• The move to the new server is done. There are some software and database maintenance updates in process. This has us passing the hat around to help out. We appreciate any donations. Seriously, even a dollar helps. The payment page may be found here - https://www.audiokarma.org/support.html

Virus attack after log in

Thankfully at home, AVG has been blocking it and removing the files well.

Just something I've noticed at home.... I leave my laptop setting with only AK open on it. It can sit there for a half hour without me touching it, then suddenly AVG will pop open stopping things from loading.

That really makes me think it's an ad, since that's the only thing on the AK pages that would be reloading or refreshing.

Norton Security Suite has blocked it for me too, most recently as of last night. Have been saving all my cached files in FF - hoping to find the offending script source but haven't yet.
 
I have blocked all scripts from AK which seems to be the only way around this for me at this time. If its not on AK's server then what else is left but the ads?
 
I think it's an ad now too.

Norton flagged malware on me again - from "ireaud.com".

My browser cache shows this, snippet attached. Looks to me like this one came from a purebluemedia.com ad script (the big ad on bottom of page), with a zipped payload.

Code:
HTTP:http://d5.purebluemedia.com/scripts/728x90/ad.js
necko:classified
request-method
GET
request-Accept-Encoding
gzip, deflate
response-head
HTTP/1.1 200 OK
Date: Thu, 29 Dec 2011 19:23:08 GMT
Server: Apache/1.3.34 (Debian) mod_perl/1.29
P3P: CP="NOI DSP COR PSDa OUR NAV"
Pragma: no-cache
Content-Type: text/javascript
Via: 1.1 50.57.185.189
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 229
HTTP:http://content.talkerumbelshogun.com/track?egYGVXtZDUMSCBVsQW0AXAcEYGB4FVICLwQOExYAUQhaFUkgDF8EAH5lfR0GQEZCARUWAAlIE1AdYQJcBgVoZnkLA1YEA2xBDUEHVl8BFWYXGlxrJW0kR0AASkMcSUIXVRsDHUM/XEFeVTk+
necko:classified
request-method
GET
response-head
HTTP/1.1 302 Found
Server: nginx/1.0.9
Date: Thu, 29 Dec 2011 19:23:11 GMT
Content-Type: text/html; charset=iso-8859-1
[COLOR="red"]Location: http://ireaud.com/main[/COLOR]
Expires: Thu, 29 Dec 2011 19:23:08 GMT
HTTP:http://d5.purebluemedia.com/40004/728x90/728x90centurylink.jpg
request-method
GET
response-head
HTTP/1.1 200 OK
Date: Thu, 29 Dec 2011 19:23:50 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 20 Dec 2011 22:41:31 GMT
Etag: "e4675-50f3-4b48dc4bdbcc0"
Accept-Ranges: bytes
Content-Length: 20723
Content-Type: image/jpeg
 
Change your DNS servers to 8.8.8.8 and 8.8.4.4 and the DNS server will block this stuff.

I've been following this discussion since its beginning, and I haven't seen any warnings. I use Chrome and Firefox on several different computers. I have several different antivirus programs, but none have indicated a problem with AK.
 
For reference, I was on 8.0.1 FF when I got hit. Laptop had corporate Symantec A/V running realtime and it went through it like Sherman through Georgia... the Windows XP Security Alert critter.

Still running 8.0.1, yahoo edition, but I added NoScript and blocked all javascripts for AK domain before returning with my new laptop. I'll update to 9.0 if you guys determine there is any improvement in protection against this particular weevil.

My home PC is an older desktop running 3.5 or 3.6 FF with similar Symantec A/V but I also use Spybot/TeaTimer on that one and have not been attacked. I did add NoScript last week as an added layer of protection. Virtually nothing on AK requires java anyway, it disables some auto-fill stuff in the Search tool and the PM notification pop-ups but seriously how hard is it to check that stuff manually vs. risk of reinfecting?

John

As far as we can tell, it's not the ads. This issue is affecting far more web sites than just AK. Guys, I need to stress as strongly as I can that we are very, very concerned about this, and we're doing everything we can to address it. The problem is that, although it's a horribly painful mess for those who've been hit by the malware, it's affecting such a small number of folks compared to the number that are logged in on any given day that it's really, really hard to come up with a common factor.

