Next Generation Emulation banner
21 - 37 of 37 Posts

· Banned
Joined
·
35,081 Posts
Discussion Starter · #21 ·
Dax, click the more details link, it should tell you which portion of the script the infection is coming from.
 

· Heroes Might& Magic Champ
Joined
·
9,320 Posts
I don't have a virus scanner, but I presume my PC would be acting funky if I were infected. Right now I have ads unblocked due to some testing on my own site, perhaps Firefox and Windows 7 with UAC has saved my hide for now. :p
comeon xtreme, you know better then to presume that. :p We all know not all viruses hog the cpu cycles or cause noticeable weird behavior.

When I finally decided to allow access to the site earlier today I was infected 4 times with the iframe payload virus since noscript's iframe blocking wasn't enabled at the time. Dax was infected 3 times and he was using firefox + adblock(uptodate) + noscript(defaultsettings).

Iframe blocking has to be enabled.
 

· Heroes Might& Magic Champ
Joined
·
9,320 Posts
lol, lay off the diet coke man. Aspartame is known to causes memory problems. Here are my 4 infections.



Squall suggests using hostfile to block it.
 

· The Hunter
Joined
·
17,202 Posts
Kaspersky also reports virii on every page for me. Any CG responses? >.>
Chrono has sent an email to Sanjay 4 hours ago. Right now we just have to wait for a reply. When I see something at the staff board I'll let you know right away, but otherwise you have to be patient for Chrono to dig into it. Seeing how it's nighttime in the States now, it'll take a few hours. I'm sorry guys, as an smod I can only be the messenger. :)
 

· The Hunter
Joined
·
17,202 Posts
Also, I would like to ask what can be done as a workaround. I'm using the latest Firefox, with Adblock Plus (Easylist Germany (Deutschland) + EasyList) and have found no problems or alarms. Therefore I would suggest you to do the same until a solution has been found. I'd like to get feedback from others as well if this is the solution. If this is the case I can see if I can make a global announcement, given the scale of the issue.
 

· God of Douchebagness™
Joined
·
15,294 Posts
same here, and all ive got is a pop-up blocker.
 

· Read Only
Joined
·
10,484 Posts
Man I just reinstalled windows 7 (not because of this), but I came to the forums without adblock and noscript first.

I blocked Iframe from noscript, but how do I know I if got infected from it.

I'm only running MS Security Essentials atm.
 

· Registered
Joined
·
4,727 Posts
I have Nod32 4, and he doesn't say nothing about the page. ;)
 

· Registered
Joined
·
66 Posts
For me kaspersky flags the entire forum - every single page, every single section.



The similarity is that me koko and nosound.97 all have kaspersky which detects it.

So those without kaspersky many not get the warning.
This seems to be a kaspersky sensitivity issue. I did some googling and found that there are a lot fo false positives because of some new advanced heurestic algorithms incorporated into kaspersky.

From their own forums: HEUR: TROJAN.Script.Iframer - Kaspersky Lab Forum
 

· Registered
Joined
·
66 Posts
We are going to continue to look into this and do research. Please post anythign that might be helpful in uncovering this issue. If you use kaspersky please look up this alert on their forums- I think it will make you comfortable that this is not a hostile trojan, but possibly a false positive from kaspersky's method of evaluating active processes.

If anyone finds anything else that might be a clue let us know, but we are running diagnostics on our end.
 

· Registered
Joined
·
67 Posts
The issue was related to an exploit released this morning in the VBSEO software. The JS was exploiting clickthroughs and page views to try and illegally gain traffic. We have patched our VBSEO install and we thank the ngemu community for your prompt response to the problem at hand. Let us know if anything else arises.

-CG Team
 

· Registered
Joined
·
4,727 Posts
Thanks, P3R3. ;)
 
21 - 37 of 37 Posts
This is an older thread, you may not receive a response, and could be reviving an old thread. Please consider creating a new thread.
Top