TechSpot

Another suspicious character

By macx
Jul 3, 2007
  1. All of a sudden when I open my browser (FF) I'm getting a window
    that says I've chosen to download or open something called
    oasadgenerator.aspx, which of course I haven't. Pops up every
    time I log on. It's from something called //publish.vx.roo.com.

    I tried opening that site but then I get a window that asks if
    I want to either download or open something else from them,
    doesn't even list a name for it.

    I've tried blocking cookies and designated it an untrusted site
    but it still seems to come up.

    It disturbs me - of course I've never even heard of it let alone
    tried downloading or opening anything from it - -

    anybody know what it is, if/how dangerous it may be, and how
    to stop it?

    Thanks!
     
  2. A_DOG73

    A_DOG73 TS Rookie Posts: 170

    Uninstall and Reinstall FF

    First backup your favorites etc. for FF.

    Then uninstall FF completely.

    Then run antivirus and antispyware tools.

    Reboot.

    Then reinstall FF.

    See if the problem still occurs after that.
     
  3. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Your system is most likely infected with malware.

    Important: Please read this thread HERE before you decide whether to clean or reformat your system.

    Should you decide to clean your computer, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. Do follow all the instructions exactly. They will provide logs for analysis of your system so I will know how to instruct you to proceed.

    Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

    Also, please let me know the results of the AVG Antirootkit scan


    Regards,
    Your friendly momok =)

    This thread is for the use of macx only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  4. michaelgreenwic

    michaelgreenwic TS Rookie

    I've got this same problem. I reformatted my computer on 7/6 and now the message is back today. I've been using AVG free edition and the free version of zone alarm for security. Spybot Search and Destroy and Ad-Aware don't find anything when I do a system scan.
     
  5. michaelgreenwic

    michaelgreenwic TS Rookie

    I think that this problem may have something to do with the website excite.com. This is my home page and I get the download prompt continuously (with firefox) whenever I go there. I don't get the message on other sites.
     
  6. macx

    macx TS Evangelist Topic Starter Posts: 712

    I think you're right - I recently noticed I'd just get it when I went to
    Excite, not when I opened FF (Excite isn't my home page).

    Another real oddity - my wife gets it on her Mac with excite & FF, too!
    And she's going thru a router/firewall.
    But not when opening Excite from her other browser (can't think of the
    name right now), but does get some kind of message that something
    won't open - might be that same thing?

    Have you tried uninstalling and reinstalling Excite?
    I've done a search for that thing to no avail, also done a complete
    Detailed scan w/AVG Suite, Ad Aware, and several others with no
    results.

    Probly some kind of trojan horse, spyware, or whatever.
    Or, as the name seems to imply, at least some kind of
    tracking thingy for ads.
     
  7. momok

    momok TS Rookie Posts: 2,265

    Hi,

    This is the 2nd time I'm repeating this. It is highly likely your system is infected with adware, and possibly spyware and other nasties. Same goes for your wife's Mac. If you wish to clean, I need to see your logs.

    Very Important: Malware infections can possibly lead to identity theft, loss of funds from bank accounts, misuse of credit card information etc. Therefore I strongly encourage you to please read this thread HERE before deciding what course of action to take regarding your infection.

    Should you decide to clean your computer, please go ahead to Viruses/Spyware/Malware, preliminary removal instructions and follow the steps given. Do follow all the instructions exactly. They will provide logs for analysis of your system so I will know how to instruct you to proceed.

    Thereafter, please post fresh HijackThis, AVG Antispyware and Combofix logs as attachments into this thread. Do not copy and paste your logs if not it will be ignored and/or removed.

    Also, please let me know the results of the AVG Antirootkit scan


    Regards,
    Your friendly momok =)

    This thread is for the use of macx only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...