![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#101 |
Confirmed User
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
|
Go back to their website and download their latest version, the program updates you get now won't change the GUI or the program icons, you'll need to re-install the latest version to have the coolness I have lol.
It's cool though, the voice prompts are now female and not the boooooming male voice "VIRUS DATABASES HAVE BEEN UPDATED" I think they are now using the AT&T Voicepacks maybe? -Loki-
__________________
MAKE MONEY WITH 3D TOONS! Need hosting? LokiCa$h Uses Amerinoc and love them! Skype: LokiPorn Or Email 3dloki|at|gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#102 |
Confirmed User
Join Date: Jun 2005
Location: EU
Posts: 278
|
that white square is hidden iframe which can be recognized as
hidden iframe containg javascript in the source of the page either gfy source page or advertisers iframe source page
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#103 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
here is some more info on helping you to get rid of this shit
Look for these entries and Remove them These might not be the same on your comp but they will be simillar R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:5555 R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O4 - HKLM\..\Run: [flquqogp] C:\Documents and Settings\xxxx\Local Settings\Application Data\iwtnxrmxj\lkceppetssd.exe O4 - HKLM\..\Run: [asam] C:\Documents and Settings\Administrator\Local Settings\Application Data\asam.exe O4 - HKLM\..\Run: [ixbdhntx] C:\Documents and Settings\Administrator\Local Settings\Application Data\lbakdayih\tlduisstssd.exe O4 - HKLM\..\Run: [fjscgslq] C:\Documents and Settings\xxxxx\Local Settings\Application Data\wjogyytnf\wmcjfdbtssd.exe O4 - HKCU\..\Run: [flquqogp] C:\Documents and Settings\xxxx\Local Settings\Application Data\iwtnxrmxj\lkceppetssd.exe O4 - HKCU\..\Run: [asam] C:\Documents and Settings\xxxx\Local Settings\Application Data\asam.exe O4 - HKCU\..\Run: [fjscgslq] C:\Documents and Settings\xxxx\Local Settings\Application Data\wjogyytnf\wmcjfdbtssd.exe O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - Adobe - Adobe Acrobat: Create PDF file, edit PDF file, convert PDF to word, convert PDF to doc O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thi...wnloadCtrl.cab O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) After you remove these download hijackthis 2.04, Then run CCleaner and make sure all entries are checked and then run the registry cleaner Run Cleanup! Then go to start, run, type msconfig and press enter. Go to the Startup tab, click disable all, then recheck your antivirus entry, then reboot Reboot back into safemode Then run Combofix, Malwarebytes, Microsoft Security Essentials, Remove all infections found with malwarebytes and MSE. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#104 | |
Confirmed User
Industry Role:
Join Date: Jul 2003
Posts: 4,787
|
Quote:
Same as Loki here |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#105 | |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
![]() Quote:
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#106 |
Hmm
Industry Role:
Join Date: Sep 2005
Location: On an endless road around the world for rock and roll.
Posts: 12,642
|
Yes, I got it too ...wtf admin does?! I mean no Eric, he's not tech... but there is a tech admin here, am I right?
![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#107 | |
Confirmed User
Join Date: Apr 2009
Posts: 1,319
|
Quote:
![]() I had to enable ads to find it but the domain ESET is seeing as a threat is http://qa.dep.lt/ (ps: don't click that URL unless you are protected ![]()
__________________
History will be kind to me for I intend to write it. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#108 |
Amateur Pimpin
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
|
I'm still not sure what and where I'm putting those things into the FF network screen
__________________
Make easy money with Webcams |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#109 |
Confirmed User
Join Date: Sep 2006
Location: internets
Posts: 6,954
|
Ok so i had that popup but right now no fake antivirus app, so am I in the clear? Running malwarebytes right now.
__________________
Teen Porn Models / Solo Girls |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#110 |
8.8.8.8
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
|
i saw a white banner in the banner space, maybe that was it
__________________
TAEMDLRMSKRJIXMRLSMRJ. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#111 |
ICQ:649699063
Industry Role:
Join Date: Mar 2003
Posts: 27,763
|
GFY installs malware? I am not aware and I did not see any signs that this happened.
