Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Results 1 to 9 of 9
  1. #1
    Senior Techie
    Points: 6,451, Level: 52
    Level completed: 51%, Points required for next Level: 99
    Overall activity: 0.4%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Apr 2008
    Posts
    236
    Liked
    0 times

    Google Chrome showing Malware detected on safe pages

    Hi,
    Google chrome is showing the alert message that many websites contain "elements from the site ads.vk987.info which appears to host malware".

    I am getting this message for google.com,raymond.cc and many safe sites.Sometimes KIS 2009 shows a red alert window showing that cntlm.exe(the proxy authentication program for the university proxy) is loading some trojan program and access has been denied to that.Refreshing the page for some time sometimes solves the problem.

    In firefox and google chrome,sometimes I get the error message "Cache Access Denied".Refreshing the page sometimes solves the problem.
    Please help.
    Thanks!
    Last edited by Albin; 10-20-2008 at 10:12 PM.

  2. #2
    Experienced User
    Points: 14,118, Level: 77
    Level completed: 17%, Points required for next Level: 332
    Overall activity: 0.5%
    Achievements:
    Recommendation Second Class31 days registered3 months registered100 Experience PointsTagger Second Class

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,962
    Liked
    3 times
    Your PC could be infected. Scan it.
    Happy To Help

  3. #3
    Senior Techie
    Points: 6,451, Level: 52
    Level completed: 51%, Points required for next Level: 99
    Overall activity: 0.4%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Apr 2008
    Posts
    236
    Liked
    0 times
    Hi,
    The problem got solved somehow.I did a full scan and it found two trojan programs and removed them.But these files were present much before the problem started.
    I used CCleaner and it cleaned some cookie files including that of ads.vk987.info.When Google Chrome was loading a page,I could see "Waiting for ads.vk987.info.
    Thanks!

  4. #4
    Experienced User
    Points: 14,118, Level: 77
    Level completed: 17%, Points required for next Level: 332
    Overall activity: 0.5%
    Achievements:
    Recommendation Second Class31 days registered3 months registered100 Experience PointsTagger Second Class

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,962
    Liked
    3 times
    Can you post a HijackThis log please

  5. #5
    Senior Techie
    Points: 6,451, Level: 52
    Level completed: 51%, Points required for next Level: 99
    Overall activity: 0.4%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Apr 2008
    Posts
    236
    Liked
    0 times
    Hi,
    Here is the HijackThis log file.I had to change the extension to .txt for uploading the file.The problem appears to have been solved.
    Thanks!
    Attached Files Attached Files
    Last edited by Albin; 10-22-2008 at 12:52 AM.

  6. #6
    Experienced User
    Points: 14,118, Level: 77
    Level completed: 17%, Points required for next Level: 332
    Overall activity: 0.5%
    Achievements:
    Recommendation Second Class31 days registered3 months registered100 Experience PointsTagger Second Class

    Join Date
    Feb 2008
    Location
    Socket LGA 771
    Posts
    1,962
    Liked
    3 times
    Suspicious entries :

    O23 - Service: ICKVESNAZ - Unknown owner - C:\Users\user\AppData\Local\Temp\ICKVESNAZ.exe (file missing)

    O13 - Gopher Prefix:

    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    ----------------------------------------------------------------------------------------------

    Do you have any proxies installed ?

  7. #7
    Verified Member
    Points: 5,847, Level: 49
    Level completed: 49%, Points required for next Level: 103
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jan 2008
    Location
    Fgura, Malta
    Posts
    535
    Liked
    1 times
    A university uh? At my Learning institute we got a crappy antivirus (symantec antivirus [not norton]) and a stupid filter which denies acess to many proxies and websites including raymond.cc. Crappy education intitues.

    http://www.f-secure.com/v-descs/m-amoeba.shtml <-- The truth

  8. #8
    Senior Techie
    Points: 6,451, Level: 52
    Level completed: 51%, Points required for next Level: 99
    Overall activity: 0.4%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Apr 2008
    Posts
    236
    Liked
    0 times
    Hi,
    I had Sun Web Proxy installed which I uninstalled afterwards.I am not sure if the uninstallation was proper and that it works on Windows.I didn't know what it was when I installed it.It was an unnecessary action.
    I use cntlm for authentication of the university proxy.Sometimes I use ntlmaps.
    nivek_hcerg,what does the link(the truth) mean?
    Thanks!

  9. #9
    Verified Member
    Points: 5,847, Level: 49
    Level completed: 49%, Points required for next Level: 103
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jan 2008
    Location
    Fgura, Malta
    Posts
    535
    Liked
    1 times

    Confused

    the truth about much educational buildings (look at the last message which says it's encrypted)

 

 

Similar Threads

  1. Replies: 3
    Last Post: 11-04-2011, 04:30 AM
  2. Replies: 1
    Last Post: 06-07-2011, 07:18 AM
  3. AVAST 5 FREE SHOWING INFECTION OF WIN 32:malware-gen
    By qrius2noall in forum Spyware/Viruses
    Replies: 25
    Last Post: 03-07-2010, 01:33 PM
  4. Replies: 8
    Last Post: 09-25-2009, 02:13 PM
All times are GMT +8. The time now is 10:59 PM.