Page 2 of 3 FirstFirst 1 2 3 LastLast
Results 21 to 40 of 43

Thread: i've been hacked--warning!!!

  1. #21
    Eye Shooter Steve Cebu's Avatar
    Join Date
    Nov 2011
    Location
    New Hampshire
    Posts
    909
    Thanks
    1,025
    Thanks Received
    896

    Default Re: i've been hacked--warning!!!

    I run a firewall and that stops a lot from getting through. You might just think your PC is clean when in fact it could have bad stuff on it. It's best to check if you have nothing then you are lucky.

  2. #22
    Pachi Puro RaymondV's Avatar
    Join Date
    Nov 2006
    Location
    Mt Clemens, MI
    Posts
    4,152
    Thanks
    5,557
    Thanks Received
    4,107

    Default Re: i've been hacked--warning!!!

    I had this same thing on Friday night.
    It was a pain in the a$$ to get rid of it.
    Pachislo - Super Bingo-King Camel-Mephisto-Neo Pharaoh Zetz-Nangokusodachi-Mu Mu World DX-Super BlackJack-Death Valley-Gin Gin Maru-Power Jump
    Pachinko - Fever the King-Monster Village-Top Gun-Thunderzone-Casino Fever-Super Sea Story

  3. #23
    MacGruber JACKSJE4's Avatar
    Join Date
    Dec 2008
    Location
    Denver, CO
    Posts
    5,002
    Thanks
    11,367
    Thanks Received
    14,376

    Default Re: i've been hacked--warning!!!

    As some of you know, my primary "day" job is to provide computer tech support for a very large, global company. While I am a small fish in a large pond, I occasionally stumble upon simple solutions to what seem like big problems. This week I spent 10-12 hours each day assisting my "customers" with removing the "XP Security 2012" malware (and several other versions like it) from their computers. Through lots of researching, conversing with coworkers across the country who perform the same function, as well as a LOT of trial and error, we developed an approach to removing this @#$%^& malware that appears to be simple and effective. Remembering this thread, I thought I would post it here to help save all of you some time should your computer become infected.


    It's important to note that our company is a Windows XP shop, so this remedy was developed for Windows XP users. I do not know how/if it will work on any other version.


    1. Find the link on the XP security 2012 'scan' page to "register/activate" the software (typically in the upper right) and enter this Registration Key: 3425-814615-3990. The malware will activate, and drop some of its defenses.

    2. Download and run Rkill.exe ( Bleeping Computer Downloads: RKill ) Note: rkill takes 15-25 seconds to appear after you launch it, so be patient! Rkill will end all spyware processes and allow you to install Malwarebytes

    3. Download, install and update the free version of Malwarebytes ( Malwarebytes : Free anti-malware, anti-virus and spyware removal download ). This program will remove the malware files and registry keys. Perform a "quick scan" and remove all infections it finds. Click on "Yes" to reboot your computer when it is done.

    4. Save the text file (attached below) to your desktop. Change the file extension of this txt file to .reg and run it on the system. This will correct any file association issues that some versions of the malware create

    5. Click Start -> Run, and type sfc /scannow on the "Open" line. Click OK. This will correct any residual windows system file issues that can cause problems with the network card, among other things.

    6. Reboot your computer.


    I also recommend creating a second user account with full administrator access. Some versions of the malware will not activate with the above code, and rkill will not run while the malware is active. To get around this issue, you can right-click on rkill.exe and select "Run As..." then enter the name and password (if any) of your second user account. rkill should launch and run normally.

    I sincerely hope you don't fall victim to any of the malware programs circulating around the internet right now, but if you do, these steps should help you get your computer healthy again.

    Jeff
    Attached Files Attached Files
    Last edited by JACKSJE4; 12-30-2011 at 08:09 PM.
    Jeff Jackson, Denver CO

    There is a fine line between "hobby" and "mental illness."

  4. The following 8 users say "Thanks" to JACKSJE4


  5. #24
    Day Dream Believer beachcat's Avatar
    Join Date
    Jul 2008
    Location
    Atlantic Beach Florida
    Posts
    4,451
    Thanks
    7,520
    Thanks Received
    3,469

    Default Re: i've been hacked--warning!!!

    Jeff, this information is valuable! Thank you for sharing it.. this needs to be made a sticky for future references


  6. The following user says "Thanks" to beachcat


  7. #25
    Pachi Puro RaymondV's Avatar
    Join Date
    Nov 2006
    Location
    Mt Clemens, MI
    Posts
    4,152
    Thanks
    5,557
    Thanks Received
    4,107

    Default Re: i've been hacked--warning!!!

    I got this damn thing on my computer again today.
    I used Jeff's method to get rid of it.
    Pachislo - Super Bingo-King Camel-Mephisto-Neo Pharaoh Zetz-Nangokusodachi-Mu Mu World DX-Super BlackJack-Death Valley-Gin Gin Maru-Power Jump
    Pachinko - Fever the King-Monster Village-Top Gun-Thunderzone-Casino Fever-Super Sea Story

  8. The following user says "Thanks" to RaymondV


  9. #26
    Eye Shooter Microbus99's Avatar
    Join Date
    Sep 2009
    Location
    Aurora, Co. (suburb of Denver)
    Posts
    896
    Thanks
    1,958
    Thanks Received
    1,550

    Default Re: i've been hacked--warning!!!

    Jeff, Thanks for your technical expert advice. I got bit by the same viruses mentioned by everyone. Its usually calls itself an "antivirus removal program" and totally takes over your computer. It was also on my work laptop and wouldnt let me access our secured server. I run Mcaffee Antivirus and the virus disables this program.

    I had to send my laptop to our corporate IT department and they took care of it. I have no idea how they did it but they returned my computer in the exact condition before the virus attacked. Windows Restore doesnt change anything and Malwarebytes didnt help either.

    Surf the net wisely!!

  10. #27
    Closet Okie Meathead's Avatar
    Join Date
    May 2006
    Location
    Foresthill, California
    Posts
    2,718
    Thanks
    2,332
    Thanks Received
    6,304

    Default Re: i've been hacked--warning!!!

    My wife's laptop just picked it up. She has Vista though. Opened a window called "System Check" Any suggestions for removal? Is it the same process as XP?
    A Hardy har har...

  11. #28
    Fever Hunter mark1120's Avatar
    Join Date
    Jul 2005
    Location
    United States
    Posts
    240
    Thanks
    280
    Thanks Received
    454

    Default Re: i've been hacked--warning!!!

    Has anyone else sent a PM to Sid? I did so about a week ago, but at the time I wasn't 100% certain that pachitalk.com was the source...but that's obviously the case now. I'm now hesitant to visit the site. About 20% of the time, my malware alert goes off when I log on.

  12. #29
    Pachi Puro RaymondV's Avatar
    Join Date
    Nov 2006
    Location
    Mt Clemens, MI
    Posts
    4,152
    Thanks
    5,557
    Thanks Received
    4,107

    Default Re: i've been hacked--warning!!!

    Quote Originally Posted by Meathead View Post
    My wife's laptop just picked it up. She has Vista though. Opened a window called "System Check" Any suggestions for removal? Is it the same process as XP?
    I have Vista, it worked for me.
    I don't think Pachitalk is the source, not for me anyway.
    Pachislo - Super Bingo-King Camel-Mephisto-Neo Pharaoh Zetz-Nangokusodachi-Mu Mu World DX-Super BlackJack-Death Valley-Gin Gin Maru-Power Jump
    Pachinko - Fever the King-Monster Village-Top Gun-Thunderzone-Casino Fever-Super Sea Story

  13. #30
    Ensign Newton owennewton's Avatar
    Join Date
    Mar 2007
    Location
    McMinnville, Oregon, United States
    Posts
    4,830
    Thanks
    32,278
    Thanks Received
    5,244

    Default Re: i've been hacked--warning!!!

    It is the banner ads that are the issue and not the site.
    the

    LLTR

  14. The following user says "Thanks" to owennewton


  15. #31
    Eye Shooter Steve Cebu's Avatar
    Join Date
    Nov 2011
    Location
    New Hampshire
    Posts
    909
    Thanks
    1,025
    Thanks Received
    896

    Default Re: i've been hacked--warning!!!

    Quote Originally Posted by owennewton View Post
    It is the banner ads that are the issue and not the site.

    Time for some new sponsors then.

  16. #32
    Goodwill Ambassador luckydog's Avatar
    Join Date
    Nov 2004
    Location
    bradenton, florida
    Posts
    31,487
    Thanks
    13,448
    Thanks Received
    24,112

    Default Re: i've been hacked--warning!!!

    I don't think the people running ads are responsible, the ads are being hacked too!!
    幸運わんわん Luckydog or Yukiwanwan in Japanese

  17. The following user says "Thanks" to luckydog


  18. #33
    MacGruber JACKSJE4's Avatar
    Join Date
    Dec 2008
    Location
    Denver, CO
    Posts
    5,002
    Thanks
    11,367
    Thanks Received
    14,376

    Default Re: i've been hacked--warning!!!

    I am not sure what the source of this malware is, but I suspect that a "seed" is transmitted via Java, Flash, a .JPG or some other transport medium, and then the "seed" slowly downloads the malware installer over a short period of time and assembles/builds the malware on your hard drive. I have been infected with it on my computer, and the only sites I had visited was CNN, Craigslist and PachiTalk. I assisted one of my work "customers" who got hit over the Christmas weekend, and all he did was connect to his parents WiFi network, and without opening a web page it took over his computer (possibly transmitted by another computer on the network??). Perhaps there are multiple ways it can propagate.

