Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

Help with New Pron-Ad Virus or Bot (vanity)
vanity ^ | Dec. 6, 2010 | piytar

Posted on 12/06/2010 9:34:59 AM PST by piytar

Running Windows XP with Microsoft Security Essentials and Ad-Aware for protection. Getting random nasty (and I mean nasty) pron ads and links popping up. Sec Essentials and Ad-Aware scans show zilch. About to go through the misery of the Major Geek/Hijack This cleaning process, which takes hours (but does work). Thought I'd ask here first if anyone knew of a specific new pron virus/bot that's making the rounds. If so, it might help me clean it out quicker. Thanks!

PS I do searches for manufacturing for certain clients, so I end up on Chinese mfg sites a bit. (Trying to buy American, but done a search for mfg lateley? You get a LOT of hits in China et al.) Wonder if one of those was "dirty"? Does that help anyone id the virus/bot?


TOPICS: Computers/Internet
KEYWORDS: malware; pron; virus
Navigation: use the links below to view more comments.
first 1-2021-28 next last
See body.
1 posted on 12/06/2010 9:35:01 AM PST by piytar
[ Post Reply | Private Reply | View Replies]

To: piytar

I have had success with Superantispyware. It found items Malwarebytes did not.


2 posted on 12/06/2010 9:39:05 AM PST by UB355 (Slower traffic keep right)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

Not that I enjoy asking stupid questions I can answer anyway, but I have NEVER been able to figure out why any human being would take the time or delight in creating these things to harm innocent people who’ve never done any harm to them? Why? It just beyond comprehension to purposefully destroy something for absolutely NO reason?


3 posted on 12/06/2010 9:44:28 AM PST by Doc Savage (Stay Thirsty My Friend!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: UB355

Thanks! Will give it a try!


4 posted on 12/06/2010 9:49:31 AM PST by piytar (0's idea of power: the capacity to inflict unlimited pain and suffering on another human being. 1984)
[ Post Reply | Private Reply | To 2 | View Replies]

To: piytar

Try this first.

http://downloadcenter.trendmicro.com/index.php?clk=tbl&clkval=355&regs=NABU&lang_loc=1#undefined

then this

http://free.antivirus.com/


5 posted on 12/06/2010 9:52:30 AM PST by smokingfrog ( ><{{{{{(0>)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar
Ad-Aware is worthless. It is Swedish and owned by, I think, Norman ASA, both of which need to be avoided like the plague, for two reasons: 1, no good for detection - this is a 35th-rate outfit. 2, Antisemitic and pro-jihad company culture and a history of, well, like the Beagle Boys, in the case of Norman. Try and guess the number of actual criminals connected with the company - 0,1,2,3,4...

Generally, when AV-companies shows you tests (100% detection and so on), the test is fraudulent. That is because these tests are done against a small subset of viruses known as the wildlist. Compiling the wildlist is a small number of AV people and cronies. The problem with that is that the wildlist is a very small percentage of what is known to be in the wild.

What is known to be in the wild is collected by a couple of companies who, in practice, solicits new viruses. *That* list stands at several million. And those companies, like the subset-keepers, are paid by the AV-companies. At least, that was how things worked not very long ago, been a few months since I actually took that stuff apart.

If you deal with the AV establishment (like Trend, K7, Symantec, Norman and so on), there's a fairly high chance that you're being ripped off, contribute to very bad actors, or both.

6 posted on 12/06/2010 9:54:14 AM PST by Hardraade (I want gigaton warheads now!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: smokingfrog

Don’t even.

Try Avast instead. Free, effective and almost no footprint.


7 posted on 12/06/2010 9:56:04 AM PST by Hardraade (I want gigaton warheads now!!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: piytar

Fixwareout.exe

It runs in a ‘DOS’ or ‘command’ box.

Run it in Safe Mode only.


8 posted on 12/06/2010 10:00:25 AM PST by Bigh4u2 (Denial is the first requirement to be a liberal)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

Browse the web with a vmware machine running linux. Furthermore, use an “undoable disk”.


9 posted on 12/06/2010 10:00:40 AM PST by ROTB (Sans Christian revival, we are government slaves, or nuked by China/Russia when we finally revolt.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Hardraade

Good info, thanks for posting.
What do you know about Webroot/Spy Sweeper?


10 posted on 12/06/2010 10:09:02 AM PST by Lancey Howard
[ Post Reply | Private Reply | To 7 | View Replies]

To: piytar

Well, it COULD be an extreme use of flash cookies to call ads, the link to the settings manager http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager08.html.
Only take a minute to delete all.

And make sure you use the “full scan” of sec essentials. I assume you checked your host file, cleaned your cache.

Good luck.


11 posted on 12/06/2010 10:15:49 AM PST by mrsmith
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

I find this tool helpful for Windows systems as well as linux you can boot it up and scan your system without any programs running has lots of good rescue tools you can find information about it at www.distrowatch.com it is called Trinity Rescue Kit.


