Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Virus and keyloggers on my350z

Thread Tools
 
Search this Thread
 
Old Mar 11, 2010 | 11:34 AM
  #161  
speedlimit's Avatar
speedlimit
IB Staff
 
Joined: Jan 2009
Posts: 91
Likes: 0
Default

Hi everyone!

I want to update you on the current status of our investigation relative to malware/virus concerns. I also want to assure you that your 350Z admins were on this with our techs from the beginning. Our techs have done a deep search of the site and have not found any evidence that our servers are hosting and serving any virus or malware. We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites. The other possibility is that an infected image has been uploaded, however, we not found any evidence of that at this time.

We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!

Bob..
Reply
Old Mar 11, 2010 | 11:46 AM
  #162  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by speedlimit
Hi everyone!
We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites.
You just stated you couldn't find the issue on this site, and there is obviously something lurking around in here, so I suspect you're not going to see it on your other sites either.

I don't think the 'user injected content' angle is going to pan out.
Reply
Old Mar 11, 2010 | 12:21 PM
  #163  
Driven1's Avatar
Driven1
Professional
iTrader: (2)
 
Joined: Jan 2006
Posts: 4,397
Likes: 0
From: Virginia
Default

There's a previous post that said it's going on over on G35Driver.......
Reply
Old Mar 11, 2010 | 12:23 PM
  #164  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

Originally Posted by tware
You just stated you couldn't find the issue on this site, and there is obviously something lurking around in here, so I suspect you're not going to see it on your other sites either.

I don't think the 'user injected content' angle is going to pan out.
They have tried everything to replicate the problem just without any luck.

You make it sound as if IB created the virus and distributed it or as if they knowingly allowed for this to happen or as if they're just not doing anything. None of us are having these issues anymore, correct? So at the very least, it's temporarily gone which would explain why they can't locate the source.

The IB technicians have been on it and will continue to stay on top of it in case there's another outbreak.


Anyway, for those who may have missed it the first time:
We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!
Reply
Old Mar 11, 2010 | 12:23 PM
  #165  
Tian's Avatar
Tian
Registered User
 
Joined: Oct 2006
Posts: 199
Likes: 0
From: South FL
Default

Originally Posted by speedlimit
Hi everyone!

I want to update you on the current status of our investigation relative to malware/virus concerns. I also want to assure you that your 350Z admins were on this with our techs from the beginning. Our techs have done a deep search of the site and have not found any evidence that our servers are hosting and serving any virus or malware. We don't believe it's a virus from one of our advertising partners because we are not seeing this issue on any of the other sites. The other possibility is that an infected image has been uploaded, however, we not found any evidence of that at this time.

We need your help by posting a screenshot of any antivirus pop up or other viewing problems. Please include as much information as you can concerning your activities (view page, pic etc) leading up to the virus appearing. Thanks!

Bob..
This image must be on driver as well then because it's infecting users on G35Driver. I'll take a screen shot of the error code page although I'm sure this won't help. It's just bogging my google chrome and safari down. I did a virus sweep and i'm squeaky clean here. Mostly PC's
Reply
Old Mar 11, 2010 | 12:43 PM
  #166  
Entaille's Avatar
Entaille
New Member
iTrader: (16)
 
Joined: Sep 2008
Posts: 9,043
Likes: 21
From: WA
Default

lol at the spyware doctor ads the forum has now. gotta love how adaptive they are.
Reply
Old Mar 11, 2010 | 01:01 PM
  #167  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

Can you guys please start posting the links where you are getting flags?
Reply
Old Mar 11, 2010 | 01:04 PM
  #168  
3hree5ive0ero's Avatar
3hree5ive0ero
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

__________________
__________________
__________________
__________________
Reply
Old Mar 11, 2010 | 01:11 PM
  #169  
VO...'s Avatar
VO...
Administrator
iTrader: (25)
 
Joined: Jun 2005
Posts: 58,609
Likes: 2,747
From: Down Under & Dirty
Default

I recieved the pop-up earlier this week. I just "X" it out and left it alone. I figured it was BS, because it didn't ressemble my company's traditional anti-virus pop-ups. Never saw it again or had any problems with my work PC...
Reply
Old Mar 11, 2010 | 03:21 PM
  #170  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by 3hree5ive0ero
You make it sound as if IB created the virus and distributed it or as if they knowingly allowed for this to happen or as if they're just not doing anything.
Not at all. IB is as much a victim of this as the members. I already stated that I believe it is the ultimate responsibility of the user to harden their browsers. You are as likely to get this ANYWHERE else on the web. I still believe it was served thru the ad network. It is getting quite common. However, most sites are much more responsive in protecting their users. That is my only criticism, the massive delay. And no, I dont mean from Mods. Most of what I posted was trying to help users.

