TriStateTuners.com :: Home of Tristate Auto Enthusiast  

Go Back TriStateTuners.com :: Home of Tristate Auto Enthusiast > Community > Off-Topic
Register Rules & Info

Notices

Reply
 
Thread Tools Display Modes
Old 11-26-2007, 10:53 AM   #1
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Malware: SUCKS

Well recently my computer has been having a lot of IE pop ups with a thing that pops up that says "Ad served by context tool" and my computer will play random sounds and sometimes even random commercials like "Congratulations you've been selected to win a free ipod nano."

I run the Adaware program and Norton Antivirus and it doesn't solve the problem so I looked into it more last night.

Apparently there is a newer type of infectious programs out there labeled Malware which are basically ****ty virus made to annoy people.

Any body have any experinece with this crap? I've made a post on techsupportfourm.com and they seem really technical over there. They gave me some steps to create some logs and they have gys that review the logs and help you clean up you ****.
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 11:10 AM   #2
05GT
The TST IT Ninja
 
05GT's Avatar
 
Join Date: Mar 2006
Location: PA
Member #1598

My Ride:
2007 SRT8 Jeep / 2013 Shelby GT500

iTrader: (0)
Yes. Malware is not a new thing.

You need to scan with Adaware from www.lavasoftusa.com if that isn't the one you said you used. Make sure it's definitions are up to date.

Also, get a program called Hijackthis. But be warned, it deep scans and shows things that if you delete them, it could mess up your computer. You could scan with it, then save the log and email to me, or post it here, and I can tell you EXACTLY what needs to be deleted. Then you will be good to go.

And FYI....Nortons is useless.

If it is Adaware from the link I posted that you are using, then you definitely need to run Hijackthis.


Edit - Here is the link you can download Hijackthis from : http://www.majorgeeks.com/download5554.html

Last edited by 05GT; 11-26-2007 at 11:13 AM.
05GT is offline   Reply With Quote
Old 11-26-2007, 11:26 AM   #3
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Yeah I use Adaware and run a scan pretty regularly. I've been informed to run Hijackthis and post the logs. I'll do this when I get home from work.

I won't delete anything that it finds until I'm informed by somebody to do so.
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 11:27 AM   #4
05GT
The TST IT Ninja
 
05GT's Avatar
 
Join Date: Mar 2006
Location: PA
Member #1598

My Ride:
2007 SRT8 Jeep / 2013 Shelby GT500

iTrader: (0)
Quote:
Originally Posted by Jeffros Spec V View Post
Yeah I use Adaware and run a scan pretty regularly. I've been informed to run Hijackthis and post the logs. I'll do this when I get home from work.

I won't delete anything that it finds until I'm informed by somebody to do so.
Well just make sure that whoever you show the log to, if it isn't me, knows what they are doing. If not, you might have to kiss your OS goodbye lol.
05GT is offline   Reply With Quote
Old 11-26-2007, 11:29 AM   #5
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Quote:
Originally Posted by 05GT View Post
Well just make sure that whoever you show the log to, if it isn't me, knows what they are doing. If not, you might have to kiss your OS goodbye lol.

ahahahahha thanks for the heads up
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 11:49 AM   #6
05GT
The TST IT Ninja
 
05GT's Avatar
 
Join Date: Mar 2006
Location: PA
Member #1598

My Ride:
2007 SRT8 Jeep / 2013 Shelby GT500

iTrader: (0)
Quote:
Originally Posted by Jeffros Spec V View Post
ahahahahha thanks for the heads up
LOL. Yeah no prob. Like I said, you can PM me the log or post it here, and I can tell you. Unless you have someone else that will do it for you.
05GT is offline   Reply With Quote
Old 11-26-2007, 02:07 PM   #7
james_ls
TST Ruined My Life!
 
james_ls's Avatar
 
Join Date: Mar 2006
Location: Warrington
Member #1614

My Ride:
1998 Acura Integra LS//VTEC

iTrader: (0)
Send a message via AIM to james_ls
Are you using Internet Explorer. If so. Fail.
__________________
Heller Dope - When the **** is doper than Hellen Keller; it's Heller Dope

To view links or images in signatures your post count must be 10 or greater. You currently have 0 signatures.
BUY MY STUFF!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 signatures.
james_ls is offline   Reply With Quote
Old 11-26-2007, 02:29 PM   #8
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Quote:
Originally Posted by james_ls View Post
Are you using Internet Explorer. If so. Fail.
Nope, I use Firefox and have been since it first came out.
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 02:44 PM   #9
Scapegoat
TST Ruined My Life!
 
Scapegoat's Avatar
 
Join Date: Dec 2005
Location: stop looking at my gold
Member #1208

 
iTrader: (1)
delete porn = problem solved
Scapegoat is offline   Reply With Quote
Old 11-26-2007, 02:45 PM   #10
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Quote:
Originally Posted by Scapegoat View Post
delete porn = problem solved
I don't have any porn and I don't look at porn. Leave my thread.
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 02:47 PM   #11
Scapegoat
TST Ruined My Life!
 
