Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-11-2010, 12:01 PM   #101
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
Go back to their website and download their latest version, the program updates you get now won't change the GUI or the program icons, you'll need to re-install the latest version to have the coolness I have lol.

It's cool though, the voice prompts are now female and not the boooooming male voice "VIRUS DATABASES HAVE BEEN UPDATED"

I think they are now using the AT&T Voicepacks maybe?

-Loki-
__________________
MAKE MONEY WITH 3D TOONS!
Need hosting? LokiCa$h Uses Amerinoc and love them!
Skype: LokiPorn Or Email 3dloki|at|gmail.com
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:01 PM   #102
Zverka
Confirmed User
 
Zverka's Avatar
 
Join Date: Jun 2005
Location: EU
Posts: 278
Quote:
Originally Posted by holograph View Post
white square i was talking about earlier next to top banner

that white square is hidden iframe which can be recognized as
hidden iframe containg javascript in the source of the page
either gfy source page or advertisers iframe source page
__________________
Zverka is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:03 PM   #103
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
here is some more info on helping you to get rid of this shit

Look for these entries and Remove them These might not be the same on your comp but they will be simillar

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:5555

R3 - URLSearchHook: (no name) - - (no file)

O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll

O4 - HKLM\..\Run: [flquqogp] C:\Documents and Settings\xxxx\Local Settings\Application Data\iwtnxrmxj\lkceppetssd.exe

O4 - HKLM\..\Run: [asam] C:\Documents and Settings\Administrator\Local Settings\Application Data\asam.exe

O4 - HKLM\..\Run: [ixbdhntx] C:\Documents and Settings\Administrator\Local Settings\Application Data\lbakdayih\tlduisstssd.exe

O4 - HKLM\..\Run: [fjscgslq] C:\Documents and Settings\xxxxx\Local Settings\Application Data\wjogyytnf\wmcjfdbtssd.exe

O4 - HKCU\..\Run: [flquqogp] C:\Documents and Settings\xxxx\Local Settings\Application Data\iwtnxrmxj\lkceppetssd.exe

O4 - HKCU\..\Run: [asam] C:\Documents and Settings\xxxx\Local Settings\Application Data\asam.exe

O4 - HKCU\..\Run: [fjscgslq] C:\Documents and Settings\xxxx\Local Settings\Application Data\wjogyytnf\wmcjfdbtssd.exe

O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab

O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - Adobe - Adobe Acrobat: Create PDF file, edit PDF file, convert PDF to word, convert PDF to doc

O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thi...wnloadCtrl.cab

O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)

After you remove these download hijackthis 2.04,

Then run CCleaner and make sure all entries are checked and then run the registry cleaner

Run Cleanup!

Then go to start, run, type msconfig and press enter. Go to the Startup tab, click disable all, then recheck your antivirus entry, then reboot

Reboot back into safemode

Then run Combofix, Malwarebytes, Microsoft Security Essentials, Remove all infections found with malwarebytes and MSE.
__________________

Get FREE website listings on Cryptocoinshops.net

Last edited by halfpint; 05-11-2010 at 12:07 PM..
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:03 PM   #104
Fabien
Confirmed User
 
Industry Role:
Join Date: Jul 2003
Posts: 4,787
Quote:
Originally Posted by Loki View Post
halfpint: this is what I have been seeing for the last two hours now:


Notice the address is this thread, I tab GFY most times, so I had just opened this thread in a new tab and got that warning, and the other screenshot above (stop shot) is as far as I can get without manually coming to the 2nd page

What I'm using:
Avast 5.0.507
Virus Definitions version: 100511-0

All live scans are enabled (or shields)

-Loki-


Same as Loki here
Fabien is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:06 PM   #105
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
:2cents

Quote:
Originally Posted by NanoBot View Post
You know what's not cool is that dudes are quick to ban people over petty shit around these parts, but we can sit here getting infected with whatever and nobody gives a shit. I guarantee if post: "Hey guys, meet me over at (insert another adult board here) since GFY is fucking up", I will be banned within minutes.

If it's the banners then all somebody would have to do is remove the ad codes, fix this shit, then put them back... right? Or at least give that a try?

