1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

A relitivly new form of attack

Discussion in 'Windows - Virus and spyware problems' started by Mez, Dec 6, 2012.

Thread Status:
Not open for further replies.
  1. Mez

    Mez Active member

    Joined:
    Aug 12, 2005
    Messages:
    2,895
    Likes Received:
    9
    Trophy Points:
    68
    Tainted adds request a plug-in which is actually malware. In many places it can fake your OS to believe you have consented to install something but you do not even see a dialog box to let you know something is going on.

    Once the malware is attached to your browser that is all she wrote! All downloads can be tainted with what ever the malware wants you to install. It will install dlls and executable all over the place making it impossible to remove You can only remove it by formatting your disk. It has access through your fire wall. It doesn't need to keylog it has everything you send to the internet before the encryption. It is not detectable by Highjackthis and does not behave as a virus so malware detectors do not see any malicious behavior. Chances are if you do not have an add blocker you have one or more of these critters on your computer as you read this.
     
  2. aldan

    aldan Active member

    Joined:
    Mar 24, 2007
    Messages:
    1,724
    Likes Received:
    42
    Trophy Points:
    78
    disturbing to say the least.i would go crazy without simple adblock.if im curious about a product or service i will research it.
     
  3. Mez

    Mez Active member

    Joined:
    Aug 12, 2005
    Messages:
    2,895
    Likes Received:
    9
    Trophy Points:
    68
    Had I not been sandboxed I would not have been suspicious. If you download files it puts them in the sandbox and asks you what to do with it. If you have been away from your desk you get creeped out with a message 'where should I put this file'. I also get warnings that the browser can't be modified while sandboxed again often this happens during an idle period. I can only assume that there are multiple attacks occuring from various threats in just a few minutes. You can also see that files were added to your system folders without your permission. If it were not sandboxed who would notice a few extra files in your system folder but being sandboxed they are the only files there and there should be NO files. With the frequency of my attacks I would be very surprised if everyone wasn't infected unless they are very careful.

    Addblock seems to be helpful. I have not seen anything suspicious in a half hr on this site. That is a first. I will check out the sand box and the user area before I delete this user.
     
    Last edited: Dec 11, 2012
  4. Mez

    Mez Active member

    Joined:
    Aug 12, 2005
    Messages:
    2,895
    Likes Received:
    9
    Trophy Points:
    68
    I was attacked by at least one very tough customer which I am familiar with. It attacked my sandbox. I do not dare keep this user. It installs more software during startup. Deleting it after each use is tedious but not as tedious as formatting C:.
     
  5. Ripper

    Ripper Active member

    Joined:
    Feb 20, 2006
    Messages:
    4,697
    Likes Received:
    13
    Trophy Points:
    68
    Mez, I appreciate your posts but sometimes I do think you need a breath of fresh air occasionally.

    While I don't doubt that something like you've described exists, I think to suggest that everyone is probably infected with it and to go to such extreme measures as creating and then destroying a new user account every time you browse the web is a bit much.

    You don't mention anything about timescale from infection to full-blown meltdown of Windows, nor if it is a gradual degradation of the OS or a sudden lack of proper function.

    FWIW, I have never had a serious enough infection to warrant formatting a HDD.
     
  6. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    I agree with Ripper, Mez must be the loneliest person on the forum..
    [​IMG]
     
  7. Mez

    Mez Active member

    Joined:
    Aug 12, 2005
    Messages:
    2,895
    Likes Received:
    9
    Trophy Points:
    68
    There is no degradation. Maybe I am paranoid because I get worried when I come to a site like AD and within 30 minutes I get a new folder filled with database files and java script files. It is possible that they are not malicious but it I refrain from going to any sites with adds I do not see these files.

    I agree, [a deep breath] maybe I need to research a good deal more before I make out.


    2old That is quite a statement! How do you figure I am the loneliest person on the forum? What makes you think I am lonely at all? I post about an hour a week today it is closer to 2. Is that too much or too little or is it something else that makes me so lonely? Maybe you also need a breath of fresh air?
     
  8. Ripper

    Ripper Active member

    Joined:
    Feb 20, 2006
    Messages:
    4,697
    Likes Received:
    13
    Trophy Points:
    68
    So if there is no degradation of the OS, then what is the problem?

    I spend far more time here than you and 2Old combined, I should think, so I wouldn't worry about that comment!
     
  9. ddp

    ddp Moderator Staff Member

    Joined:
    Oct 15, 2004
    Messages:
    39,158
    Likes Received:
    134
    Trophy Points:
    143
    i don't have that problem & i spend more time on this site then any of you do combined.
     
  10. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Well, Mez, I just had the thought that if you had a girlfriend then you wouldn’t spend so much time on the internet and maybe your paranoia of catching something that couldn’t be fixed would just go away.. Look around. There are some cute little things out there that can cure all your ills. Live, love and be happy…[​IMG]

    2oG
     
Thread Status:
Not open for further replies.

Share This Page