Forum issues

Status
Not open for further replies.

Katya

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Feb 23, 2010
34,804
120,145
SoCal
Some of the bitcoin malware is installed as a root kit so it's not detectable by standard scanning processes. If this is the case, you're going to need to use something stronger than Malwarebytes.

Normally in cases like this, I'd recommend ComboFix from Bleeping Computer. However, this is a very powerful tool that if used improperly, can brick your machine in a heartbeat.

Try the new root kit scanner from Malwarebytes. Malwarebytes | Anti-Rootkit BETA - Free Rootkit Scanner & Remover

We'll go from there.

Oh my...

"All Beta versions are non-final products. Malwarebytes does not guarantee the absence of errors which might lead to interruption in the normal computer operations or data loss."

Thanks, Retired. I'll try the Anti-Root later tonight. But I'm scared. :facepalm:
 

Bamrz

Z.A.P.T. Member*
ECF Veteran
Verified Member
Dec 8, 2010
9,013
36,660
PA, near Philly
I use FF with the "Tab Mix Plus" add-on. I keep the ECF threads I follow on tabs.

With the "old" software when I'd close FF (eg. overnight)...then reopen it and click on a tab...it would open on the next new post since I last visited the thread.

With the "new" software when I close FF...then reopen it and click on a tab...it opens on the last post I had read. I then have to reload the page to see the subsequent "New" posts.

Is this just a "glitch" in FF...or...is it "just the way" the Xen Foro works???
I use FF with "Morning Coffee" add on. When I reopen FF, it shows only unread posts. Not sure if you'd want to change, but letting you know it's out there. :)
 

Katya

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Feb 23, 2010
34,804
120,145
SoCal
Took me about 20 minutes to do the full scan. If it finds something, it will let you know at the end of the scan.

JC_Hi5.gif


It worked! But not quite as it was "supposed" to work.

I used Malwarebytes | Anti-Rootkit BETA - Free Rootkit Scanner & Remover as you suggested. But when I hit the download button, I got an instant pop up window announcing, "Gotcha, sucker--click here to get rid of it." So I clicked and it was all over--in an instant. It happened so fast that I wasn't sure what to do next, so I started from the beginning--clicked download again and this time I was able to run a full scan. It took 20 minutes and I was pronounced virus free.
girl_bye.gif


I came back here, clicked on the dreaded page 3--and it loaded!

Now, if I could only figure out how and where I got infected...
proxy.php


So, Retired, how can I thank you? I could make a donation to your favorite vaping-advocacy organization or do a month of community service in either New Members forum or in ATV. Thank you from the bottom of my heart!
proxy.php
 

retired1

Administrator
Admin
Supporting Member
ECF Veteran
Verified Member
Apr 5, 2013
50,732
45,041
Texas
We're not out of the woods yet. While the underlying active part appears to be gone, we still need to make sure that the remnants are cleared out so a reinfection doesn't occur.

Run another full scan using your anti-virus program. It might be a good idea to use a different scanner as well, just to get a second opinion.

Microsoft Safety Scanner - Free Virus Scan with the Microsoft Safety Scanner

Now, if I could only figure out how and where I got infected...

If you aren't running some type of adblock plugin, you should. A good number of infections come from "malvertising". If you have java installed on your computer, I'd highly recommend uninstalling it via Programs and Features. Unless you're a game addict and absolutely must have java installed, it's not needed.
 
Last edited:
Mouse over the Member link at the very top of the page.
Wow. Not many people are going to look in there !

I guess if the goal is to reduce use of the gallery ... that is a good spot.
Removing Media as a Tab is a good idea .... as you have more important Tabs.

A more accessible location would be the subnav bar ...
which currently has ...

Mark Forums Read
Search Forums
Watched Forums
Watched Threads
Calendar
New Posts
Threads You Ignore
Watched Tags
Forums You Ignore



I would say Media would be much more used than any of these three.

Watched Forums
Threads You Ignore
Forums You Ignore

How about putting Media on the subnav bar to the right of "New Posts" ?

Signed, a xenforo nerd :)
 
  • Like
Reactions: tiburonfirst

Katya

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Feb 23, 2010
34,804
120,145
SoCal
run another full scan using your anti-virus program. It might be a good idea to use a different scanner as well, just to get a second opinion.

Microsoft Safety Scanner - Free Virus Scan with the Microsoft Safety Scanner

Done and done. All clear. That Microsoft scan took forever...

If you aren't running some type of adblock plugin, you should. A good number of infections come from "malvertising". If you have java installed on your computer, I'd highly recommend uninstalling it via Programs and Features. Unless you're a game addict and absolutely must have java installed, it's not needed.

I had an adblock but I felt it was slowing me down so I got rid of it. What do you guys use/like/recommend nowadays?

I have Java 6 update 26 right here on my desktop. :facepalm: I downloaded it years ago because some website somewhere required it--don't remember which one. Not a gamer. [I just play games with Tibs in Snails, occasionally. :)]

I might uninstall it and see what happens. Worst case, I'll have to reinstall it.

Thanks again! :)
 

retired1

Administrator
Admin
Supporting Member
ECF Veteran
Verified Member
Apr 5, 2013
50,732
45,041
Texas
Oh gawd. That version is old and a HUGE security nightmare. Get rid of it. That's most likely the avenue of infection, right there.

With Firefox, I use AdBlock Plus. Works very well and I consider it an essential part of my security arsenal. Even on Linux.
 

Katya

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Feb 23, 2010
34,804
120,145
SoCal
Oh gawd. That version is old and a HUGE security nightmare. Get rid of it. That's most likely the avenue of infection, right there.

girl_blush2.gif


With Firefox, I use AdBlock Plus. Works very well and I consider it an essential part of my security arsenal. Even on Linux.

That's what I had.

TY
 
  • Like
Reactions: tiburonfirst
Status
Not open for further replies.

Users who are viewing this thread