Barefootsies... try working your mod magic, bro. Pretend somebody just broke a rule and you need to contact somebody in charge asap so you can make a banned thread.
__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:07 PM   #106
Cyber Fucker
Hmm
 
Cyber Fucker's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: On an endless road around the world for rock and roll.
Posts: 12,642
Yes, I got it too ...wtf admin does?! I mean no Eric, he's not tech... but there is a tech admin here, am I right? Can't you just secure the server and script?
__________________
Cyber Fucker is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:09 PM   #107
ProG
Confirmed User
 
Join Date: Apr 2009
Posts: 1,319


I had to enable ads to find it but the domain ESET is seeing as a threat is http://qa.dep.lt/

(ps: don't click that URL unless you are protected)
__________________
History will be kind to me for I intend to write it.
ProG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:20 PM   #108
CIVMatt
Amateur Pimpin
 
CIVMatt's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
I'm still not sure what and where I'm putting those things into the FF network screen
__________________
Make easy money with Webcams
CIVMatt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:24 PM   #109
starpimps
Confirmed User
 
Join Date: Sep 2006
Location: internets
Posts: 6,954
Ok so i had that popup but right now no fake antivirus app, so am I in the clear? Running malwarebytes right now.
__________________
Teen Porn Models / Solo Girls
starpimps is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:27 PM   #110
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
i saw a white banner in the banner space, maybe that was it
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:29 PM   #111
fatfoo
ICQ:649699063
 
Industry Role:
Join Date: Mar 2003
Posts: 27,763
GFY installs malware? I am not aware and I did not see any signs that this happened.
__________________
Send me an email: [email protected]
fatfoo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:30 PM   #112
Jayvis
Confirmed User
 
Industry Role:
Join Date: Nov 2005
Location: Cincinnati, Ohio
Posts: 5,427
I got hit, guys its a simple solution... just buy the malware software when its installed! Wall-ah! Problem fixed.
Jayvis is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:34 PM   #113
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
Jayvis: LMAO.. um... NO, Well I mean sure if you want to risk some good ole' fashioned identity theft then go right ahead and buy it.

IF a company creates fake viruses to pimp out their software they MUST be an honest and safe company to give your credit card info to.

IF you're NOT talking about the payload software (the software that keeps popping up once your infected) then disregard my post ;)

-Loki-
__________________
MAKE MONEY WITH 3D TOONS!
Need hosting? LokiCa$h Uses Amerinoc and love them!
Skype: LokiPorn Or Email 3dloki|at|gmail.com
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:36 PM   #114
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Jayvis View Post
I got hit, guys its a simple solution... just buy the malware software when its installed! Wall-ah! Problem fixed.
The irony is that is impossible,since it always popup how you are infected and slowing system a lot.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:38 PM   #115
Zverka
Confirmed User
 
Zverka's Avatar
 
Join Date: Jun 2005
Location: EU
Posts: 278
Quote:
Originally Posted by tical View Post
some of these adware installations will dump password data from browsers and ftp clients and send them to a host somewhere... i've seen it happen on several machines of mine over the years

i would find a plain text file on my system that had all of my usernames/passwords in it (ie, firefox, cuteftp)
to BIGTYMER tical already explain this to you
in addition I can say they install keylogger on
your machine.

I hope all you have root password on the paper clip
instead stored somewhere in the files.

Good luck lads
__________________

Last edited by Zverka; 05-11-2010 at 12:46 PM.. Reason: typo
Zverka is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:40 PM   #116
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
And all this shit could be avoided if ff and adblock pro was used.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:47 PM   #117
MikeFold
Confirmed User
 
MikeFold's Avatar
 
Join Date: Nov 2001
Location: semi-retired
Posts: 465
Grabbed the page info----

Location: /http/://qa.dep.lt/info/us1.html/s002102317805r0409J00020401R3f1d03ebXd11548b9Y9afc 18fbZ03003f36

Type: application/pdf

Size:`44.16 KB (45,215 bytes)

Dimensions: 0px × 0px

Page: http://www.gofuckyourself.com/showth...=967899&page=3
__________________
nothing to promote

Last edited by MikeFold; 05-11-2010 at 12:50 PM.. Reason: removed url tags
MikeFold is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:47 PM   #118
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by CIVMatt View Post
I'm still not sure what and where I'm putting those things into the FF network screen
are you trying to change the proxy settings in the FF network ?
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:50 PM   #119
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
KlenTelaris:not 100% true, I only use FF and I have Adblock Pro turned on, I only avoided the issue by having the latest and most updated Avast running on my machines.

The funny thing is ABP is flawed as hell, don't believe me
head to a site like http://www.blogtalkradio.com for example,

look at all the ads that ABP allows to still come through,

then "Open blockable items" and find the shown ads and manually block them

reload the page and see the MOST of the same ads.

Don't get me wrong ABP is GOOD helper BUT it just don't stop all that it could stop,and day by day the ad networks are finding ways around ABP and other blockers.

-Loki-
__________________
MAKE MONEY WITH 3D TOONS!
Need hosting? LokiCa$h Uses Amerinoc and love them!
Skype: LokiPorn Or Email 3dloki|at|gmail.com
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:58 PM   #120
BarryP
Confirmed User
 
BarryP's Avatar
 
Industry Role:
Join Date: Oct 2002
Posts: 145
This has been located and should be resolved. Please let me know if you see this error from now on.
__________________
Who will be the next MissGFY?!
Attention Industry Females & Solo Girls - Register Now for MissGFY Q4


GoFuckYourself.com
Have a Suggestion? Issue? Interested in Advertising? Contact me!
Barryp AT adult.com | icq 559539603
BarryP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 12:59 PM   #121
Barefootsies
Choice is an Illusion
 
Barefootsies's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: Land of Obama
Posts: 42,635
Quote:
Originally Posted by BarryP View Post
This has been located and should be resolved.
__________________
Should You Email Your Members?

Link1 | Link2 | Link3

Enough Said.

"Would you rather live like a king for a year or like a prince forever?"
Barefootsies is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:06 PM   #122
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
BarryP: Cool Cool, however the first page of this thread is STILL setting off Avast (I'm thinking due to Smokey's post #46 where he showed the code of the exploit)

-Loki-
__________________
MAKE MONEY WITH 3D TOONS!
Need hosting? LokiCa$h Uses Amerinoc and love them!
Skype: LokiPorn Or Email 3dloki|at|gmail.com
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:09 PM   #123
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by BarryP View Post
This has been located and should be resolved. Please let me know if you see this error from now on.
Barry I know this is not your fault but to leave the forum for so long with this maleware running just aint funny. I spent a good half a day trying to get this off my comp.

Glad its sorted now
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:12 PM   #124
BarryP
Confirmed User
 
BarryP's Avatar
 
Industry Role:
Join Date: Oct 2002
Posts: 145
Quote:
Originally Posted by Loki View Post
BarryP: Cool Cool, however the first page of this thread is STILL setting off Avast (I'm thinking due to Smokey's post #46 where he showed the code of the exploit)

-Loki-
Try it now.
__________________
Who will be the next MissGFY?!
Attention Industry Females & Solo Girls - Register Now for MissGFY Q4


GoFuckYourself.com
Have a Suggestion? Issue? Interested in Advertising? Contact me!
Barryp AT adult.com | icq 559539603
BarryP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:32 PM   #125
CurrentlySober
Too lazy to wipe my ass
 
CurrentlySober's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,534
Edit. Just seen what I posted in another thread.
__________________


👁️ 👍️ 💩

Last edited by CurrentlySober; 05-11-2010 at 01:34 PM..
CurrentlySober is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:37 PM   #126
Nikki_Licks
Confirmed User
 
Nikki_Licks's Avatar
 
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
Finally was able to remove this damn thing...looks good so far.

Fucking spyware
__________________
Amateur Content
ICQ: 292 356 077
Nikki_Licks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:40 PM   #127
Jayvis
Confirmed User
 
Industry Role:
Join Date: Nov 2005
Location: Cincinnati, Ohio
Posts: 5,427
Quote:
Originally Posted by Loki View Post
Jayvis: LMAO.. um... NO, Well I mean sure if you want to risk some good ole' fashioned identity theft then go right ahead and buy it.

IF a company creates fake viruses to pimp out their software they MUST be an honest and safe company to give your credit card info to.

IF you're NOT talking about the payload software (the software that keeps popping up once your infected) then disregard my post ;)

-Loki-

I was kidding around, did a hard boot from yesterday and it was gone.
Jayvis is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:41 PM   #128
Dirty Dane
Sick Fuck
 
Dirty Dane's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: www
Posts: 9,491
This shit happens everywhere. Even on paysites and affiliate programs.


