World Photography Forum

World Photography Forum (https://www.worldphotographyforum.com/index.php)
-   Computers and The Internet (https://www.worldphotographyforum.com/forumdisplay.php?f=26)
-   -   Virus checker stopping unothorised Visa up-load (https://www.worldphotographyforum.com/showthread.php?t=1905)

Saphire 08-02-07 16:45

1 Attachment(s)
I have done a screen capture of what I am getting. Today it seems to be everytime I leave the machine idle.

Vernon Barker 08-02-07 17:02

Just a thought, why not restore the system to a date before the problem started?

nirofo 08-02-07 17:07

Quote:

Originally Posted by Saphire (Post 16689)
I have done a screen capture of what I am getting. Today it seems to be everytime I leave the machine idle.

Hi Saphire

Looks to me like your Firefox web browser is trying to access a Google web link, maybe to install one of their many toolbars. I guess you must have installed some software recently which craftily leads you into ticking (or not ticking) a box that allows this download, you've really got to be on alert for this subterfuge these days. Only thing I can suggest is to fully uninstall your recent software (one at a time), restart your computer and see if you still have this problem. Also, go to the Start Menu, click on Run, type in msconfig and press return. Click on the Startup tab at the top of the box that appears, carefully go down the list of programs that automatically start when you start Windows, if you see one that looks like Google or Firefox, untick it and restart your computer. Dont untick any others at this stage !! If you see any others that look iffy but don't have Microsoft Windows attached to them you can untick these also one at a time, restart computer after unticking each one. If you find that some of your programs don't work after you have unticked a certain program just retick it and restart the computer.

Hope this helps.

nirofo.

Saphire 08-02-07 17:08

Looking back over my old log files it has been going on for months in the background, but this past week these have been the first warnings. All the logged ones before then were being passed as sent.

Saphire 08-02-07 17:13

1 Attachment(s)
This is what I have in startup at the moment, I can't see anything untoward.

nirofo 08-02-07 17:29

Hi Saphire

This is what is displayed when the web page address is accessed.

Quote:

