Author Topic: Dafuq?  (Read 4189 times)

0 Members and 1 Guest are viewing this topic.

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Dafuq?
« on: Wed, 13 November 2013, 20:56:35 »
43947-0

dafuq is this???

Has anyone else seen these? Or should I run a virus scan on my PC?

****'s freaking me out...
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Michael

  • Formerly Bro Caps
  • * Maker
  • Posts: 4632
  • REEEeeeeEEEEEEEEeeeeeeeeeeeEEEEEEEEEEEEEEEeeeee
Re: Dafuq?
« Reply #1 on: Wed, 13 November 2013, 20:57:25 »
Not a virus, but a browser hack. I had the same thing. Need to run some anti-malware

Offline meiosis

  • * Esteemed Elder
  • Posts: 1281
  • Location: 408
  • Time
Re: Dafuq?
« Reply #2 on: Wed, 13 November 2013, 20:57:58 »
Adware/Spyware
Keyboards:
Filco Majestouch 2 - Sakura Edition [MX Blue]
Filco Majestouch 2 - Lotus Edition [MX Brown]
Realforce 23ub - Modded with 55g Domes.
Aripeko TKL

Offline demik

  • Pronounced "demique"
  • Posts: 11159
Re: Dafuq?
« Reply #3 on: Wed, 13 November 2013, 20:58:02 »
l2adblock noob.

obi wan's reaction is priceless tho. so say we all!
No, he’s not around. How that sound to ya? Jot it down.

Offline Pacifist

  • Report me *again* if there are gifs in my sig
  • * Elevated Elder
  • Posts: 3599
  • Location: Cali
  • on hiatus
Re: Dafuq?
« Reply #4 on: Wed, 13 November 2013, 20:58:24 »
What's with your white GH?

Offline Dubsgalore

  • Banned
  • Posts: 2849
  • Location: 75% You have received a warning for attempting to circumvent the classifieds rules
    • Dubs - Sneakers, Keyboards, and Life
Re: Dafuq?
« Reply #5 on: Wed, 13 November 2013, 21:00:08 »
might be something in your extensions? sometimes bull**** things like that sneak into chrome..just go uninstall it or uncheck it

and adblock it up too :p

Offline uberknarf

  • Posts: 26
  • Location: Toronto
Re: Dafuq?
« Reply #6 on: Wed, 13 November 2013, 21:02:39 »
What's with your white GH?

I think's its the Thoriated theme, if I'm not mistaken.

http://geekhack.org/index.php?action=profile;area=theme, then click "change" at the toppish.

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #7 on: Wed, 13 November 2013, 21:03:44 »
might be something in your extensions? sometimes bull**** things like that sneak into chrome..just go uninstall it or uncheck it

and adblock it up too :p

Had adblock installed since I installed Chrome. Must have snuck past it...

Gonna try some anti-malware/adware and see if that takes care of it.
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #8 on: Wed, 13 November 2013, 21:05:43 »
Any suggestions for a free anti-malware software?
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Puddsy

  • nice
  • * Elated Elder
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Dafuq?
« Reply #9 on: Wed, 13 November 2013, 21:11:52 »
Any suggestions for a free anti-malware software?

malwarebytes

So good I paid for pro.

It's still got 60 days free or something.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #10 on: Wed, 13 November 2013, 21:12:23 »
Any suggestions for a free anti-malware software?

malwarebytes

So good I paid for it.

Thanks, already running it. :thumb:
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Puddsy

  • nice
  • * Elated Elder
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Dafuq?
« Reply #11 on: Wed, 13 November 2013, 21:12:52 »
Any suggestions for a free anti-malware software?

malwarebytes

So good I paid for it.

Thanks, already running it. :thumb:

I ninja edited like 3 times sorry :| :|
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline keymaster

  • Topre Revolution Theorist
  • Posts: 1148
Re: Dafuq?
« Reply #12 on: Wed, 13 November 2013, 21:15:11 »
Post your extensions/plugins. You probably installed some software recently that installed spyware into Chrome.

