GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   GFY Installing Malware - Post If You've Got Hit (https://gfy.com/showthread.php?t=967899)

Barefootsies 05-11-2010 12:59 PM

Quote:

Originally Posted by BarryP (Post 17129386)
This has been located and should be resolved.

:thumbsup

Loki 05-11-2010 01:06 PM

BarryP: Cool Cool, however the first page of this thread is STILL setting off Avast (I'm thinking due to Smokey's post #46 where he showed the code of the exploit)

-Loki-

halfpint 05-11-2010 01:09 PM

Quote:

Originally Posted by BarryP (Post 17129386)
This has been located and should be resolved. Please let me know if you see this error from now on.

Barry I know this is not your fault but to leave the forum for so long with this maleware running just aint funny. I spent a good half a day trying to get this off my comp.

Glad its sorted now

BarryP 05-11-2010 01:12 PM

Quote:

Originally Posted by Loki (Post 17129422)
BarryP: Cool Cool, however the first page of this thread is STILL setting off Avast (I'm thinking due to Smokey's post #46 where he showed the code of the exploit)

-Loki-

Try it now.

CurrentlySober 05-11-2010 01:32 PM

Edit. Just seen what I posted in another thread.

Nikki_Licks 05-11-2010 01:37 PM

Finally was able to remove this damn thing...looks good so far.

Fucking spyware :321GFY

Jayvis 05-11-2010 01:40 PM

Quote:

Originally Posted by Loki (Post 17129328)
Jayvis: LMAO.. um... NO, Well I mean sure if you want to risk some good ole' fashioned identity theft then go right ahead and buy it.

IF a company creates fake viruses to pimp out their software they MUST be an honest and safe company to give your credit card info to.

IF you're NOT talking about the payload software (the software that keeps popping up once your infected) then disregard my post ;)

-Loki-


I was kidding around, did a hard boot from yesterday and it was gone. :winkwink:

Dirty Dane 05-11-2010 01:41 PM

This shit happens everywhere. Even on paysites and affiliate programs.


If you are worried about local FTP accounts being compromised (+ the keylogger), try WinPatrol monitoring.

For simpler PDF usage, use Sumatra reader.

Run browsers and software in encrypted sandboxie. As portable versions, if possible.

Don't run your OS by default in administrative mode.

Only turn javascript and flash on, when you fap off to your own tubes :)

CIVMatt 05-11-2010 01:42 PM

Shit happens, thanks for getting it Berry

halfpint 05-11-2010 01:43 PM

Quote:

Originally Posted by Dirty Dane (Post 17129529)

Only turn javascript and flash on, when you fap off to your own tubes :)

:1orglaugh:1orglaugh

Loki 05-11-2010 01:44 PM

Quote:

Originally Posted by BarryP (Post 17129439)
Try it now.

All is good on page 1 now (hence I can quote now lol)

-Loki-

halfpint 05-11-2010 01:45 PM

Quote:

Originally Posted by CIVMatt (Post 17129531)
Shit happens, thanks for getting it Berry

have you got it removed from your comp now ?

SpongeBub 05-11-2010 01:50 PM

Glad I use NoScript and don't run javascript on GFY.com. I have had no problems because viruses cannot install themselves when you don't run javascript. GFY doesn't require JS (like a good website should not) and therefore, it displays and functions just fine without it.

CurrentlySober 05-11-2010 01:51 PM

ImageVenue .com has it now!

http://safeweb.norton.com/report/sho...imagevenue.com

ProG 05-11-2010 01:56 PM

Quote:

Originally Posted by SpongeBub (Post 17129556)
GFY doesn't require JS (like a good website should not)

Sorry but all 'good websites' use JavaScript :winkwink:

Deej 05-11-2010 01:58 PM

Is this just today? ... I havent logge don until now seeing this thread first....

halfpint 05-11-2010 01:59 PM

Quote:

Originally Posted by Deej (Post 17129580)
Is this just today? ... I havent logge don until now seeing this thread first....

Happened to me this morning ... UK time

Jim_Gunn 05-11-2010 02:01 PM

I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!

itto 05-11-2010 02:02 PM

Quote:

Originally Posted by adultish (Post 17129168)
I have forgot to warning you that if you are infected and have ftp accounts stored somewhere in your computer that high
chances all your sites resides in that ftp accounts are infected
also. So check it out now or your sites will be flagged by google
as spyware source. Good luck lads. It is such pain in the ass.
When that happened to me I was in killing mood for days.

I wanted to point this out again as i can unfortunately positively confirm that i found this shit injected into some of my sites.. (only those sites are affected, where i saved the account details in my ftp client). I can also confirm that this triggers some sort of "killing mood".

