• I want to thank all the members that have upgraded your accounts. I truly appreciate your support of the site monetarily. Supporting the site keeps this site up and running as a lot of work daily goes on behind the scenes. Click to Support Signs101 ...

Fred: VIRUS ALERT

RobbyMac

New Member
I got two last night also. detected by avg, something about a blackhole worm thingy. Main page, and again when I hit NEW POSTS. but later came back and didnt get any alerts
 

Fred Weiss

Merchant Member
Thanks for the report. I got it once last night but not again. Checked around some and found nothing so I assumed it had come from some other site. I'll check more thoroughly now.
 

phototec

New Member
Yep, I notified Fred late last night, my Norton kept giving me a notice that it has detected and stopped an intrusion attempt, while I was on Signs101.

See attachment:

Hope Fred can fix the issue?

:omg:
 

Attachments

  • Intrusion attempt 11-12-11 logging onto Signs101.jpg
    Intrusion attempt 11-12-11 logging onto Signs101.jpg
    80.5 KB · Views: 81

qmr55

New Member
No problem here at all....

But I also do have all ad's blocked from loading on the page....
 

Fred Weiss

Merchant Member
It is evidently what is called a Black Hole Exploit that is passed around and sold to various miscreants as a "Malicious Toolkit Website". It comes out of Russia and redirects browsers to phishing sites and the like. I have seen it once in this go around and it was picked up by the Link Scanner feature of AVG anti virus software.

So far I have put in a ticket with our server management contractor; researched what there is to know about it; browsed all files and folders with recent dates that may be suspicious; run searches for certain words both in the forum and in our databases; and I am now going through all threads with posts in them today.

As far as I can guesstimate, it must be coming from a link in a post or an image ... just haven't found it yet. It appears to have started around 2 AM to 2:45 AM this morning. I have found no indication yet that we were hacked, in the traditional sense, with an intruder finding a backdoor into our server and changing files. There are numerous reports of similar happenings to other sites from the virus software companies and through Google.

So, if you don't have a recently updated virus package, I'd recommend that you go away and check back through our Facebook page until we announce that a solution has been found.

Anyone with up to date technical knowledge that might be of help here is invited to contact me by email, PM or in this thread.
 

phototec

New Member
As far as I can guesstimate, it must be coming from a link in a post or an image ... just haven't found it yet. It appears to have started around 2 AM to 2:45 AM this morning.

Yep, late last night (2:45am CT) is when my Norton 360 blocked it, just as I was going to the next page, it happened several times.

It was trying to access my computer everytime I would go to another page or open a different thread.

However, today (NOW), it is NOT happening anymore?

:thumb:
 
J

john1

Guest
Got it as well, I am using the free avg anti-virus. Nothing came up today though, i did get 2 pop ups last night about it though.
 

RobbyMac

New Member
Got the avg pop up on ie
c:documents and settings\...\temp\WPBT0.DLL
Win32/Kryptik.VHJ
Severity level: 4 red bars (This is bad... no?)
Category: Trojan
Description: This is a known Trojan/Backdoor. It is recommended that you quarantine this threat.

After Quarantine:
2 processes terminated:
regsvr32.exe
WPBT0.DLL

After quarantine screencap shown as vir.jpg


then closed ie, went to post here on firefox, and got another pop up
screen cap vir2.jpg
 

Attachments

  • vir.jpg
    vir.jpg
    98.6 KB · Views: 92
  • vir2.jpg
    vir2.jpg
    59.5 KB · Views: 73

phototec

New Member
Fred,

It is still roaming Signs101, just selected the "Merchant Directory", and Norton blocked an intrusion attempt.

Malicious Toolkit Website 9

November 12, 2011 11:00 pm CT

See attachment lower right corner.

:omg:
 

Attachments

  • 11-12-11 11-00 pm.jpg
    11-12-11 11-00 pm.jpg
    65.3 KB · Views: 73
Top