Page 1 of 2

Invasive virus alert

Posted: Sat Feb 26, 2011 6:51 pm
by Pennpaul
I accessed the Pandora message block and the photo url. Now I have an insideous virus macro called "System Tool" that is hitting me with virus, trojan and spyware msgs. It has also placed an overlay msg on my desk top. So far it has pretty much disabled my software, and McAfee. Even the task manager has been disabled. I am taking my PC tower into the Geek Squad.

Anyone have any info on this d***n thing

4P

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 7:20 pm
by JohnM
Here is a decent tutorial on it.



Usually, these nest themselves in the .htaccess file in the root of the persons website and only activate when you reach the site using a search engine. But, this new version sounds even worse.

I clicked on all the links but did not get anything obvious, but on Mac's they usually don't do anything bit sit there. I will run a full scan and see where it may be hiding.

JohnM

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 7:39 pm
by Indrid Cold
I didn't click on any of the links, thank goodness.

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 7:48 pm
by LadyAsh
Oh dear, this is a complex one

Here is a website that tells you how to get rid of it

http://www.bleepingcomputer.com/virus-r ... ystem-tool

But it is long and eventually uses malwarebytes antimalware (when you can finally download it, the virus will try to block access to the site for download) which I love and have on my laptop. I advise everyone to have antimalware as it is the best I have found to deal with these rogue anti-spyware programs. If, like me, you have a trouble with patience on computers, the Geek Squad is the best bet.

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 10:21 pm
by Bluestone
Pennpaul,

Thanks for bringing this matter to our attention. We have deleted the links to Pandora's site and advised her of the virus that appears to have infected her site. We have also asked her to advise us when, and if, the virus has been effectively removed from her site.

To All FF Members,

FF is a safe, virus free environment, but please be careful when you click links that take you away from FF as we cannot protect you from the dangers inherit on the Internet. As always, it is vital that you maintain up-to-date virus protection and that you take care to only visit trusted sites.

If any members have any other tips to combat this virus, please post that information here for everyone's assistance.

Blue

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 10:37 pm
by Indrid Cold
Talk about opening Pandora's Box...

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 11:23 pm
by misspandora
As I posted on my thread, that was a link to DFN, darkfetsihnet.com.

I don't run that site. It was a link to my social networking profile there.

Many of you should be familiar with that site-it's the main social networking site for erotic horror.

If they have a virus, that would be odd because no one has mentioned it on their discussion forum. I personally have never had a problem or heard of any problems. And people posted replies to my thread indicating they clicked the link with no problem.

Anyway, you guys who have viruses, you need to notify the administrators at Darkfetshnet.com, not me.


Pennpaul wrote:I accessed the Pandora message block and the photo url. Now I have an insideous virus macro called "System Tool" that is hitting me with virus, trojan and spyware msgs. It has also placed an overlay msg on my desk top. So far it has pretty much disabled my software, and McAfee. Even the task manager has been disabled. I am taking my PC tower into the Geek Squad.

Anyone have any info on this d***n thing

4P

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 11:23 pm
by misspandora
Like I said, this was NOT a link to my site.
Bluestone wrote:Pennpaul,

Thanks for bringing this matter to our attention. We have deleted the links to Pandora's site and advised her of the virus that appears to have infected her site. We have also asked her to advise us when, and if, the virus has been effectively removed from her site.

To All FF Members,

FF is a safe, virus free environment, but please be careful when you click links that take you away from FF as we cannot protect you from the dangers inherit on the Internet. As always, it is vital that you maintain up-to-date virus protection and that you take care to only visit trusted sites.

If any members have any other tips to combat this virus, please post that information here for everyone's assistance.

Blue

Re: Invasive virus alert

Posted: Sat Feb 26, 2011 11:33 pm
by JohnM
DFN is clean. I have checked out suggestions of viruses before and just moments ago ran the site though:
http://www.unmaskparasites.com/
Which, if you are ever worried about a site, run it through this before you go to it.