Scapegoat's Avatar
 
Join Date: Dec 2005
Location: stop looking at my gold
Member #1208

 
iTrader: (1)
Quote:
Originally Posted by Jeffros Spec V View Post
Leave my thread.
um... no?

Porn, mp3's, mpeg's, etc can open bridges to pop up's to come in. Best to back up any files you want to keep and delete those that you no longer need.

Try AVG's free software. They have an adaware like program as well as a anti virus. Both kick ass.
Scapegoat is offline   Reply With Quote
Old 11-26-2007, 03:00 PM   #12
Jeffros Spec V
Tri-State Post Whore
 
Join Date: Mar 2005
Location: Langhorne PA
Member #263

 
iTrader: (0)
Send a message via AIM to Jeffros Spec V
Quote:
Originally Posted by Scapegoat View Post
um... no?

Porn, mp3's, mpeg's, etc can open bridges to pop up's to come in. Best to back up any files you want to keep and delete those that you no longer need.

Try AVG's free software. They have an adaware like program as well as a anti virus. Both kick ass.
Thanks, that is better advice than assuming its linked directly to porn. I do however have a lot of songs that I download. Is this crap linked to Youtube or photobucket or myspace at all?
Jeffros Spec V is offline   Reply With Quote
Old 11-26-2007, 03:00 PM   #13
05GT
The TST IT Ninja
 
05GT's Avatar
 
Join Date: Mar 2006
Location: PA
Member #1598

My Ride:
2007 SRT8 Jeep / 2013 Shelby GT500

iTrader: (0)
Sorry but AVG sucks.

And MP3s aren't "linked" to anything per say. What is more common is that when you download MP3's, attached onto them sometimes are viruses, or spyware applications that silently run or install once you open the MP3 or file, etc.
05GT is offline   Reply With Quote
Old 11-26-2007, 03:09 PM   #14
Scapegoat
TST Ruined My Life!
 
Scapegoat's Avatar
 
Join Date: Dec 2005
Location: stop looking at my gold
Member #1208

 
iTrader: (1)
Quote:
Originally Posted by 05GT View Post
Sorry but AVG sucks.

And MP3s aren't "linked" to anything per say. What is more common is that when you download MP3's, attached onto them sometimes are viruses, or spyware applications that silently run or install once you open the MP3 or file, etc.
as far as free goes, I'll take it over anything microsoft, norton, or macafee offers...

Linked was a bad word to use. But yes, whenever you download something from the internet there is a chance that it won't be alone.
Scapegoat is offline   Reply With Quote
Old 11-26-2007, 05:54 PM   #15
den9
Tri-State Post Whore
Banned
 
den9's Avatar
 
Join Date: Dec 2005
Location: doylestown
Member #1198

My Ride:
turbo diesel

iTrader: (0)
Send a message via AIM to den9
u shouldnt have any problems with firefox, but adaware from lavasoft is ur best bet
den9 is offline   Reply With Quote
Old 11-27-2007, 12:29 PM   #16
JET02WRX
Tri-State Addict
 
JET02WRX's Avatar
 
Join Date: Jun 2006
Location: Chester Co.
Member #2133

My Ride:
2002 WRX Wagon

iTrader: (1)
Heres some info on what alot of people have been seeing lately...the problem isn't the content you are downloading...its those sweet little adds that forums, most websites, myspace...etc..etc..have chosen to allow on their sites to make extra money. Those ads are being used as a path to put spam on your PC.


DoubleClick Serves Up Vast Malware Blitz


On Nov. 12, Web sites' marketing professionals were flooding industry e-mail lists with reports of complaints from readers that they have been receiving inappropriate ads. Marketing professionals have complained of their ad servers being "hijacked" at sites, including The Wall Street Journal, Discovery and BizJournals. It's not that the servers have been hijacked, Harvey said, but rather that a toolbar or some other mechanism is overlaying the intended ad with inappropriate content.

ADVERTISEMENT "It looks like we are all in the same boat," one marketer said in a message to the mailing list.

Another marketer said his company had already shut down one of its networks that was devoted to serving up ads and had suspended all third-party ads on another site.

It's not clear yet whether all the sites are having the same problem, given that some sites are delivering the bogus anti-spyware and others are experiencing normal ads being replaced with ads for porn or other inappropriate material.

To read about why the Google-DoubleClick deal is facing Senate scrutiny, click here.

As for the bogus anti-spyware code its origin the German company AdTraff.com. AdTraff had not responded to inquiries as of the time this article posted. Google, which has proposed a $3.1 billion buyout of DoubleClick, declined to comment.

Harvey said in a statement that this is "an industry-wide challenge; unfortunately, there are bad actors who misrepresent themselves and purchase advertising as an avenue to distribute malware. This has the potential to affect all businesses and consumers in the online environment."

Even as DoubleClick monitors its online environment for malware—it has a dedicated team that works around the clock on the issue—malware writers are working to adapt to its new security measures, Harvey said in the statement.

