Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Members whose system was infected by the recent virus outbreak ONLY

Thread Tools
 
Search this Thread
 
Old 07-23-2010, 11:24 PM
  #61  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Black Z Eddie

Using FF, Google, or Opera results in no warning. For whatever reason, at least on my system, seems to only do it on for IE(7).
no, I have it with FF as well.

this evening I didnt get the blank popups with ubuntu. but still blocked on win machines with KIS or KAV.

Last time, the issue wasnt on this server either. It's certainly possible that its a false positive. It would be one of the very few FP's on a website (not counting FPs on files) I've seen in 3 years of using KAV.

Last edited by tware; 07-23-2010 at 11:25 PM.
tware is offline  
Old 07-25-2010, 03:36 PM
  #62  
Checkmate58
Registered User
iTrader: (11)
 
Checkmate58's Avatar
 
Join Date: Nov 2005
Location: Bay Area
Posts: 350
Likes: 0
Received 1 Like on 1 Post
Default

My antispyware program blocks this everytime I come to the forum front page.

188.120.232.15
Checkmate58 is offline  
Old 07-26-2010, 04:51 AM
  #63  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

We are 99% certain this is a false positive scenario. That IP ^^ is a new one, I'll be sure to add it to our notes on this issue. Thanks.
Robb M. is offline  
Old 07-26-2010, 05:52 PM
  #64  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

I run noscript and I dont recall a script from autodiva.ru before.
tware is offline  
Old 07-28-2010, 10:05 AM
  #65  
Brrcats
Registered User
iTrader: (10)
 
Brrcats's Avatar
 
Join Date: Jan 2007
Location: Westerville, OH
Posts: 2,370
Likes: 0
Received 0 Likes on 0 Posts
Default

Just stopped two attacks as soon as I opened the page.

Running outlook, some oracle apps for work, came from graveyarddeals.com, but the notice didnt hit me till I was about halfway done loading the page.

oh, and I noticed something was amiss becuase it looked like java was opening or something, had the initialization screen up for java

Last edited by Brrcats; 07-28-2010 at 10:06 AM.
Brrcats is offline  
Old 07-28-2010, 10:07 AM
  #66  
kacz07
Registered User
iTrader: (15)
 
kacz07's Avatar
 
Join Date: Sep 2007
Location: NJ
Posts: 2,936
Likes: 0
Received 4 Likes on 3 Posts
Default

I got two threats right away that were blocked by Avast. Happened right when I loaded the page.
kacz07 is offline  
Old 07-28-2010, 11:49 AM
  #67  
03threefiftyz
350Z-holic
iTrader: (25)
 
03threefiftyz's Avatar
 
Join Date: Aug 2007
Location: Frederick, MD
Posts: 9,848
Received 117 Likes on 63 Posts
Default

I've been getting warnings today as well........on top of the site running insanely slow.
03threefiftyz is offline  
Old 07-28-2010, 05:48 PM
  #68  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

no no, they are 99% sure its false.. oh, sorry about that 1%.

come on, even if this is a FP, and I'm not that sure it is anymore, IB is big enough to get Kaspersky's attention! This is kinda ridiculous to go on for this long even as a FP. If this turns out to be a real exploit, its beyond excusable. Why would you not start pulling code until you found it? Or checking 3rd party content?! even if only from the angle of lost ad revenue from so many blocked visitors......
tware is offline  
Old 07-28-2010, 07:22 PM
  #69  
Black Z Eddie
New Member
 
Black Z Eddie's Avatar
 
Join Date: Jun 2007
Location: San Pedro
Posts: 947
Received 9 Likes on 3 Posts
Default

One thing kinda peculiar, if it's a false positive, why would different AV softwares detect it as a threat.
Black Z Eddie is offline  
Old 07-28-2010, 07:43 PM
  #70  
FATPUBUS
Registered User
iTrader: (30)
 
FATPUBUS's Avatar
 
Join Date: Aug 2009
Location: Underneath the bridge
Posts: 858
Likes: 0
Received 0 Likes on 0 Posts
Default