Offline tp4tissue

  • * Destiny Supporter
  • Posts: 13723
  • Location: Official Geekhack Public Defender..
  • OmniExpert of: Rice, Top-Ramen, Ergodox, n Females
Re: Dafuq?
« Reply #13 on: Wed, 13 November 2013, 21:16:33 »
Nothing like Restoring from an Image.. for peace of mind... saves so much time...

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #14 on: Wed, 13 November 2013, 21:17:18 »
Post your extensions/plugins. You probably installed some software recently that installed spyware into Chrome.

That's the weird thing, I haven't installed anything lately except for a couple games through Steam (and Steam itself).

(could that do it?)
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Puddsy

  • nice
  • * Elated Elder
  • Posts: 12281
  • Location: RSTLN E
  • "Do you shovel to survive, or survive to shovel?"
Re: Dafuq?
« Reply #15 on: Wed, 13 November 2013, 21:20:48 »
Post your extensions/plugins. You probably installed some software recently that installed spyware into Chrome.

That's the weird thing, I haven't installed anything lately except for a couple games through Steam (and Steam itself).

(could that do it?)

Steam no, games yes

Some games are a bit fishy, especially greenlight games.

I limit myself to indie (not greenlight) and AAA games.

Still only play DotA.
QFR | MJ2 TKL | "Bulgogiboard" (Keycon 104) | ctrl.alt x GON 60% | TGR Alice | Mira SE #29 | Mira SE #34 | Revo One | z | Keycult No. 1 | First CW87 prototype | Mech27v1 | Camp C225 | Duck Orion V1 | LZ CLS sxh | Geon Frog TKL | Hiney TKL One | Geon Glare TKL



"Everything is worse, but in a barely perceptible and indefinable way" -dollartacos, after I came back from a break | "Is Linkshine our Nixon?" -NAV | "Puddsy is the Puddsy of keebs" -ns90

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #16 on: Wed, 13 November 2013, 21:23:14 »
Post your extensions/plugins. You probably installed some software recently that installed spyware into Chrome.

That's the weird thing, I haven't installed anything lately except for a couple games through Steam (and Steam itself).

(could that do it?)

Steam no, games yes

Some games are a bit fishy, especially greenlight games.

I limit myself to indie (not greenlight) and AAA games.

Still only play DotA.

Games installed: COD Black Ops and COD Black Ops II

Only just started noticing this after I got done playing multiplayer (can malware be transferred through games like that?)
« Last Edit: Wed, 13 November 2013, 21:30:22 by Computer-Lab in Basement »
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #17 on: Wed, 13 November 2013, 21:29:04 »
Ran Malwarebytes, removed all threats, didn't resolve the problem.

Next step: Windows Defender (cuz I don't have any use for real antivirus 99% of the time).
« Last Edit: Wed, 13 November 2013, 21:31:25 by Computer-Lab in Basement »
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Jack

  • Posts: 95
  • Location: Dallas
Re: Dafuq?
« Reply #18 on: Wed, 13 November 2013, 21:39:18 »
Try it again, quick scan will do, may uncover things that were being protected by what was removed on the first pass.

Check chrome://extensions/ and see if there's anything unfamiliar. Try disabling them one at a time and see when the problem goes away.

Never heard of malware through playing a game (that is, the playing itself). Could have adware/PUP bundled if you didn't pay attention to the installer, or maybe driveby download.

