Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

OT: Source of this?

10 views
Skip to first unread message

Terry Pinnell

unread,
May 16, 2013, 1:23:53 AM5/16/13
to
A friend reports he is getting this small image overlaid on many posts in
several forums he uses, usually over an embedded image included with the
post. I'm guessing some software accidentally installed, or option
unknowingly enabled. Anyone recognise it please?

https://dl.dropboxusercontent.com/u/4019461/OverlaidImage.jpg

--
Terry, East Grinstead, UK

Andy Burns

unread,
May 16, 2013, 3:02:05 AM5/16/13
to

Mentalguy2k8

unread,
May 16, 2013, 6:15:55 AM5/16/13
to

"Terry Pinnell" <terr...@dial.pipex.com> wrote in message
news:n1r8p816mluac4n6l...@4ax.com...
I'd scan for malware, and disable any browser add-ons that aren't
recognised/needed, the procedure is different for each browser.

Try this software, I've found it excellent:

http://www.malwarebytes.org/products/malwarebytes_free/

Install it and do a "quick scan", it normally picks up the stuff that
shouldn't be there and it's free.

Mentalguy2k8

unread,
May 16, 2013, 6:32:38 AM5/16/13
to

"Mentalguy2k8" <Mental...@gmail.com> wrote in message
news:kn2bdm$t63$1...@dont-email.me...
I should add that any "malware" scanning software will give you a list of
results of malware that's on your PC after the scan, and you can then look
them up online if you're interested in where a particular malware originated
or how it works, and the (possible) effects it can have.

Shadow

unread,
May 16, 2013, 9:18:21 AM5/16/13
to
It's spyware. I get it on 4shared. There are 4 boxes, from
left to right:

Facebook spyware
Google spyware
Twitter spyware
Dunno, probably KGB

Analyzing the Twitter icon:

http://www.4shared.com/servlet/signin/twitter?fp=http://www.4shared.com/account/home.jsp"

Which will allow 4Shared to:

Read Tweets from your timeline.
See who you follow, and follow new people.
Update your profile.
Post Tweets for you.

IOW, be you, sell you, fuck with you.

Just put google, twitter, facebook and KGB in your hosts file.
You will be safe(r).
[]'s

--
Don't be evil - Google 2004
We have a new policy - Google 2012

Terry Pinnell

unread,
May 16, 2013, 10:14:54 AM5/16/13
to
Thanks!

Mark Warner

unread,
May 16, 2013, 10:53:57 AM5/16/13
to
On 5/16/2013 6:15 AM, Mentalguy2k8 wrote:
> "Terry Pinnell" <terr...@dial.pipex.com> wrote
>>
>> A friend reports he is getting this small image overlaid on many posts in
>> several forums he uses, usually over an embedded image included with the
>> post. I'm guessing some software accidentally installed, or option
>> unknowingly enabled. Anyone recognise it please?
>>
>> https://dl.dropboxusercontent.com/u/4019461/OverlaidImage.jpg

> I'd scan for malware, and disable any browser add-ons that aren't
> recognised/needed, the procedure is different for each browser.
>
> Try this software, I've found it excellent:
>
> http://www.malwarebytes.org/products/malwarebytes_free/
>
> Install it and do a "quick scan", it normally picks up the stuff that
> shouldn't be there and it's free.

In this case, I'd also suggest a run of SuperAntiSpyware. Between the
two, that should clean up any crap that they've picked up.

--
Mark Warner
...lose .inhibitions when replying

Brian Gaff

unread,
May 16, 2013, 12:24:23 PM5/16/13
to
So what software is he using for the group.

Brian

--
From the Sofa of Brian Gaff Reply address is active
"Terry Pinnell" <terr...@dial.pipex.com> wrote in message
news:n1r8p816mluac4n6l...@4ax.com...

Brian Gaff

unread,
May 16, 2013, 12:28:50 PM5/16/13
to
One has to ask why anyone would read posts in a newsgroup online in the
first place instead of with a client that shows the bare text, but I can say
that Malwarebytes is very good, though just lately less so for the blind due
to inaccessible text on some screens.

Brian

--
From the Sofa of Brian Gaff Reply address is active
"Mentalguy2k8" <Mental...@gmail.com> wrote in message
news:kn2ccv$278$1...@dont-email.me...

