Just a Heads Up

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • Status
    Not open for further replies.

    Prometheus

    Master
    Rating - 100%
    1   0   0
    Jan 20, 2008
    4,462
    48
    Northern Indiana
    Avast just went nuts on my machine as well. Good news is Avast catches and terminates such attempts. No infection for me.

    Here is the originator:
    http://analytics.type16secure. XXX com/x/pdf.php

    I inserted the XXX and the two spaces to prevent someone from accidentally clicking it or re embedding it into this thread.

    For those looking for some of the best virus software around (and it's free for individuals) go to www.avast.com
     

    Scutter01

    Grandmaster
    Rating - 100%
    2   0   0
    Mar 21, 2008
    23,750
    48
    We've had one other person with a similar report, but we can't find anything in any of the code on the website. I suspect that if it's coming from INGO, it may be bad code in one of the ads presented by our ad server. If you see it again, please try to get a screenshot of the page you're on when the alert happens. PM me for my e-mail address and you can send it to me.
     

    lovemachine

    Grandmaster
    Rating - 100%
    17   0   0
    Dec 14, 2009
    15,601
    119
    Indiana
    It's probably from all the talk about bacon. I keep telling everyone it's unhealthy, nothing good can come from it. But NO, nobody listens to me. :dunno:




















    :D
     

    Scutter01

    Grandmaster
    Rating - 100%
    2   0   0
    Mar 21, 2008
    23,750
    48
    I've temporarily removed our banner ads until our ad server can scan their code. Please PM me if you get another warning.
     

    MinuteMan47

    Master
    Rating - 100%
    3   0   0
    Dec 15, 2009
    1,901
    38
    IN
    I scan using AVG every other day. My last scan showed no infections. I just used the link Rooster provided and it is finding numerous infections. Why would AVG not have found them???
     

    CarmelHP

    Grandmaster
    Rating - 0%
    0   0   0
    Mar 14, 2008
    7,633
    48
    Carmel
    Kaspersky detected the trojan twice today. Last time when I came here about an hour ago. (approx 10:30-11PM on 7/8).
     

    360

    Shooter
    Rating - 0%
    0   0   0
    Feb 7, 2009
    3,626
    38
    We've had one other person with a similar report, but we can't find anything in any of the code on the website. I suspect that if it's coming from INGO, it may be bad code in one of the ads presented by our ad server. If you see it again, please try to get a screenshot of the page you're on when the alert happens. PM me for my e-mail address and you can send it to me.

    I think you would be better off to have a screenshot of the source code from whatever page is causing it?
     

    Rooster Cogburn

    Sharpshooter
    Rating - 100%
    4   0   0
    Nov 25, 2008
    305
    16
    MSG2 - Indianapolis
    I use AVAST and it didn't catch it. Dunno why...

    Yes after much reading about the malware, it is typically embedded in codes such as banners and such. The desktop of XP and IE 7 was relatively easy to repair once I downloaded the fixes provided on the link. And followed the instructions to the letter.

    However, when I came here to post originally, the laptop was infected and much more of an issue. Following the instructions didn't work. :xmad: It has Vista and IE 8. The quick way was to put the fix files on a flash drive and fix it by downloading and implementing the files directly. I hope that trick helps someone else as it took me awhile to come to that conclusion.

    Definitely wasn't an INGO issue and I do apologize if that was the way it appeared. I was freaking when the laptop went south. I know INGO would never put us in harms way.

    :ingo:
     

    Prometheus

    Master
    Rating - 100%
    1   0   0
    Jan 20, 2008
    4,462
    48
    Northern Indiana
    I think you would be better off to have a screenshot of the source code from whatever page is causing it?

    See my post on page one. It's the page, but I didn't screen shot it.

    Rooster:
    Each virus program works differently...

    Avast is one of the best (along with the pricey Kaspersky one poster mentioned) at stopping virus' BEFORE they embed themselves.

    AVG works better (for some issues) at removing the virus once it's in, but does poorly at stopping them "at the gate" so to speak.

