Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old 03-11-2010, 11:34 AM
  #161  
speedlimit
IB Staff
 
speedlimit's Avatar
 
Join Date: Jan 2009
Posts: 91
Likes: 0
Received 0 Likes on 0 Posts
Default

Hi everyone!

I want to update you on the current status of our investigation relative to malware/virus concerns. I also want to assure you that your 350Z admins were on this with our techs from the beginning. Our techs have done a deep search of the site and have not found any evidence that our servers are hosting and serving any virus or malware. We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites. The other possibility is that an infected image has been uploaded, however, we not found any evidence of that at this time.

We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!

Bob..
Old 03-11-2010, 11:46 AM
  #162  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by speedlimit
Hi everyone!
We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites.
You just stated you couldn't find the issue on this site, and there is obviously something lurking around in here, so I suspect you're not going to see it on your other sites either.

I don't think the 'user injected content' angle is going to pan out.
Old 03-11-2010, 12:21 PM
  #163  
Driven1
Professional
iTrader: (2)
 
Driven1's Avatar
 
Join Date: Jan 2006
Location: Virginia
Posts: 4,398
Likes: 0
Received 0 Likes on 0 Posts
Default

There's a previous post that said it's going on over on G35Driver.......
Old 03-11-2010, 12:23 PM
  #164  
3hree5ive0ero
Retired Admin
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

Originally Posted by tware
You just stated you couldn't find the issue on this site, and there is obviously something lurking around in here, so I suspect you're not going to see it on your other sites either.

I don't think the 'user injected content' angle is going to pan out.
They have tried everything to replicate the problem just without any luck.

You make it sound as if IB created the virus and distributed it or as if they knowingly allowed for this to happen or as if they're just not doing anything. None of us are having these issues anymore, correct? So at the very least, it's temporarily gone which would explain why they can't locate the source.

The IB technicians have been on it and will continue to stay on top of it in case there's another outbreak.


Anyway, for those who may have missed it the first time:
We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!
Old 03-11-2010, 12:23 PM
  #165  
Tian
Registered User
 
Tian's Avatar
 
Join Date: Oct 2006
Location: South FL
Posts: 199
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by speedlimit
Hi everyone!

I want to update you on the current status of our investigation relative to malware/virus concerns. I also want to assure you that your 350Z admins were on this with our techs from the beginning. Our techs have done a deep search of the site and have not found any evidence that our servers are hosting and serving any virus or malware. We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites. The other possibility is that an infected image has been uploaded, however, we not found any evidence of that at this time.

We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!

Bob..
This image must be on driver as well then because it's infecting users on G35Driver. I'll take a screen shot of the error code page although I'm sure this won't help. It's just bogging my google chrome and safari down. I did a virus sweep and i'm squeaky clean here. Mostly PC's
Old 03-11-2010, 12:43 PM
  #166  
Entaille
New Member
iTrader: (16)
 
Entaille's Avatar
 
Join Date: Sep 2008
Location: WA
Posts: 9,043
Received 21 Likes on 16 Posts
Default

lol at the spyware doctor ads the forum has now. gotta love how adaptive they are.
Old 03-11-2010, 01:01 PM
  #167  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Can you guys please start posting the links where you are getting flags?
Old 03-11-2010, 01:04 PM
  #168  
3hree5ive0ero
Retired Admin
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

__________________
__________________
__________________
__________________
Old 03-11-2010, 01:11 PM
  #169  
VO...
Administrator
iTrader: (25)
 
VO...'s Avatar
 
Join Date: Jun 2005
Location: Down Under & Dirty
Posts: 58,609
Received 2,747 Likes on 1,836 Posts
Default

I recieved the pop-up earlier this week. I just "X" it out and left it alone. I figured it was BS, because it didn't ressemble my company's traditional anti-virus pop-ups. Never saw it again or had any problems with my work PC...
Old 03-11-2010, 03:21 PM
  #170  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 3hree5ive0ero
You make it sound as if IB created the virus and distributed it or as if they knowingly allowed for this to happen or as if they're just not doing anything.
Not at all. IB is as much a victim of this as the members. I already stated that I believe it is the ultimate responsibility of the user to harden their browsers. You are as likely to get this ANYWHERE else on the web. I still believe it was served thru the ad network. It is getting quite common. However, most sites are much more responsive in protecting their users. That is my only criticism, the massive delay. And no, I dont mean from Mods. Most of what I posted was trying to help users.