Ive had the Java warnings all day, which I've ignored and closed, every time I come on, with a Norton popup saying they just blocked an attack.
FATPUBUS is offline  
Old 08-02-2010, 07:49 AM
  #71  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

We are investigating new reports that some kind of javascript exploit is live on the sites.
Robb M. is offline  
Old 08-02-2010, 05:19 PM
  #72  
PerfZ
New Member
iTrader: (3)
 
PerfZ's Avatar
 
Join Date: Sep 2003
Location: hilliard ohio
Posts: 2,402
Received 14 Likes on 13 Posts
Default

Kaspersky gives me warnings on every page I go to on this site but I figure at least it is blocking whatever it is.8/2/2010 9:25:17 PM

From Kaspersky log: https://my350z.com/forum/mid-atlanti...on-thread.html Firefox Processing error: HEUR:Trojan.Script.Iframer

Last edited by PerfZ; 08-02-2010 at 05:26 PM.
PerfZ is offline  
Old 08-02-2010, 06:40 PM
  #73  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Robb M.
We are investigating new reports that some kind of javascript exploit is live on the sites.
if by new you mean over a week.
tware is offline  
Old 08-02-2010, 06:54 PM
  #74  
jonnylaw
Registered User
iTrader: (3)
 
jonnylaw's Avatar
 
Join Date: May 2006
Location: Meifumado
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

Yea, I'm still getting warnings and alerts from Kaspersky that require system restarts to purge.
jonnylaw is offline  
Old 08-03-2010, 12:30 PM
  #75  
bkaa
Registered User
iTrader: (5)
 
bkaa's Avatar
 
Join Date: Feb 2008
Location: los angeles, CA
Posts: 107
Likes: 0
Received 0 Likes on 0 Posts
Default

im still having the same problem......
bkaa is offline  
Old 08-03-2010, 12:40 PM
  #76  
jonnylaw
Registered User
iTrader: (3)
 
jonnylaw's Avatar
 
Join Date: May 2006
Location: Meifumado
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

What is Autodiva.ru?

Last edited by jonnylaw; 08-03-2010 at 12:41 PM.
jonnylaw is offline  
Old 08-04-2010, 08:57 AM
  #77  
koren
New Member
iTrader: (23)
 
koren's Avatar
 
Join Date: Jul 2008
Location: MIami, FL
Posts: 403
Received 2 Likes on 2 Posts
Default

It is the club for women-drivers in Russia. Why do you asking???
koren is offline  
Old 08-04-2010, 09:30 AM
  #78  
jonnylaw
Registered User
iTrader: (3)
 
jonnylaw's Avatar
 
Join Date: May 2006
Location: Meifumado
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

^lol b/c that is what the website is redirecting to when you first enter it. Wondering if it has to do with the trojan/virus/warnings
jonnylaw is offline  
Old 08-04-2010, 04:33 PM
  #79  
Phreakdout
Registered User
iTrader: (32)
 
Phreakdout's Avatar
 
Join Date: Apr 2008
Location: Ann Arbor, Michigan
Posts: 2,115
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by PerfZ
Kaspersky gives me warnings on every page I go to on this site but I figure at least it is blocking whatever it is.8/2/2010 9:25:17 PM

From Kaspersky log: https://my350z.com/forum/mid-atlanti...on-thread.html Firefox Processing error: HEUR:Trojan.Script.Iframer
IT just recently uploaded Kaspersky onto my work laptop. Murphy's Law has it I get infectected and IT swarms in like a Phreakin SWAT team. I take it there is some alert system when a user gets infected. Sooo, now my work computer is off limits to My350Z.com. Well, crap!

I hope this is solved soon so I don't have to buy a second computer. Keep at it guys.
Phreakdout is offline  
Old 08-05-2010, 05:12 AM
  #80  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

I've re-filed a ticket with tech to get this dealt with first thing today.
Robb M. is offline  


Quick Reply: Members whose system was infected by the recent virus outbreak ONLY



All times are GMT -8. The time now is 12:22 PM.