    Also, I have no idea why anyone would use IE as a browser. The security issues alone make it a POS browser, let alone the memory it hogs.

    I'm very careful what I surf from my TouchPro2... I'm hoping this same issue isn't corrupting my phone.

    It was from a specific ad... I'm hoping that ad didn't pop up while browsing yesterday. On the plus side, I didn't surf from my phone today. :n00b:

    Scutter and Fenway, I'd have a SERIOUS talk with your ad hosting service about the ^&*( it sends out.
     

    Scutter01

    Grandmaster
    Rating - 100%
    2   0   0
    Mar 21, 2008
    23,750
    48
    I think you would be better off to have a screenshot of the source code from whatever page is causing it?

    Ideally, yes, but so far I haven't gotten anyone to send me anything at all. Prometheus had the most useful information, but nothing is on the server and so far nothing has been found in any of the ads. It's easy to claim it came from INGO (or the ad agency), but without more info, I can't confirm that. CarmelHP says he got an alert around 10:30, but that was hours after the ad service was suspended.

    And anyway, if I could get someone to send me a screen shot of the source code, then they'd also know how to just send me the source code as a text file. I have to request the things that I feel I'm likely to be able to get.
     

    bmwdud

    Marksman
    Rating - 0%
    0   0   0
    Feb 19, 2010
    211
    18
    fort wayne
    i picked up some thing yesterday about 4 10 pm . . may have 10:34 am
    the onley place i went was INGO
    ok now . got 2 trojan's
    will see if i can find the names if that will help


    virus name . Trojan.Zefarch!gen

    file names . Exyocefuw.dll and overlay.xul
     
    Last edited:

    Rooster Cogburn

    Sharpshooter
    Rating - 100%
    4   0   0
    Nov 25, 2008
    305
    16
    MSG2 - Indianapolis
    Also, I have no idea why anyone would use IE as a browser. The security issues alone make it a POS browser, let alone the memory it hogs.

    I use Firefox exclusively. But if you read the page link I sent, you must go into IE to change the LAN settings. Changing it in FF doesn't work.

    I have used FF exclusively for 4 years now...will never go back to IE. WIll give up my Internet addiction first! :evilangel:
     

    Prometheus

    Master
    Rating - 100%
    1   0   0
    Jan 20, 2008
    4,462
    48
    Northern Indiana
    Ideally, yes, but so far I haven't gotten anyone to send me anything at all. Prometheus had the most useful information, but nothing is on the server and so far nothing has been found in any of the ads. It's easy to claim it came from INGO (or the ad agency), but without more info, I can't confirm that. CarmelHP says he got an alert around 10:30, but that was hours after the ad service was suspended.

    And anyway, if I could get someone to send me a screen shot of the source code, then they'd also know how to just send me the source code as a text file. I have to request the things that I feel I'm likely to be able to get.

    Sorry Scutter if you were a few seconds faster on asking for the screen shot I would have grabbed it.

    Hasn't happened since, but Avast defaults to permanent blocking and i won't see that exact same attack notification again.

    My Avast log shows this:
    7/8/2010 7:05:58 PM SYSTEM 1672 Sign of "JS:Pdfka-gen [Expl]" has been found in "http://analytics.type16secure.XYZ/x/pdf.php" file.

    That is a verbatim copy except replace ".XYZ" with .com
     

    Scutter01

    Grandmaster
    Rating - 100%
    2   0   0
    Mar 21, 2008
    23,750
    48
    My Avast log shows this:
    7/8/2010 7:05:58 PM SYSTEM 1672 Sign of "JS:Pdfka-gen [Expl]" has been found in "http://analytics.type16secure.XYZ/x/pdf.php" file.

    replace ".XYZ" with .com

    Yeah, I got that much of it, but that didn't come from our servers. It either came from something already on your PC or it came from our ad provider. The screenshot or source code would help me determine which ad is the culprit or which site template might be affected (again, assuming INGO was involved in some way). The time stamp might help a little, though.
     
    Status
    Not open for further replies.
    Top Bottom