Page 1 of 1

Microsoft Security Virus

Posted: Mon Dec 19, 2011 6:08 pm
by BadMofoPimp
Yep, RealGM is the only website I usually have on my Mozilla Firefox browser.

A week ago my old work PC got the Microsoft Security Virus while RealGM was the only website on my PC. Well, while removing the virus my Hard Drive crashed. It was an old PC anyways. So, I got a new PC. Fortunately, I don't even use the Hard Drive and map ALL my work data to a network drive.

I go on Vacation.

I am back two days with a brand new PC with 2 anti-virus software running including CCleaner and this Microsoft Security Virus appears again. RealGM is the only site I have been to and it is in the morning. I quickly deleted from running on Task Bar and run System Restore.

I had used my old work PC to visit RealGM for 2 years without getting any virus's. But, this virus got through CClearner and my Norton. Fortunatley, I was able to run System Restore and then cleaned my PC and removed from Registry afterwards. Unfortunately, I have XP on my work PC and Windows 7 at home.

Now, I am affraid to visit RealGM for fear of getting this rogue virus again. Please advise.

Funny that after 2 years, I get the same virus in one week on two different PC's from RealGM.

Re: Microsoft Security Virus

Posted: Mon Dec 19, 2011 6:26 pm
by Nolan
^
I've gotten the same virus before and I kinda thought I got it from here as well.

Re: Microsoft Security Virus

Posted: Mon Dec 19, 2011 7:03 pm
by CR Reina
I don't believe we have received any other complaints of this issue arising. It is likely from another source because our system administrator has said that everything looks fine on his end.

Let me know if you can provide any other information about the virus so we can look into it further to make sure that we aren't have any issues with the site.

Re: Microsoft Security Virus

Posted: Mon Dec 19, 2011 7:35 pm
by BadMofoPimp
Well, this is a refurbished PC with Norton, CCleaner, Microsoft Sec Essentials plus all running at the same time. I picked it up from the store myself. Only used it 3 days. RealGM is the only website I visited today and the virus popped up at approximately 12:30pm.

Now, I thought I beat the virus with a System Restore. But, it looks like I got the evil "Ping.exe" virus that crashed my PC last week. There is no way to remove it.

I think I beat it going into Safe Mode and removing in Registry. Anyways, it appears to be fine for the past 2 hours.

Just hope you guys be advised that this Virus could be attaching itself onto one of your advertisers for PC's with XP.

Re: Microsoft Security Virus

Posted: Wed Dec 21, 2011 4:22 pm
by BadMofoPimp
Not sure why this virus came through RealGM or one of its advertisers, but it ended up being the infamous Ping.exe virus.

In case anyone ever gets this virus, I couldn't find anything on Google to truly help me. Also, it disabled my Outlook from connecting to the server.

Hence, I eliminated this myself and got everything back to normal by doing:

1) First thing, boot into Safe mode, then go into Registry and delete all entries for ping.exe and pathping.exe. Do not remove ping6.exe.
2) Booted in Safe mode removed Ping.exe and pathping.exe from System32 folder, but did not remove these files from i386 folder.
3) To remove Google redirect Ran the Kapersky's tdsskiller file, this worked. This is available online everywhere. It is free.
4) Outlook would not connect to server, so I did a System Restore to last Wednesday and it worked.

Of course, to find all these entries in Registry, you have to search for them via {Control} {F} and type in ping.exe.

Re: Microsoft Security Virus

Posted: Thu Dec 22, 2011 8:01 pm
by CR Reina
Glad you were able to removed the threat.

I Googled ping.exe virus and it looks like there has been a ton of activity for it over the past few weeks.

Re: Microsoft Security Virus

Posted: Thu Dec 22, 2011 8:31 pm
by BadMofoPimp
Well, I logged onto my PC this morning. Then, after 2 hours I visit RealGM and it is the only website I have visited today. I post a few times and then I get the XP 2012 Windows Security virus while being on a secure network. I followed the instructions to remove the virus, but it somehow disabled my internet. So, our network administrator is convinced it came from one of RealGM's advertisers as it most likely is downloading with your advertising Java scripts.

