Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Members whose system was infected by the recent virus outbreak ONLY

Thread Tools
 
Search this Thread
 
Old Jul 23, 2010 | 11:24 PM
  #61  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by Black Z Eddie

Using FF, Google, or Opera results in no warning. For whatever reason, at least on my system, seems to only do it on for IE(7).
no, I have it with FF as well.

this evening I didnt get the blank popups with ubuntu. but still blocked on win machines with KIS or KAV.

Last time, the issue wasnt on this server either. It's certainly possible that its a false positive. It would be one of the very few FP's on a website (not counting FPs on files) I've seen in 3 years of using KAV.

Last edited by tware; Jul 23, 2010 at 11:25 PM.
Old Jul 25, 2010 | 03:36 PM
  #62  
Checkmate58's Avatar
Checkmate58
Registered User
iTrader: (11)
 
Joined: Nov 2005
Posts: 350
Likes: 1
From: Bay Area
Default

My antispyware program blocks this everytime I come to the forum front page.

188.120.232.15
Old Jul 26, 2010 | 04:51 AM
  #63  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

We are 99% certain this is a false positive scenario. That IP ^^ is a new one, I'll be sure to add it to our notes on this issue. Thanks.
Old Jul 26, 2010 | 05:52 PM
  #64  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

I run noscript and I dont recall a script from autodiva.ru before.
Old Jul 28, 2010 | 10:05 AM
  #65  
Brrcats's Avatar
Brrcats
Registered User
iTrader: (10)
 
Joined: Jan 2007
Posts: 2,370
Likes: 0
From: Westerville, OH
Default

Just stopped two attacks as soon as I opened the page.

Running outlook, some oracle apps for work, came from graveyarddeals.com, but the notice didnt hit me till I was about halfway done loading the page.

oh, and I noticed something was amiss becuase it looked like java was opening or something, had the initialization screen up for java

Last edited by Brrcats; Jul 28, 2010 at 10:06 AM.
Old Jul 28, 2010 | 10:07 AM
  #66  
kacz07's Avatar
kacz07
Registered User
iTrader: (15)
 
Joined: Sep 2007
Posts: 2,936
Likes: 4
From: NJ
Default

I got two threats right away that were blocked by Avast. Happened right when I loaded the page.
Old Jul 28, 2010 | 11:49 AM
  #67  
03threefiftyz's Avatar
03threefiftyz
350Z-holic
Premier Member
iTrader: (25)
 
Joined: Aug 2007
Posts: 9,848
Likes: 118
From: Frederick, MD
Default

I've been getting warnings today as well........on top of the site running insanely slow.
Old Jul 28, 2010 | 05:48 PM
  #68  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

no no, they are 99% sure its false.. oh, sorry about that 1%.

come on, even if this is a FP, and I'm not that sure it is anymore, IB is big enough to get Kaspersky's attention! This is kinda ridiculous to go on for this long even as a FP. If this turns out to be a real exploit, its beyond excusable. Why would you not start pulling code until you found it? Or checking 3rd party content?! even if only from the angle of lost ad revenue from so many blocked visitors......
Old Jul 28, 2010 | 07:22 PM
  #69  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

One thing kinda peculiar, if it's a false positive, why would different AV softwares detect it as a threat.
Old Jul 28, 2010 | 07:43 PM
  #70  
FATPUBUS's Avatar
FATPUBUS
Registered User
iTrader: (30)
 
Joined: Aug 2009
Posts: 858
Likes: 1
From: Underneath the bridge
Default

Ive had the Java warnings all day, which I've ignored and closed, every time I come on, with a Norton popup saying they just blocked an attack.
Old Aug 2, 2010 | 07:49 AM
  #71  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

We are investigating new reports that some kind of javascript exploit is live on the sites.
Old Aug 2, 2010 | 05:19 PM
  #72  
PerfZ's Avatar
PerfZ
New Member
iTrader: (3)
 
Joined: Sep 2003
Posts: 2,402
Likes: 14
From: hilliard ohio
Default

Kaspersky gives me warnings on every page I go to on this site but I figure at least it is blocking whatever it is.8/2/2010 9:25:17 PM

From Kaspersky log: https://my350z.com/forum/mid-atlanti...on-thread.html Firefox Processing error: HEUR:Trojan.Script.Iframer

Last edited by PerfZ; Aug 2, 2010 at 05:26 PM.
Old Aug 2, 2010 | 06:40 PM
  #73  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

Originally Posted by Robb M.
We are investigating new reports that some kind of javascript exploit is live on the sites.
if by new you mean over a week.
Old Aug 2, 2010 | 06:54 PM
  #74  
jonnylaw's Avatar
jonnylaw
Registered User
iTrader: (3)
 
Joined: May 2006
Posts: 1,957
Likes: 2
From: Meifumado
Default

Yea, I'm still getting warnings and alerts from Kaspersky that require system restarts to purge.
Old Aug 3, 2010 | 12:30 PM
  #75  
bkaa's Avatar
bkaa
Registered User
iTrader: (5)
 
Joined: Feb 2008
Posts: 107
Likes: 0
From: los angeles, CA
Default

im still having the same problem......
Old Aug 3, 2010 | 12:40 PM
  #76  
jonnylaw's Avatar
jonnylaw
Registered User
iTrader: (3)
 
Joined: May 2006
Posts: 1,957
Likes: 2
From: Meifumado
Default

What is Autodiva.ru?

Last edited by jonnylaw; Aug 3, 2010 at 12:41 PM.
Old Aug 4, 2010 | 08:57 AM
  #77  
koren's Avatar
koren
New Member
iTrader: (23)
 
Joined: Jul 2008
Posts: 403
Likes: 3
From: MIami, FL
Default

It is the club for women-drivers in Russia. Why do you asking???
Old Aug 4, 2010 | 09:30 AM
  #78  
jonnylaw's Avatar
jonnylaw
Registered User
iTrader: (3)
 
Joined: May 2006
Posts: 1,957
Likes: 2
From: Meifumado
Default

^lol b/c that is what the website is redirecting to when you first enter it. Wondering if it has to do with the trojan/virus/warnings
Old Aug 4, 2010 | 04:33 PM
  #79  
Phreakdout's Avatar
Phreakdout
Registered User
iTrader: (32)
 
Joined: Apr 2008
Posts: 2,115
Likes: 0
From: Ann Arbor, Michigan
Default

Originally Posted by PerfZ
Kaspersky gives me warnings on every page I go to on this site but I figure at least it is blocking whatever it is.8/2/2010 9:25:17 PM

From Kaspersky log: https://my350z.com/forum/mid-atlanti...on-thread.html Firefox Processing error: HEUR:Trojan.Script.Iframer
IT just recently uploaded Kaspersky onto my work laptop. Murphy's Law has it I get infectected and IT swarms in like a Phreakin SWAT team. I take it there is some alert system when a user gets infected. Sooo, now my work computer is off limits to My350Z.com. Well, crap!

I hope this is solved soon so I don't have to buy a second computer. Keep at it guys.
Old Aug 5, 2010 | 05:12 AM
  #80  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

I've re-filed a ticket with tech to get this dealt with first thing today.



All times are GMT -8. The time now is 01:22 PM.