Just became member to inform admins url is infected. | Page 2 | FerrariChat

Just became member to inform admins url is infected.

Discussion in 'New Member Introductions' started by DinoSR8LM, Dec 10, 2010.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,406
    Houston, Texas
    Full Name:
    Bubba
    I DO have some interesting "art' though......
     
  2. NeuroBeaker

    NeuroBeaker Advising Moderator
    Moderator

    Oct 1, 2008
    40,186
    Huntsville, AL., USA
    Full Name:
    Andrew
    I know a few members have downloaded DrS cards and reposted them. What's the associated risk with having downloaded a card on a Windows XP machine, if that is the vulnerable operating system?

    All the best,
    Andrew.
     
  3. Bob Zambelli

    Bob Zambelli F1 Rookie
    Silver Subscribed

    Nov 3, 2003
    3,673
    Manning, SC
    Full Name:
    Robert G. Zambelli
    #28 Bob Zambelli, Dec 11, 2010
    Last edited: Dec 11, 2010
    Not Bob, but Juan-Manuel Fantango here, but he is signed on as I cannot and use the K anti virus solfware, etc.

    What does all this mean? Please explain in laymans terms. I need my Ferrarichat fix, but am terified of these viruses these selohssa launch. They should recieve the death penalty, as Bob says, after they are tortured. And we will be happy to administer the punishment. I have a strong back, but weak mind and I need to put it to use.
     
  4. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    I have learned from Yin that it could be on of the google ads before sign in. Rob has suggested to turn off the Kaspersky or add the site to a safe list that I haven't figured out how to do yet.
     
  5. Jedi

    Jedi Moderator
    Moderator Lifetime Rossa Owner

    Mar 18, 2008
    32,331
    Seattle Area
    Full Name:
    Dave
    So for heaven's sake TELL US ABOUT YOUR DINO!! Welcome to F-Chat - perhaps the
    most unusual entry EVER.

    :)

    Jedi
     
  6. SPEEDCORE

    SPEEDCORE Four Time F1 World Champ

    Jul 11, 2005
    46,182
    Full Name:
    Toe Knee
    #31 SPEEDCORE, Dec 11, 2010
    Last edited by a moderator: Sep 7, 2017
    Ahh! When I 1st saw this thread I did the usual checks and Fchat came up clean but El Wayne said he was aware of the issue so didn't reply. :eek:
    Image Unavailable, Please Login
    Image Unavailable, Please Login
     
  7. ylshih

    ylshih Shogun Assassin
    Honorary Owner

    Mar 21, 2004
    20,579
    Northern CA
    Full Name:
    Yin
    #32 ylshih, Dec 12, 2010
    Last edited: Dec 12, 2010
    You would have to have Windows XP/SP2 or earlier and never patched/updated it after 2004. Regardless, whether their OS is safe or not, users who made copies of those cards should just delete them. There is absolutely no reason to perpetuate a bad file if you know it is bad and can easily get to them.

    Just to be clear, we don't know 100% that the old DrS cards are the cause of the Kaspersky blocking; it could be seeing something else. However, the cards are the only thing we do know that has been shown to be suspect and Kaspersky gives an alert that is suspiciously like the scenario that *was* analyzed, so that's why we think that's the most likely explanation.

    Right now Kaspersky is the only antivirus that blocks the site rather than quarantines the JPG (which is what MSE does). Since it blocks the site, it prevents us from confirming what is happening. It is possible that Kaspersky is seeing something in another uploaded JPG (user or sponsor) or that content that is being sourced via re-direct (such as GoogleAds) is the source of a problem. However, I run MSE continuously, as well as MalwareBytes and AVG scans and this combo has never found anything on the site, except MSE was the first one that found the cards previously mentioned.

    Based on this, we're suggesting that users who have Kaspersky switch to another antivirus or find the Kaspersky method for safelisting a site to remove the block on Fchat. Those users that have Kaspersky AND have a penchant for detective work can try to clear the block and then check for Kaspersky triggering an alert on old cards, new cards, sponsor JPGs, and GoogleAds content (not subscribed or logged in). That would help us confirm the false positive or give us leads to track down if something else is going on.
     
  8. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    #33 DinoSR8LM, Dec 12, 2010
    Last edited: Dec 12, 2010
    Did it again when I just got home. It's definitely on the sign in when the google ads are up and its any web address for the site (ferrari101 bestemployee ect). Right now I have the Kapersky turned off and I'm gonna see if my pc has anything when I turn it back on.
     
  9. SPEEDCORE

    SPEEDCORE Four Time F1 World Champ

    Jul 11, 2005
    46,182
    Full Name:
    Toe Knee
  10. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    64,282
    Southlake, TX
    Full Name:
    Rob Lay
    Turn Kapersky on and come to FerrariChat, if you get the warning, send me screen shot of what you are seeing when it blocks. Also try skipping over main page to a direct thread link like here and sees what happens.

    It is possible we have another problem with the Google ads or like the recent hack we had that put a 3rd parties Google ads at bottom of each page. We just need data from everyone to pinpoint it.

    FYI, no one should see Google Ads entering the main page, even if a guest or non-subscribed. Only Google Ads guests or non subscribed users should see are between posts in threads.

    The banner at top right is through my own software on my server, but one of the banners provided by the Sponsor may be infected, I don't know yet.

    We just need more data. Thank you.
     
  11. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    #36 DinoSR8LM, Dec 12, 2010
    Last edited: Dec 12, 2010
    just emailed you shots, screen goes white and can't see what it is. I also did a full scan after I turned it off and nothing found.I'm going to submit a false positive report to Kaspersky and see what they say.
     
  12. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    Just signed on with the Kaspersky on :)
     
  13. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    64,282
    Southlake, TX
    Full Name:
    Rob Lay
    Update, we did find a malicious link unrelated to Dr.S card's, we removed and working on more security.
     
  14. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,406
    Houston, Texas
    Full Name:
    Bubba
    Well, I am running the same stuff Yin is using, so I guess that's as good as it gets.....
     
  15. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    Good to know, I thought Kapsersky made it a safe site after I reported it.
     

Share This Page