Anyways, I am so fed up with 2 computers crashing as this current one is only 2 weeks old refurbished with Windows XP with 4 gig ram and 3 anti-virus running at the same time still not stopping it, we went out and bought (2) brand new Windows 7 machines with 4 gig ram.

Hence, RealGM advertisers won't be giving me virus's like they have recently.

But seriously, if I was able to use the same machine with Firefox for 2 years before RealGM inadvertently gave me Virus's that ruined (2) Computers within 10 days, that should be some concern.

I only visit (3) websites each day while working. Hotmail, RealGM and Orange County Property Records. Only RealGM was open when I got these virus's.

Re: Microsoft Security Virus

Posted: Fri Dec 23, 2011 10:04 pm
by swstein
I keep getting warnings from Google Chrome that the page I'm visiting could have malware on. It gives me the option to proceed or go back.

I'm not getting it with any other sites, only realgm forum.

Image

I've had it 3 or 4 times today now.

Re: Microsoft Security Virus

Posted: Tue Dec 27, 2011 7:10 pm
by BadMofoPimp
I hear ya. Unfortunately, when a website gets as big as RealGM, they will have a hard time controlling their advertisers quality of service. Hence, the more aggressive virus's will still be able to jump on their servers for short periods of time and wreak havoc on a select few.

Here, I copied my Norton log from a virus that I got today from RealGM. I know for sure it is RealGM or an Advertiser as I only use Firefox for RealGM. Then, I use IE for our work software and State and County websites.

Anyways, I don't visit any other websites and this is only the 3rd day using this brand new computer Duo Core 64bit Windows 7 with 3 anti-virus software running. Hence, I can track where I am getting virus from and this came through once I click on a thread. Must be one of RealGM's advertisers.

Image

Re: Microsoft Security Virus

Posted: Wed Dec 28, 2011 5:04 pm
by CR Reina
swstein wrote:I keep getting warnings from Google Chrome that the page I'm visiting could have malware on. It gives me the option to proceed or go back.

I'm not getting it with any other sites, only realgm forum.

Image

I've had it 3 or 4 times today now.


Can you send me the specific URL of where you received that message? It is from a user who has an avatar from a suspicious site. We can clear that sig/av from their account and eliminate the issue.

Re: Microsoft Security Virus

Posted: Wed Dec 28, 2011 6:37 pm
by dream34
Do you browse RealGM at home? Or only at work? Was it only your work computers affected? I've never had any problems and I'm on RealGM.com at least 40 hours a week. Are you sure it's not something on your work's network? Another computer could have been infected and spread it across. Could you be inserting a flash drive with an infected file on it? Checking your email?

I'm not saying it's not possible, but I feel pretty confident that the issue isn't with RealGM. It would be a lot more widespread of a problem, instead of isolated incidents. I think most of our ads come from Google who does a great job of scanning them for viruses. As always though, you should protect your computer. Enable your firewall and have multiple anti virus software running. If it gives you peace of mind, you might look to install the AdBlock extension for Firefox.

Re: Microsoft Security Virus

Posted: Wed Dec 28, 2011 8:50 pm
by BadMofoPimp
dream34 wrote:Do you browse RealGM at home? Or only at work? Was it only your work computers affected? I've never had any problems and I'm on RealGM.com at least 40 hours a week. Are you sure it's not something on your work's network? Another computer could have been infected and spread it across. Could you be inserting a flash drive with an infected file on it? Checking your email?

I'm not saying it's not possible, but I feel pretty confident that the issue isn't with RealGM. It would be a lot more widespread of a problem, instead of isolated incidents. I think most of our ads come from Google who does a great job of scanning them for viruses. As always though, you should protect your computer. Enable your firewall and have multiple anti virus software running. If it gives you peace of mind, you might look to install the AdBlock extension for Firefox.


It is all possibly as you say. I am just monitoring for now. Nobody else on the network has had problems except me with 2 brand new PC's. This on my work PC. But, it is all good now I got Windows 7.

Re: Microsoft Security Virus

Posted: Thu Dec 29, 2011 2:17 am
by dream34
Sounds good. Please keep us updated if you find anything new.