What the heck? Attack Site?

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

TruePaige

Diamond Member
Oct 22, 2006
9,878
2
0
Eh, I use Chrome and have never had an issue like this. PEBKAC, like 99.99999% of all virus problems.

Don't be a jackass.

A variety of people reporting the same problem...hmm!

It's NOT an anti-virus issue, apparently you have no idea how the attack site database works. It checked the url of a provider (googleanalyticz) and found it to be "Blacklisted".

My rig is clean thank you very much.
 

EagleKeeper

Discussion Club Moderator<br>Elite Member
Staff member
Oct 30, 2000
42,591
5
0
Just got the Virus alert and a complaint about Adobe 3D
 

Avalon

Diamond Member
Jul 16, 2001
7,567
152
106
Using Chrome as well, got that same popup. Also running Microsoft Security Essentials like some of you out there. It doesn't appear that my machine has been hijacked by a fake redirection virus, as I'm not seeing any of the symptoms. I guess I could run bit defender just to be safe.
 

IEC

Elite Member
Super Moderator
Jun 10, 2004
14,359
5,017
136
I only see it come up as blocked by noscript when in Off Topic - have not been able to get googleanalyticsz to show up on other forums.
 

Lanyap

Elite Member
Dec 23, 2000
8,128
2,167
136
Received Adobe message "A 3D data parsing error has occured" then Antivirus Soft started up. I'm running ESET NOD32 v4 and it did not catch it. Used malwarebytes to clean it up. Glad it's not just me...

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxfvxhjh (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxfvxhjh (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
 

PM650

Senior member
Jul 7, 2009
476
2
0
Received Adobe message "A 3D data parsing error has occured" then Antivirus Soft started up. I'm running ESET NOD32 v4 and it did not catch it. Used malwarebytes to clean it up. Glad it's not just me...

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxfvxhjh (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wxfvxhjh (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
I got the same message - just chalked it up to adobe being extra shitty (have a pdf open). Now I'm running malwarebytes to clean it up - Avira didn't pick anything up after the message, although I didn't get anything else after that. Regedit itsn't showing me having the same infected keys, might be safe.
 
Last edited:
Feb 19, 2001
20,158
20
81
I got the same message - just chalked it up to adobe being extra shitty (have a pdf open). Now I'm running malwarebytes to clean it up - Avira didn't pick anything up, although I didn't get anything else after the adobe message.

I figured NOD would pick that up like no other. i've NEVER had spyware issues at home since using ESET Smart Security.

Symantec at work doesn't relaly do anything. Viruses, sure, but not spyware.

Recommendations to anyone who's been hit:

1) Reboot into safe mode w/ networking
2) Run Malware Bytes/SuperAntiSpyware/HiJack This. I recommend running at least 2/3 of those. Typically I take the first two. SAS seems to get more than Malware Bytes in my experience, but I can't be certain.

I'm surprised how easy this thing got through Chrome though. I remember when I've gotten spyware before it used to be from IE6 and accidentally clicking YES on a dialogue menu. Interesting about Chrome though... Very interesting...
 

PM650

Senior member
Jul 7, 2009
476
2
0
Bleh. I just loaded a few more atot pages after reading some lengthy threads - got the adobe 3d message again. Malwarebytes didn't pick anything up with a full scan after the first hit, but I'm running it again anyways. No issues with actual malware yet even though Avira doesn't appear to be doing anything...

running ie8 btw
 

drnickriviera

Platinum Member
Jan 30, 2001
2,422
205
116
I figured NOD would pick that up like no other. i've NEVER had spyware issues at home since using ESET Smart Security.

Symantec at work doesn't relaly do anything. Viruses, sure, but not spyware.

Recommendations to anyone who's been hit:

1) Reboot into safe mode w/ networking
2) Run Malware Bytes/SuperAntiSpyware/HiJack This. I recommend running at least 2/3 of those. Typically I take the first two. SAS seems to get more than Malware Bytes in my experience, but I can't be certain.

I'm surprised how easy this thing got through Chrome though. I remember when I've gotten spyware before it used to be from IE6 and accidentally clicking YES on a dialogue menu. Interesting about Chrome though... Very interesting...

I would also like to note these things enable a proxy. To update your spyware or get to the net you have to turn it off. control panel > internet options > connections tab > lan settings > uncheck proxy

Glad i'm not the only one. That's the last time I try to search for pictures of Mosh's feet! lol. I was reading the UFC thread when it hit me, wonder what specific ad it is.
 
Sep 7, 2009
12,960
3
0
WTF I got popped too.

PC has no spyware, running updated nod32.

Booted up, opened FF, went to AT (no other sites/tabs), clicked a/v forums and got a PDF popup with some sort of '3d processing' error with a fake 'Ok' box.







Please get your advertisers under control, WTGDF.
 

Tempered81

Diamond Member
Jan 29, 2007
6,374
1
81
got the same warning on chrome on a few sites. Dunno what it is, but just started yesterday
 

lxskllr

No Lifer
Nov 30, 2004
57,653
7,882
126
I read an article on this recently(can't remember where) that said adservers have been getting hacked at an alarming rate. Legitimate sites all over the web have been serving up malicious ads from various sources. Ya gotta keep your guard up. You can't become complacent....
 

Shlong

Diamond Member
Mar 14, 2002
3,129
55
91
Similar thing happened while browsing Dailytech, some anti-virus software started installing out of the blue. Quickly ended it in task manager and saw Acrobat was open (when it shouldn't have been)... probably an advertisement using an exploit through Acrobat. Removed all instances of the spyware so I'm good now, but users should watch out.
 

Czar

Lifer
Oct 9, 1999
28,510
0
0
http://safebrowsing.clients.google....//www.anandtech.com/video/showdoc.aspx?i=3783

"What happened when Google visited this site?

Of the 25 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-03-27, and the last time suspicious content was found on this site was on 2010-03-26.

Malicious software includes 2 trojan(s). Successful infection resulted in an average of 3 new process(es) on the target machine.

Malicious software is hosted on 3 domain(s), including mjgjo.com/, googleanalyticz.com/, googleanalyticsz.com/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including whoiz.shit.la/.

This site was hosted on 1 network(s) including AS36643 (EICOMM)."
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,425
8,388
126
i got the same when i went to cpu-chipsets on the main page.

hacked adservers are a bad thing.



my sister got that fake anti-virus. it took a couple runs of mcafee and malwarebytes, but i think i cleared it all out. if you get it i would unplug myself from the internets asap because it will start trying to download other crap as well.
 

AnonymouseUser

Diamond Member
May 14, 2003
9,943
107
106
Note to self: As soon as you get back to work, uninstall Adobe Acrobat Reader and install Foxit Reader.
 

HeXen

Diamond Member
Dec 13, 2009
7,832
38
91
It could be a Flash malware, many legit websites of course have flash ads that come from some AD company which sometimes tend to get hacked, so any website that presents such an Ad, then all of its users can be suspeptable. Chrome may be detecting some kind of problem like that i suppose, like an Ad trying to do something to get the user to click on it inadvertantly downloading it.
 

Ryan Smith

The New Boss
Staff member
Oct 22, 2005
537
117
116
www.anandtech.com
Just to erase all doubts, yes, we know about this. Our IT guys are hard at work on this, but they're still trying to track down the source. If any of you get the error, we'd really like to get the page source code.
 

DaveSimmons

Elite Member
Aug 12, 2001
40,730
670
126
I got the Adobe 3D error in Flash here in ATOT last night, but apparently it just crashed without delivering the trojan payload.

If this keeps up I may need to look into adblock
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |