
Re: Disable For Moderatore IP Traking
Well my browsers are up to date with legitimate BHO's etc, but on two occasions I visit
h**p://***.phpbb-es.com/foro/docs-s...il-vt15970.html
(General Info for others:
Don't visit this link unless your PC is protected.)
I get two occasions of the virus blocked and sent to the vault, and if I hang around long enough, it gets worse with some acive-x trying to add to the registry; and not only that it's persistant and the process has to be killed.
Now I'm going to check my PC for any scumware that may have got through - Something I do on a regular basis after these encounters.
So I don't share your confidence that something is not wrong with that site.
Edit:
Update:
The time in the toolbar of the first pic is 8:00AM - the time of the Attack of geBrgnOg.
At 24/06/2008 8:00:18AM After a reboot These files all appeared with the same date and time.
Removeafile.bat
Virtumonde.dll
pmnnKay.dll
mIJAtRjb.dll
geBrgnOg.dll
geBrgnOg.dll and mIJAtRjb.dll - are particularly BAD ones to remove as they lodge in the Startup, System32 DIR, Registry and Memory.
Automatic Updates are disabled and "Masked" so that one is not aware of it.
S&D and AdAware are useless at removing it, as are some of the others. And it took SUPERANTISpyware to clean out all 16 entries (Memory - Files - Registry) that nothing else would remove.
I was so impressed with the "Free" version, that I upgraded to Professional.
And you suggest that there are no viruses on that site. I'm convinced that the evidence above indicates otherwise.