SUBSIM Radio Room Forums

SUBSIM Radio Room Forums (https://www.subsim.com/radioroom/index.php)
-   Comments to SUBSIM Review (https://www.subsim.com/radioroom/forumdisplay.php?f=172)
-   -   FAO NEAL: Reported Attack Site? Anyone else getting this too? (https://www.subsim.com/radioroom/showthread.php?t=176196)

ajrimmer42 10-27-10 11:31 AM

Quote:

Originally Posted by Seeadler (Post 1522708)
did you clear your browser cache?

:shifty:

tis fine now :yeah:

Reece 10-27-10 08:37 PM

Excellent, I think it is about time for Neal to make a statement/comment on the situation.:yep:

reignofdeath 10-27-10 09:58 PM

I didnt have firefox problems but i did get "Malware infested site" reports while using safari for about a week? I used IE and nothing bad came up and it loaded properly and everything.

SeaWolf U-57 10-28-10 04:58 PM

Well Well take a look at this

http://www.siliconindia.com/shownews...275-cid-2.html :hmmm:

Reece 10-28-10 06:28 PM

WOW!!:o I must upgrade my FF to 3.6.12 today, also Avira and Ad-Aware definitions, I wonder where the svchost.exe would be stored if created!.:hmmm:

Herr-Berbunch 10-28-10 06:52 PM

Quote:

Originally Posted by Reece (Post 1524075)
WOW!!:o I must upgrade my FF to 3.6.12 today, also Avira and Ad-Aware definitions, I wonder where the svchost.exe would be stored if created!.:hmmm:

along with every other svchost.exe I'm guessing - it's always been a favourite as it's nearly always running multiple occurrances! :nope:

I've just checked my pc for this file and I have six in the prefetch folder (C:\Windows\Prefetch) (which are supposed to be there, but are ok to delete - they'll just come back when needed), and a few others that were installed in July when the OS was put on.

If there were any from the last month not in the Prefetch folder,and you've not reinstalled your OS recently I'd delete and scan, or scan and delete. :yep:

Gerald 10-28-10 06:57 PM

Thanks for the link,
 
Quote:

Originally Posted by SeaWolf U-57 (Post 1524026)
Well Well take a look at this

http://www.siliconindia.com/shownews...275-cid-2.html :hmmm:

:up:

Reece 10-28-10 07:19 PM

Quote:

Originally Posted by Herr-Berbunch (Post 1524091)
along with every other svchost.exe I'm guessing - it's always been a favourite as it's nearly always running multiple occurrances! :nope:

I've just checked my pc for this file and I have six in the prefetch folder (C:\Windows\Prefetch) (which are supposed to be there, but are ok to delete - they'll just come back when needed), and a few others that were installed in July when the OS was put on.

If there were any from the last month not in the Prefetch folder,and you've not reinstalled your OS recently I'd delete and scan, or scan and delete. :yep:

I don't have any in the C:\Windows\Prefetch folder, only a load of .pf files that don't contain the word "svchost", the only svchost.exe is located in the C:\Windows\System32 folder.:yep:

Onkel Neal 10-28-10 08:08 PM

Rack911 reported back that the server had been rooted,:cry: and they cleaned it up. They have been monitoring it the last few days and I wanted to wait before posting the news. Steven says he has updated the server, and hardened it. All good stuff, I am sure.

When this first broke out, I suspected a problem with the Google ads. I had heard about this before on other websites such as this one. But even though I suspected the google ads, I knew that I did not know with certainty what the problem was, so I contacted Scott at AdminGeeks. He had done some work for me before and did it well, in a timely fashion. Not this time. When AdminGeeks reported no issues (after 4 days delay), I thought it could be false positives on some AVs, especially since many people did not get AV alerts. I never got an AV warning from Norton, not at home, college or the hotel. Turns out it was not a false positive.

When the problem persisted, I contacted Planet Advance Services to find this problem. They ran a clamscan and let it go at that. That was not what I asked them to do, I specifically directed them to find the problem, at any cost, and they showed no initiative in helping. When a long time customer (7 years) reports the number of users getting alerts on their server, they should be much more proactive .It should be their problem too. I made it clear to them I wanted to know if they could handle this, and if not, let me know who could. Their responses were very sketchy. I'm talking with their management about this now.

I apologize to everyone that this happened. I sincerely apologize. When I get messages from multiple members about something like this, I have to turn it over to an IT expert. It's a shame that you cannot depend on professionals to follow through.

Neal

Zachstar 10-28-10 09:41 PM

I never got an alert from my virus scan and I do not see any strange processes working. However because I was here before google locked the site and had the issue of not being able to post. I will have to keep an eye on things.

I hope the butthole that did this gets arrested and charged.

SeaWolf U-57 10-29-10 04:22 AM

If you received the notification to up-date your Java script
and if you clicked yes then you would be at danger of hosting
the exploit code somewhere on your computer.
if not you should be ok and clear of any problem the messages
received through your browser were never a problem just
a bit of a nuisance to some who didn’t really believe there
was a problem in the first place.
check out my post above
thank you Neal for the update I’m glad it’s all sorted now :up:

Dowly 10-29-10 05:34 AM

Thanks for the update Neal and no apology needed, these things happen and it's quite a remarkable that big site like Subsim has been going without such incidents for so long. Just good thing we have this sorted now. *knocks the wood* :up:


All times are GMT -5. The time now is 08:01 AM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.