I'll be busy this weekend helping clean up (fresh install) some member's PCs so, this does actually affect me, even tho my machine has not been exploited because I run noscript and ABP.
Old 03-11-2010, 05:35 PM
  #171  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Take a screenshot of the full page if you get a flag as well...
Old 03-11-2010, 06:34 PM
  #172  
zerafian
New Member
Thread Starter
iTrader: (24)
 
zerafian's Avatar
 
Join Date: Nov 2007
Location: Chattanooga, Tn
Posts: 4,180
Received 16 Likes on 13 Posts
Default

damn, I didnt expect this to happen when I made this thread. I could have sworn this issue had been brought up before ever mentioned it.
Old 03-14-2010, 05:29 AM
  #173  
se-r altima dri
Registered User
 
se-r altima dri's Avatar
 
Join Date: Oct 2009
Location: PA
Posts: 20
Likes: 0
Received 0 Likes on 0 Posts
Default

The one that popped up on me 2 or 3 times was the windows defender virus. I was looking in the classified section (Turbo, nitrous or engine or tuning under 350Z section)and the browser was redirected to the site that popped up the scanning of the computer saying windows defender. I hit cntrl alt delete and ended the process of the IE browser. That was my experience. Just scanned the computer and did the windows essentials and everything seems fine.

I guess the Anti virus people need money again. lol

Last edited by se-r altima dri; 03-14-2010 at 05:51 AM.
Old 03-14-2010, 06:09 AM
  #174  
Jay'Z
Banned
iTrader: (118)
 
Jay'Z's Avatar
 
Join Date: Apr 2005
Location: Carbon Fiber, TX
Posts: 10,944
Likes: 0
Received 1 Like on 1 Post
Default

I had a virus for 1 week due to this site.. Just got it back up and running.... FTMFL...
Old 03-14-2010, 06:50 AM
  #175  
MDHRZ
Registered User
iTrader: (14)
 
MDHRZ's Avatar
 
Join Date: Apr 2008
Location: Southern MD
Posts: 4,026
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by phreaktor
Take a screenshot of the full page if you get a flag as well...
Why? It doesn't matter what page you are viewing. It matters what ad you get.
Old 03-14-2010, 12:17 PM
  #176  
Black Z Eddie
New Member
 
Black Z Eddie's Avatar
 
Join Date: Jun 2007
Location: San Pedro
Posts: 947
Received 9 Likes on 3 Posts
Default

Originally Posted by Black Z Eddie
On a serious note, I almost wanna install virtual pc and maybe run a screen capture app that way can check out frame by frame to see about when/where it happens.
I went ahead and did this using XP SP3 but couldn't duplicate the problem, not to say it doesn't exist 'cause clearly it does. I had no AV or ad/script blocker running on this tester. It was just open for anything to try anything. I also installed all necessary components to play videos from Youtube and Streetfire.
Old 03-14-2010, 05:05 PM
  #177  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

Originally Posted by MDHRZ
Why? It doesn't matter what page you are viewing. It matters what ad you get.
The screenshot will have the ad in it along with the exact virus name. Not that ads have been confirmed as the portal yet.
Old 03-14-2010, 06:28 PM
  #178  
Driven1
Professional
iTrader: (2)
 
Driven1's Avatar
 
Join Date: Jan 2006
Location: Virginia
Posts: 4,398
Likes: 0
Received 0 Likes on 0 Posts
Default

Haven't been able to duplicate it lately.....
Old 03-14-2010, 07:06 PM
  #179  
se-r altima dri
Registered User
 
se-r altima dri's Avatar
 
Join Date: Oct 2009
Location: PA
Posts: 20
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by phreaktor
The screenshot will have the ad in it along with the exact virus name. Not that ads have been confirmed as the portal yet.
the browser was redirected to the site that popped up the scanning of the computer saying windows defender.
There is no chance of getting a screen shot before it was too late.

It happened when I switched to a new page, for example:
Viewing page 3 in my350z.com/forum/tuning/utec information/page=3 then I clicked to switch to page 2 and as soon as page 2 loaded, it would redirect the browser immediatly to a new website, phished website, showing windows defender software and animated scanning, (looks real time) of the fake software almost like an animated gif or flash movie.
You would have to screen shot every page for it to ever have a chance to work and the redirect was so fast that you would have switched pages before you had a chance to get the image. Just so your software guys know what was happening. If it was an ad then it was redirecting the client computer on load of the new page. Probably done using a javascript or some other script running on page load command.
Hope that helps.
Old 03-15-2010, 02:54 PM
  #180  
phreaktor
¯¯\_(ツ)_/¯
iTrader: (22)
 
phreaktor's Avatar
 
Join Date: Jan 2007
Location: The Marketplace
Posts: 28,233
Received 32 Likes on 24 Posts
Default

OK I see what you guys are saying now. I think I got something different, because my AV flagged it and displayed a message of the threat that was blocked.


Quick Reply: Virus and keyloggers on my350z



All times are GMT -8. The time now is 05:24 PM.