I will check out your profile, Pandora, and see if there is anything, but I suspect it was a latent virus that might have been already picked up and was waiting for a cue of sorts.

One person in my family still runs a Windows-based pc so I still get to deal with those issues from time to time. I had a run it with the that particular virus and they can be sneaky in when they strike.

JohnM

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 12:34 am
by Bluestone
misspandora wrote:As I posted on my thread, that was a link to DFN, darkfetsihnet.com.

I don't run that site. It was a link to my social networking profile there.
Pandora,

There was also a link posted to a site with your photos. I believe it was this site that was the problem, not DFN.

Blue

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 12:34 am
by smudger
I was very concerned since I also checked out Pandora's site. I have had no infection and have run a full Norton sweep, no problems. It's pretty much impossible to tell where these shitty things come from. The best advice is as stated, if you pay, do a chargeback and report the putrid scammers.

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 12:51 am
by misspandora
If you all clicked on a link, it would've either been:

1) my darkfetishnet.com profile, which has tons of my photos.

OR

2) my pandorahorror.com site.

Neither of which have viruses. I checked with my ISP-they almost laughed at me over email.

I suspect this virus came from an email the OP clicked on, or an IM. That's the way most trojans are sent.

Like Smudger said,it can be very hard to figure out where these things come from. I'm just glad I have a Mac and don't have to deal with that type of thing anymore!

Guess I sure made a splash with my first post, huh!

:shake: :shake:

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 1:06 am
by Sandi
I merely wish to add a second 'vote' or word of praise for Malwarebytes' AntiMalware.

The last time I became infected, and eventually had to wipe out my system and reload the original XP disc, I spent 3 phone calls of 3 hours apiece with Microsoft's free number.

Yes, all with Pakistani and Indian phone contacts.

Finally, they raised me to a higher status of Troubleshooter and he took over my machine, installed Malwarebytes' software even though I RUN Microsoft's OWN MS Essentials every night!!

I thought that was a rather significant endorsement of Malwarebytes, when MS uses it themselves over their own Product!

And at on that occasion, and again last WEEK when one of those mysterious 'YOU ARE INFECTED" messages comes up that one cannot get rid of and that leads to the infections, I ran Malwarebytes and it caught and fixed ALL the problems, including the ones Essentials did not catch...lol.

The MS Tech installed it remotely, did not remove it, and so it's been 'free' to me and helped me twice already.

Sandi

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 1:38 am
by misspandora
My ISP hosts thousands of sites and said they've never had a virus on any of their servers.

If you run my site thru that unmaskpirates.com page, it says:

This page seems to be <clean>
Would you like to check other pages?

@Webmaster: This is not a definitive test. Check the report below. Maybe you can spot some suspicious details there.

For more comprehensive diagnostics consider the following additional tests.

Website security is an ongoing process. Bookmark this service and check your web pages regularly.
Report
General
Title:
Miss Pandora's House of Erotic Horror - Home
URL: http://www.pandorahorror.com
Google: not currently listed as suspicious* (details)
Generator: Parallels Plesk Sitebuilder 4.5.0
Last checked: 0 minutes ago (results are cached for 1 hour)
This report:
External References
No external references found.

The fact that I check my site on my PC all the time and never got a virus, and the fact that smudger and others clicked on my link with no problem, suggests to me, something else is going on there.

Serenga from DFN told me sometimes McAfee and other software pops up virus alerts on his site, but he runs hardcore antivirus software on the servers.

Re: Invasive virus alert

Posted: Sun Feb 27, 2011 2:01 am
by Bluestone
misspandora wrote:Guess I sure made a splash with my first post, huh!
Sure did! :D

Well, it looks like those who were infected must have received the infection elsewhere. Anyway, at least we've received a lot of advice about anti-virus software and how important it is in today's ever-changing Internet world.

Blue