"As with any system (Norton, McAfee, etc.) designed to root out bad actors, there are going to be times when the bad actors are a step ahead—when this occurs, we immediately cease serving the infected ads, and then work to refine our system so that similar ads are captured and disabled before they are ever served (just like when Norton provides a 'patch' in response to a new threat)," the statement said.

DoubleClick has alerted its clients, particularly publishing clients, of the need to pay close attention to the advertisers, agencies and networks with which they work.

When clicked on, the bogus anti-spyware ad presents in the lower right-hand screen corner a dialog box informing users that their computer is infected and that they need to download a scanner immediately.



Warning: If clicking on the following link, do not click "OK" to any dialog boxes; instead, simply close out the browser window. This is a link to the bogus infection scan that's presented to victims. Eckelberry said that the Trojan consistently reports that malware has been found even on systems known to the security firm to be perfectly clean.

Sunbelt and other security researchers see this type of misleading ad, which uses convincing warning dialog boxes that look like legitimate Windows messages, on a regular basis.

Adam Thomas, a researcher at Sunbelt, said the IP address for the AdTraff.com ads overlaps with those used by Innovative Marketing, which has a long history of misleading on the Internet. AdTraff.com's domain registration also lists the same Yahoo.com e-mail address as Innovative Marketing, Thomas said.

"These guys are just slimy advertising guys," Eckelberry said.

Ad hijacking is a constant problem, Eckelberry said. That makes it essential that online publishers and others who serve ads vet the advertisers to whom they hand their space—and their visitors' eyeballs.
__________________
2002 WRX "Fun-Wagon"
JET02WRX is offline   Reply With Quote
Old 11-27-2007, 12:49 PM   #17
Kiel
Tri-State Aficionado
 
Kiel's Avatar
 
Join Date: Aug 2007
Location: Morton, PA
Member #5456

My Ride:
2003 WRX - Sonic Yellow

iTrader: (0)
Send a message via AIM to Kiel
Quote:
Originally Posted by james_ls View Post
Are you using Internet Explorer. If so. Fail.
Get over yourself.
__________________
TST Work Crew/Saturday Club
To view links or images in signatures your post count must be 10 or greater. You currently have 0 signatures.
Kiel is offline   Reply With Quote
Old 11-27-2007, 12:52 PM   #18
Spocknasty
Meh
 
Spocknasty's Avatar
 
Join Date: Oct 2005
Member #986

 
iTrader: (5)
Run msconfig. See if theres any weird stuff going on in there, google those, and go from there.

Start task manager. Look at your processes. If you see anything weird in there, google those, and find out what they are.

IE is the devil.
__________________
*formerly CRXed*


To view links or images in signatures your post count must be 10 or greater. You currently have 0 signatures.

I <3 JSC Speed and Liquid Powder Coats!
Spocknasty is offline   Reply With Quote
Old 11-27-2007, 12:53 PM   #19
05GT
The TST IT Ninja
 
05GT's Avatar
 
Join Date: Mar 2006
Location: PA
Member #1598

My Ride:
2007 SRT8 Jeep / 2013 Shelby GT500

iTrader: (0)
JET, while all of that is true, in no way is it anything new. For years sites have been doing that. Anytime you click an add, if something tells you it needs to install "ActiveX Controls" or it needs to run anything, unless it is a REPUTABLE site, and you know for sure what it's asking you to install, you should never click yes or ok to anything of that nature.

Sometimes, even if what you are clicking looks legit, and the dialog box looks ok, or you know what it is, it sometimes will still contain silent code or scripts, viruses, etc that will run in the background and cause havoc.

Running MSCONFIG will not help too much in most cases. Most of the newer, more dangerous spyware and malware put themselves in multiple places in your Windows installation, and even if you remove or delete them from MSCONFIG, or even if you actually manually find the file and delete them, they will spawn back up from another hidden location.

That's why you need tools like "hijackthis".

Last edited by 05GT; 11-27-2007 at 12:55 PM.
05GT is offline   Reply With Quote
Old 11-27-2007, 03:01 PM   #20
Z3R0
Tri-State Aficionado
 
Z3R0's Avatar
 
Join Date: Jun 2007
Location: Carneys Point, NJ
Member #5129

My Ride:
2002.5 Volkswagen Jetta GLS

iTrader: (0)
Lookup the WMF Exploit...there might be variants.
__________________
Quote:
R.I.P. 1997 Monte Carlo...Got hit by a HUMMER...nuff said
Z3R0 is offline   Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware thread? 99SL2_Modder TST Forum Info and Feedback 8 08-20-2009 05:57 PM
Goodbye sucks, tst sucks ahhh! whine whine!!! teh DIRT Off-Topic 41 04-26-2009 11:19 PM
why my job sucks? Scapegoat Off-Topic 70 05-16-2008 11:41 PM
best buy sucks redg2 Off-Topic 23 09-22-2007 04:52 PM
This sucks! 180sxDrifter Off-Topic 7 12-16-2005 08:32 PM


All times are GMT -4. The time now is 03:22 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.