the .exe program that is running. restart in safe mode with networking and google for a guide to remove it. Look for one that is just a step by step guide of manual things, dont install any kind of 'remover' that is specific to it...

good luck!
Old 02-26-2010 | 06:23 AM
  #3  
3FIDDYZED's Avatar
3FIDDYZED
Thread Starter
Registered User
iTrader: (2)
 
Joined: Jul 2007
Posts: 569
Likes: 0
From: London, UK
Default

Originally Posted by 06blueZ
you're going to have to do more than just x'ing out of those screens, you need to update registry settings and delete the .exe program that is running. restart in safe mode with networking and google for a guide to remove it. Look for one that is just a step by step guide of manual things, dont install any kind of 'remover' that is specific to it...

good luck!
Yeh ran malwarebytes before and it found it and removed. Just reformatted my machine to reload win7 and Office 10 yesterday and been on a few websites but the first time its happened again was when I was on here
Old 02-26-2010 | 09:55 AM
  #4  
Shift_SpecV's Avatar
Shift_SpecV
350Z-holic
Premier Member
iTrader: (3)
 
Joined: Dec 2005
Posts: 5,301
Likes: 0
From: H-town
Default

3fiddyzed, I will ask IB staff about this.
Old 03-06-2010 | 01:13 AM
  #5  
scoobyrex247's Avatar
scoobyrex247
Registered User
iTrader: (7)
 
Joined: Feb 2008
Posts: 234
Likes: 0
From: the 626
Default

I've had a similar experience this entire week with "Vista Guardian 2010" First I infected my gf's laptop. She said it's probably your 350club site, i said non sense, then my home desktop. Then her home desktop all two days in a row. this blows.
Old 03-06-2010 | 01:16 AM
  #6  
calin's Avatar
calin
Banned
iTrader: (39)
 
Joined: Jan 2007
Posts: 10,107
Likes: 0
From: So-cal
Default

Same thing happened to me today
Old 03-06-2010 | 03:43 AM
  #7  
Russ@Z1's Avatar
Russ@Z1
New Member
iTrader: (65)
 
Joined: Oct 2004
Posts: 3,493
Likes: 19
From: georgia
Default

I just installed a brand new hard drive with a fresh windows setup and I've gotten this b.s. three times in the past four days.
Old 03-06-2010 | 05:37 AM
  #8  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,234
Likes: 32
From: The Marketplace
Default

Run Malwarebytes in safe mode... It happened to my work PC and it worked. Update your virus definitions too.
Old 03-06-2010 | 05:58 AM
  #9  
Driven1's Avatar
Driven1
Professional
iTrader: (2)
 
Joined: Jan 2006
Posts: 4,398
Likes: 0
From: Virginia
Default

Phreak...if you get it like I did on my work PC...it won't even let you open Malwarebytes...and quickly not even allow you on the net.

IB needs to do something about this.
Old 03-06-2010 | 07:46 AM
  #10  
manual g's Avatar
manual g
Registered User
iTrader: (5)
 
Joined: Aug 2008
Posts: 32
Likes: 0
From: NJ
Default

The older versions of this malware can easily be removed with Malwarebytes. For those of you that have the newer version, its a little tricky.

If your infected and need to get on the net do this: (for Internet Explorer) go to internet options, click the connections tab, click the LAN settings button and uncheck the option "use proxy for LAN connection." That's a setting that is changed by the malware. Now you should be able to get on the net.

If you can't open any executables (.exe), there is a workaround that I found. Download smitfraudfix.exe, its a removal tool created specifically for this malware. You don't have to install it since it runs from the command line. When you try to run it, the malware won't let you and you get a popup that says "the .exe is infected blah blah." When you get this popup LEAVE IT THERE, don't click OK or exit. While its open press ctrl-alt-del and you'll be able to get to the task manager, you might have to do it twice. Now end all processes that are running under your username except explorer.exe. Now update and run malwarebytes and/or the removal tool, restart in safemode and run the programs again.

If it matters to anyone this is my line of work. Hope this helps some of you guys. Feel free to PM me.
Old 03-08-2010 | 09:13 AM
  #11  
GeauxLadyZ's Avatar
GeauxLadyZ
Registered User
iTrader: (9)
 
Joined: Mar 2008
Posts: 3,798
Likes: 3
From: Htown
Default

Ok guys i keep getting this like crazy, and i found out that when you go into task manager, the malware's id in task manager is AV.exe or something with AV.****.

If you end that process, you will be able to access everything (IE, Programs, etc) but it somehow is still blocking my Malwarebytes program so i cant remove it. Also, it is still running after you end this process because the icon for it is still in my tray on the start bar.

MODS, please fix this if you can, IT is getting pissed at me because they keep having to fix my CPU, lol.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Workshop12
Exterior & Interior
256
03-23-2020 01:45 PM
sales@czp
Engine
33
09-23-2019 03:30 PM
MicVelo
NorCal Marketplace
9
10-04-2015 07:55 PM
Tochigi_236
Feedback & Suggestions for Our Forum
8
09-27-2015 03:40 PM



Quick Reply: my350z Phishing Virus



All times are GMT -8. The time now is 12:09 AM.