If you are worried about local FTP accounts being compromised (+ the keylogger), try WinPatrol monitoring.

For simpler PDF usage, use Sumatra reader.

Run browsers and software in encrypted sandboxie. As portable versions, if possible.

Don't run your OS by default in administrative mode.

Only turn javascript and flash on, when you fap off to your own tubes
Dirty Dane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:42 PM   #129
CIVMatt
Amateur Pimpin
 
CIVMatt's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
Shit happens, thanks for getting it Berry
__________________
Make easy money with Webcams
CIVMatt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:43 PM   #130
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Dirty Dane View Post

Only turn javascript and flash on, when you fap off to your own tubes
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:44 PM   #131
Loki
Confirmed User
 
Loki's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Michigan
Posts: 4,420
Quote:
Originally Posted by BarryP View Post
Try it now.
All is good on page 1 now (hence I can quote now lol)

-Loki-
__________________
MAKE MONEY WITH 3D TOONS!
Need hosting? LokiCa$h Uses Amerinoc and love them!
Skype: LokiPorn Or Email 3dloki|at|gmail.com
Loki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:45 PM   #132
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by CIVMatt View Post
Shit happens, thanks for getting it Berry
have you got it removed from your comp now ?
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:50 PM   #133
SpongeBub
Confirmed User
 
SpongeBub's Avatar
 
Industry Role:
Join Date: May 2005
Posts: 470
Glad I use NoScript and don't run javascript on GFY.com. I have had no problems because viruses cannot install themselves when you don't run javascript. GFY doesn't require JS (like a good website should not) and therefore, it displays and functions just fine without it.
SpongeBub is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:51 PM   #134
CurrentlySober
Too lazy to wipe my ass
 
CurrentlySober's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: A Public Bathroom
Posts: 38,534
ImageVenue .com has it now!

http://safeweb.norton.com/report/sho...imagevenue.com
__________________


👁️ 👍️ 💩
CurrentlySober is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:56 PM   #135
ProG
Confirmed User
 
Join Date: Apr 2009
Posts: 1,319
Quote:
Originally Posted by SpongeBub View Post
GFY doesn't require JS (like a good website should not)
Sorry but all 'good websites' use JavaScript
__________________
History will be kind to me for I intend to write it.
ProG is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:58 PM   #136
Deej
I make pixels work
 
Deej's Avatar
 
Industry Role:
Join Date: Jun 2005
Location: I live here...
Posts: 24,386
Is this just today? ... I havent logge don until now seeing this thread first....
__________________

Deej's Designs n' What Not
Hit me up for Design, CSS & Photo Retouching


Icq#30096880
Deej is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 01:59 PM   #137
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Deej View Post
Is this just today? ... I havent logge don until now seeing this thread first....
Happened to me this morning ... UK time
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:01 PM   #138
Jim_Gunn
Confirmed User
 
Jim_Gunn's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!
__________________
Jim Gunn
Filming Cinematic Porn
Skype JimGunnProductions
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:02 PM   #139
itto
Confirmed User
 
itto's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: world wide
Posts: 1,363
Quote:
Originally Posted by adultish View Post
I have forgot to warning you that if you are infected and have ftp accounts stored somewhere in your computer that high
chances all your sites resides in that ftp accounts are infected
also. So check it out now or your sites will be flagged by google
as spyware source. Good luck lads. It is such pain in the ass.
When that happened to me I was in killing mood for days.
I wanted to point this out again as i can unfortunately positively confirm that i found this shit injected into some of my sites.. (only those sites are affected, where i saved the account details in my ftp client). I can also confirm that this triggers some sort of "killing mood".
__________________
itto is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:04 PM   #140
Ecchi22
Too lazy to set a custom title
 
Ecchi22's Avatar
 
Industry Role:
Join Date: Nov 2005
Posts: 10,012
This is what I found in the pdf file:

Quote:
Robyn privs simon tortoise simpsons hello rainbow abuta swearer ablepharia flowers dieter. Absorbency abstractitious abthainrie abkari acalepha tamara judith absorbency abstractitious abkari acalepha tamara. Ablactate mellon protect abthainrie abkari acalepha tamara judith absorbency abstractitious simon. Abstractitious tortoise simpsons hello rainbow abuta swearer ablepharia flowers dieter. Absorbency abstractitious rainbow abuta swearer ablepharia flowers dieter ersatz. Tamara judith absorbency abstractitious abuta swearer.
__________________
Ecchi22 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:04 PM   #141
BIGTYMER
Junior Achiever
 
BIGTYMER's Avatar
 
Industry Role:
Join Date: Nov 2004
Location: Walled Garden
Posts: 17,066
Quote:
Originally Posted by itto View Post
I wanted to point this out again as i can unfortunately positively confirm that i found this shit injected into some of my sites.. (only those sites are affected, where i saved the account details in my ftp client). I can also confirm that this triggers some sort of "killing mood".
What FTP client do you use?
BIGTYMER is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:05 PM   #142
itto
Confirmed User
 
itto's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: world wide
Posts: 1,363
Quote:
Originally Posted by BIGTYMER View Post
What FTP client do you use?
i use FileZilla
__________________
itto is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:05 PM   #143
halfpint
GFY's Halfpint
 
halfpint's Avatar
 
Industry Role:
Join Date: Jun 2007
Location: UK
Posts: 15,223
Quote:
Originally Posted by Jim_Gunn View Post
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!
Have you got IE installed as well cause you should check the proxy settings in that as well

I had to do it twice and also make sure you browsers are shut down when you do the scan

I posted a log of some of the crap which you can remove manually to clean your comp. It wont be exactly the same but it will be similar
__________________

Get FREE website listings on Cryptocoinshops.net
halfpint is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:06 PM   #144
Ecchi22
Too lazy to set a custom title
 
Ecchi22's Avatar
 
Industry Role:
Join Date: Nov 2005
Posts: 10,012
Aaaand this: http://pastebin.com/Nz8iVr2M
__________________
Ecchi22 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:10 PM   #145
Nikki_Licks
Confirmed User
 
Nikki_Licks's Avatar
 
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
Quote:
Originally Posted by Jim_Gunn View Post
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!
I had a time with it, but finally got mallwarebytes to launch and it found 14 infections. I haven't had any problems since I rebooted...knock on wood.

And yes, you are right what a way to waste allot of time
__________________
Amateur Content
ICQ: 292 356 077
Nikki_Licks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:12 PM   #146
beerptrol
Confirmed Asshole
 
beerptrol's Avatar
 
Industry Role:
Join Date: Feb 2003
Location: Half way between sobriety and fubar.
Posts: 12,722
I got hit with Antispyware Soft.
I looked up what process were running and narrowed it to uoxottgtssd.exe
I then rebooted in safe mode deleted this file, started normally and had a problem with the proxies after restarting the computer
so I rebooted again and restored my computer back 2 days. Got rid of the damn problem. I ran a couple different scans to make sure It was gone lol
__________________
“If we are to have another contest in the near future of our national existence, I predict that the dividing line will not be Mason and Dixon's but between patriotism and intelligence on the one side, and superstition, ambition and ignorance on the other.”
-- Ulysses S. Grant

Last edited by beerptrol; 05-11-2010 at 02:13 PM..
beerptrol is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:32 PM   #147
Altwebdesign
Guest
 
Posts: n/a
Bloody damn thing. All clear now?!
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:46 PM   #148
kristin
GOO!
 
Industry Role:
Join Date: Sep 2002
Location: Back Home : )
Posts: 9,768
D'oh got someone in the office. =)
__________________
Vacares rules.

"Usually only fat guys have the kind of knowledge and ability that Kristin has."
kristin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 02:49 PM   #149
PersianKitty
Meow Media Inc.
 
PersianKitty's Avatar
 
Industry Role:
Join Date: Jul 2001
Location: In the valley of the sun, cactus, tacos, tequila, and nod
Posts: 7,785
Crossing my fingers that my warning of the exploit late last night means that Kaspersky caught it n all is well. I did see a little box about an adobe error this morning, but nothing more. Almost afraid to reboot. n for me, the warning popped off a top banner on the main page of this forum.

Last edited by PersianKitty; 05-11-2010 at 03:00 PM..
PersianKitty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-11-2010, 03:04 PM   #150
Altwebdesign
Guest
 
Posts: n/a
It took effect for me without rebooting I went to login to gfy and about 30 seconds later it popped up installed
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.