12 posted on 12/06/2010 10:15:58 AM PST by Lees Swrd ("Arms discourage and keep the invader and plunderer in awe and preserve order in the world as well")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Hardraade

By the way, IIR, Ad-Aware is owned by a company called ‘Lavasoft’. I used to have that (actually a paid subscription) but it ran out and they never even emailed me to solicit renewal or acknowledged me as a customer. This was a couple of years ago. It was odd, and made me suspicious of what kind of company it is. So I forgot about it.


13 posted on 12/06/2010 10:18:31 AM PST by Lancey Howard
[ Post Reply | Private Reply | To 6 | View Replies]

To: All

Thanks, all! Will try some/all of the suggestions. Really hate doing the Hijack This routine. Will report back if any of the suggestions work.


14 posted on 12/06/2010 10:22:07 AM PST by piytar (0's idea of power: the capacity to inflict unlimited pain and suffering on another human being. 1984)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Doc Savage

Well, in the case of pron viruses/bots, it’s usually about the money and using other people’s computers to store nasty stuff (i.e., avoiding criminal liability).

Personally, I think people who write these things should get life in jail. Many times I’ve lost an entire day’s work dealing with a virus. As a small business, that can REALLY hurt. Multiply that by thousands of people, and these things really do consume lifetimes or work and productivity. Hence, life in jail is just about right!


15 posted on 12/06/2010 10:25:27 AM PST by piytar (0's idea of power: the capacity to inflict unlimited pain and suffering on another human being. 1984)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Lancey Howard

Lavasoft more or less died, being that they got no attention from Norman I think. Far as I remember, the updates just stopped.

When Norman showed itself to be both incompetent, on turbo bigotry and more or less criminal, I went to Malwarebytes for a while, but that is sort of like a properly done Ad-Aware.

But have been running Avast for a year or two, very effective against everything (and I go some very hairy places), unobtrusive and totally trouble free. The company also seems remarkably clean, in a business sector that is basically a thieves market - for example, when Norman got a new CEO in from Symantec a few months back, my first impression was The Beagle Boys hiring a Gambino.


16 posted on 12/06/2010 10:34:21 AM PST by Hardraade (I want gigaton warheads now!!)
[ Post Reply | Private Reply | To 13 | View Replies]

To: piytar

If you download anything, especially from a porn site, then that increases your chances of hijackers/virus/spam...

Best way to avoid this is to not surf porn and to be very careful when downloading a file. Best way to download a file is to save it to your desktop, and then scan it before you install it.


17 posted on 12/06/2010 10:54:51 AM PST by Sprite518
[ Post Reply | Private Reply | To 1 | View Replies]

To: Hardraade
Lavasoft more or less died, being that they got no attention from Norman I think. Far as I remember, the updates just stopped.

Thanks! I guess that explains why they didn't care about subscribers going away.

How about Webroot? I have been running Spy Sweeper (now Webroot AV) for at least 5 years and have had pretty good experience with it. I am not, however, real impressed with the new screen format they came up with a year or two ago.

18 posted on 12/06/2010 10:56:18 AM PST by Lancey Howard
[ Post Reply | Private Reply | To 16 | View Replies]

To: piytar
I do searches for manufacturing for certain clients, so I end up on Chinese mfg sites a bit. (Trying to buy American, but done a search for mfg lateley? You get a LOT of hits in China et al.) Wonder if one of those was "dirty"?

Very likely. I saw somewhere a survey of infected websites, by country. It was staggering - half the websites in some countries are infected. I can't advise you what to scan your computer with, but it might be quicker and more certain to reload Windows. If you really must browse risky foreign websites, you ought to boot your Windows PC temporarily from a Linux CD (no installation required) and browse the Internet using the FireFox browser in Linux. When finished, remove the Linux CD and reboot to Windows. I don't know a safer way to "surf".

19 posted on 12/06/2010 10:56:37 AM PST by TexasRepublic (Socialism is the gospel of envy and the religion of thieves)
[ Post Reply | Private Reply | To 1 | View Replies]

To: piytar

Make sure before you run your full virus and spyware scans, you reboot the computer first and press f8 inbetween the cmos startup and windows splash screen to get to the windows boot menu, choose safe mode without networking. You may end up with a very basic video setting with a decreased resolution, but work around it.

Then run a full virus scan on all drive partitions (C:, D:, etc...) on your computer. Then run any adware removal type programs to remove anything else. This may take an hour or more to finish the scan depending on how much data you have on the machine.

Also check your startup configuration to see if anything has been set to start everytime you boot that shouldn’t be there.

Quick way is to run: msconfig

You can start it by typing that in the run programs area.

Check the startup tab. You’ll see what programs are set load on reboots everytime. You can always google search on anything listed there that seems suspect by either the file name or program name. Just becare not to disable or delete important things like mouse and video drivers, etc...

Once all that is done, you can try reboot as you normally do. Hopefully, that will clean out anything that was missed before.


20 posted on 12/06/2010 10:57:36 AM PST by Proud_USA_Republican ("The problem with socialism is that you eventually run out of other people's money.")
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson