Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Members whose system was infected by the recent virus outbreak ONLY

Old 08-05-2010, 12:54 PM
  #81  
DavesZ#3
350Z-holic
iTrader: (26)
 
DavesZ#3's Avatar
 
Join Date: Jul 2003
Location: Louisiana
Posts: 15,887
Likes: 0
Received 22 Likes on 17 Posts
Default

Originally Posted by koren
It is the club for women-drivers in Russia. Why do you asking???
Some of us are seeing references to http://autodiva.ru when browsing the forum. If you look in your temporary internet files folder, you'll probably see a file named 1.html (http://autodiva.ru/1.html).

That HTML file contains this script...

<!--LiveInternet counter--><script type="text/javascript"><!--
document.write("<a href='http://www.liveinternet.ru/click' "+
"target=_blank><img src='//counter.yadro.ru/hit?t14.2;r"+
escape(document.referrer)+((typeof(screen)=="undefined")?"":
";s"+screen.width+"*"+screen.height+"*"+(screen.colorDep th?
screen.colorDepth:screen.pixelDepth))+";u"+escape(document.U RL)+
";"+Math.random()+
"' alt='' title='LiveInternet: показано число просмотров за 24"+
" часа, посетителей за 24 часа и за сегодня' "+
"border='0' width='88' height='31'><\/a>")
//--></script><!--/LiveInternet-->

<script type="text/javascript">

var _gaq = _gaq || [];
_gaq.push(['_setAccount', 'UA-17571440-1']);
_gaq.push(['_trackPageview']);

(function() {
var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
})();
Maybe somebody a lot smarter than me can figure out what that is doing. I looks like it's generating hits on their website.
DavesZ#3 is offline  
Old 08-05-2010, 02:42 PM
  #82  
jonnylaw
Registered User
iTrader: (3)
 
jonnylaw's Avatar
 
Join Date: May 2006
Location: Meifumado
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

^^yep, I'm no tech, but there are references to java and I think this might be one of the causes for the trojan/virus warnings. Also google analytics..When browsing the forum, the bottom left corner will often direct to autodiva.ru and google-analytics.This script is embedded in the website?
jonnylaw is offline  
Old 08-05-2010, 03:24 PM
  #83  
DavesZ#3
350Z-holic
iTrader: (26)
 
DavesZ#3's Avatar
 
Join Date: Jul 2003
Location: Louisiana
Posts: 15,887
Likes: 0
Received 22 Likes on 17 Posts
Default

Probably not the website, likely something feeding the ads.

If you use IE, you can add autodiva.ru to the Restricted Sites and that will stop it from running the script. There may be an equivalent function in other browsers.
DavesZ#3 is offline  
Old 08-05-2010, 04:33 PM
  #84  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

is that what we are reduced to? instead of IB fixing this after weeks, we're just going to tip toe thru the mine field this place is becoming? With all due respect, as I maintain production servers myself and fully understand the challenge here, this deserved their FULL attention the minute reports came in. To leave this situation as it is for weeks now is irresponsible at best. Do they really not care at all about us? While nobody should ever fully trust any web content, it's really not fair to members who do trust this site and expect ads served thru it to be legit. I think surfing **** is safer than checking my PMs now.
tware is offline  
Old 08-05-2010, 04:53 PM
  #85  
DavesZ#3
350Z-holic
iTrader: (26)
 
DavesZ#3's Avatar
 
Join Date: Jul 2003
Location: Louisiana
Posts: 15,887
Likes: 0
Received 22 Likes on 17 Posts
Default

IB has been working this issue for the last couple of weeks. I know because I have been hounding them daily.
DavesZ#3 is offline  
Old 08-05-2010, 06:31 PM
  #86  
jonnylaw
Registered User
iTrader: (3)
 
jonnylaw's Avatar
 
Join Date: May 2006
Location: Meifumado
Posts: 1,957
Likes: 0
Received 2 Likes on 2 Posts
Default

hmm. what about counter.yabro.ru that is coming up now as well?

Last edited by jonnylaw; 08-05-2010 at 06:33 PM.
jonnylaw is offline  
Old 08-06-2010, 03:32 AM
  #87  
DavesZ#3
350Z-holic
iTrader: (26)
 
DavesZ#3's Avatar
 
Join Date: Jul 2003
Location: Louisiana
Posts: 15,887
Likes: 0
Received 22 Likes on 17 Posts
Default

It's being called from that autodiva.ru script shown above.
DavesZ#3 is offline  
Old 08-06-2010, 08:53 AM
  #88  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

Are you guys still seeing these issues today? We had a bunch of things kind of blow up in the server centre overnight. Hoping that all issues are now resolved...
Robb M. is offline  
Old 08-06-2010, 03:23 PM
  #89  
Black Z Eddie
New Member
 
Black Z Eddie's Avatar
 
Join Date: Jun 2007
Location: San Pedro
Posts: 947
Received 9 Likes on 3 Posts
Default

Yes.
Black Z Eddie is offline  
Old 08-08-2010, 03:24 AM
  #90  
amr_electron
Registered User
iTrader: (8)
 
amr_electron's Avatar
 
Join Date: Nov 2009
Location: On Earth
Posts: 337
Received 13 Likes on 11 Posts
Default

Received this today,



More Info,



Hope it's useful.
amr_electron is offline  
Old 08-08-2010, 04:00 AM
  #91  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

argh!!!!

Our continued apologies, as I thought that we had finally cleared this up on Friday. Apparently we were wrong
Robb M. is offline  
Old 08-08-2010, 09:50 AM
  #92  
koren
New Member
iTrader: (23)
 
koren's Avatar
 
Join Date: Jul 2008
Location: MIami, FL
Posts: 403
Received 2 Likes on 2 Posts
Default

What's funny is that none of the other Anti-virus catching that, only Kaspersky...
That's right, only Russians can stop Russians))))))))
koren is offline  
Old 08-08-2010, 11:46 AM
  #93  
03threefiftyz
350Z-holic
iTrader: (25)
 
03threefiftyz's Avatar
 
Join Date: Aug 2007
Location: Frederick, MD
Posts: 9,848
Received 117 Likes on 63 Posts
Default

Originally Posted by koren
What's funny is that none of the other Anti-virus catching that, only Kaspersky...
That's right, only Russians can stop Russians))))))))
False....I was getting warnings with Norton and Spyware Doctor.
03threefiftyz is offline  
Old 08-08-2010, 01:21 PM
  #94  
Hobart187
Registered User
iTrader: (4)
 
Hobart187's Avatar
 
Join Date: Sep 2009
Location: Fort Walton Beach
Posts: 40
Likes: 0
Received 0 Likes on 0 Posts
Default

I run avg and it caught it, and spybot warned me like 5 times of something trying to change my registry. Just clicked deny and moved it to the vault. Problem solved.
Hobart187 is offline  
Old 08-08-2010, 09:48 PM
  #95  
3hree5ive0ero
Retired Admin
Thread Starter
iTrader: (95)
 
3hree5ive0ero's Avatar
 
Join Date: Dec 2000
Location: Dallas / Chicago
Posts: 1,337,017,813
Received 78 Likes on 50 Posts
Default

Originally Posted by Hobart187
I run avg and it caught it, and spybot warned me like 5 times of something trying to change my registry. Just clicked deny and moved it to the vault. Problem solved.
I use AVG too, but nothing happened to me.

I'm using FF with ABP, though.
3hree5ive0ero is offline  
Old 08-09-2010, 06:44 AM
  #96  
JCat
---------------
iTrader: (4)
 
JCat's Avatar
 
Join Date: Mar 2004
Location: JC in Atlanta Georgia
Posts: 3,985
Received 73 Likes on 48 Posts
Default

What the hell is this ?

Does not look good http://safeweb.norton.com/report/sho...lebotsen.co.cc
Attached Thumbnails Members whose system was infected by the recent virus outbreak ONLY-350z.jpg  

Last edited by JCat; 08-09-2010 at 06:46 AM.
JCat is offline  
Old 08-09-2010, 07:39 AM
  #97  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

Yep, there's a new one. We're working to remove now.
Robb M. is offline  
Old 08-09-2010, 01:38 PM
  #98  
Hobart187
Registered User
iTrader: (4)
 
Hobart187's Avatar
 
Join Date: Sep 2009
Location: Fort Walton Beach
Posts: 40
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 3hree5ive0ero
I use AVG too, but nothing happened to me.

I'm using FF with ABP, though.
I dont know either. I got literally 5 different popups from spybot saying so and so wants to change your registry startup. If it isnt directly related to a program i have installed i always deny. However, i was on the site earlier that same day and nothing happened. So im not sure. Might be a different browser, i use google chrome because it lightweight. I run a lot of programs at once. I really dont know why some are getting it and others not.
Hobart187 is offline  
Old 08-30-2010, 09:20 PM
  #99  
tware
Registered User
iTrader: (12)
 
tware's Avatar
 
Join Date: Jun 2003
Location: Little Rock
Posts: 2,332
Likes: 0
Received 0 Likes on 0 Posts
Default

and.... a month later........
tware is offline  
Old 08-31-2010, 05:13 AM
  #100  
Robb M.
IB Staff
 
Robb M.'s Avatar
 
Join Date: Feb 2010
Location: Barrie, ON
Posts: 450
Received 18 Likes on 15 Posts
Default

Originally Posted by tware
and.... a month later........
What? we're clean, no?
Robb M. is offline  

Thread Tools
Search this Thread
Quick Reply: Members whose system was infected by the recent virus outbreak ONLY



All times are GMT -8. The time now is 10:27 AM.