[goog-black-url 1.8576 update]
+http://www.sjmanhole.com/.secureserv....org/login.htm c
-http://cari.diyzone.net/icons/pp/login.html
+http://200.67.222.214/00med/img/ccd....gon/index.html c
+http://202.64.93.106/www.paypal.com/...login-run2652/ c
+http://203.101.67.147/.secure.region...Visa/index.htm c
+http://203.177.52.70/www.regions.com...user&pass.html c
+http://209.197.151.46/~josh/sitekey/...file/step1.htm c
+http://211.222.16.52:84/www.ebay.com/ c
+http://211.96.149.51/usage/secure.re...ogon/index.htm c
+http://218.247.5.46/.www.paypal.com/...ypal/index.php c
+http://256k.org/service.capitalone.com/oas/login.htm c
+http://62.167.10.183:16080/ c
+http://63.247.75.211/phplive/web/onl...ices/login.htm c
+http://64.143.174.64/main.php c
+http://d192-24-111-218.try.wideopenw...me=p/index.php c
+http://libertytidings.info/_files/ht...l.dorigine_or/ c
+http://suncorp.com.au.suncorp_id.bre...nfo/start.htm/ c
+http://www.53.com.bankingportal.id39...onf/script.php c
+http://www.53.com.bankingportal.id97...end.info/conf/ c
+http://www.behealthier.com/media/www....au/logon.html c
+http://www.feuerwehr-elbenberg.com/L...esmar/main.htm c
+http://www.gomagma.nl/onlineid-sessi...date/step1.htm c
+http://www.googlezh.com/ c
+http://www.kunstwereld.nl/afb/update...he%20West.html c
+http://www.pen.nl/ubb/update.htm c
+http://www.postbank.de.-snm-76790411...end.info/pbde/ c
+http://www.postbank.de.privat.app51g...rm/welcome.do/ c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
-http://amazinglifegames.org/eAuction/www.bankofamerica.com/bankofamericacongratultion/new-bank-2007/signon/onlinebankingthankyou/index.html
-http://www.bankofamerica.com.onlinebankingid9304011.poyap e.co.nz/session.cgi/
-http://www.volksbank.de.networld.onlineid306184486.poyape .co.nz/kunde.htm
-http://www.volksbank.de.networld.onlineid54709.poyape.co. nz/kunde.htm
-http://www.volksbank.de.networld.onlineid66499.poyape.co. nz/kunde.htm
-http://www.volksbank.de.networld.onlineid786830.poyape.co .nz/kunde.htm
-http://www.volksbank.de.networld.onlineid92696.poyape.co. nz/kunde.htm/fr1.htm
-http://www.volksbank.de.networld.onlineid993887.poyape.co .nz/kunde.htm/
+http://sv1.melbhosting.com.au/~forcast/index.html c
+http://www.53.com.bankingportal.id38...i3or.biz/conf/ c
+http://www.53.com.bankingportal.id7135393075.o0site.biz c
+http://www.53.com.bankingportal.id77...i3or.biz/conf/ c
+http://www.53.com.bankingportal.id77...onf/script.php c
+http://www.corbeau.ch/bankofamerica/ c
+http://www.volksbank.de.vr-web.netwo...m/anmelden.cgi c
+http://www.volksbank.de.vr-web.netwo...m/anmelden.cgi c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
-http://200.110.75.30/icons/%20/eb/eBayISAPI.dllSignIn-ssPageName-hhsin.php
-http://24.94.243.27:82/www.paypal.com/cgi-bin/webscr=home=p/index.php
-http://66.226.238.59:84/pp/login.html
-http://login.myspace.com-index.cfm2fuseaction.frasespararecordar.com/process8MyToken-c076f3c5-9878-4f0e-9b51-f05d1f8aa6a9.php
-http://www.53.com.businessandcorporate.umgar.at/customerdata/
-http://www.volksbank.de.networld.onlineid252267675.umgar. at/kunde.htm/fr1.htm
-http://www.volksbank.de.networld.onlineid974424.umgar.at/kunde.htm
+http://dellandmeonline.com/onlineid-...date/index.htm c
+http://nnnnnuhuk.makingtourismwork.eu/.%20/index.html c
+http://www.germanguns.com/cart/image...ce-online-ssl/ c
+http://www.homediaries.com/.%20/sign...UsingSSL=.html c
+http://www.messblack.com/addons/mess.../Sign%20In.php c
+http://www.muzicano.com/uploads/rest...pdates-paypal/ c
-http://kickingsawdust.org/novacam/http:/www.sparkasse.de/
-http://www.htvestfold.org/cutenews/_vti_cnf/www.ebay.com/signin.ebay.com.ws.eBayISAPI.dllSignIn&co_partnerI d=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif= &UsingSSL.html
-http://www.volksbank.de.networld.onlineid5724891446.alltd irect.info/kunde.htm/
+http://1051134647:16080/ c
+http://200.67.73.220/.web/pnc/index.html c
+http://200.86.128.197/~paypal/secure/index.php c
+http://grace.ac.th/edit/www.paypal.c...Pal/index1.htm c
+http://item250076880855.pop3.ru/ISAP...&errmsg=9.html c
+http://kokok.makingtourismwork.eu/.%20/index.html c
+http://libertytidings.info/_files/ht...-bin/rbaccess/ c
+http://members.lycos.co.uk/my78/msn.php c
+http://www.53.com.bankingportal.id17...0site.biz/conf c
+http://www.53.com.bankingportal.id40...site.biz/conf/ c
+http://www.53.com.bankingportal.id62...micf.info/conf c
+http://www.ebank-egg.co.uk/wellsfargo/update/index.htm c
+http://www.postbank.de.-snm-05234710...0site.biz/pbde c
+http://www.postbank.de.-snm-36995558-.o0site.biz/pbde c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
-http://staeudle.com/unavailable/
-http://www.53.com.bankingportal.id96591161090.poyape.co.n z/conf/
-http://www.bankofamerica.com.onlinebankingid212520868.poy ape.co.nz/session.cgi
-http://www.bankofamerica.com.onlinebankingid260614983.poy ape.co.nz/session.cgi
-http://www.volksbank.de.networld.onlineid274857.poyape.co .nz/kunde.htm/
+http://www.bnkofamerica.us/ c
+http://www.volksbank.de.networld.onl....net/kunde.htm c
+http://www.volksbank.de.networld.onl...de.htm/fr1.htm c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
+http://www.volksbank.de.vr-web.netwo...m/anmelden.cgi c
+http://www.volksbank.de.vr-web.netwo.../anmelden.cgi/ c
-http://203.115.117.51/.paypal.com/login-run.html
-http://mail.constructoranacional.com.co/.paypal.com/cgi-bin/webscr/cmd_login/128bit_ssl-secure_account-verify/login.htm
-http://www.al-khawarizmi.com/img/cgi.ebay.com/ws/ebayisapi_dllsignin&co_partnerid=2/ebayisapi_dllsignin&co_partnerid=2/
-http://www.volksbank.de.networld.onlineid7044689.eztland. biz/kunde.htm/fr1.htm

Looks to me like it's trying to invoke some sort of E Banking, there's mention of PayPal, Visa and various world bank web addresses.

NOT SURE WHAT ALL THIS MEANS, IN YOUR SHOES I WOULD DO A COMPLETE SYSTEM WIPE AND REINSTALL> MAKE SURE YOU BACK UP YOUR PERSONAL FILES AND PHOTO'S FIRST !!

nirofo.

steve2005 08-02-07 17:44

I would totally agree with nirofo, having just visited a couple of the sites.
Firefox tells me, with no uncertainty, that these sites are attempting web forgery.

Saphire 08-02-07 17:50

Ooh! that looks nasty. I never save my visa No when I have bought online and I always clear private data and reboot, I have a place secured in the virus checker called visa which has nothing in apart from the last 4 digits.Should I do a seach for the whole Number on my computer and delete if I find any or would they be hidden.

Saphire 08-02-07 17:57

Would I have to totally re-install everything or would or would the new install recognize all programs.

nirofo 08-02-07 18:25

Quote:

Originally Posted by Saphire (Post 16701)
Would I have to totally re-install everything or would or would the new install recognize all programs.

I'm afraid a new install would need you to reinstall all your software as new, windows will not associate with any previous software installs. You need to do a complete format to be sure you removed everything before re-installing Windows XP. However, if you have more than 1 hard drive in your computer, (not separate partitions on the same drive), then you can locate all your personal files and photo's etc on the spare drive. Make sure you backup your e-mail cache also, you can sift through these later without accessing them.

Don't chance a repair, you'll never be sure you totally cleared the trojan / malware / spyware / virus etc.

nirofo.


All times are GMT +1. The time now is 12:35.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.