Just thought I'd tell ya'

mtm2 and other sensible chat
N_Gage_18
Member
Posts: 498
Joined: Wed May 14, 2008 7:20 am
Location: Behind you

Just thought I'd tell ya'

Post by N_Gage_18 »

Hey guys(and girls, just in case), I may not be on very often for a while. First off, My brother is on here practically 24/7. Second, My computer is somehow acquiring DOZENS of Trojan Horse viruses, and my dad thinks it's either this site or another site my brother always goes to. Just thought I'd tell everyone.
Admin of the MTM2 Draggers facebook page, find it here!
https://m.facebook.com/groups/337032006 ... =bookmarks

Nat Gage (She/They, pls)
I used to be PM Customs but now I'm taking meds for that ;)
User avatar
Slayer
Member
Posts: 1822
Joined: Sun Oct 16, 2005 4:39 pm
Location: Winnipeg Manitoba, Canada

Post by Slayer »

I think I had that virus ones, took me out.... Time to reformat. Give Avira a try, I am curious if it solves it. if its the same as me, your explorer.exe has been modified and is now downloading viruses whenever you are connected to the internet.
Image
Shoot-me
Member
Posts: 7
Joined: Fri Dec 26, 2008 5:57 pm

Post by Shoot-me »

Are you useing Internet Explorer?
User avatar
Slayer
Member
Posts: 1822
Joined: Sun Oct 16, 2005 4:39 pm
Location: Winnipeg Manitoba, Canada

Post by Slayer »

Me or him? I got it through Opera.
Image
N_Gage_18
Member
Posts: 498
Joined: Wed May 14, 2008 7:20 am
Location: Behind you

Post by N_Gage_18 »

Mozilla Fire fox with Norton 360.
Admin of the MTM2 Draggers facebook page, find it here!
https://m.facebook.com/groups/337032006 ... =bookmarks

Nat Gage (She/They, pls)
I used to be PM Customs but now I'm taking meds for that ;)
User avatar
TlathamXmahtalT
Member
Posts: 702
Joined: Sun Jun 08, 2008 7:46 am
Location: In BinEdit, using YOUR models.
Contact:

Post by TlathamXmahtalT »

PM Customs wrote:Mozilla Fire fox with Norton 360.
That is the exact same as me.

But Norton is a trial.
User avatar
JerOutlaw
Member
Posts: 130
Joined: Thu May 31, 2007 12:19 am
Location: 3 hours from Alaska

Post by JerOutlaw »

get super antispyware or spybot search and destroy.
norton is garbage
Image
User avatar
TlathamXmahtalT
Member
Posts: 702
Joined: Sun Jun 08, 2008 7:46 am
Location: In BinEdit, using YOUR models.
Contact:

Post by TlathamXmahtalT »

JerOutlaw wrote:get super antispyware or spybot search and destroy.
norton is garbage
I tried Search & Destroy and it wouldn't work. My computer wouldn't connect to the server to install.

I'll try Super Anti-Spyware and see if it works.
User avatar
TlathamXmahtalT
Member
Posts: 702
Joined: Sun Jun 08, 2008 7:46 am
Location: In BinEdit, using YOUR models.
Contact:

Post by TlathamXmahtalT »

Actually, first, I'm going to try Avira Antivirus.

Slayer told me that when he came back, and I'll take him up on his offer first since he suggested something first. If it doesn't do its job, I'll try Super Antispyware.
User avatar
Slayer
Member
Posts: 1822
Joined: Sun Oct 16, 2005 4:39 pm
Location: Winnipeg Manitoba, Canada

Post by Slayer »

I've never heard of super anti spyware.... But doesn't sound like it will help you with a virus.

Spybot S&D and malwarebytes are the two best spyware/adware removal tools around. And Avira is a virus scanner and removal. Ideally you should have all three at least :). I have Avira running on my ancient system with only 256mb of RAM, Avira's memory footprint is... 13,732k in task manager.
Image
User avatar
TlathamXmahtalT
Member
Posts: 702
Joined: Sun Jun 08, 2008 7:46 am
Location: In BinEdit, using YOUR models.
Contact:

Post by TlathamXmahtalT »

Slayer wrote:malwarebytes...
Man...

I thought I had too much protection and it would slow my PC down if I kept some of them, so I deleted Malwarebytes... [uhoh] [uhoh] [uhoh]

You have a link to it so I can install it again?
N_Gage_18
Member
Posts: 498
Joined: Wed May 14, 2008 7:20 am
Location: Behind you

Post by N_Gage_18 »

Um, did you guys read my first post completely? My dad said the viruses could be coming from the TRUCK/TRACK pages. Can Phin run a virus scan on the pages or something? I would hate for everyone else to have to deal with this too.
Admin of the MTM2 Draggers facebook page, find it here!
https://m.facebook.com/groups/337032006 ... =bookmarks

Nat Gage (She/They, pls)
I used to be PM Customs but now I'm taking meds for that ;)
User avatar
TlathamXmahtalT
Member
Posts: 702
Joined: Sun Jun 08, 2008 7:46 am
Location: In BinEdit, using YOUR models.
Contact:

Post by TlathamXmahtalT »

PM Customs wrote:Um, did you guys read my first post completely? My dad said the viruses could be coming from the TRUCK/TRACK pages. Can Phin run a virus scan on the pages or something? I would hate for everyone else to have to deal with this too.
Would you really think a Trojan came from here, unless they WANTED you to get a virus?
Woody
Member
Posts: 96
Joined: Wed Nov 01, 2000 2:01 pm
Location: Minneapolis KS
Contact:

Post by Woody »

Um, did you guys read my first post completely? My dad said the viruses could be coming from the TRUCK/TRACK pages. Can Phin run a virus scan on the pages or something? I would hate for everyone else to have to deal with this too.
Since you are the only person that has reported this problem out of all the people that get files here I think its safe to say that this site is not the origin of the trouble.
Reality is for those that cant handle video games.
User avatar
Kasey9fan
Member
Posts: 241
Joined: Thu Jul 05, 2007 4:04 pm

Post by Kasey9fan »

PM Customs wrote:Um, did you guys read my first post completely? My dad said the viruses could be coming from the TRUCK/TRACK pages. Can Phin run a virus scan on the pages or something? I would hate for everyone else to have to deal with this too.
Lol...
-Jordan Robson
Image
Image
User avatar
Kmaster
MTM2 Engineer
Posts: 1369
Joined: Fri Oct 10, 2003 6:19 pm
Location: Valparaíso, Chile.
Contact:

Post by Kmaster »

PM Customs wrote:Can Phin run a virus scan on the pages or something? I would hate for everyone else to have to deal with this too.
I lol'd

Your computer is your problem, you're obviously infected.
User avatar
Slayer
Member
Posts: 1822
Joined: Sun Oct 16, 2005 4:39 pm
Location: Winnipeg Manitoba, Canada

Post by Slayer »

me 2, you have a virus that is auto downloading viruses whenever you are connected to the internet. This sort of virus is fairly effortless to create, there are literately millions of proof of concept programs for doing just this if you google it. The most common is using the memory modifying API. To basically tell explorer.exe to run commands. such as silently downloading files!
These exploits are already proven to defeat UAC. I even tried it, I found a site that provided VB6 code that could do it!


Get Avira on that machine, that should clean it up.
Image
User avatar
Kmaster
MTM2 Engineer
Posts: 1369
Joined: Fri Oct 10, 2003 6:19 pm
Location: Valparaíso, Chile.
Contact:

Post by Kmaster »

Thanks for the info Slay, I wonder if there's any way to know if explorer.exe is silently downloading any files. Port checking perhaps?
User avatar
Slayer
Member
Posts: 1822
Joined: Sun Oct 16, 2005 4:39 pm
Location: Winnipeg Manitoba, Canada

Post by Slayer »

whatsrunning can tell you, it will show explorer.exe having TCP sessions open and having CPU usage higher than normal.

http://www.whatsrunning.net/whatsrunning/main.aspx
Image
User avatar
Phineus
Glow Ball
Posts: 24
Joined: Tue Feb 02, 1999 7:00 pm

Post by Phineus »

Pod files cannot contain viruses. They do not execute in any way shape or form.

This server is UNIX. It is not windows. If you have a windows virus, you got it someplace else.

This site is proudly ten years virus free.
Post Reply