HJT may show something useful.

http://www.bleepingcomputer.com/download/hijackthis/

Getting a log: http://www.malwarehelp.org/how-to-curepart-3-using-hijackthis-scan-and-save.html
Comprehensive manual: http://www.bleepingcomputer.com/tutorials/how-to-use-hijackthis/
« Last Edit: Wed, 13 November 2013, 21:40:49 by Jack »

Offline kmiller8

  • Banned
  •  Post Reporting Timeout
  • Posts: 1589
  • Who is that kmiller8 guy?
Re: Dafuq?
« Reply #19 on: Wed, 13 November 2013, 21:43:55 »
as others said, chrome://extensions

I had this same problem, it was the Ask toolbar extensions. I think it was bundled with java or flash or something. Something required to use the internet to the full extent

And not to start a flame war, but don't adblock :/ that's just a douche-move

Offline eth0s

  • Posts: 1137
  • Location: New York City
  • Peace & Love
Re: Dafuq?
« Reply #20 on: Wed, 13 November 2013, 21:45:58 »
use the spock button, luke.


I ♥ Click Clack.  I ♥♥♥ Bro Caps.

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #21 on: Wed, 13 November 2013, 21:46:26 »
Try it again, quick scan will do, may uncover things that were being protected by what was removed on the first pass.

Check chrome://extensions/ and see if there's anything unfamiliar. Try disabling them one at a time and see when the problem goes away.

Never heard of malware through playing a game (that is, the playing itself). Could have adware/PUP bundled if you didn't pay attention to the installer, or maybe driveby download.


Getting it from an installer is damn near impossible considering the way I install things (I ALWAYS make sure I am installing JUST the software I want, with none of the bull**** that will slow my computer down).  So that's out...

Whatever it was, it was called "Better Surf" and it was a Chrome extension. No ****ing idea how the hell it got installed, cuz I sure as hell didn't do it...

Also got a few Windows Defender alerts saying it found a keylogger and "WPAkiller" (whatever that is). Removed both.
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #22 on: Wed, 13 November 2013, 21:47:59 »
use the spock button, luke.

Show Image



But why would Spock need to use the Spock button? 
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline eth0s

  • Posts: 1137
  • Location: New York City
  • Peace & Love
Re: Dafuq?
« Reply #23 on: Wed, 13 November 2013, 21:49:35 »
use the spock button, luke.

Show Image



But why would Spock need to use the Spock button? 
Show Image


cuz he's afraid to use the force?
I ♥ Click Clack.  I ♥♥♥ Bro Caps.

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #24 on: Wed, 13 November 2013, 21:51:33 »
use the spock button, luke.

Show Image



But why would Spock need to use the Spock button? 
Show Image


cuz he's afraid to use the force?

Please, no intertwining of the Star Trek/Wars...

And logic trumps the force. :P
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline Jack

  • Posts: 95
  • Location: Dallas
Re: Dafuq?
« Reply #25 on: Wed, 13 November 2013, 22:01:57 »
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=HackTool%3AWin32%2FWpakill#tab_2

It may have been necessary if you have an ~alternatively acquired~ copy of Windows.

Glad you found the cause though. Now maybe it's time for password changes, given the keylogger.

Offline swill

  • * Elevated Elder
  • Posts: 3365
  • Location: Canada eh
  • builder & enabler
    • swillkb.com
Re: Dafuq?
« Reply #26 on: Wed, 13 November 2013, 22:11:32 »
I had something similar happen.  I had to disable all my extensions and turn them on 1 by 1 to find which one was the culprit.  I did not have to do anything other than isolate the extension and remove it...

Hope that helps...

Offline nubbinator

  • Dabbler Supreme
  • * Maker
  • Posts: 8658
  • Location: Orange County, CA
  • Model M "connoisseur"
Re: Dafuq?
« Reply #27 on: Wed, 13 November 2013, 22:25:49 »
Do you have Flash running or Java enabled in the browser?  Sometimes you can get a driveby spyware/malware installation that way.  That's why I have Java disabled by default, Flashblock installed, and Adblock Pro installed.

As for spyware/malware software, Malwarebytes (MBAM) that was already mention is solid, as is SuperAntiSpyware.  There are also some good AVs you can install now that Defender is on the way to no longer being supported.  If you're super paranoid, you can boot with ClamAV, Avast, Kaspersky, F-Secure, AVG, and so on live discs.