One of the more intriguing clues is that, as far as I've been able to tell, there have been zero hits to members running Chrome or to members running the most current version of FF. If anybody running Chrome or FF 9.0.1 has been infected, speak up.

Bill, every new pc came with the standard load signed off on when the final design was done. It's unlikely it has the latest version of FF.
 
FWIW, my hard drive was not physically damaged at all when I was attacked. IT removed it from the laptop and connected it to another computer so they could scrub it w/o trying to boot that drive. Worked fine, they ran Malwarebytes and got rid of things pretty well. It was an unfortunate error in allowing the reassembled laptop to resync with our network that wiped away my data files. Had they copied those to a fresh address outside the sync environment, I would have come away virtually unscathed. They did replace the whole machine a couple of weeks later following a reinfection (yep, from AK before I had installed NoScript), but that's partly because I was due for an upgraded machine anyway (silver lining).

DO NOT let an amateur loose on that thing, but your drive is probably physically intact at this point. The virus warnings are all BS. It appears to destroy the user profile and also flipped all of my local data files to "hidden" but they were still there when the drive was read using an ininfected machine.

John

Will not boot. Recovery failed. Brick as in brick.
 
As far as we can tell, it's not the ads. This issue is affecting far more web sites than just AK. Guys, I need to stress as strongly as I can that we are very, very concerned about this, and we're doing everything we can to address it. The problem is that, although it's a horribly painful mess for those who've been hit by the malware, it's affecting such a small number of folks compared to the number that are logged in on any given day that it's really, really hard to come up with a common factor.

One of the more intriguing clues is that, as far as I've been able to tell, there have been zero hits to members running Chrome or to members running the most current version of FF. If anybody running Chrome or FF 9.0.1 has been infected, speak up.

Bill, every new pc came with the standard load signed off on when the final design was done. It's unlikely it has the latest version of FF.

FWIW, I've been running IE6 on W2K (in a VM) for close to a week now for malware trolling, no protections whatsoever. Still clean, three of the major online scanners report nothing.
 
I fully understand, but I don't think the majority of average folks on the internet are ever going to set up a VM, no matter how much of a good idea it is.
 
Yeah, I understand, even though it's no more difficult than installing any other software because that's all it is, just another software app...but that wasn't the point.

I just find it interesting it seems newer, latest/greatest stuff is getting hit whereas so far this hasn't.
 
I think it's an ad now too.

Norton flagged malware on me again - from "ireaud.com".

My browser cache shows this, snippet attached. Looks to me like this one came from a purebluemedia.com ad script (the big ad on bottom of page), with a zipped payload.

Code:
HTTP:http://d5.purebluemedia.com/scripts/728x90/ad.js
necko:classified
request-method
GET
request-Accept-Encoding
gzip, deflate
response-head
HTTP/1.1 200 OK
Date: Thu, 29 Dec 2011 19:23:08 GMT
Server: Apache/1.3.34 (Debian) mod_perl/1.29
P3P: CP="NOI DSP COR PSDa OUR NAV"
Pragma: no-cache
Content-Type: text/javascript
Via: 1.1 50.57.185.189
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 229
HTTP:http://content.talkerumbelshogun.com/track?egYGVXtZDUMSCBVsQW0AXAcEYGB4FVICLwQOExYAUQhaFUkgDF8EAH5lfR0GQEZCARUWAAlIE1AdYQJcBgVoZnkLA1YEA2xBDUEHVl8BFWYXGlxrJW0kR0AASkMcSUIXVRsDHUM/XEFeVTk+
necko:classified
request-method
GET
response-head
HTTP/1.1 302 Found
Server: nginx/1.0.9
Date: Thu, 29 Dec 2011 19:23:11 GMT
Content-Type: text/html; charset=iso-8859-1
[COLOR="red"]Location: http://ireaud.com/main[/COLOR]
Expires: Thu, 29 Dec 2011 19:23:08 GMT
HTTP:http://d5.purebluemedia.com/40004/728x90/728x90centurylink.jpg
request-method
GET
response-head
HTTP/1.1 200 OK
Date: Thu, 29 Dec 2011 19:23:50 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Tue, 20 Dec 2011 22:41:31 GMT
Etag: "e4675-50f3-4b48dc4bdbcc0"
Accept-Ranges: bytes
Content-Length: 20723
Content-Type: image/jpeg

i would like to look at the ad for sport but i don't see a big ad .just little ones ..any chance of posting the link ? or just post without the http www. bit to save any problems
 
Yeah, I understand, even though it's no more difficult than installing any other software because that's all it is, just another software app...but that wasn't the point.

