getting a virus warning as I log in to BF.

Status
Not open for further replies.
The scan at Anubis is VERY thorough.
Takes about 12 minutes, and I suspect it scans the entire bladeforums site.

this mutex:
Mutex: [ _SHuassist.mtx ]
was definitely found.
 
Getting the following message on Camino 2.1 on Mac OS X 10.6.8.

Reported Malware Site













This web site at www.bladeforums.com has been reported as a malware site and has been blocked for your protection.










Malware sites try to install programs that steal private information, use your computer to attack others, or damage your system.

Some malware sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.

Your computer can be infected just by proceeding to this site, without any further action on your part.



For more information about why this site was blocked, see Camino’s Safe Browsing Documentation.

When I try to report this malware blockage as an error, I get the following:

Safe Browsing
Diagnostic page for bladeforums.com

What is the current listing status for bladeforums.com?

Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 8 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 156 pages we tested on the site over the past 90 days, 14 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2011-12-18, and the last time suspicious content was found on this site was on 2011-12-18.

Malicious software includes 21 trojan(s), 12 exploit(s), 7 scripting exploit(s). Successful infection resulted in an average of 7 new process(es) on the target machine.

Malicious software is hosted on 2 domain(s), including ggghhhhhhhh.c0m.li/, gsdgsdgsdssssssss.c0m.li/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including openx.net/.

This site was hosted on 1 network(s) including AS19235 (HOSTING).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, bladeforums.com did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

How did this happen?

In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.
 
I couldn't post the entire report (too long).
But it's a rogue (fake) antivirus.
It changes the proxy settings in Internet explorer and redirects, etc.
A real pain.
Usually doesn't cause problems until after the next re-boot.
If the admin scans his site he can determine if any exploits are present.
Anubis doesn't rely on virus signatures. It runs executables (or visits sites) and notes the behaviour in real time.
 
I ran the anubis report and it's not reporting anything infected. The response you are getting seems to be coming from the yui interface for the quick reply bar - the presence of a mutex doesn't neccessarily ggggmean that it's infected, right?

What worries me about the report is that it seems to be changing proxies.
 
I just checked with IE8 , no warnings , no infection, no banners .

Firefox have had a hard time connecting to the site , had to shut it down manually & retry twice today,
also had a couple of Firefox crashes yesterday when trying to connect.

1234,,,,,,,,
 
Patrice Lemée;10298319 said:
I still get the warning with Firefox. When I click on "ignore this" and "This is not an attack site" a webpage opens up, http://www.stopbadware.org.

I'm getting the same warning from Google search.

Wondering if someone was recently banned or had issues with BF reported the site as having malware?

Just a thought, I'm sure it'll be fixed soon (hopefully).
 
I just got my first warning.It was a maleware alert.I proceeded anyway since I read you had it under control.

I'm using Google Chrome & Windows 7.
 
I am platinum and when I tried to log in this morning I got the warning maleware alertas well. Ran full scans both on AVG and Maleware and no infections!!! So I'm not sure what's going on here but I stayed off all day, logged in tonight and now I didn't get a warning. :confused:
 
Running Firefox here with Microsoft Security Essentials and Zone Alarm.

Here is the initial warning happening right now:

Reported Attack Page!
This web page at www.bladeforums.com has been reported as an attack page and has been blocked based on your security preferences.
Attack pages try to install programs that steal private information, use your computer to attack others, or damage your system.Some attack pages intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.

"Why was this site blocked" gives more information:

What happened when Google visited this site?

Of the 156 pages we tested on the site over the past 90 days, 14 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2011-12-18, and the last time suspicious content was found on this site was on 2011-12-18.

Malicious software includes 21 trojan(s), 12 exploit(s), 7 scripting exploit(s). Successful infection resulted in an average of 7 new process(es) on the target machine.

Malicious software is hosted on 2 domain(s), including ggghhhhhhhh.c0m.li/, gsdgsdgsdssssssss.c0m.li/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including openx.net/.

This site was hosted on 1 network(s) including AS19235 (HOSTING).
 
Good Lord!!! Do you actually know what that means?

Anyway, if it helps, I only use IE 8 and run plain ole Norton Anti-Virus with Antispyware and have had no problems. Been on and off the site all day.

