| Post/Author/DateTime | Post |
|---|---|
| #1PennarinNov 01, 2008 23:50:05 | There was a thread on WotC's forums, mirrored on RPGNow and ENWorld, and probably other websites, about a "free grave wights article". A Google search shows the mirrors everywhere. All such links leading to the article appear broken, and WotC's link to the thread on this very forum is now gone. I initially reported the post to a Wiz_O when clicking on the article link resulted in an instant blue screen of death. Since, the thread has been deleted. Anyone heard of something like this ever happening? Was it a hack or a prank? Was my blue screen of death pure coincidence? |
| #2outlaw68Nov 02, 2008 4:31:19 | There was a thread on WotC's forums, mirrored on RPGNow and ENWorld, and probably other websites, about a "free grave wights article". A Google search shows the mirrors everywhere. I saw it at enworld.. i clicked on it, nothing happened but a blank webpage loaded. And since that is the case, i would say it was some sneaky bugger trying to sneak some malware on to systems... i run on mac, much harder to hit (and hit a lot less often because of how small the market share is).. if your running on Windows it was malware for sure. It might be worth hitting your virus and spyware scans... |
| #3farmer42_dupNov 02, 2008 7:50:36 | Yeah, that's a pretty standard malware set-up. Definately boot into safemode and run a scan. Don't just do it in normal mode, especially if it BSOD'd on you. |
| #4PennarinNov 02, 2008 7:52:53 | Nah, whatever malware was installed has already been eaten or broken apart by the veritable malware ecology evolving in my computer ever since I've been unable to remove a firewall program that interferes with running a clean sweep of my system... |
| #5farmer42_dupNov 02, 2008 8:04:42 | Ehh, I'd still try your anti-virus software in Safe mode. It should, in theory, bypass the firewall issue. |
| #6outlaw68Nov 02, 2008 8:09:33 | Ehh, I'd still try your anti-virus software in Safe mode. It should, in theory, bypass the firewall issue. Definitely.. you wouldn't want it to be a program that records key strokes or anything like that.. I am a computer tech, and i have seen a heap of this sort of thing getting around lately. And Pennarin, the Firewall software you are having dramas with.. have you tried running a registry cleaner to help get rid of it? Often with windows (well XP and before.. i have worked with Mac since Vista came out) programs like that get set up in your registry and it takes an un-installer program or a registry cleaner to get rid of them.. |
| #7farmer42_dupNov 02, 2008 8:35:25 | Definitely.. you wouldn't want it to be a program that records key strokes or anything like that.. I am a computer tech, and i have seen a heap of this sort of thing getting around lately. Shh...I was trying to keep this simple... And Pen, if you ever, EVER, see anything about "AntivirusXP/AntispywareXP 200x" (Where 200x is a year), immediately boot into safemode and start scrubbing. What you stumbled upon is the most standard way it infects people. Key stroker recorders are also a likely culprit, especially if you haven't seen anything since it happened. |
| #8PennarinNov 02, 2008 10:06:13 | What's the name of that Firewall lots of people have...? Anyways, it asks for a password so it can be removed through Add/Remove programs, and navigating inside the program does not reveal an Option tab which would allow the retrieval/modification of this password. Crazy. People on the web have listed ways of getting it out at this point, but it's insane, all about deleting files with crazy names from folders with crazy names. Plans to crash the whole thing. Mmm, safe mode + scrubbing, nice idea. I'll try. |
| #9archangel_jamesNov 02, 2008 21:09:16 | That's why I use Firefox with NoScript. I haven't even needed an antivirus since I got NoScript. I'm a little surprised that they chose to target a group with such a high tech-geek per capita. |
| #10ssvegeta555Nov 02, 2008 21:21:08 | CCleaner does wonders to remove registry errors. And I also agree with Farmer42, scanning in safe mode is your best bet. Firewalls shouldn't even load in safe mode from what I've seen. |
| #11farmer42_dupNov 02, 2008 21:59:00 | As far as getting rid of the firewall is to go through msconiv and turn off all related services and start-up processes then deleting the foder in safe mode. It isn't the most elegant solution, and it can cause problems later on, but if the firewall is blocking your anti-virus, then I'd personally say the AV software takes precedence. And James is right, NoScript in FF works wonders for prevention. Personally, I just use Ubuntu and FreeBSD as OS's, so I bypass the problem (almost) entirely. Nothing makes me giggle quite like getting fraudware pop-ups telling me my Windows has viruses. |
| #12ssvegeta555Nov 02, 2008 22:05:35 | As far as getting rid of the firewall is to go through msconiv and turn off all related services and start-up processes then deleting the foder in safe mode. You mean msconfig right? |
| #13farmer42_dupNov 02, 2008 22:17:19 | You mean msconfig right? Yes. Sorry bout the typo. I was doing research on a different desktop, and was dividing my attention. |
| #14PennarinNov 03, 2008 8:39:06 | Mmm, safe mode + scrubbing, nice idea. I'll try. Dididn't work simply because to install the antivirus software you need to remove ZoneAlarm. Had the same problem as thousand of other people: ZoneAlarm required a password to uninstall, password I didn't know. Went in Safe Mode, then Run / regedit, removed the two "store" folders under ZoneAlarm, and then went to C: and removed the two .drb (IIRC) files in Windows / Internet Logs (IIRC, again), flushed the recycle bin, rebooted in Normal mode, and could then uninstal ZoneAlarm.... /sight Cleaned my computer with Kaspersky, found more adware than animals in Noah's Ark, and now it's all good except that my internet connection is not working..../double sight |
| #15farmer42_dupNov 03, 2008 8:45:06 | Dididn't work simply because to install the antivirus software you need to remove ZoneAlarm. That would be Kaspersky. Go into it's firewall and make sure you have an allowance for IE. It's one of the (many) reasons I dislike KAV. Also, be careful, if you notice a drastic number of BSODs in the next week or so, contact Kaspersky. The newest version for some reason will cause it to blue screen sometimes. There's a fix for it out there somewhere. |
| #16malkav666Nov 03, 2008 9:23:44 | (1). Start your PC in SAFE MODE (2) Open "C:\WINDOWS\Internet Logs" folder (3) Delete *.RDB files viz BACKUP.RDB, IAMDB.RDB (4) Restart in normal mode.......that's it..ZA will start with fresh default settings that too without any password (5) uninstall via add/remove programs. love, malkav |
| #17PennarinNov 03, 2008 10:55:27 | That would be Kaspersky. Go into it's firewall and make sure you have an allowance for IE. It's one of the (many) reasons I dislike KAV. Also, be careful, if you notice a drastic number of BSODs in the next week or so, contact Kaspersky. The newest version for some reason will cause it to blue screen sometimes. There's a fix for it out there somewhere. BSODs? malkav666, I believe that's what I said, but thanks for comfirming the terms I used, wasn't so sure. |
| #18ranadielNov 03, 2008 11:17:43 | BSODs? I think BSOD means blue screen of death. |
| #19PennarinNov 03, 2008 12:23:52 | Doh, he even said blue screen of death afterwards. Gotcha. And I will attempt to tell Kaspersky to create a safe pathway for IE/Firefox/GoogleChrome. EDIT: Great success! |