I just find it interesting it seems newer, latest/greatest stuff is getting hit whereas so far this hasn't.

Which version of VM Ware is free? I run virtual machines at work via VM Ware, but don't have it here at the house.

Our old IT guy said he used it anytime he would surf into warez sites (not at our work, he was freelance) or places that were known to have nasties about. Get hit, delete that machine, and load a new one.
 
Which version of VM Ware is free? I run virtual machines on work via VM Ware, but don't have it here at the house.

Our old IT guy said he used it anytime he would surf into warez sites (not at our work, he was freelance) or places that were known to have nasties about. Get hit, delete that machine, and load a new one.

VMware Player is free.

There's a bunch of Linux OS appliances you can download for free too, or just install an OS in it like I did with W2K.
 
Bummin.. Checked my machine and it's nice and clean, but now I'm starting to get a couple site popups.. the bad ad sites that put a popup on top of the site popup.. .

Only getting it while on AK..

Here's the newest two I've had to my restricted sites..

ireaud.com
easytestsite.com
 
Bummin.. Checked my machine and it's nice and clean, but now I'm starting to get a couple site popups.. the bad ad sites that put a popup on top of the site popup.. .

Only getting it while on AK..

Here's the newest two I've had to my restricted sites..

ireaud.com
easytestsite.com

the easytestsite.com comes up with a pop up thing to say you have won something and locks up google chrome ....dodgy scripts me thinks ...
Congratulations!
Are you the Birmingham winner for December 29th?

Please select a prize and enter your email on the next page to claim.
ireaud.com gives me a 403 Forbidden
 
My Windows 7 PC got hit on AK tonight. I was running Firefox 8.0 (Firefox says it's up to date, which I now know is not true). I am running Kaspersky Anti-virus 2012, completely up to date. All of my Windows updates are current, too. I got the Win7 Anti-virus 2012 Trojan malware. The only warning I got was Kaspersky popped up and said "blocked access to URL" or something like that and then my computer rebooted. I knew I was hosed at that point. I was able to use Malwarebytes to get rid of the infection, and I think I'm clean, but that's 4 hours of my life I won't get back. I'm posting from my Mac now. Until I figure out exactly what will keep me clean, my AK browsing will be Mac/iPhone only.

This is only the second time in about 4 years that I've been hit with something like this. It stinks because I did nothing wrong - didn't click on an ad or open an email attachment or anything. I didn't have any browser tabs or windows open besides AK at the time. I'm awfully disappointed in Windows, Firefox, Kaspersky, and humanity in general...
 
Mirrors what happened to me. I've just spent 8 hours and several hundred dollars I didn't have on an external CDROM drive and a new copy of window 7. Wearing a huge happy hat here. I will only access AK via my iPod until this is sorted.
 
Running win 7 with McAfee and Microsoft Security Essentials and Malwarebytes.
Everything is up to date mostly use Chrome 99% of the time. it seems a bit faster than IE or F/F I have F/F 9 and IE9 also.
Chrome seems to be the most secure at least for me . Had a couple of browser warnings a while back on AK but nothing since and no infections or problems.
I`m running McAfee security suite with site adviser on it is pretty good in alerting to suspicious scripting and seems to block stuff ok for me . M.S.E. has also caught a couple of Trojans here and there not from AK. Running AVG and M.S.E on second win XP box . I think Chrome may be an advantage security wise.
M.S.E. can be downloaded free from Microsoft it has automatic update option as well
much better than the Older windows Defender. I uninstalled W.D. and went with M.S.E.
on both boxes .
 
Mirrors what happened to me. I've just spent 8 hours and several hundred dollars I didn't have on an external CDROM drive and a new copy of window 7. Wearing a huge happy hat here. I will only access AK via my iPod until this is sorted.

Ditto here. Just came in to check status fom my laptop, and when I went to reply to this thread was immediately hi with the xp antivirus crap. Combofixing it now. Like mr. Wigwam, im only going to use non windows devices until this is fixed. Can't run vmware as my windows media is buried in storage, and its so rainy I can't pull anything out to look. Too bad I have to take porn site measures with AK. Good luck to those working on this!
 
Back
Top Bottom