Virus
Page 1 of 1
McSheep_CK




Posts: 4

PostPosted: Sun, 6th Mar 2005 01:41    Post subject: Virus
Whats with the virus www.nforce.nl is handing out ?

Not very nice thing to do is it Mad

Bloodhound.Exploit.20

Quote:
The definition of perfection


not at the min your not, i know a few ppl who are extreamly pissed off about and as such have boycotted the site Evil or Very Mad
Back to top
AnimalMother




Posts: 12390
Location: England
PostPosted: Sun, 6th Mar 2005 01:47    Post subject: Re: Virus
McSheep_CK wrote:
Whats with the virus www.nforce.nl is handing out ?

Not very nice thing to do is it Mad

Bloodhound.Exploit.20

Quote:
The definition of perfection


not at the min your not, i know a few ppl who are extreamly pissed off about and as such have boycotted the site Evil or Very Mad


Refer to sig.


"Techniclly speaking, Beta-Manboi didnt inject Burberry_Massi with Benz, he injected him with liquid that had air bubbles in it, which caused benz." - House M.D

"Faith without logic is the same as knowledge without understanding; meaningless"
Back to top
razor1394
VIP Member



Posts: 3571
Location: Sweden
PostPosted: Sun, 6th Mar 2005 08:01    Post subject:
What virus checker are you using? Some virus checkers give false alarms.
Back to top
TheSaint
Dalai Lama



Posts: 6586
Location: Cook Islands
PostPosted: Sun, 6th Mar 2005 20:25    Post subject:
hmm i do not think nforce gives out any virus but we have to check it out!
Back to top
dryan
Banned



Posts: 2446

PostPosted: Sun, 6th Mar 2005 21:26    Post subject:
Bloodhound.Exploit.20 is a heuristic detection for animated cursor(.ani) files that have been designed to exploit the Microsoft Windows Kernel .ani file Parsing and Denial of Service Vulnerability (as described in Microsoft Security Bulletin MS05-002). This exploit does not affect Microsoft Windows XP SP2 Operating Systems.


Im a cockfag
Back to top
razor1394
VIP Member



Posts: 3571
Location: Sweden
PostPosted: Sun, 6th Mar 2005 22:12    Post subject:
Another guy who got that error had updated everything.
Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Mon, 7th Mar 2005 10:40    Post subject:
I don't see a virus on our site, could you get more details as in which file the virus is?
Back to top
[sYn]
[Moderator] Elitist



Posts: 8374

PostPosted: Mon, 7th Mar 2005 12:30    Post subject:
Rinze wrote:
I don't see a virus on our site, could you get more details as in which file the virus is?


As far as I can tell from the virus description the "virus" is designed to sit (as code) inside of a webpage, this then reacts with a windows systems ".ani" files and exploits them to have various effects (these details are not needed).

I imagine his virus scanner is being overly cautious and simply seeing some sort of innocent script (probably the script checking for a cookie to auto logon the main page and show the needed NFO content) which is then sparking off a reaction.

I seriously wouldn't worry, but possibly look into any scripts that would access a persons computer, just to see if they can be modified to stop such problem in the future.

Edit: Man I cant spell today Razz
Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Mon, 7th Mar 2005 14:20    Post subject:
There is some third-party content on our site, and even if it's caused by our own scripts we would still like to fix it, so as not to alarm our visitors.
Back to top
[mrt]
[Admin] Code Monkey



Posts: 1342

PostPosted: Wed, 9th Mar 2005 00:51    Post subject: Re: Virus
McSheep_CK wrote:
Whats with the virus www.nforce.nl is handing out ?

Not very nice thing to do is it Mad

Bloodhound.Exploit.20

Right, we arent handing out no viruses. Not knowingly anyway.

First, please just tell us what OS, Browser and antivirus software your using and i'll try to duplicate your "virus problem" so we can fix it. Please be specific, also which virus definitions your using, version numbers etc.
Also, if you can post a log or something of the detection. Anything that might give us the idea where it originated from (source URL ect).