__________________
Send me an email: [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#112 |
Confirmed User
Industry Role:
Join Date: Nov 2005
Location: Cincinnati, Ohio
Posts: 5,427
|
I got hit, guys its a simple solution... just buy the malware software when its installed! Wall-ah! Problem fixed.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#113 |
Confirmed User
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
|
Jayvis: LMAO.. um... NO, Well I mean sure if you want to risk some good ole' fashioned identity theft then go right ahead and buy it.
IF a company creates fake viruses to pimp out their software they MUST be an honest and safe company to give your credit card info to. IF you're NOT talking about the payload software (the software that keeps popping up once your infected) then disregard my post ;) -Loki-
__________________
MAKE MONEY WITH 3D TOONS! Need hosting? LokiCa$h Uses Amerinoc and love them! Skype: LokiPorn Or Email 3dloki|at|gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#114 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#115 | |
Confirmed User
Join Date: Jun 2005
Location: EU
Posts: 278
|
Quote:
in addition I can say they install keylogger on your machine. I hope all you have root password on the paper clip instead stored somewhere in the files. Good luck lads
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#116 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
And all this shit could be avoided if ff and adblock pro was used.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#117 |
Confirmed User
Join Date: Nov 2001
Location: semi-retired
Posts: 465
|
Grabbed the page info----
Location: /http/://qa.dep.lt/info/us1.html/s002102317805r0409J00020401R3f1d03ebXd11548b9Y9afc 18fbZ03003f36 Type: application/pdf Size:`44.16 KB (45,215 bytes) Dimensions: 0px × 0px Page: http://www.gofuckyourself.com/showth...=967899&page=3
__________________
nothing to promote |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#118 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
are you trying to change the proxy settings in the FF network ?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#119 |
Confirmed User
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
|
KlenTelaris:not 100% true, I only use FF and I have Adblock Pro turned on, I only avoided the issue by having the latest and most updated Avast running on my machines.
The funny thing is ABP is flawed as hell, don't believe me head to a site like http://www.blogtalkradio.com for example, look at all the ads that ABP allows to still come through, then "Open blockable items" and find the shown ads and manually block them reload the page and see the MOST of the same ads. Don't get me wrong ABP is GOOD helper BUT it just don't stop all that it could stop,and day by day the ad networks are finding ways around ABP and other blockers. -Loki-
__________________
MAKE MONEY WITH 3D TOONS! Need hosting? LokiCa$h Uses Amerinoc and love them! Skype: LokiPorn Or Email 3dloki|at|gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#120 |
Confirmed User
Industry Role:
Join Date: Oct 2002
Posts: 145
|
This has been located and should be resolved. Please let me know if you see this error from now on.
__________________
Who will be the next MissGFY?! ![]() ![]() GoFuckYourself.com
Have a Suggestion? Issue? Interested in Advertising? Contact me! Barryp AT adult.com | icq 559539603 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#121 |
Choice is an Illusion
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#122 |
Confirmed User
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
|
BarryP: Cool Cool, however the first page of this thread is STILL setting off Avast (I'm thinking due to Smokey's post #46 where he showed the code of the exploit)
-Loki-
__________________
MAKE MONEY WITH 3D TOONS! Need hosting? LokiCa$h Uses Amerinoc and love them! Skype: LokiPorn Or Email 3dloki|at|gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#123 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
Glad its sorted now |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#124 |
Confirmed User
Industry Role:
Join Date: Oct 2002
Posts: 145
|
Try it now.
__________________
Who will be the next MissGFY?! ![]() ![]() GoFuckYourself.com
Have a Suggestion? Issue? Interested in Advertising? Contact me! Barryp AT adult.com | icq 559539603 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#125 |
Too lazy to wipe my ass
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,534
|
Edit. Just seen what I posted in another thread.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#126 |
Confirmed User
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
|
Finally was able to remove this damn thing...looks good so far.
Fucking spyware ![]()
__________________
Amateur Content ICQ: 292 356 077
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#127 | |
Confirmed User
Industry Role:
Join Date: Nov 2005
Location: Cincinnati, Ohio
Posts: 5,427
|
Quote:
I was kidding around, did a hard boot from yesterday and it was gone. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#128 |
Sick Fuck
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
|
This shit happens everywhere. Even on paysites and affiliate programs.
