PDA

View Full Version : Just a friendly (or not so friendly) virus reminder....


Silverleaf
12-23-08, 05:16 AM
Greetings,

This is a bit odd, but I thought I'd post the details of it to help fellow gamers avoid some critical problems with their system. I recently started getting pop-ups here at Subsim with Firefox 3.0.5, and when I'd run AVG 8.0 it would capture a couple freescan.htm files, place them in the Virus Vault and I'd reboot to finish the job.

I kept getting them.

So, phase two, install a spyware product - given that AVG's Free spyware software is no longer supported. I knew of a few good ones, but the best on the market is SuperAntiSpyware. Yes there may be "better ones" out there - but when you include free updates, auto scan AND removal, well it can't be beat - and it's totally free.

So, installed and bang, it found 5 items AVG Spware missed. Reboot, delete good to go right?

I kept getting them.

Sent an email to AVG and a couple other companies I deal with regarding my problem, even included a log file and all pertinent information. They gave me something to try, removed it, rebooted.

I kept getting them.

Searched online, no exact fix, no exact description fit my problem. On a whim, I started searching my older computers because I remembered something in the back of my cerebral cortex about Netscape Navigator and Internet Explorer incompatibility issues. 7 hours later I was down to one last full manual scan of system files, going through anything that looked suspicious and if that didn't work, well...

12 hours later before I prepare for "How R.S. lost his sanity" - commonly known as "Reinstall Time"....

I come back online to check email, and in the midst of doing so I have a popup again. I just glance in the upper left hand corner before AVG captures it and asks me what I want to do with it when I see it. The rat fink that's been causing all sorts of problems for the last 4 days.

Internet Explorer itself.

I use firefox, have not, will not use I.E. on threat of death. So why is it firing pop-ups that nothing can stop?

I open I.E. and start checking options - under "Allowed Popups" I have a listing of 27 links. All 27 turn out to be viral in nature - and because I.E. was allowing them, they couldn't be stopped because AVG/etc. didn't have full access to do so.

I did not give them access!.

So after firing off a final report to a few services I:

ran AVG, rebooted
ran SuperAntiSpyware, rebooted
used my 2nd favoritie uber-utility RegSeeker, rebooted.
ScanDisk, rebooted
Reg Defrag, rebooted
Defrag, rebooted

Started up Firefox and ... and... no pop-ups !!!!.

The system is flying..and I'll make this bold as a plea/reminder to everyone. After I checked everything one last time:

I made a Backup System Restore point - so in case I have an issue in the future, I can pop back to this ultimate awesome point.

So after all that - if you experience the same thing, please check your old - still installed browser's pop-ups and security settings - don't allow any pop-ups, set security to max, turn off active X etc.

Windows Xp still uses I.E. for some services - therefore you need it even if you don't use it.

I'm not sure if Vista does this - if so Be Careful

Save yourself the same headache I just experienced.

Cheers and Merry Christmas...

XabbaRus
12-23-08, 06:42 AM
Hmmm, some how I don't buy this.

If you exclusively use Firefox and not IE then you shouldn't have any links in IE

"
I open I.E. and start checking options - under "Allowed Popups" I have a listing of 27 links. All 27 turn out to be viral in nature - and because I.E. was allowing them, they couldn't be stopped because AVG/etc. didn't have full access to do so"

although Explorer is at the heart of the XP operating system if you don't use IE6 or 7 to access the web then how come you end up with the allowed popups list?

Digital_Trucker
12-23-08, 03:13 PM
Probably because the virus has modified the IE settings to allow the bad links.

Silverleaf
12-23-08, 03:47 PM
I still don't fully understand how it happened, but have sent reports to all Anti-Virus parties involved.

Probably because the virus has modified the IE settings to allow the bad links.

That's what I'm thinking, though I don't have validation at this point.

Task Force
12-23-08, 03:52 PM
Anyone know of a good virus scanner. I got a popup about a Trojan yesterday. (I hope it was blocked.)

Silverleaf
12-23-08, 07:58 PM
AVG 8.0

http://www.avg.com/

SUBMAN1
12-24-08, 12:14 AM
Quit wasting time with AVG spyware blocker or whatever. There is only a couple decent adware/spyware blockers, and if the name isn't Spybot Search and Destroy, or Lavasoft's Adaware, then you are wasting your time.

Both these tools should be in everyones toolbox these days. Adaware is the program that started it all (I was on the beta test group of the first rev's), but Search and Destroy seems to have better results lately and is Adawares main competition. Adaware personal is free but if you want the real time protection version, you need to pay for it. This is contrary to what they told me back when I beta tested their product for them - they told me it would 'always' be free. Not quite true I guess.

Try this first - http://www.download.com/Spybot-Search-amp-Destroy/3000-8022_4-10122137.html - If that doesn't squash your bug, well, good luck to ya! :D It will work though.

-S

PS. By the way, you may be a victim of a cross site scripting vulnerability found in browsers lately. If you use Firefox, try adding noscript to it. its a plugin that will allow you to control when scripts are run in your browser.

PPS. Your infection may not be your computer. There are some router hacks lately that can redirect your DNS queries.