Offline MKULTRA

  • Posts: 1197
  • Location: IN
  • telling it how it is
Re: Dafuq?
« Reply #28 on: Wed, 13 November 2013, 23:48:33 »
That is what you call adware.  Lots of mirror sites like CNET can give you that ****.

Offline iri

  • Posts: 1031
  • Location: England
Re: Dafuq?
« Reply #29 on: Thu, 14 November 2013, 00:49:43 »
If you're super paranoid, you can boot with ClamAV, Avast, Kaspersky, F-Secure, AVG, and so on live discs.
it's so much fun to boot with kasperskiy and nod32 and look how they fight each other. that's what microsoft windows is for!
(...)Whereas back then I wrote about the tyranny of the majority, today I'd combine that with the tyranny of the minorities. These days, you have to be careful of both. They both want to control you. The first group, by making you do the same thing over and over again. The second group is indicated by the letters I get from the Vassar girls who want me to put more women's lib in The Martian Chronicles, or from blacks who want more black people in Dandelion Wine.
I say to both bunches, Whether you're a majority or minority, bug off! To hell with anybody who wants to tell me what to write. Their society breaks down into subsections of minorities who then, in effect, burn books by banning them. All this political correctness that's rampant on campuses is b.s.

-Ray Bradbury

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #30 on: Thu, 14 November 2013, 07:09:58 »
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=HackTool%3AWin32%2FWpakill#tab_2

It may have been necessary if you have an ~alternatively acquired~ copy of Windows.

Glad you found the cause though. Now maybe it's time for password changes, given the keylogger.

Oh, so now I'm gonna have to re-install my "make my Windows legit" software... ndb.

And I'm not even sure if it was a keylogger, I think I misread "keygen" for "keylogger" (cuz I know I have some keygens on my PC, for pirated stuff).  Even if it was a keylogger, all my passwords were autosaves/autofills anyways, so I'm not even gonna bother with a ****-ton of password changes.


Oh, and the reason why I posted this here to begin with was because this malware thing only showed up on Geekhack, so I was afraid it might have been the beginning of a r00tw0rm 2.0 or something...
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline kolonelkadat

  • Posts: 180
  • Location: the vicinity of an area adjacent to a location
    • Force Project X
Re: Dafuq?
« Reply #31 on: Thu, 14 November 2013, 07:25:59 »
I REALLY wanted that ad to say "meet horny singles in Basement" like those geoip ads are wont to do. I would have laughed for days.
"Obviously, windows are central to Windows. But what is a window?"

Offline Computer-Lab in Basement

  • The needs of the many outweigh the needs of the few.
  • * Elevated Elder
  • Thread Starter
  • Posts: 3026
  • Location: NCC-1701, USS Enterprise
  • Live long and prosper
Re: Dafuq?
« Reply #32 on: Thu, 14 November 2013, 08:13:16 »
I REALLY wanted that ad to say "meet horny singles in Basement" like those geoip ads are wont to do. I would have laughed for days.

43994-0
tp thread is tp thread
Sometimes it's like he accidentally makes a thread instead of a google search.

IBM Model M SSK | IBM Model F XT | IBM Model F 122 | IBM Model M 122 | Ducky YOTD 2012 w/ blue switches | Poker II w/ Blue switches | Royal Kludge RK61 w/ Blue switches

Offline kolonelkadat

  • Posts: 180
  • Location: the vicinity of an area adjacent to a location
    • Force Project X
Re: Dafuq?
« Reply #33 on: Thu, 14 November 2013, 21:35:24 »
 :)) Thank you. This has made my day.
"Obviously, windows are central to Windows. But what is a window?"

Offline catnipz0098

  • Posts: 163
  • Location: Iowa
Re: Dafuq?
« Reply #34 on: Thu, 14 November 2013, 22:07:08 »
I REALLY wanted that ad to say "meet horny singles in Basement" like those geoip ads are wont to do. I would have laughed for days.

(Attachment Link)

I thought that was the original spam ad until I looked back at the OP.  :))