Page 1 of 2 1 2 LastLast
Results 1 to 20 of 21

Thread: Spyware     submit to reddit submit to twitter

  1. #1
    Smells like Onions
    Join Date
    Dec 2008
    Posts
    8
    BG Level
    0

    Spyware

    Hey guys

    Long time viewer of these forums.

    I have been running STOPzilla on, and for some reason there are a lot of attempts from something on this website trying to get into my computer. Stopzilla has popped up several messages saying it prevented them.

    Is it possible the RMT banners are causing this? I didn't have any other websites open and it found several just from looking at several post's and topics on this page.

    -Trummp

  2. #2
    Ridill
    Join Date
    Aug 2004
    Posts
    12,275
    BG Level
    9
    FFXIV Character
    Septimus Atumre
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut

    Quote Originally Posted by Trummp View Post
    Hey guys

    Long time viewer of these forums.

    I have been running STOPzilla on, and for some reason there are a lot of attempts from something on this website trying to get into my computer. Stopzilla has popped up several messages saying it prevented them.

    Is it possible the RMT banners are causing this? I didn't have any other websites open and it found several just from looking at several post's and topics on this page.

    -Trummp
    That is entirely possible, they have done that with ads on other sites.

    I would suggest staying logged in (since you don't get ads), and installing NoScript to block out anything from outside of this page from loading. If you still have problems, then we are going to have an angry Ragn that will hunt down the source and make it pay.

  3. #3
    Smells like Onions
    Join Date
    Dec 2008
    Posts
    8
    BG Level
    0

    Ugh,

    I'm now getting tons of popups too... since viewing these forums, and tons of new infections. Once I quit the browser on this website, tons of popups for the same website kept coming up, second after second, and it crashed my computer.. I had to restart. Someone please look into this, this has updated definitions too and cannot stop all of them.

    BTW, hello septimus- You helped me get my moldavite earring about 3 years ago

  4. #4
    Hydra
    Join Date
    Oct 2008
    Posts
    100
    BG Level
    3
    FFXI Server
    Lakshmi

    You sure it's not all the porn sites you been on? BG not doin anything like that for me.

  5. #5
    Chram
    Join Date
    Jun 2006
    Posts
    2,539
    BG Level
    7

    You already have spyware, and it is giving you the popups.

  6. #6
    With milk. With love
    Join Date
    Apr 2005
    Posts
    1,629
    BG Level
    6
    FFXI Server
    Siren
    WoW Realm
    Cenarion Circle

    What sort of specific popups? Please elaborate.

  7. #7
    2600klub
    I donated 5 bucks and all I got was this shitty title from Zet

    Join Date
    Jun 2007
    Posts
    2,688
    BG Level
    7
    FFXI Server
    Ragnarok

    This site has been 100% clean for me since I started lurking a long-ass time ago. I'd say you've already got a malware infestation that's causing your pop-ups.

    1. Google "Spybot" and download it. Update, run the Immunization feature, then run the full scan.
    2. Google "Threatfire", download it. Run a scan and let it stay resident (loaded in your systray).
    3. Extra insurance; download "Malwarebytes" and run that scan.

    The above should handle your current malware issue (maybe; if not, you might have to boot in safe mode).

    4. Go to AVG Free - Download antivirus and antispyware software for Windows XP and Vista and download the free edition of AVG Anti-Virus 8.0. It's a great virus scanner and malware scanner, in one package.
    5. If, after all this, you still have issues, Google "Hijackthis", run it, and choose to scan and save a log file. Post the contents of the log file here, but don't do anything else with it just yet.

  8. #8
    With milk. With love
    Join Date
    Apr 2005
    Posts
    1,629
    BG Level
    6
    FFXI Server
    Siren
    WoW Realm
    Cenarion Circle

    Quote Originally Posted by Trummp View Post
    Ugh,

    I'm now getting tons of popups too... since viewing these forums, and tons of new infections. Once I quit the browser on this website, tons of popups for the same website kept coming up, second after second, and it crashed my computer.. I had to restart. Someone please look into this, this has updated definitions too and cannot stop all of them.

    BTW, hello septimus- You helped me get my moldavite earring about 3 years ago
    Most likely then you've got some kind of rootkit or other deeply embedded malware infecting your system. Try disabling system restore then rerun the scan.

    Also, look for MalwareBytes in Google and download it, then run that sucker. It's been known to find the more difficult to remove malware better than anything else out there.

  9. #9
    Dice and rum
    Not necessarily in that order

    Join Date
    May 2006
    Posts
    2,025
    BG Level
    7
    FFXI Server
    Odin

    Posts like this make me love Firefox, noscript, adblock, etc all the more.

  10. #10
    DAKPluto
    Guest

    Quote Originally Posted by Thistle View Post
    Posts like this make me love Firefox, noscript, adblock, etc all the more.
    this

  11. #11
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Quote Originally Posted by Trummp View Post
    Ugh,

    I'm now getting tons of popups too... since viewing these forums, and tons of new infections. Once I quit the browser on this website, tons of popups for the same website kept coming up, second after second, and it crashed my computer.. I had to restart. Someone please look into this, this has updated definitions too and cannot stop all of them.

    BTW, hello septimus- You helped me get my moldavite earring about 3 years ago
    You are very likely infected with a virus. I suggest you run a virus scan. This virus is likely installing malware and taking you to sites which exploit browser vulnerabilities to install more malware on your machine. It's a relatively common exploit.

    Then install at least two types of adware/malware removal tools. Do this after you run your virus scan. The adware/malware removers can be uninstalled once they're done cleaning your system.

    When you're done there, update your installation of flash/IE and run windows update.

