Forum Home Forum Home > Site News, Newbies, Help and Improvements > Help us improve the site
  New Posts New Posts RSS Feed - Malware Pop-upsite
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Topic ClosedMalware Pop-upsite

 Post Reply Post Reply Page  <12345>
Author
Message
ZowieZiggy View Drop Down
Prog Reviewer
Prog Reviewer


Joined: April 19 2005
Location: Siem Reap
Status: Offline
Points: 311
Direct Link To This Post Posted: December 06 2007 at 10:51
I confirm this problem as well. It started some 10 days ago or so. When I get it, I close the PA window immediately. Usually, after I restart, I don't get straight away. But when I relaunch PA later on (or if I want to get several PA sections at the same time) it reappears regularly.
 
I have this at home, but as well at the office where we have firewall, virus detectors etc.
 
Please address this problem accordingly. It is a real P.I.T.A.
 
Regards,
 
 
 
Daniel.
ZowieZiggy
Back to Top
Easy Livin View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator / Retired Admin

Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
Direct Link To This Post Posted: December 06 2007 at 10:53
Is it a specific page perhaps, or a signature?
Back to Top
M@X View Drop Down
Forum & Site Admin Group
Forum & Site Admin Group
Avatar
Co-founder, Admin & Webmaster

Joined: January 29 2004
Location: Canada
Status: Offline
Points: 4028
Direct Link To This Post Posted: December 06 2007 at 10:57
is it in the forum or the site? 
Prog On !
Back to Top
Dean View Drop Down
Special Collaborator
Special Collaborator
Avatar
Retired Admin and Amateur Layabout

Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
Direct Link To This Post Posted: December 06 2007 at 11:00
No, it appears to be random - I've seen it in the Grey Room, Song Word Game and various other threads and on those specific pages I  don't recall seeing the same forum members, so dont' think it's sig-related. Also if you reload that page the malware doesn't reappear. This is one of the reasons why I'm having problems tracking it down - I cannot at the moment see where or how it attaches to the forum code.
What?
Back to Top
Easy Livin View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator / Retired Admin

Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
Direct Link To This Post Posted: December 06 2007 at 11:06

Seems to be both M@x, but not on every visit.

Back to Top
Dean View Drop Down
Special Collaborator
Special Collaborator
Avatar
Retired Admin and Amateur Layabout

Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
Direct Link To This Post Posted: December 06 2007 at 11:10
Originally posted by M@X M@X wrote:

is it in the forum or the site? 
good question Confused
 
I cannot remember if I've seen it on Site pages, but obviously I visit forum pages more - I also tend to visit the site from the forum first, and then move on to the Archive.
 
Also, the comment ZowieZiggy made about it re-appearing if you revisit the site after a break. I did find a cookie attached to the malware-URL which may explain that. I deleted it, so cannot pass you a copy.
What?
Back to Top
darkmatter View Drop Down
Forum Senior Member
Forum Senior Member
Avatar

Joined: November 23 2006
Location: New Jersey
Status: Offline
Points: 2760
Direct Link To This Post Posted: December 06 2007 at 11:18
I don't know about anyone else, but I've only seen this thing on the main page, never anywhere else on the website.  

Edited by darkmatter - December 06 2007 at 11:19
Back to Top
rushfan4 View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: May 22 2007
Location: Michigan, U.S.
Status: Offline
Points: 66007
Direct Link To This Post Posted: December 06 2007 at 11:39
It usually pops up for me when I first come to the website, but I believe there has been a time or two when I get into the main site but when I click on the tab to go to the forum the Malware has popped up.  It doesn't happen every visit but it has happened often.
Back to Top
King of Loss View Drop Down
Prog Reviewer
Prog Reviewer
Avatar

Joined: April 21 2005
Location: Boston, MA
Status: Offline
Points: 16329
Direct Link To This Post Posted: December 06 2007 at 13:39
I just had to click back right before Newbieguide struck my PC! 
Back to Top
bhikkhu View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: April 06 2006
Location: A² Michigan
Status: Offline
Points: 5109
Direct Link To This Post Posted: December 06 2007 at 14:19
Originally posted by darkmatter darkmatter wrote:


I don't know about anyone else, but I've only seen this thing on the main page, never anywhere else on the website.  


I got it clicking directly to a band page.
Back to Top
siseneg View Drop Down
Forum Newbie
Forum Newbie


Joined: November 06 2007
Location: United Kingdom
Status: Offline
Points: 2
Direct Link To This Post Posted: December 06 2007 at 17:02
This is almost the first time I've loked at the forums (being a new member) and it's been happening to me for some time.  It usually happens when I'm in the Archive and I do the first search.  I then close IE down using task manager and it doesn't happen again when I start over.
 
Has anyone anything more on it possibly changing the DNS address.  I tried to check that but my ISP states they use a dynamic DNS (whatever that means)
Back to Top
BardsGarden View Drop Down
Forum Groupie
Forum Groupie
Avatar

Joined: November 12 2006
Location: United States
Status: Offline
Points: 53
Direct Link To This Post Posted: December 06 2007 at 22:40
    If you can get into your router, compare the dns settings on the router to the dns settings on your computer. (if your provider is using dynamic dns you can still do the comparison, just know that the numbers can change whenever the router is rebooted) If the dns on the computer and router are not the same it may have been compromised, but don't freak yet since there are other reasons for the dns to be different. Just write down the odd addresses so you can check them out later, then manually change your dns address back to what it should be in your network settings.
Back to Top
BardsGarden View Drop Down
Forum Groupie
Forum Groupie
Avatar

Joined: November 12 2006
Location: United States
Status: Offline
Points: 53
Direct Link To This Post Posted: December 06 2007 at 23:19
Here are some links explaining what happens and some suggestions to stop it. One or more ads on the site intermittently spawns other ads. This is extra tricky since it spawns automatically as the page is loading where normally you have to click on a specific ad to start the spawning.

http://forum.avira.com/thread.php?threadid=29080&sid=6ca64f9058d473eb43593b0f2a1d3ec4

http://sunbeltblog.blogspot.com/2007/11/breaking-massive-amounts-of-malware.html

http://explabs.blogspot.com/
Back to Top
VanderGraafKommandöh View Drop Down
Prog Reviewer
Prog Reviewer
Avatar

Joined: July 04 2005
Location: Malaria
Status: Offline
Points: 89372
Direct Link To This Post Posted: December 07 2007 at 13:52
A P.S. from prog-chick:

I now can not log onto PA AT ALL becuase of the blinking thing, it's a really nasty bug.......... and driving me mad!

Me again:

Let's hope this gets sorted out soon.


Edited by Geck0 - December 07 2007 at 13:52
Back to Top
Nightfly View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: August 01 2007
Location: United Kingdom
Status: Offline
Points: 3659
Direct Link To This Post Posted: December 08 2007 at 07:07
Originally posted by M@X M@X wrote:

is it in the forum or the site? 
 
I always come to the site via the homepage and that's when I get it, before I even click on the Forum link. Not sure if this is relevant but I only get it when I switch my PC on and visit the site for the first time that day. If I leave and come back later before switching off my PC it's not coming up again.
 
Although I'm no expert on these things I get the impression this is more of a nusiance thing than anything that's going to cause serious damage to anyone's PC. My Norton Anti-virus picks it up imediately and get's rid of it but on my other PC that has AVG anti-virus it doesn't recognise it as a virus and doesn't pick it up at all.
Back to Top
Dean View Drop Down
Special Collaborator
Special Collaborator
Avatar
Retired Admin and Amateur Layabout

Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
Direct Link To This Post Posted: December 08 2007 at 07:52
Originally posted by Nightfly Nightfly wrote:

Originally posted by M@X M@X wrote:

is it in the forum or the site? 
 
I always come to the site via the homepage and that's when I get it, before I even click on the Forum link. Not sure if this is relevant but I only get it when I switch my PC on and visit the site for the first time that day. If I leave and come back later before switching off my PC it's not coming up again.
 
Although I'm no expert on these things I get the impression this is more of a nusiance thing than anything that's going to cause serious damage to anyone's PC. My Norton Anti-virus picks it up imediately and get's rid of it but on my other PC that has AVG anti-virus it doesn't recognise it as a virus and doesn't pick it up at all.
 
A Cautionary Tale:
 
I run AVG and have been attempting to back-track this Malware as it is a challenge that is bugging me, and to help rid the site of it. It is something I do 'professionally' since understanding how these things attach helps me solve them quicker in the future. Unfortunately I (and AVG) failed big-time - something corrupted some of my system files and I could not recover them. I have had to rebuild my operating system from scratch. Nothing critical lost as I regularily back-up important stuff, but it is a pain in the butt as I now have to re-install every item of software I use and then recover the back-up data - all these things take time I'd rather spend on other things.
 
If you close the Explorer window immediatley the Malware appears you will be okay, but if you are a wise fool like me and try and delve deeper into how it attaches then there is a serious risk involved. I take all precautions possible when doing this and I still got caught, so be careful out there Geek
What?
Back to Top
Nightfly View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator

Joined: August 01 2007
Location: United Kingdom
Status: Offline
Points: 3659
Direct Link To This Post Posted: December 08 2007 at 08:39
Originally posted by darqdean darqdean wrote:

Originally posted by Nightfly Nightfly wrote:

Originally posted by M@X M@X wrote:

is it in the forum or the site? 
 
I always come to the site via the homepage and that's when I get it, before I even click on the Forum link. Not sure if this is relevant but I only get it when I switch my PC on and visit the site for the first time that day. If I leave and come back later before switching off my PC it's not coming up again.
 
Although I'm no expert on these things I get the impression this is more of a nusiance thing than anything that's going to cause serious damage to anyone's PC. My Norton Anti-virus picks it up imediately and get's rid of it but on my other PC that has AVG anti-virus it doesn't recognise it as a virus and doesn't pick it up at all.
 
A Cautionary Tale:
 
I run AVG and have been attempting to back-track this Malware as it is a challenge that is bugging me, and to help rid the site of it. It is something I do 'professionally' since understanding how these things attach helps me solve them quicker in the future. Unfortunately I (and AVG) failed big-time - something corrupted some of my system files and I could not recover them. I have had to rebuild my operating system from scratch. Nothing critical lost as I regularily back-up important stuff, but it is a pain in the butt as I now have to re-install every item of software I use and then recover the back-up data - all these things take time I'd rather spend on other things.
 
If you close the Explorer window immediatley the Malware appears you will be okay, but if you are a wise fool like me and try and delve deeper into how it attaches then there is a serious risk involved. I take all precautions possible when doing this and I still got caught, so be careful out there Geek
 
Thanks for the warning. Nothing seems to be amiss on my PC using AVG at the moment and I haven't opened the malware programme there but just to be on the safe side I think I'll stick to using my Laptop with Norton Anti-Virus when I visit here for now.
 
Can you explain why Norton picks it up as a Virus whilst AVG does not? Is it because AVG is inferior in some way though I have heard good reports about them.


Edited by Nightfly - December 08 2007 at 08:42
Back to Top
Easy Livin View Drop Down
Special Collaborator
Special Collaborator
Avatar
Honorary Collaborator / Retired Admin

Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
Direct Link To This Post Posted: December 08 2007 at 10:23
Thnaks for the continuing info, M@x is working hard on tracking the thing down. All the info will be of great help to him. He may contact some of you at some stage to test a few things (safely of course!).
Back to Top
VanderGraafKommandöh View Drop Down
Prog Reviewer
Prog Reviewer
Avatar

Joined: July 04 2005
Location: Malaria
Status: Offline
Points: 89372
Direct Link To This Post Posted: December 08 2007 at 16:41
Other people have been experiencing problems with what maybe the same malware...

http://www.dslreports.com/forum/r19544107-Re-Really-annoying-site-via-ads-but-is-it-dangerous


Does anyone have an Hijack this scans, perchance?
Back to Top
M@X View Drop Down
Forum & Site Admin Group
Forum & Site Admin Group
Avatar
Co-founder, Admin & Webmaster

Joined: January 29 2004
Location: Canada
Status: Offline
Points: 4028
Direct Link To This Post Posted: December 08 2007 at 17:02
Guys,

Good news; I think I found the ads in the 3rd party ads network that was causing it , I will need confrimation that no one experience it.

Bad news, I can't remove the banner ads because the website wont' survive, the high cost of web hosting.

This Ads Network show ads that I don't control. I would like to remove them but I need a new revenue source to help the site.

Some ads : Google AdSense, Amazon, Ebay , are under my control and I assure you that they don't

How about we become a Social-financing website based on a members / visitors DONATION. Once we reach a certain amount we remove the third party ad-server  ?

I will need help to build that ...

Let me know.

Other solutions are welcome


M@X Geek
Prog On !
Back to Top
 Post Reply Post Reply Page  <12345>

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.113 seconds.
Donate monthly and keep PA fast-loading and ad-free forever.