I'll be busy this weekend helping clean up (fresh install) some member's PCs so, this does actually affect me, even tho my machine has not been exploited because I run noscript and ABP.
Reply
Old Mar 11, 2010 | 05:35 PM
  #171  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

Take a screenshot of the full page if you get a flag as well...
Reply
Old Mar 11, 2010 | 06:34 PM
  #172  
zerafian's Avatar
zerafian
Thread Starter
New Member
iTrader: (24)
 
Joined: Nov 2007
Posts: 4,180
Likes: 16
From: Chattanooga, Tn
Default

damn, I didnt expect this to happen when I made this thread. I could have sworn this issue had been brought up before ever mentioned it.
Reply
Old Mar 14, 2010 | 05:29 AM
  #173  
se-r altima dri's Avatar
se-r altima dri
Registered User
 
Joined: Oct 2009
Posts: 20
Likes: 0
From: PA
Default

The one that popped up on me 2 or 3 times was the windows defender virus. I was looking in the classified section (Turbo, nitrous or engine or tuning under 350Z section)and the browser was redirected to the site that popped up the scanning of the computer saying windows defender. I hit cntrl alt delete and ended the process of the IE browser. That was my experience. Just scanned the computer and did the windows essentials and everything seems fine.

I guess the Anti virus people need money again. lol

Last edited by se-r altima dri; Mar 14, 2010 at 05:51 AM.
Reply
Old Mar 14, 2010 | 06:09 AM
  #174  
Jay'Z's Avatar
Jay'Z
Banned
iTrader: (118)
 
Joined: Apr 2005
Posts: 10,944
Likes: 1
From: Carbon Fiber, TX
Default

I had a virus for 1 week due to this site.. Just got it back up and running.... FTMFL...
Reply
Old Mar 14, 2010 | 06:50 AM
  #175  
MDHRZ's Avatar
MDHRZ
Registered User
iTrader: (14)
 
Joined: Apr 2008
Posts: 4,026
Likes: 0
From: Southern MD
Default

Originally Posted by phreaktor
Take a screenshot of the full page if you get a flag as well...
Why? It doesn't matter what page you are viewing. It matters what ad you get.
Reply
Old Mar 14, 2010 | 12:17 PM
  #176  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Originally Posted by Black Z Eddie
On a serious note, I almost wanna install virtual pc and maybe run a screen capture app that way can check out frame by frame to see about when/where it happens.
I went ahead and did this using XP SP3 but couldn't duplicate the problem, not to say it doesn't exist 'cause clearly it does. I had no AV or ad/script blocker running on this tester. It was just open for anything to try anything. I also installed all necessary components to play videos from Youtube and Streetfire.
Reply
Old Mar 14, 2010 | 05:05 PM
  #177  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

Originally Posted by MDHRZ
Why? It doesn't matter what page you are viewing. It matters what ad you get.
The screenshot will have the ad in it along with the exact virus name. Not that ads have been confirmed as the portal yet.
Reply
Old Mar 14, 2010 | 06:28 PM
  #178  
Driven1's Avatar
Driven1
Professional
iTrader: (2)
 
Joined: Jan 2006
Posts: 4,397
Likes: 0
From: Virginia
Default

Haven't been able to duplicate it lately.....
Reply
Old Mar 14, 2010 | 07:06 PM
  #179  
se-r altima dri's Avatar
se-r altima dri
Registered User
 
Joined: Oct 2009
Posts: 20
Likes: 0
From: PA
Default

Originally Posted by phreaktor
The screenshot will have the ad in it along with the exact virus name. Not that ads have been confirmed as the portal yet.
the browser was redirected to the site that popped up the scanning of the computer saying windows defender.
There is no chance of getting a screen shot before it was too late.

It happened when I switched to a new page, for example:
Viewing page 3 in my350z.com/forum/tuning/utec information/page=3 then I clicked to switch to page 2 and as soon as page 2 loaded, it would redirect the browser immediatly to a new website, phished website, showing windows defender software and animated scanning, (looks real time) of the fake software almost like an animated gif or flash movie.
You would have to screen shot every page for it to ever have a chance to work and the redirect was so fast that you would have switched pages before you had a chance to get the image. Just so your software guys know what was happening. If it was an ad then it was redirecting the client computer on load of the new page. Probably done using a javascript or some other script running on page load command.
Hope that helps.
Reply
Old Mar 15, 2010 | 02:54 PM
  #180  
phreaktor's Avatar
phreaktor
Design Engineer
iTrader: (22)
 
Joined: Jan 2007
Posts: 28,233
Likes: 33
From: The Marketplace
Default

OK I see what you guys are saying now. I think I got something different, because my AV flagged it and displayed a message of the threat that was blocked.
Reply



All times are GMT -8. The time now is 07:33 AM.