    Vigilance is key. Be careful of the sites you visit and make sure you have both a virus AND a malware detection program running at all times. (Virus and Malware are two completely different animals).
    Last edited by JACKSJE4; 01-02-2012 at 01:03 AM.
    Jeff Jackson, Denver CO

    There is a fine line between "hobby" and "mental illness."

  19. The following 5 users say "Thanks" to JACKSJE4


  20. #34
    Closet Okie Meathead's Avatar
    Join Date
    May 2006
    Location
    Foresthill, California
    Posts
    2,718
    Thanks
    2,332
    Thanks Received
    6,304

    Default Re: i've been hacked--warning!!!

    Are there any recommended free anti-virus and malware programs? I have always hated some of the commercially available programs. They have dramatically slowed down my computer and greatly increased the time to boot up. My last installation of Norton I could not uninstall when I wanted to.
    A Hardy har har...

  21. #35
    Eye Shooter Microbus99's Avatar
    Join Date
    Sep 2009
    Location
    Aurora, Co. (suburb of Denver)
    Posts
    896
    Thanks
    1,958
    Thanks Received
    1,550

    Default Re: i've been hacked--warning!!!

    You're the man Jeff. By the way I've never had this problem with this site. However, when I'm logged into the VW/Audi server, it wont let me into Pachitalk because it picks up the word "gambling" somewhere and blocks it. Not every time but its funny when it does sometimes.

    Thanks again. We need you on our IT team!

  22. #36
    Goodwill Ambassador luckydog's Avatar
    Join Date
    Nov 2004
    Location
    bradenton, florida
    Posts
    31,487
    Thanks
    13,448
    Thanks Received
    24,112

    Default Re: i've been hacked--warning!!!

    malwarebytes and windows essentials are free
    幸運わんわん Luckydog or Yukiwanwan in Japanese

  23. #37
    Ensign Newton owennewton's Avatar
    Join Date
    Mar 2007
    Location
    McMinnville, Oregon, United States
    Posts
    4,830
    Thanks
    32,278
    Thanks Received
    5,244

    Default Re: i've been hacked--warning!!!

    Avast and Comodo are good virus protection and comodo is also a great firewall
    the

    LLTR

  24. The following user says "Thanks" to owennewton


  25. #38
    Eye Shooter Steve Cebu's Avatar
    Join Date
    Nov 2011
    Location
    New Hampshire
    Posts
    909
    Thanks
    1,025
    Thanks Received
    896

    Default Re: i've been hacked--warning!!!

    I use Comodo, it works very well all the years I've used it.

  26. The following user says "Thanks" to Steve Cebu


  27. #39
    Captain Weirdo Sid's Avatar
    Join Date
    Sep 2005
    Location
    Athens Greece
    Posts
    24,906
    Thanks
    19,843
    Thanks Received
    28,652

    Default Re: i've been hacked--warning!!!

    In regards to the Malware coming from Pachitalk.

    just saying or declaring that the PT is infected without pointing out exact details of where and or what happened is like saying the sky is falling the sky is falling
    there is no way to go over the entire site to see if there is an infection without some help. merely stating PT is infected without exact instances of where it occurred what you saw etc doesnt do much to help.
    neither does making generalizations that PT is the source of the malware. if it was the case i am sure that we would have had a great many more users pointing it out.


    as for the ads, our ads are provided by Google Adsense, they are reputable(industry leader in web advertising).. does this mean that there wont be issues from time to time. nope.. but they are reputable.
    should i turn the ads off? sure. but they are the thing that pays for the hosting of the site and cost of domain renewals, and software renewals.


    and finally me answering my PM's or Emails, every effort is made to reply to PM's and email but...

    As much as I'd like to have PT be the only thing i do with my life and be here 24/7 and give it sole priority in my life.
    i have the following things that unfortunately take precedent

    1) Full time job which entails a lot of overtime
    2) a Son that i am trying to see as much of as i can
    3) a significant other
    4) my need to actually get away from a computer and out of my mom's basement...
    5) its the holidays.. i'd like to enjoy them with friends and family...

    "I've stopped fighting my inner demons, we are on the same side now."

  28. The following 10 users say "Thanks" to Sid


  29. #40
    Captain Weirdo Sid's Avatar
    Join Date
    Sep 2005
    Location
    Athens Greece
    Posts
    24,906
    Thanks
    19,843
    Thanks Received
    28,652

    Default Re: i've been hacked--warning!!!

    Jeff Thanks for your helpful malware removal tips..

    "I've stopped fighting my inner demons, we are on the same side now."

  30. The following 5 users say "Thanks" to Sid


Page 2 of 3 FirstFirst 1 2 3 LastLast

Similar Threads

  1. Blue Hotaru Hacked...
    By Bartsimpson in forum Vendors & Manufacturers Pachislo
    Replies: 5
    Last Post: 09-26-2011, 07:10 PM
  2. Hacked Yellow Cab reaches the U.S.
    By JamesM in forum eBay - General Auction listings
    Replies: 8
    Last Post: 03-22-2005, 10:08 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •