Notices
Feedback & Suggestions for Our Forum This is NOT a place to ask car/modification questions!
For posting feedback, suggestions or comments regarding our My350Z.com forum.

Members whose system was infected by the recent virus outbreak ONLY

Old Aug 5, 2010 | 12:54 PM
  #81  
DavesZ#3's Avatar
DavesZ#3
350Z-holic
Premier Member
20 Year Member
iTrader: (26)
 
Joined: Jul 2003
Posts: 15,887
Likes: 23
From: Louisiana
Default

Originally Posted by koren
It is the club for women-drivers in Russia. Why do you asking???
Some of us are seeing references to http://autodiva.ru when browsing the forum. If you look in your temporary internet files folder, you'll probably see a file named 1.html (http://autodiva.ru/1.html).

That HTML file contains this script...

<!--LiveInternet counter--><script type="text/javascript"><!--
document.write("<a href='http://www.liveinternet.ru/click' "+
"target=_blank><img src='//counter.yadro.ru/hit?t14.2;r"+
escape(document.referrer)+((typeof(screen)=="undefined")?"":
";s"+screen.width+"*"+screen.height+"*"+(screen.colorDep th?
screen.colorDepth:screen.pixelDepth))+";u"+escape(document.U RL)+
";"+Math.random()+
"' alt='' title='LiveInternet: показано число просмотров за 24"+
" часа, посетителей за 24 часа и за сегодня' "+
"border='0' width='88' height='31'><\/a>")
//--></script><!--/LiveInternet-->

<script type="text/javascript">

var _gaq = _gaq || [];
_gaq.push(['_setAccount', 'UA-17571440-1']);
_gaq.push(['_trackPageview']);

(function() {
var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
})();
Maybe somebody a lot smarter than me can figure out what that is doing. I looks like it's generating hits on their website.
Old Aug 5, 2010 | 02:42 PM
  #82  
jonnylaw's Avatar
jonnylaw
Registered User
iTrader: (3)
 
Joined: May 2006
Posts: 1,957
Likes: 2
From: Meifumado
Default

^^yep, I'm no tech, but there are references to java and I think this might be one of the causes for the trojan/virus warnings. Also google analytics..When browsing the forum, the bottom left corner will often direct to autodiva.ru and google-analytics.This script is embedded in the website?
Old Aug 5, 2010 | 03:24 PM
  #83  
DavesZ#3's Avatar
DavesZ#3
350Z-holic
Premier Member
20 Year Member
iTrader: (26)
 
Joined: Jul 2003
Posts: 15,887
Likes: 23
From: Louisiana
Default

Probably not the website, likely something feeding the ads.

If you use IE, you can add autodiva.ru to the Restricted Sites and that will stop it from running the script. There may be an equivalent function in other browsers.
Old Aug 5, 2010 | 04:33 PM
  #84  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

is that what we are reduced to? instead of IB fixing this after weeks, we're just going to tip toe thru the mine field this place is becoming? With all due respect, as I maintain production servers myself and fully understand the challenge here, this deserved their FULL attention the minute reports came in. To leave this situation as it is for weeks now is irresponsible at best. Do they really not care at all about us? While nobody should ever fully trust any web content, it's really not fair to members who do trust this site and expect ads served thru it to be legit. I think surfing **** is safer than checking my PMs now.
Old Aug 5, 2010 | 04:53 PM
  #85  
DavesZ#3's Avatar
DavesZ#3
350Z-holic
Premier Member
20 Year Member
iTrader: (26)
 
Joined: Jul 2003
Posts: 15,887
Likes: 23
From: Louisiana
Default

IB has been working this issue for the last couple of weeks. I know because I have been hounding them daily.
Old Aug 5, 2010 | 06:31 PM
  #86  
jonnylaw's Avatar
jonnylaw
Registered User
iTrader: (3)
 
Joined: May 2006
Posts: 1,957
Likes: 2
From: Meifumado
Default

hmm. what about counter.yabro.ru that is coming up now as well?

Last edited by jonnylaw; Aug 5, 2010 at 06:33 PM.
Old Aug 6, 2010 | 03:32 AM
  #87  
DavesZ#3's Avatar
DavesZ#3
350Z-holic
Premier Member
20 Year Member
iTrader: (26)
 
Joined: Jul 2003
Posts: 15,887
Likes: 23
From: Louisiana
Default

It's being called from that autodiva.ru script shown above.
Old Aug 6, 2010 | 08:53 AM
  #88  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

Are you guys still seeing these issues today? We had a bunch of things kind of blow up in the server centre overnight. Hoping that all issues are now resolved...
Old Aug 6, 2010 | 03:23 PM
  #89  
Black Z Eddie's Avatar
Black Z Eddie
New Member
 
Joined: Jun 2007
Posts: 947
Likes: 9
From: San Pedro
Default

Yes.
Old Aug 8, 2010 | 03:24 AM
  #90  
amr_electron's Avatar
amr_electron
Registered User
iTrader: (8)
 
Joined: Nov 2009
Posts: 337
Likes: 14
From: On Earth
Default

Received this today,



More Info,



Hope it's useful.
Old Aug 8, 2010 | 04:00 AM
  #91  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

argh!!!!

Our continued apologies, as I thought that we had finally cleared this up on Friday. Apparently we were wrong
Old Aug 8, 2010 | 09:50 AM
  #92  
koren's Avatar
koren
New Member
iTrader: (23)
 
Joined: Jul 2008
Posts: 403
Likes: 3
From: MIami, FL
Default

What's funny is that none of the other Anti-virus catching that, only Kaspersky...
That's right, only Russians can stop Russians))))))))
Old Aug 8, 2010 | 11:46 AM
  #93  
03threefiftyz's Avatar
03threefiftyz
350Z-holic
Premier Member
iTrader: (25)
 
Joined: Aug 2007
Posts: 9,848
Likes: 118
From: Frederick, MD
Default

Originally Posted by koren
What's funny is that none of the other Anti-virus catching that, only Kaspersky...
That's right, only Russians can stop Russians))))))))
False....I was getting warnings with Norton and Spyware Doctor.
Old Aug 8, 2010 | 01:21 PM
  #94  
Hobart187's Avatar
Hobart187
Registered User
iTrader: (4)
 
Joined: Sep 2009
Posts: 40
Likes: 0
From: Fort Walton Beach
Default

I run avg and it caught it, and spybot warned me like 5 times of something trying to change my registry. Just clicked deny and moved it to the vault. Problem solved.
Old Aug 8, 2010 | 09:48 PM
  #95  
3hree5ive0ero's Avatar
3hree5ive0ero
Thread Starter
Retired Admin
iTrader: (95)
 
Joined: Dec 2000
Posts: 1,337,017,813
Likes: 78
From: Dallas / Chicago
Default

Originally Posted by Hobart187
I run avg and it caught it, and spybot warned me like 5 times of something trying to change my registry. Just clicked deny and moved it to the vault. Problem solved.
I use AVG too, but nothing happened to me.

I'm using FF with ABP, though.
Old Aug 9, 2010 | 06:44 AM
  #96  
JCat's Avatar
JCat
---------------
Premier Member
20 Year Member
Liked
Loved
Community Favorite
iTrader: (4)
 
Joined: Mar 2004
Posts: 3,996
Likes: 76
From: JC in Atlanta Georgia
Default

What the hell is this ?

Does not look good http://safeweb.norton.com/report/sho...lebotsen.co.cc
Attached Thumbnails Members whose system was infected by the recent virus outbreak ONLY-350z.jpg  

Last edited by JCat; Aug 9, 2010 at 06:46 AM.
Old Aug 9, 2010 | 07:39 AM
  #97  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

Yep, there's a new one. We're working to remove now.
Old Aug 9, 2010 | 01:38 PM
  #98  
Hobart187's Avatar
Hobart187
Registered User
iTrader: (4)
 
Joined: Sep 2009
Posts: 40
Likes: 0
From: Fort Walton Beach
Default

Originally Posted by 3hree5ive0ero
I use AVG too, but nothing happened to me.

I'm using FF with ABP, though.
I dont know either. I got literally 5 different popups from spybot saying so and so wants to change your registry startup. If it isnt directly related to a program i have installed i always deny. However, i was on the site earlier that same day and nothing happened. So im not sure. Might be a different browser, i use google chrome because it lightweight. I run a lot of programs at once. I really dont know why some are getting it and others not.
Old Aug 30, 2010 | 09:20 PM
  #99  
tware's Avatar
tware
Registered User
iTrader: (12)
 
Joined: Jun 2003
Posts: 2,332
Likes: 0
From: Little Rock
Default

and.... a month later........
Old Aug 31, 2010 | 05:13 AM
  #100  
Robb M.'s Avatar
Robb M.
IB Staff
15 Year Member
 
Joined: Feb 2010
Posts: 454
Likes: 19
From: Barrie, ON
Default

Originally Posted by tware
and.... a month later........
What? we're clean, no?

Thread Tools
Search this Thread

All times are GMT -8. The time now is 03:36 AM.