Quote:

Quote:
The definition of perfection


not at the min your not, i know a few ppl who are extreamly pissed off about and as such have boycotted the site Evil or Very Mad

Now thats just heart-breaking. Have we ever done something to hurt our users? no, so i dont see a reason why you have to be so harsh. You know we'll fix it ASAP, if it even is our fault. As Rinze said it could be a third-party (we know what we got running, we code everything ourselfs).

BTW, if you know some users who boycotted the site cause of that (yet failed to bring it to our attention somehow) tell them to try to help us then instead of just walking away. As i said, we'll do everything in our power to fix it if we are the source of the problem.


teey
Back to top
Ter0




Posts: 4

PostPosted: Thu, 10th Mar 2005 18:15    Post subject:
last night while browsing the site with Opera I got my browser to ask if I should
open/save a file called index.php, I set it to open and then my Zone Alarm closed all of a sudden.
Restarted it and then PC rebooted. When I got back online
Ive noticed I had a new "trusted zone" at my ZA rules and it was from
some ad here at nforce. Sorry if I cant tell which one was it, cause I freaked
out and deleted it as soon as I could. (IP was 62.something)
All seems back to normal ATM, and symantec antivirus got nothing
at my internet cache. Was really weird..
Back to top
[mrt]
[Admin] Code Monkey



Posts: 1342

PostPosted: Thu, 10th Mar 2005 21:59    Post subject:
Ok, thanks. I'll try sniffing it out which one it is.

Anyone else that can offer any feedback about this?


teey
Back to top
dryan
Banned



Posts: 2446

PostPosted: Thu, 10th Mar 2005 22:15    Post subject:
Since it's a "heuristic detection" I would probably guess that this is just a false positive from some crappy virus scanner.


Im a cockfag
Back to top
razor1394
VIP Member



Posts: 3571
Location: Sweden
PostPosted: Thu, 10th Mar 2005 22:50    Post subject:
Ok, we can't have to threads about the virus problem. Keeping THIS thread.
Back to top
[mrt]
[Admin] Code Monkey



Posts: 1342

PostPosted: Fri, 11th Mar 2005 11:07    Post subject:
Sorry but this is important, so i dont care if there are a dozen threads about this. We havent found anything so far but the advertisers have been confronted with the problem.

BTW, ter0 and MC_Sheep, if you could give us the index.php you have to save or the source of the main page that opens in your browsers, that would help us alot too.


teey
Back to top
StarShine




Posts: 782

PostPosted: Sat, 12th Mar 2005 00:23    Post subject:
@[mrt] Im pretty sure the virus was coming from an ad on the mainpage for virus scanning and security software ((cute eh!)) - I noticed it last week for a few days whenever the ad came up it would try to spawn a new window within firefox and generally slow down my browser for 30 secs - apparently its a virus though that doesnt affect users with sp2 so it didnt manage to do anything, my virus scanner hasnt picked anything up and spyware checks as clean.

My conclusion comes from the fact that when I noticed that there was something fishy going on with that ad I blocked images from the destination using firefox - checking firefox just there the address blocked shows as "aidintime".

If you google "aidintime" or look on any of the major anti virus sites they seem to be synonymous with serving up malware and adware so seems like a safe bet that the ad I mentioned was what was doing the damage.

Wink
Back to top
bulio
VIP Member



Posts: 126
Location: Canada
PostPosted: Tue, 15th Mar 2005 02:50    Post subject:
I don't see any virus, nor is nod32 picking anything up.
Back to top
razor1394
VIP Member



Posts: 3571
Location: Sweden
PostPosted: Tue, 15th Mar 2005 10:07    Post subject:
The virus may ignite when the ad is watched in IE and not in Opera and Firefox.
Back to top
StarShine




Posts: 782

PostPosted: Wed, 16th Mar 2005 20:18    Post subject:
bulio wrote:
I don't see any virus, nor is nod32 picking anything up.


its long gone now - I only had problems with the ad I mentioned and the virus being noticable for roughly 1-1.5 days that would have been back when it was initially reported. I've seen these ads/malware viruses on a few sites and I think due to their nature they deliver their payload over a short period of time i.e 1-2 days then disappear, moving on to the next unsuspecting site.

I miss the good ol days of "erotic glass toys" Crying or Very sad
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Site Feedback
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group