Welcome to the WWII Forums! Log in or Sign up to interact with the community.

Viruses On This Site

Discussion in 'Counter-Battery Fire' started by Volga Boatman, Sep 6, 2011.

  1. Volga Boatman

    Volga Boatman Dishonorably Discharged

    Joined:
    Nov 15, 2009
    Messages:
    1,640
    Likes Received:
    154
    Lately, I have been encountering one virus after another on this site.

    I am lucky my machine is mostly protected with anti-v software. On a site that is policed by the moderators and owners, why does this keep happening?

    What steps are the managment taking here to combat this electronic disease(s)?
     
  2. brndirt1

    brndirt1 Saddle Tramp

    Joined:
    Jul 7, 2008
    Messages:
    9,713
    Likes Received:
    1,501
    My Norton has blocked three "unauthorized access" attempts today, without any getting through my own unit. I don't know what can be done by Otto and the others at the "site" level itself, I just count on my personal Norton 2011.
     
  3. Volga Boatman

    Volga Boatman Dishonorably Discharged

    Joined:
    Nov 15, 2009
    Messages:
    1,640
    Likes Received:
    154
    Well, at least they must be informed that this occurs on their site more often than I care to admit.

    I presume it is NOT other members who are perpetrating this, so what in the blue blazes is going on? If one of these bloody things gets through, I'll not be a very happy poster. It costs money to fix.
     
  4. Skipper

    Skipper Kommodore

    Joined:
    Jun 6, 2006
    Messages:
    24,984
    Likes Received:
    2,386
    next time this happens could copy the link of the thread /post please, so we know what to look for.
     
  5. CAC

    CAC Ace of Spades

    Joined:
    Dec 1, 2010
    Messages:
    9,566
    Likes Received:
    3,068
    I've got an idea of who it is...will keep you'al posted.
     
  6. Volga Boatman

    Volga Boatman Dishonorably Discharged

    Joined:
    Nov 15, 2009
    Messages:
    1,640
    Likes Received:
    154
    My security just blocked another one.

    Seems to happen when you access the site through the main page, that is when you jump to the general page for the first time.

    For the moderators, my software report said the File Name was 129.121.212.1/Home/index.php

    Threat name was Exploit Blackhole Exploit Kit (type 1889)

    Please do not click on the above.
     
  7. Skipper

    Skipper Kommodore

    Joined:
    Jun 6, 2006
    Messages:
    24,984
    Likes Received:
    2,386
    I'll send the info to Otto . Hopefully it's a false postive.
     
  8. USMCPrice

    USMCPrice Idiot at Large

    Joined:
    Nov 15, 2009
    Messages:
    5,168
    Likes Received:
    2,140
    Location:
    God's Country
    Yeah, I've had the warnings also, both at home and at work.
     
  9. theblackalchemist

    theblackalchemist Member

    Joined:
    Dec 30, 2009
    Messages:
    294
    Likes Received:
    27
    Thanks for the info mate.

    Any recollection which link redirected you to the said page?
    Will help the admins.

    Also for those of you who have a firewall up, i'd suggest you block the ip range from 129.121.0.0 to 129.121.255.255. If you dont, i'd suggest you get one, an example being peerblock.

    Regards,
    TBA
     
  10. Skipper

    Skipper Kommodore

    Joined:
    Jun 6, 2006
    Messages:
    24,984
    Likes Received:
    2,386
    thanks for the info, Otto has been informed with link and the I.P. adress.
     
  11. Volga Boatman

    Volga Boatman Dishonorably Discharged

    Joined:
    Nov 15, 2009
    Messages:
    1,640
    Likes Received:
    154
    No link direction, but a security window pops up when you go to the 'Forum' for the first time for your daily visit.

    There was another type that was blocked, but I did not have the presence of mind to write it down.

    Hope this helps. These bloody viruses are annoying to say the least.
     