Don't know if this info helps but every Sunday night at 10:30PM I clear my cache and at 11:00PM I run a full system scan. When I was done tonight, I brought up Blade Forums, logged in, and here I am -- no problems. Norton showed no problems when I ran the scan.
 
same here using safari without antivirus of any sort. i get the message every time i refresh or click on any thread ... quite annoying.

i havent read the whole thread (you gess i have this alert each page) but is there a way to stop this from my side ?
 
Well, Bottom line is it's ether a vBulletin setting [That I doubt] or the forum has been hacked and someones waiting to launch a real virus .
Like I said [lied] the first time .. I'm not coming back till something gets detected and fixed !
Good luck !

309iur4.jpg
 
for firefox users go to Tool/options/security and uncheck the box that says block reported attack sites

that will get you back to normal untill the site owner straitens out things with google
in a couple of days go back and recheck the box.
 
same here using safari without antivirus of any sort. i get the message every time i refresh or click on any thread ... quite annoying.

i havent read the whole thread (you gess i have this alert each page) but is there a way to stop this from my side ?

Safari > Preferences > Security > Un-check the "Warn when visiting a fraudulent website" box.
 
Spark
I ran the anubis report and it's not reporting anything infected. The response you are getting seems to be coming from the yui interface for the quick reply bar - the presence of a mutex doesn't neccessarily ggggmean that it's infected, right?
What worries me about the report is that it seems to be changing proxies.

..

Here's the latest - 4:30 this morning


http://anubis.iseclab.org/?action=result&task_id=10b2ef976db7c6b2431ac21427a3a55b9&format=txt

Dec 19 4:32 am (central)

Summary:
- Changes security settings of Internet Explorer:
This system alteration could seriously affect safety surfing the World
Wide Web.

- Performs File Modification and Destruction:
The executable modifiesand destructs files which are not temporary.

- Performs Registry Activities:
The executable creates and/or modifies registry entries.
....

Not sure what you mean by "The response you are getting seems to be coming from the yui interface for the quick reply bar"
The report indicates that anubis detects the mutex within the code/scripts found at BF or a banner ad, etc.
It has nothing to do with anyones machine but the one used by Anubis when it scans Bladeforums.

Spark:
the presence of a mutex doesn't neccessarily mean that it's infected, right?


It means that Anubis is finding a script that will infect unprotected browsers. It changes security settings in Internet explorer (among other things).
The "drive-by" infections (usually banner ads) run a script, and will add a proxy to the security settings in IE.
Usually, once you re-boot all internet activity will be through the proxy set up by the individual that coded the ad. Most antivirus pages (Norton, AVG, etc) will be blocked. The real payload will begin downloading. Task manager, Cntrl/alt/delete, will be disabled, usually any searches will be re-directed, and the fake antivirus warnings will continually appear -falsely warning of infected files and prompting for payment.
If you do follow the links in the pop-ups and pay them, they then ding your card 4-5 times.

Anubis is finding this script NOW. As of 4:32 this morning.
As these 0day exploits are found, they're entered into the database of Google,Malwarebytes, Norton, etc and warnings will begin blocking BF in Internet explorer, firefox, etc.

Turning the warnings off (while the exploit is still found by Anubis) is not a good idea.

Here's an example of what's being done:

http://www.bleepingcomputer.com/forums/topic212841.html

here's a list of current 0day threats:

http://www.bleepingcomputer.com/forums/forum55.html

You can expect to continue getting warning from the various cloud based warning services - even after BF is no longer a danger.
But Anubis found an exploit at 4:32am. This is NOT residual. According to Anubis the code is currently present.
 
This help?:


4. Check in Google Webmastertools to know malware infection

Google webmaster tools shows the details about the infection in your website. If your website is infected, right after login to Google webmaster account itself you can see the following alert.

Where to check your website is infected

You can find which pages are infected in your website by clicking More Details link. You can take this information to remove infection from your website. It is recommended to check Google webmastertools every time to check any possible malware infection in your website.

http://www.corenetworkz.com/2010/09/how-to-check-virus-infection-in-my.html
 
Status
Not open for further replies.
Back
Top