• There seems to be an uptick in Political comments in recent months. Those of us who are long time members of the site know that Political and Religious content has been banned for years. Nothing has changed. Please leave all political and religious comments out of the forums.

    If you recently joined the forums you were not presented with this restriction in the terms of service. This was due to a conversion error when we went from vBulletin to Xenforo. We have updated our terms of service to reflect these corrections.

    Please note any post refering to a politician will be considered political even if it is intended to be humor. Our experience is these topics have a way of dividing the forums and causing deep resentment among members. It is a poison to the community. We appreciate compliance with the rules.

    The Staff of SOH

  • Server side Maintenance is done. We still have an update to the forum software to run but that one will have to wait for a better time.

Need some help on this

AussieMan

SOH Staff .."Bartender"
For the last couple of weeks I have been getting a pop up via my anti-virus checker. I have run a full virus scan but it is still there. I have reformatted my computer and I believe it has something to do with Google. All is well until the first time I run Google Mail. The first one comes up on a regular basis and the second one only when I run Google Mail.

 

Attachments

  • AVG 1.jpg
    AVG 1.jpg
    59.4 KB · Views: 0
  • AVG 2.jpg
    AVG 2.jpg
    50.4 KB · Views: 0
Hi Pat --

Ahhh good ol' Google. The fact that it keeps coming back after your AV removes it is troubling. It sounds like one of those little bugs that can replicate itself when part of it is removed form specific locations on the HD. I would search (in the Search Window, Start, then go down to the bottom and paste the name in...) This should show you all the locations on your machine where this thing may be hiding. I had a similar problem a few years back and the culprit had infected enough files that I had to un-install and re-install some software. Use different parts of the name your AVG gives, and use even the whole name. It won't hurt to search. Unfortunately, removing the bad guy from each location may corrupt that file, it may not.

On the better side, it may be isolated to the "images" folder as indicated by the location given by AVG. Search the "cleardot... etc" in the program search window. If that's the only location it comes up in, you may be able to delete it without having any adverse effects on your other programs and software.


I had a little bug attack my FSX.exe program a while back. I just deleted the infected FSX.exe and replaced it with another from the disk. Problem solved.

Good luck, mate.

BB686:US-flag:
 
IMHO (read: very humble), your malady could be coming from the Bing Weather Tracker. You say it only happens when you open Gmail... infected message, perhaps?

I say Bing, just because your first Attachment shows the block from a Bing affiliated site.

Just trying to be helpful...

Alan :wavey:
 
#1: This looks to be some sort of click-through traffic checking system from the wording of the URL.

#2: One reason that most local mail clients block images is that instead of embedding the images, the author links them to an online image. The link to the image can contain unique information associated with your email, so that when the author goes back to check traffic on that image, he can tell which recipients have viewed it. If you've viewed the image, then you've read the email, and you can be put on a "confirmed" contact list. These lists can be sold for big money. That "cleardot.gif" image sounds a lot like one of those.
 
The flipside of that coin is that blocked images can be perfectly innocent. Embedding an image into an email can vastly increase the bandwidth required to send it, so using hot-linked images allows the sender to distribute rich content with only a few kilobytes of html code. If the recipient's mail client blocks the images, then they have the option of whether to download the full content or not.
 
Back
Top