![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Anybody had this bullshit Antisoft Malware on their computers (Help Needed Please)
I have the bullshit antisoft spyware on my computer and cant get rid of it I have tried changing the lan settings in IE even though I dont use it as it somehow uses a proxy and changes your homepage Then I ran Rkill Then Malwarebites which does pick it up and deletes it but as soon as I load up firefox or EI it just comes back agian IV been trying all sorst to get rid of this and it dont work
I also have avast running which does not seem to pick it up at all Anybody know how to get rid of this |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() Are you making sure to close it out in task manager, and do those other steps in safe mode?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Yep I have tried it in safe mode and also using RKill to stop it from running which should I think close it down in task manager. All this was done in safemode
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 | |
Confirmed User
Industry Role:
Join Date: Mar 2009
Posts: 265
|
Quote:
![]() Hijack this will show any suspicious software / reg keys that are on your box ...dump a log on here...maybe i can help you out.
__________________
i need money. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Carpe Visio
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
|
I got it last week somehow and got rid of it quickly. It stopped pretty much anything from opening, including the Task Manager.
I found a link that recommended Malwarebyte's Anti-Malware software. I booted into Safe Mode, installed the app (freeware) and it got rid of the issue on the first try. http://download.cnet.com/Malwarebyte...=dl&tag=button |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Join Date: Jul 2002
Location: Denver
Posts: 155
|
I just got this and was able to remove it by doing a system restore. I had to run it from the f8 menu on reboot though (windows 7). it wouldn't let me do it from the system restore program in programs/accessories/system tools.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
and it does pick it up and delete it but a soon as I boot back from safemode it just comes back |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
thanks guys |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 | |
Confirmed User
Join Date: Nov 2001
Location: semi-retired
Posts: 465
|
Quote:
thanks
__________________
nothing to promote |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 | |
Carpe Visio
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
|
Quote:
So I'm wondering if it came from here as well. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Join Date: Jul 2002
Location: Denver
Posts: 155
|
I can't 100% remember, but i don't believe xp has a restore option on the f8 menu, but you could try booting in safe mode and then trying to run system restore from programs/accessories/system tools
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Join Date: Aug 2004
Location: On The Edge
Posts: 7,992
|
Get a copy of Hiren's boot cd from a clean machine, then trying running some of the programs off of it in safe mode.
__________________
~ Doer of Things at MetArtMoney Where Flawless Beauty Meets Art ~The MetArt Network ~ selena.delgado9 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Join Date: Jul 2002
Location: Denver
Posts: 155
|
hmm...me too, i just randomly got it this morning and i believe i had gfy open at the time. I had other browsers open at the time too though
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Carpe Visio
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
|
Quote:
I was surfing GFY using Chrome when things went downhill. GFY and a handful of techblogs (Gizmodo, Engadget, etc) are all I surf from this box. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Confirmed User
Industry Role:
Join Date: May 2009
Location: Onboard an airplane around the globe
Posts: 3,733
|
Quote:
__________________
---------------------------------------------------------------------------------- The truth is not affected by the beliefs, or doubts, of the majority. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Confirmed User
Join Date: Nov 2001
Location: semi-retired
Posts: 465
|
thanks andy & selena...will deal with it when i get home....
I am almost positive it was from here...I hit the bookmark, went out to have s moke, and when i returned my screen was lit up with fake warnings, and nothing on the screen was clickable. (although I have spectorsoft on my home machine, if i do a system restore i will lose the video capture from this morning, i seem to recall seeing a 'brief' pop from adobe updater?) which i 'clicked Not Now' but it was definitely java type (i noticed the hard drive clicking away and gfy not loading right) so i immediately closed gfy (too late) it was early and no coffee yet, so it could have been a fake
__________________
nothing to promote |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Confirmed User
Join Date: Feb 2002
Location: Michigan
Posts: 5,940
|
I have had good success using the free BitDefender Live CD. It boots into linux and scans. Windows never starts, so the bugs don't have a chance to load.
http://www.techmixer.com/bitdefender...tion-features/
__________________
Free jscott !!! Free OneHungLo !!! Free Baddog !!! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
I am also starting to think it was from GFY cause My comp was fine last night and after I logged in to GFY I all of a sudden had this shit on my computer
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Carpe Visio
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
|
Let's keep this bumped and hopefully they will address it. It looks like there are others who've gotten stung by this too.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 | |
Amateur Pimpin
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
|
Quote:
__________________
Make easy money with Webcams |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Confirmed User
Industry Role:
Join Date: Mar 2009
Posts: 265
|
weird ...been on here for a few hours now ...not a hiccup!
__________________
i need money. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Nov 2001
Location: semi-retired
Posts: 465
|
Did you see the adobe updater popup? I just saw it again (it was blocked on this machine).
__________________
nothing to promote |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Porn Meister
Industry Role:
Join Date: Feb 2005
Posts: 16,443
|
Just wanted to mention that when I first logged in to GFY this morning, IE warned me that it blocked some software download. I didnt think much about it until I saw that Java was running. So I logged back out and closed down everything and came back. This time there was no download attempt warnings or java.
The last time I got that malware you're talking about, it came in a PDF file. I try not to open those anymore except local pdfs.
__________________
43-922-863 Shut up and play your guitar. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
It hit me yesterday. Restart computer in safe mode and run Malwarebytes. Restart computer and when you open FireFox/IE/Chrome you need to view the internet options and remove the proxy setting that the malware installed.
IP: 127.0.0.1 Port: 5555 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
It got me on a torrent site. I was trying to get last weeks episode of Survivor.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 |
Porn Meister
Industry Role:
Join Date: Feb 2005
Posts: 16,443
|
Ah yes thats right! It sets a proxy in your browser(s) for you to go reset.
__________________
43-922-863 Shut up and play your guitar. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Yes it does do that but you reset it and reboot the computer it just comes back again after trying all the above steps with malewarebytes also used hijackthis and have saved the logfile My son has posted this on a tech forum and they are going through the logs
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#32 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
ok gonna try that again thanks
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#33 |
Porn Meister
Industry Role:
Join Date: Feb 2005
Posts: 16,443
|
I remember there'd been 2 different files I think that had been added to my startup files (trying to remember, was on another computer). They had gobblygook names. I also stopped adobe from running ANYTHING in the background since it acts like a conduit.
As I recall, AVG never knew something was wrong, I had to download Avast free version and that did find it.
__________________
43-922-863 Shut up and play your guitar. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#34 |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#35 |
Hb17uaaldwM
Industry Role:
Join Date: Nov 2002
Location: In Your Skull
Posts: 15,147
|
i've had to remove that shit off 3 family members pcs in the past month..
though i do the manual removal method.. (safe mode with networking/lan settings/delete registry entries/delete files) followed by a malware bytes scan.. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#36 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Ok I seem to have got rid of it now by running malewarebytes in safemode and then changing the proxy settings. And Im also running noscript as well
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#37 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Thanks guys for all of your help
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#38 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Ok im now running a full scan with avast and it has come up with this JS:Pdfka-AFK [Expl]
so whether that has or had anything to do with it I do not know |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#39 |
ICQ:649699063
Industry Role:
Join Date: Mar 2003
Posts: 27,763
|
I have no idea. Good luck, halfpint.
__________________
Send me an email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#40 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
thanks I have got rid of it now, just in the process of cleaning my machine
|
![]() |
![]() ![]() ![]() ![]() ![]() |