If you are worried about local FTP accounts being compromised (+ the keylogger), try WinPatrol monitoring. For simpler PDF usage, use Sumatra reader. Run browsers and software in encrypted sandboxie. As portable versions, if possible. Don't run your OS by default in administrative mode. Only turn javascript and flash on, when you fap off to your own tubes ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#129 |
Amateur Pimpin
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
|
Shit happens, thanks for getting it Berry
__________________
Make easy money with Webcams |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#130 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
![]() ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#131 |
Confirmed User
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
|
All is good on page 1 now (hence I can quote now lol)
-Loki-
__________________
MAKE MONEY WITH 3D TOONS! Need hosting? LokiCa$h Uses Amerinoc and love them! Skype: LokiPorn Or Email 3dloki|at|gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#132 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
have you got it removed from your comp now ?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#133 |
Confirmed User
Industry Role:
Join Date: May 2005
Posts: 470
|
Glad I use NoScript and don't run javascript on GFY.com. I have had no problems because viruses cannot install themselves when you don't run javascript. GFY doesn't require JS (like a good website should not) and therefore, it displays and functions just fine without it.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#134 |
Too lazy to wipe my ass
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,534
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#135 |
Confirmed User
Join Date: Apr 2009
Posts: 1,319
|
Sorry but all 'good websites' use JavaScript
![]()
__________________
History will be kind to me for I intend to write it. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#136 |
I make pixels work
Industry Role:
Join Date: Jun 2005
Location: I live here...
Posts: 24,386
|
Is this just today? ... I havent logge don until now seeing this thread first....
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#137 |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Happened to me this morning ... UK time
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#138 |
Confirmed User
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
|
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!
__________________
Jim Gunn Filming Cinematic Porn Skype JimGunnProductions |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#139 | |
Confirmed User
Industry Role:
Join Date: Jul 2006
Location: world wide
Posts: 1,363
|
Quote:
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#140 | |
Too lazy to set a custom title
Industry Role:
Join Date: Nov 2005
Posts: 10,012
|
This is what I found in the pdf file:
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#141 | |
Junior Achiever
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#142 |
Confirmed User
Industry Role:
Join Date: Jul 2006
Location: world wide
Posts: 1,363
|
__________________
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#143 | |
GFY's Halfpint
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
|
Quote:
I had to do it twice and also make sure you browsers are shut down when you do the scan I posted a log of some of the crap which you can remove manually to clean your comp. It wont be exactly the same but it will be similar |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#144 |
Too lazy to set a custom title
Industry Role:
Join Date: Nov 2005
Posts: 10,012
|
Aaaand this: http://pastebin.com/Nz8iVr2M
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#145 | |
Confirmed User
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
|
Quote:
And yes, you are right what a way to waste allot of time ![]()
__________________
Amateur Content ICQ: 292 356 077
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#146 |
Confirmed Asshole
Industry Role:
Join Date: Feb 2003
Location: Half way between sobriety and fubar.
Posts: 12,722
|
I got hit with Antispyware Soft.
I looked up what process were running and narrowed it to uoxottgtssd.exe I then rebooted in safe mode deleted this file, started normally and had a problem with the proxies after restarting the computer so I rebooted again and restored my computer back 2 days. Got rid of the damn problem. I ran a couple different scans to make sure It was gone lol
__________________
“If we are to have another contest in the near future of our national existence, I predict that the dividing line will not be Mason and Dixon's but between patriotism and intelligence on the one side, and superstition, ambition and ignorance on the other.” -- Ulysses S. Grant |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#147 |
Guest
Posts: n/a
|
Bloody damn thing. All clear now?!
|
![]() ![]() ![]() ![]() ![]() |
![]() |
#149 |
Meow Media Inc.
Industry Role:
Join Date: Jul 2001
Location: In the valley of the sun, cactus, tacos, tequila, and nod
Posts: 7,785
|
Crossing my fingers that my warning of the exploit late last night means that Kaspersky caught it n all is well. I did see a little box about an adobe error this morning, but nothing more. Almost afraid to reboot. n for me, the warning popped off a top banner on the main page of this forum.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#150 |
Guest
Posts: n/a
|
It took effect for me without rebooting I went to login to gfy and about 30 seconds later it popped up installed
|
![]() ![]() ![]() ![]() ![]() |