![]() |
SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997 |
![]() |
#1 |
CINC Pacific Fleet
Join Date: Sep 2003
Location: Down Under
Posts: 34,688
Downloads: 171
Uploads: 0
|
Beware Possible FileFront - malware!
I had just uploaded a file at FileFront & this launched a window to an ad called aShopping.com, this tried to launch "~.exe" that COMODO picked up, now although I blocked it after a scan the virus (HIDDENEXT/Crypted) was found in the C:\Documents and Settings\myprofile\Local Settings\Temporary Internet Files, I have deleted it & all is ok but thought I'd give the warning, a bit poor of FileFront IMO!
![]() ![]() Edit: Looks like I may be infected, ever so often when I open a new page with firefox a window opens to here: http://403.hqhost.net/index.html thank goodness it's an error message, or is it? any advise welcome. ![]() I think it has infected firefox, this is what opens: ![]()
__________________
Sub captains go down with their ship! Last edited by Reece; 12-16-08 at 12:33 AM. |
![]() |
![]() |
![]() |
#2 |
Crusty Capt.
![]() Join Date: Sep 2007
Posts: 2,752
Downloads: 40
Uploads: 25
|
![]()
I went to Filefront without issue. I think you got worm in your system.
![]() lol good luck dude. I hope you kill it before it spreads. ![]() |
![]() |
![]() |
![]() |
#3 |
CINC Pacific Fleet
Join Date: Sep 2003
Location: Down Under
Posts: 34,688
Downloads: 171
Uploads: 0
|
![]()
Well it was straight after uploading a file there! only spot before was Photobucket, hope it wasn't there!! I am about to re-ghost my machine, I'd love to get a hold of the creeps who make these, damn maggots!!
![]()
__________________
Sub captains go down with their ship! |
![]() |
![]() |
![]() |
#4 |
Sea Lord
![]() Join Date: Feb 2005
Location: Shreveport, Louisiana
Posts: 1,956
Downloads: 13
Uploads: 0
|
![]()
You need to be 100 percent sure it is filefront before accusing them of infecting your system.
#1 If they were responsible it would be all over the net news right now. Many people use filefront. #2 Filefront is a quality site. Not the biggest and not some small operation. |
![]() |
![]() |
![]() |
#5 |
Navy Seal
![]() Join Date: Apr 2005
Posts: 5,501
Downloads: 19
Uploads: 0
|
![]()
Sounds suspiciously like the Virtumonde trojan.
My wife got it last week, presumably through facebook or one of her frequented forums. Spybot picked it up but I had to rid it manually. Took a few hours. Oddly it got past both her hardware and software firewalls and her online virus scanner. |
![]() |
![]() |
![]() |
#6 | |
Crusty Capt.
![]() Join Date: Sep 2007
Posts: 2,752
Downloads: 40
Uploads: 25
|
![]() Quote:
I removed it and through our system. I was using Norton antivirus 2009 but I canceled the service. It didn't even stop it. I found it using Microsoft malware tool remover. That one is a real pain. It got through my routers firewall and my software's Finally have my system cleaned for the last week now. |
|
![]() |
![]() |
![]() |
#7 | ||
CINC Pacific Fleet
Join Date: Sep 2003
Location: Down Under
Posts: 34,688
Downloads: 171
Uploads: 0
|
![]() Quote:
![]() What I did was to start firefox this morning after completing a mod, I went to Photobucket to upload some pics, that went ok, I then went to FileFront & uploaded a file, I went through the browse & selected the file as soon as I clicked on "Upload" the progress bar came up & a new window opened to "aShopping.com", then COMODO came up with a warning, I didn't respond straight away when the damn virus warning popped up as in the image above, this is why the warning!! ![]() Neither Ad-Aware or Avira could fix it!! ![]() An urgent thread warning was a must!! ![]() Thank goodness I had re-ghosted only a week ago. ![]() Quote:
__________________
Sub captains go down with their ship! |
||
![]() |
![]() |
![]() |
#8 |
Crusty Capt.
![]() Join Date: Sep 2007
Posts: 2,752
Downloads: 40
Uploads: 25
|
![]()
Spybot only removed the adware that vundo added to the system 2 weeks ago.
Lol my wife says my new Dell XPS 730 is the cause. It started not long after we got the system. I said it was the antivirus not doing its job. I finally did some research and found some removal tools. Then I deleted any files that contained the virus. Her system too. Funny thing is my old rig wasn't effected. Just mine and my wifes Sony viao. Very strange...:hmm: Last edited by Wolfehunter; 12-16-08 at 12:26 AM. |
![]() |
![]() |
![]() |
#9 |
Ocean Warrior
![]() |
![]()
I would bet money it didn't come from Filefront. One of my computers was also recently infected, and it also bypassed my firewalls and antivirus protection.
You defiantly have the Virtumonde trojan as was mentioned, and its a royal pain to get rid of if you don't know what your doing (and most virus and spyware scanners cannot directly fix it due to how the virus works). Its also very common for these things to delay activation by days, weeks or even longer to prevent the trojan from being traced back to the host site. Now for getting rid of it... Go to this site and download Spybot S&D http://www.safer-networking.org/en/home/index.html Have it update and run a scan It should find Virtumonde, now look for the 2 .dll files that Spybot found (don't reboot). Go to the directory their in (/windows/system32) find them both (make sure you have unhidden the files) and rename them both to something else and remove the .dll extension. Now reboot, delete the renamed files by hand and have Spybot clean up the rest. If you can't rename the files then use something like Dr. Delete to have the files deleted on system startup Last edited by NeonSamurai; 12-16-08 at 12:34 AM. |
![]() |
![]() |
![]() |
#10 |
CINC Pacific Fleet
Join Date: Sep 2003
Location: Down Under
Posts: 34,688
Downloads: 171
Uploads: 0
|
![]()
Yes there sneaky damned things, If I could change the title to "Possible" I would, but at the time I was just frantic to get the warning up for others here on Subsim, then save certain files like "Outlook Express" and re-ghost, for some reason I'm not game enough to try it again!!
![]() ![]() Edit: Just posted same time as Me NeonSamurai, are you able to change the title?
__________________
Sub captains go down with their ship! Last edited by Reece; 12-16-08 at 12:36 AM. |
![]() |
![]() |
![]() |
#11 | |
Ocean Warrior
![]() Join Date: Sep 2006
Location: Connecticut
Posts: 2,507
Downloads: 145
Uploads: 0
|
![]() Quote:
I would love to meet the *expletive, expletive, explitive* who wrote that damn trojan. It's one of the most prevalent ones out there now. EVERYONE is getting it. My own parents got it on their computer and they don't go anywhere but CNN.com and they don't use email. If I ever find the *expletive, expletive, expletive* who wrote it, I'm going to shove my foot so far up his *expletive* that he won't every be able to *expletive* in comfort ever again ! ![]() (By the way.. virus and spyware scanners won't get rid of it. It will even shut down most of them.)
__________________
![]() ![]() ![]() ![]() Last edited by Blacklight; 12-16-08 at 02:48 AM. |
|
![]() |
![]() |
![]() |
#12 |
Sea Lord
![]() Join Date: May 2006
Location: 5 Miles Inland West Of Lake Huron
Posts: 1,936
Downloads: 139
Uploads: 0
|
![]()
I've been uploading a few artfiles over the last 2 weeks, and have not had any problems with Filefront.
__________________
A legislative act contrary to the Constitution is not law. -John Marshall Chief Justice of the Supreme Court --------------------- |
![]() |
![]() |
![]() |
#13 | |
Rear Admiral
![]() Join Date: Mar 2005
Posts: 13,224
Downloads: 5
Uploads: 0
|
![]() Quote:
"PC freezes and creahes" ?! ![]() |
|
![]() |
![]() |
![]() |
#14 |
Watchdog
![]() Join Date: Jan 2007
Location: Hampshire UK
Posts: 971
Downloads: 152
Uploads: 0
|
![]()
Reece, I have come in late on this and someone else may have already covered - but the message you were getting is NOT genuine, it is a false claim caused by a driveby download, nothing to do with Filefront.
You have picked it up from somewhere without realising it ( which is by design), and it will pop up these lurid messages about infections you haven't got, trying to get you to by the product, which is a scam and a waste of money. This link http://news.bbc.co.uk/1/hi/technology/7779223.stm tells you about scareware, and though the one you have may not be named here, it is of that class.Sorry if this is already dealt with - in a rush and no time to read all messages ![]() Here is a very good anti-malware site that has removal instructs for this. http://www.bleepingcomputer.com/malw...-antivirus-360. Hope it helps Last edited by She-Wolf; 12-16-08 at 11:27 AM. |
![]() |
![]() |
![]() |
#15 |
Grey Wolf
![]() Join Date: Mar 2008
Posts: 913
Downloads: 16
Uploads: 0
|
![]()
I don't know if anyone else has experienced this but there seem to be an awful lot of pop-ups on Filefront lately (last 3-4 days). My pop-up blocker has been kept pretty busy whenever I've been there recently. Think that I'll steer clear of the site for a while...
|
![]() |
![]() |
![]() |
|
|