NationStates Jolt Archive


Ack!

HotRodia
10-06-2006, 07:44
So I was posting a reply in this thread (http://www.nation-states.net/showthread.php?t=486946) and got a Popup Blocked notification in the browser window. Then suddenly I get a VirusScan Alert right afterward, and I find that I have a trojan on my computer and it's replicating waaaay too fast for my comp to keep up. So I press the power button until everything goes dark and then let the reborn card work its magic. I'm not real worried about it affecting me but it could be a serious problem for other folks.

Any thoughts?
The Most Glorious Hack
10-06-2006, 08:21
"nation-states"?
HotRodia
10-06-2006, 08:25
"nation-states"?

I used that URL to get to the forums this time around because the site wouldn't load at first when I turned the comp back on. Previously, when I encountered the trojan it was the usual http://forums.jolt.co.uk/ url.
HotRodia
10-06-2006, 08:36
Dammit. It just happened again as I tried to edit my second post in this thread. :mad:

It's just too ironic, needing protection from a trojan.
A_B
10-06-2006, 08:57
Trojan is to virus as spyware is to pop-ups(some pop-ups are activated routinely by spyware programs on your PC). To make a long story short, there's a main trojan program you have which is very hard to get rid of. It sounds like it's "replications" are either weaker trojans, or being sent to the website/other people. Whatever you did, it's not getting rid of the core trojan.

It remains to be seen wether it has infected the site or came from it, in the mean time, you may want to take a look around sites that stay on top of the latest virus/trojan/worm to see if you can get rid of it without smashing your motherboard and getting a new one.
A_B
10-06-2006, 09:34
Is it popping up multiple windows called "vxgame4.exe" by any chance?
HotRodia
10-06-2006, 09:46
Is it popping up multiple windows called "vxgame4.exe" by any chance?

No. Why?
A_B
10-06-2006, 09:51
I may be encountering the same problem, exactly what is the nature of yours? Multiple pop-up windows at all?
HotRodia
10-06-2006, 09:56
I may be encountering the same problem, exactly what is the nature of yours? Multiple pop-up windows at all?

No, but then I have a very effective pop-up blocker. It could have been trying to generate multiple pop-up windows, but it's hard to tell, and I don't let it run long enough to find out so it doesn't infect the rest of my network.
HotRodia
10-06-2006, 10:28
It seems to be activated by the TitanQuest ad on Jolt.
A_B
10-06-2006, 11:02
Then it's most likely a spyware process that activates a pop-up which your computer/computer's software is not compatible with(and which outsmarts your pop-up blocker). I've had that problem with newgrounds pop-ups before. Try and set it to block all pop-ups, except when you're holding control(so that links that spawn in a new window can still be accessed), see if the problem continues.
HotRodia
10-06-2006, 11:13
Then it's most likely a spyware process that activates a pop-up which your computer/computer's software is not compatible with(and which outsmarts your pop-up blocker). I've had that problem with newgrounds pop-ups before. Try and set it to block all pop-ups, except when you're holding control(so that links that spawn in a new window can still be accessed), see if the problem continues.

Ummm...it doesn't outsmart the pop-up blocker. The pop-ups don't appear at all. The difficulty is that the virus was still downloading itself despite the lack of pop-ups. And the problem seems to be resolved now. The last couple times it's happened McAfee has had an easier time dealing with it and it hasn't struck again for quite a while now.
HotRodia
10-06-2006, 11:38
Nevermind. It just happened again. Time to notify the upper-level IT folks here that we have a trojan on this workstation that's fairly impressive.
A_B
10-06-2006, 20:44
Yes but the reason for that may be that it locks your computer up before the pop-up can spawn(hence why I emphasied it's possible incompatibility with your PC). Though it shouldn't be alerting macafee.