    Then ask the mods to move this thread into tech support.

  12. #12
    The God Damn Kuno
    Join Date
    Dec 2004
    Posts
    13,360
    BG Level
    9
    FFXIV Character
    Kuno Sedai
    FFXIV Server
    Gilgamesh
    FFXI Server
    Bahamut

    Quote Originally Posted by Correction View Post
    You are very likely infected with a virus. I suggest you run a virus scan. This virus is likely installing malware and taking you to sites which exploit browser vulnerabilities to install more malware on your machine. It's a relatively common exploit.

    Then install at least two types of adware/malware removal tools. Do this after you run your virus scan. The adware/malware removers can be uninstalled once they're done cleaning your system.

    When you're done there, update your installation of flash/IE and run windows update.

    Then ask the mods to move this thread into tech support.

    Do this, then when you're 100% clean change your password.

  13. #13
    Smells like Onions
    Join Date
    Dec 2008
    Posts
    8
    BG Level
    0

    Malwarebytes' Anti-Malware 1.31
    Database version: 1551
    Windows 5.1.2600 Service Pack 2

    12/26/2008 5:17:59 PM
    mbam-log-2008-12-26 (17-17-59).txt

    Scan type: Quick Scan
    Objects scanned: 52680
    Time elapsed: 5 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 4
    Registry Keys Infected: 9
    Registry Values Infected: 4
    Registry Data Items Infected: 5
    Folders Infected: 0
    Files Infected: 10

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\system32\fopihofu.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\pasufizi.dll (Trojan.Vundo) -> Delete on reboot.
    C:\WINDOWS\system32\botapepe.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\ponegiwu.dll (Trojan.Vundo.H) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{ac7f4ff3-1a7c-4aff-974b-bf8eb6f4b095} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ac7f4ff3-1a7c-4aff-974b-bf8eb6f4b095} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{d5bf49a2-94f1-42bd-f434-3604812c807d} (Trojan.BHO) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\bivevegine (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\cpm2b18779e (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\fopihofu.dll -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fopihofu.dll -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\fopihofu.dll -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\ponegiwu.dll -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\ponegiwu.dll -> Delete on reboot.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\pasufizi.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\izifusap.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\botapepe.dll (Trojan.Vundo.H) -> Delete on reboot.
    c:\WINDOWS\system32\ponegiwu.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\fopihofu.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\system32\sorofita.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\xmbexxid.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\yayyVppo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\jkkIbAtu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\gebegimi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

  14. #14
    Smells like Onions
    Join Date
    Dec 2008
    Posts
    8
    BG Level
    0

    I also disabled Windows Restore, do you think they might have been using that to keep restoring the files? StopZILLA found much of the same files that Malware did, but they kept coming back.

  15. #15
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    Go into your system 32 folder and make sure the files listed as "Delete on reboot" are really gone. If they're not, download Killbox and try to delete them through that.

    Can also try a special vundofix tool, which you can grab from Here

    Though it's probably best to just reformat.

  16. #16

  17. #17
    Salvage Bans
    Join Date
    Feb 2007
    Posts
    811
    BG Level
    5
    FFXIV Character
    Orinthia Warsong
    FFXIV Server
    Excalibur
    FFXI Server
    Bahamut

    Sounds like your host file got mangled. That's the only thing that can screw around with all browsers in windows. If in winxp goto C:\WINDOWS\system32\drivers\etc and look inside the file named "hosts" (has no extension). If you've never messed with it before then it should be fairly empty. If mangled it should be filled with redirections for popular sites to malware sites.

    Learn more about the hosts files here: Blocking Unwanted Parasites with a Hosts File

    I recommend Hostman to help you manage the file itself. Go here for it: abelhadigital.com It'll make adding and deleting entries much, much easier. Just be sure to restart your browsers when you make an edit. Sometimes the online updated hosts files contain sites that shouldn't be blocked so you'll have to do a little searching with hostman to get those pages to work again but it's worth the small hassle to block access to the sites within completely for all programs.

  18. #18
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Okay it doesn't sound like you're following directions. Did you run a virus scan? Do you even have an antivirus installed?

  19. #19
    Nidhogg
    Join Date
    Oct 2005
    Posts
    3,612
    BG Level
    7
    FFXIV Character
    Glick Wick
    FFXIV Server
    Ultros
    FFXI Server
    Bahamut

    Wow, stay off the porn sites.

  20. #20
    2600klub
    I donated 5 bucks and all I got was this shitty title from Zet

    Join Date
    Jun 2007
    Posts
    2,688
    BG Level
    7
    FFXI Server
    Ragnarok

    Quote Originally Posted by Correction View Post
    Okay it doesn't sound like you're following directions. Did you run a virus scan? Do you even have an antivirus installed?
    ^ This .....and what the fuck, do your Windows updates, jesus.
    Malwarebytes' Anti-Malware 1.31 Database version: 1551 Windows 5.1.2600 Service Pack 2

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Anyone heard of this spyware
    By Ratatapa in forum Tech
    Replies: 9
    Last Post: 2009-08-04, 08:49
  2. Virus/Spyware Problem
    By Stu in forum Tech
    Replies: 4
    Last Post: 2009-05-21, 03:51
  3. Replies: 12
    Last Post: 2009-01-07, 04:04
  4. Finding ze spyware
    By Apelila in forum Tech
    Replies: 2
    Last Post: 2008-09-22, 13:09
  5. Spyware Free P2P?
    By Francisco II in forum Tech
    Replies: 9
    Last Post: 2007-03-18, 03:34
  6. best spyware removal program
    By Tyche in forum Tech
    Replies: 8
    Last Post: 2007-02-10, 15:59