• Hi Guest - Come check out all of the new CP Merch Shop! Now you can support CigarPass buy purchasing hats, apparel, and more...
    Click here to visit! here...

Malware

Bama46

New Member
Joined
Oct 23, 2008
Messages
12
Reaction score
0
Location
Chatham, IL
Every time I open this site, I get a message indicating outgoing Malware has been blocked. I am glad my virus protection is working, but since it only happens when I am on CP, I must conclude that the critter is resident here.
 
Every time I open this site, I get a message indicating outgoing Malware has been blocked. I am glad my virus protection is working, but since it only happens when I am on CP, I must conclude that the critter is resident here.

Outgoing Malware ???

Download MalwareBytes and scan your system. The problem isn't with CP, I don't think.
 
Does this warning include an offer to buy protection software?

Does it act like it's scanning your system?

Which Virus protection are you using, and is the warning from that software?


edit for spelling.
 
Every time I open this site, I get a message indicating outgoing Malware has been blocked. I am glad my virus protection is working, but since it only happens when I am on CP, I must conclude that the critter is resident here.


No. You may have a browser hijack program,

What is the exact warning...a screen shot would help.

malewarebytes works...

and you can go to housecall.trendmicro.com for their checker.

kapersky also has some free software checkers.
 
I am using Malwareby, and it tells me that it blocked an outgoing malware program. It gives me the time and a file number. i am familiar with the fake virus protection scams that want to sell you a program, but in reality are a virus.
The ONLY time it ever shows up is on CP and it shows up is here and it shows up on a regular basis. That is why I was thinking the problem originates here.
 
It's not CP, as many of us that are reasonably aware of how trojans / viruses / malware work surf here and don't have such issues.

Scan your system using Malware Bytes, SuperAntiSpyware, and a decent anti virus package. I've always liked Mircrosoft Secruity Essentials....free, constantly updated, and very solid.

It bears mentioning that if you don't keep you system up to date with updated virus signatures, updated security patches, up to date browser versions (which feature better control over such malware).....sooner or later a bug or two will make it's way into your system and you're essentially screwed.

Bottom line....quit blaming CP and start looking for the real cause. It ain't CP....believe me.

B.B.S.



I am using Malwareby, and it tells me that it blocked an outgoing malware program. It gives me the time and a file number. i am familiar with the fake virus protection scams that want to sell you a program, but in reality are a virus.
The ONLY time it ever shows up is on CP and it shows up is here and it shows up on a regular basis. That is why I was thinking the problem originates here.
....if it's blocking an OUTGOING program, how can CP be the issue....?? Dude, you're infected. Quit blaming CP and search out some real answers.
 
It's not CP, as many of us that are reasonably aware of how trojans / viruses / malware work surf here and don't have such issues.

Scan your system using Malware Bytes, SuperAntiSpyware, and a decent anti virus package. I've always liked Mircrosoft Secruity Essentials....free, constantly updated, and very solid.

It bears mentioning that if you don't keep you system up to date with updated virus signatures, updated security patches, up to date browser versions (which feature better control over such malware).....sooner or later a bug or two will make it's way into your system and you're essentially screwed.

Bottom line....quit blaming CP and start looking for the real cause. It ain't CP....believe me.

B.B.S.

Sir,
I would submit that asking questions, pondering answers and stating facts is most definitely not blaming anyone.

I am using Malwareby, and it tells me that it blocked an outgoing malware program. It gives me the time and a file number. i am familiar with the fake virus protection scams that want to sell you a program, but in reality are a virus.
The ONLY time it ever shows up is on CP and it shows up is here and it shows up on a regular basis. That is why I was thinking the problem originates here.
....if it's blocking an OUTGOING program, how can CP be the issue....?? Dude, you're infected. Quit blaming CP and search out some real answers.
 
Sir,
I would submit that asking questions, pondering answers and stating facts is most definitely not blaming anyone.
I would also submit that saying your anti-virus software is blocking an OUTGOING program would point not at the web page being browsed, but rather the PC on which the browsing is being done.

Questions are how we learn, but there are many reasonably computer and network savvy folks that regularly browse these pages. If CP was infected, there are a few folks that would know.

No offense meant - B.B.S.
 
Sir,
I would submit that asking questions, pondering answers and stating facts is most definitely not blaming anyone.
I would also submit that saying your anti-virus software is blocking an OUTGOING program would point not at the web page being browsed, but rather the PC on which the browsing is being done.

Questions are how we learn, but there are many reasonably computer and network savvy folks that regularly browse these pages. If CP was infected, there are a few folks that would know.

No offense meant - B.B.S.


I would concur with your assessment had I not run malwarebytes and had no hits AND if this were happening anywhere else exept CP. I freely admit I don't know what is going on.
 
Sir,
I would submit that asking questions, pondering answers and stating facts is most definitely not blaming anyone.
I would also submit that saying your anti-virus software is blocking an OUTGOING program would point not at the web page being browsed, but rather the PC on which the browsing is being done.

Questions are how we learn, but there are many reasonably computer and network savvy folks that regularly browse these pages. If CP was infected, there are a few folks that would know.

No offense meant - B.B.S.


I would concur with your assessment had I not run malwarebytes and had no hits AND if this were happening anywhere else exept CP. I freely admit I don't know what is going on.

What EXACT MESSAGE is coming from the program?

Now go here:

Download the TDSS Killer and the Virus Removal Tool for 2011 (file on the left)

LINKY

(note - is malewarebytles up to date? Also...can you get to a 'windows update' page?)

These details are important to figure our what's happening.

It could be a JAVA exploit...an IE exploit...or even an Adobe exploit.

note note...I would run these in windows safe mode.
 
......I freely admit I don't know what is going on.
...and upon this, we can build....:thumbs:

Computer security has gotten more and more complicated as time goes on. The software has been getting smarter, but so have the "bad guys". Having been at the PC game a bit I can give you my opinions, and that all they are. I'll try to be brief.....:p

Let me make the assumption that you are running a Windows system.

- System updates: Run them, need them, do it often..!! Windows Update does a great job....
- Browsers: There is Firefox and Chrome and other 2nd party browsers. I had the worst virus infestation ever let in by FireFox. One man's opinion here....I won't run 'em. Give me IE9 and Microsoft Security Essentials. Period.
- Virus Scanners: There are a bunch; Microsoft Security Essentials may not be the "best" but it's damn good. I run it, and it works for me.

Keep in mind that all of this is free.

If your system is up to date, your browser is up to date, and your virus scanner has up to date signatures and is running, you'll find that 99.95% of your problems go away.

One man's experiences - B.B.S.
 
After doing each step BBS and Gary suggested and you still have problems, open regedit and do a search on cigarpass.com. It's possible to eradicate the offending program, but the registry entry for the hijack may have been missed.
 
If you ever find it, send me a sample. Probably just another virtumod or TDSS variant, which have fairly harmless payloads, so it won't hurt you to take your time and make sure you find all the components. Check your MBR while you're at it.
 
Top