Ecchi22 05-11-2010 02:04 PM

This is what I found in the pdf file:

Quote:

Robyn privs simon tortoise simpsons hello rainbow abuta swearer ablepharia flowers dieter. Absorbency abstractitious abthainrie abkari acalepha tamara judith absorbency abstractitious abkari acalepha tamara. Ablactate mellon protect abthainrie abkari acalepha tamara judith absorbency abstractitious simon. Abstractitious tortoise simpsons hello rainbow abuta swearer ablepharia flowers dieter. Absorbency abstractitious rainbow abuta swearer ablepharia flowers dieter ersatz. Tamara judith absorbency abstractitious abuta swearer.

BIGTYMER 05-11-2010 02:04 PM

Quote:

Originally Posted by itto (Post 17129598)
I wanted to point this out again as i can unfortunately positively confirm that i found this shit injected into some of my sites.. (only those sites are affected, where i saved the account details in my ftp client). I can also confirm that this triggers some sort of "killing mood".

What FTP client do you use?

itto 05-11-2010 02:05 PM

Quote:

Originally Posted by BIGTYMER (Post 17129606)
What FTP client do you use?

i use FileZilla

halfpint 05-11-2010 02:05 PM

Quote:

Originally Posted by Jim_Gunn (Post 17129593)
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!

Have you got IE installed as well cause you should check the proxy settings in that as well

I had to do it twice and also make sure you browsers are shut down when you do the scan

I posted a log of some of the crap which you can remove manually to clean your comp. It wont be exactly the same but it will be similar

Ecchi22 05-11-2010 02:06 PM

Aaaand this: http://pastebin.com/Nz8iVr2M :)

Nikki_Licks 05-11-2010 02:10 PM

Quote:

Originally Posted by Jim_Gunn (Post 17129593)
I rebooted to safe mode and ram Malwarebytes and it fund the infection.My proxy settings in FF were normal. But upon re-boot to normal mode the infection came back twice already and I still cannot get rid of this thing! This is ending up to be a whole day wasted and I had a lot of work to do today!

I had a time with it, but finally got mallwarebytes to launch and it found 14 infections. I haven't had any problems since I rebooted...knock on wood.

And yes, you are right what a way to waste allot of time :disgust

beerptrol 05-11-2010 02:12 PM

I got hit with Antispyware Soft.
I looked up what process were running and narrowed it to uoxottgtssd.exe
I then rebooted in safe mode deleted this file, started normally and had a problem with the proxies after restarting the computer
so I rebooted again and restored my computer back 2 days. Got rid of the damn problem. I ran a couple different scans to make sure It was gone lol

Altwebdesign 05-11-2010 02:32 PM

Bloody damn thing. All clear now?!

kristin 05-11-2010 02:46 PM

D'oh got someone in the office. =)

PersianKitty 05-11-2010 02:49 PM

Crossing my fingers that my warning of the exploit late last night means that Kaspersky caught it n all is well. I did see a little box about an adobe error this morning, but nothing more. Almost afraid to reboot. n for me, the warning popped off a top banner on the main page of this forum.

Altwebdesign 05-11-2010 03:04 PM

It took effect for me without rebooting I went to login to gfy and about 30 seconds later it popped up installed

rowan 05-11-2010 03:11 PM

So it looks like the exploit is from Adobe [pdf] Reader?

It's a bloated piece of shit and this isn't the first time it has been exploited...

Change to Foxit Reader... you'll never look back...

GrouchyAdmin 05-11-2010 03:14 PM

http://www.hybridcars.com/files/imag...k-smug-313.gif

Barefootsies 05-11-2010 03:14 PM

Quote:

Originally Posted by rowan (Post 17129815)
It's a bloated piece of shit and this isn't the first time it has been exploited...

Agreed.
:thumbsup

Jakez 05-11-2010 03:14 PM

Quote:

Originally Posted by candyflip (Post 17128611)
Yep...definitely has something to do with Adobe, PDF and Reader.

ROFL, not surprising one bit.

quantum-x 05-11-2010 03:15 PM

Quote:

Originally Posted by rowan (Post 17129815)
So it looks like the exploit is from Adobe [pdf] Reader?

It's a bloated piece of shit and this isn't the first time it has been exploited...

Change to Foxit Reader... you'll never look back...

FoxIt is great, but is / was vulnerable to the latest round of attacks. Just so you know.

Vendzilla 05-11-2010 03:16 PM

I got hit, then contacted ICS, thanx Barry

I have AVAST, no worries, it blocked it

rowan 05-11-2010 03:17 PM

Quote:

Originally Posted by quantum-x (Post 17129827)
FoxIt is great, but is / was vulnerable to the latest round of attacks. Just so you know.

Well that's put a real downer on things! :winkwink: I'd better go update. :error

rowan 05-11-2010 03:22 PM

PS: Vendors who change the look n' feel of their software every other update, suck.

mechanicvirus 05-11-2010 03:57 PM

bump for answers, who is getting banned for this stunt?

potter 05-11-2010 04:19 PM

Quote:

Originally Posted by mechanicvirus (Post 17129934)
bump for answers, who is getting banned for this stunt?

Anyone running windows deserved to get hit with a virus :2 cents:


All times are GMT -7. The time now is 09:12 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123