Terry Pinnell

unread,
May 16, 2013, 3:25:52 PM5/16/13
to
"Brian Gaff" <Bri...@blueyonder.co.uk> wrote:

>One has to ask why anyone would read posts in a newsgroup online in the
>first place instead of with a client that shows the bare text, but I can say
>that Malwarebytes is very good, though just lately less so for the blind due
>to inaccessible text on some screens.
>
>Brian

And for sighted members of forums discussing and exchanging images and
videos? For which 'bare text' has some rather obvious limitations!

troppo

unread,
May 16, 2013, 4:51:59 PM5/16/13
to
Terry Pinnell <terr...@dial.pipex.com> wrote in
news:n1r8p816mluac4n6l...@4ax.com:
Maybe I'm stating the bleedin' obvious here, but it's a standard
invitation to log in, eg you get to respond, download attachments etc.
Can login using InYaFace, Googlesplat, Twit etc instead of registering
direct. Not very effective if it's malware.

alan

unread,
May 16, 2013, 6:06:30 PM5/16/13
to
On 16/05/2013 11:15, Mentalguy2k8 wrote:

> Try this software, I've found it excellent:
>
> http://www.malwarebytes.org/products/malwarebytes_free/
>
> Install it and do a "quick scan", it normally picks up the stuff that
> shouldn't be there and it's free.


+1 for Malwarebytes

Also go into the menu Malwarebytes "More Tools" and download the
Anti-Rootkit (Beta) which is also free.


--
mailto:news{at}admac(dot}myzen{dot}co{dot}uk

harry

unread,
May 17, 2013, 2:48:45 AM5/17/13
to
On May 16, 11:15 am, "Mentalguy2k8" <Mentalguy...@gmail.com> wrote:
> "Terry Pinnell" <terry...@dial.pipex.com> wrote in message
Just tried it. (I am having trouble with popup adverts)
It found eight "undesireables" which looked advertising related. I
deleted them but the problem remains.

G.F.

unread,
May 17, 2013, 6:59:03 AM5/17/13
to
"harry" <harry...@btinternet.com> ha scritto nel messaggio
news:fcc36949-1117-4093...@g9g2000vbl.googlegroups.com...
On May 16, 11:15 am, "Mentalguy2k8" <Mentalguy...@gmail.com> wrote:

> It found eight "undesireables" which looked advertising related
> I deleted them but the problem remains

It's useless to say that there are many antimalware programs...
For example, you could try Adwcleaner:
http://general-changelog-team.fr/fr/downloads/viewdownload/20-outils-de-xplode/2-adwcleaner


G.F.

unread,
May 17, 2013, 7:06:19 AM5/17/13
to
"G.F." <nos...@grazie.it> ha scritto nel messaggio
news:51960d71$0$37130$4faf...@reader1.news.tin.it...
Of course pay attention to false positives (for example, Adwcleaner
considers Ghostery for Internet Explorer as malware).



Shadow

unread,
May 17, 2013, 8:38:09 AM5/17/13
to
Try *hijackythis. Look for anything out of the ordinary,
specially BHOs and redirects.

*available on sourceforge

Mark Warner

unread,
May 17, 2013, 11:10:27 AM5/17/13
to
Clear all your restore points. Then re-run MBAM and SAS:

http://www.superantispyware.com/

Might be wise to run both in Safe Mode followed by both in Normal Mode.

Terry Pinnell

unread,
May 19, 2013, 9:25:58 AM5/19/13
to
alan <ju...@admac.myzen.co.uk> wrote:

>On 16/05/2013 11:15, Mentalguy2k8 wrote:
>
>> Try this software, I've found it excellent:
>>
>> http://www.malwarebytes.org/products/malwarebytes_free/
>>
>> Install it and do a "quick scan", it normally picks up the stuff that
>> shouldn't be there and it's free.
>
>
>+1 for Malwarebytes
>
>Also go into the menu Malwarebytes "More Tools" and download the
>Anti-Rootkit (Beta) which is also free.

I'm pretty sure that after a scan using MalwareBytes I used to be able to
right click on an entry in the results and get some details of it. But
that's not true now if it ever was.

Also, what is the point of 'Vendor information'? It just takes me to the
MalwareBytes home page. Elsewhere in the right click menu the term
'vendor' appears to mean the author or supplier of the malware entry...
0 new messages