  12. LRusso216

    LRusso216 Graybeard Staff Member

    Joined:
    Jan 5, 2009
    Messages:
    14,290
    Likes Received:
    2,607
    Location:
    Pennsylvania
    While I'm glad Otto has been informed, I get no virus warnings from Norton. I wonder where they are coming from?
     
  13. theblackalchemist

    theblackalchemist Member

    Joined:
    Dec 30, 2009
    Messages:
    294
    Likes Received:
    27
    I hope no one is still sticking to internet explorer here, if you are, you are literally begging to be attacked.

    Regards,
    TBA
     
  14. 36thID

    36thID Member

    Joined:
    May 23, 2008
    Messages:
    1,059
    Likes Received:
    202
    I love this site but the warnings are alarming.

    Last Sunday I got one, I stayed away until today and got another.

    These creeps that pull this nonsense need their kiesters kicked !
     
  15. brndirt1

    brndirt1 Saddle Tramp

    Joined:
    Jul 7, 2008
    Messages:
    9,713
    Likes Received:
    1,501
    I just got a "MalWare" warning from what appears to be Google, however when I went to my Norton what I found was this:

    ?Category: Norton Product Tamper Protection
    Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
    9/9/2011 11:50 AM,Medium,Unauthorized access blocked (Open Process Token),Blocked,No Action Required,"Friday, September 09, 2011 11:50 AM",C:\PROGRAM FILES\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,3604,C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe,2220,Open Process Token,Unauthorized access blocked


    ?Category: Norton Product Tamper Protection
    Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
    9/9/2011 12:00 PM,Medium,Unauthorized access blocked (Set Regietry Security Key),Blocked,No Action Required,"Friday, September 09, 2011 12:00 PM",C:\WINDOWS\SYSTEM32\SVCHOST.EXE,888,HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BHDRVX86\0000\Control\,0,Set Regietry Security Key,Unauthorized access blocked


    ?Category: Norton Product Tamper Protection
    Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
    9/9/2011 12:03 PM,Medium,Unauthorized access blocked (Open Process Token),Blocked,No Action Required,"Friday, September 09, 2011 12:03 PM",C:\PROGRAM FILES\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,4560,C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe,2220,Open Process Token,Unauthorized access blocked

    All medium risk, all blocked. Don't know what is going on or why, this is the first MalWare warning I've ever received since Volga Boatman started claiming he was getting virus warnings.
     
  16. Gebirgsjaeger

    Gebirgsjaeger Ace

    Joined:
    Jun 11, 2010
    Messages:
    4,333
    Likes Received:
    290
    Don´t worry about the warning Clint! I do have the Norton 360 and this warning pops up so often no matter if i´m on this site or not! So i ignore them.
     
  17. urqh

    urqh Tea drinking surrender monkey

    Joined:
    Dec 23, 2002
    Messages:
    9,683
    Likes Received:
    955
    Google warns the site is dangerous again....Happened months ago. Go in thru Yahoo and no problems whatsoever.
     
  18. jagdpanther44

    jagdpanther44 Battlefield wanderer

    Joined:
    Sep 2, 2007
    Messages:
    1,894
    Likes Received:
    553
    Location:
    Cheshire, England
    Same here - Google warns me that the site has malaware.

    Like others, I also encountered this problem a few month back and this is the first time since then that i've had the warning.
     
  19. OpanaPointer

    OpanaPointer I Point at Opana Staff Member WW2|ORG Editor

    Joined:
    Jun 5, 2008
    Messages:
    18,341
    Likes Received:
    5,701
    You can turn off the alarm in /Options/Tools/Security. I just ran three AVs with no hits.
     
  20. LRusso216

    LRusso216 Graybeard Staff Member

    Joined:
    Jan 5, 2009
    Messages:
    14,290
    Likes Received:
    2,607
    Location:
    Pennsylvania
    I also ran a full scan with Norton and received nothing. I don't know where the problem is, but I also turned off the warning.
     

Share This Page