Aaron, Might want to think about a scan on the servers.
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Aaron, Might want to think about a scan on the servers.
OK so I know this is normally a client side thing and I know for a fact that my machine is not infected and I've just run another scan after killing all the IE process and there are none of the baddies listed on my machine.
One click on the main forum page and the complaint here shows up. It says I've caught a bunch of bad things.... Not so.
http://www.washingtonlakes.com/forum/vi ... =7&t=19632
When I try to X out of the pop up, it launches another IE process. Then win 8.1 asks if I want to allow the script to run...... It's trying to install a root kit or something.
Catching this stuff was my livelihood for many years. Best check your code, it's reaching out in an unfriendly manner.
One click on the main forum page and the complaint here shows up. It says I've caught a bunch of bad things.... Not so.
http://www.washingtonlakes.com/forum/vi ... =7&t=19632
When I try to X out of the pop up, it launches another IE process. Then win 8.1 asks if I want to allow the script to run...... It's trying to install a root kit or something.
Catching this stuff was my livelihood for many years. Best check your code, it's reaching out in an unfriendly manner.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
First this pops up:

Then this when you try to X out:

Finally this is the real quarantine:

The listed threats are well known and SC Endpoint is quite familiar with them. It's trying to load something else.

Then this when you try to X out:

Finally this is the real quarantine:

The listed threats are well known and SC Endpoint is quite familiar with them. It's trying to load something else.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
Re: Aaron, Might want to think about a scan on the servers.
I really don't know what to do here. An infection is an infection. It's not picky. Either we're infected, and everyone should see something going on, or we're not, in which case I'm inclined to blame the client. At the very least I would expect more than 1 or 2 complaints.
Can you reproduce this on another machine/device? Do you think it's only IE/Windows 8 related? I haven't used IE in... when was Chrome released?
- Aaron
Can you reproduce this on another machine/device? Do you think it's only IE/Windows 8 related? I haven't used IE in... when was Chrome released?
- Aaron
Re: Aaron, Might want to think about a scan on the servers.
Alrighty then. It's IE related. I loaded the forum with IE and received the notice. I'll see what I can find. Just another reason to never ever ever use IE.
- needs2hunt
- Warrant Officer
- Posts: 140
- Joined: Wed Sep 05, 2012 6:01 pm
Re: Aaron, Might want to think about a scan on the servers.
firefox ... FTW (for the win)...
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
I would but, when MS pays my salary, they kind of expect us to use IE. For code testing we can use anything but...... If one of the big boys swings through, I don't like answering those kind of questions, right or wrong......Aaron wrote:Alrighty then. It's IE related. I loaded the forum with IE and received the notice. I'll see what I can find. Just another reason to never ever ever use IE.
![Sad [sad]](./images/smilies/msp_sad.gif)
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
Re: Aaron, Might want to think about a scan on the servers.
My fear is that it's Banner ad related... coming through from one of the ad networks. My initial quick scan using Malwarebytes came up with nothing. Security Essentials shows nothing. That tells me there's...... nothing.
- Aaron
- Aaron
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
That is a distinct possibility. On the second pic have a look at the start of the url, definitely not one of yours. =)Aaron wrote:My fear is that it's Banner ad related... coming through from one of the ad networks. My initial quick scan using Malwarebytes came up with nothing. Security Essentials shows nothing. That tells me there's...... nothing.
- Aaron
I'd almost put money on it being the ADs. Necessary evil but an unpleasant one.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
- MarkFromSea
- Admiral
- Posts: 1934
- Joined: Mon Feb 16, 2009 1:38 pm
- Location: Kirkland
Re: Aaron, Might want to think about a scan on the servers.
Hewes had the same issue a few weeks back...
if you look at your captured picture of security essentials alert, the red one, the word "MIGHT" is misspelled."migth". that tells me that is not an alert from security essentials..but a fake... it's the Ruskies at it again.. it is red after all!
I haven't rcvd these messages... but have been experiencing some big slow downs on this old computer... Firefox quit working, deleted it.... that sped up chrome, which I'm now using.
I noticed in my processes, when the slow down returns, that a MS "something" cranks way up in CPU usage. Not related to here.... Some other forums I'm on report massive daily attacks... so much so.. one forum recently changed their software package out to run the forum... any way... it's happening all over more intensely.. it seems to me.. CHEERS! Keep your tip up and your line tight! Limits of clams last Tues! Easy pickins!
if you look at your captured picture of security essentials alert, the red one, the word "MIGHT" is misspelled."migth". that tells me that is not an alert from security essentials..but a fake... it's the Ruskies at it again.. it is red after all!
I haven't rcvd these messages... but have been experiencing some big slow downs on this old computer... Firefox quit working, deleted it.... that sped up chrome, which I'm now using.
I noticed in my processes, when the slow down returns, that a MS "something" cranks way up in CPU usage. Not related to here.... Some other forums I'm on report massive daily attacks... so much so.. one forum recently changed their software package out to run the forum... any way... it's happening all over more intensely.. it seems to me.. CHEERS! Keep your tip up and your line tight! Limits of clams last Tues! Easy pickins!
"Fish Hard and Fish Often!"
Re: Aaron, Might want to think about a scan on the servers.
Anyone still seeing this as of this morning? I've received a few complaints via email about it, but I can no longer reproduce the problem. My hope is that is was in fact being delivered via a banner ad exploit and the publisher of the ad has cleaned their systems. I've done everything I can on my end to find and remove it, but everything we have comes up as clean.
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
I had it pop up on me Sunday evening. Nothing this morning. It may be a failure to launch but I kill the thread anyway.Aaron wrote:Anyone still seeing this as of this morning? I've received a few complaints via email about it, but I can no longer reproduce the problem. My hope is that is was in fact being delivered via a banner ad exploit and the publisher of the ad has cleaned their systems. I've done everything I can on my end to find and remove it, but everything we have comes up as clean.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
Re: Aaron, Might want to think about a scan on the servers.
It showed on my work computer last night shortly after 3:00 am and on my home computer at about 9:00 am this morning.
The only way for me to get rid of it is killing the thread and doing a computer reboot.
The only way for me to get rid of it is killing the thread and doing a computer reboot.
- The Quadfather
- Rear Admiral One Star
- Posts: 3868
- Joined: Tue May 08, 2007 2:27 pm
- Location: Carkeek Park, North Seattle
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
I've got the same thing, as Bodo's below screen shot. Maybe I will consider a different browser if that is what we are saying will fix the issue? MS doesn't write my checks.

Re: Aaron, Might want to think about a scan on the servers.
Wa Lakes was infected as I had the same problem at home last night. Got out and scanned my machine and it was clean, its the website.
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
Pretty sure it's the AD Banners. Aaron scanned all the servers. 3rd Party content, what can ya do......strider43 wrote:Wa Lakes was infected as I had the same problem at home last night. Got out and scanned my machine and it was clean, its the website.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
Re: Aaron, Might want to think about a scan on the servers.
I just had this happen 5 minutes ago when I tried to login. I just ran the cc cleaner and the malwarebytes last night.
- hewesfisher
- Admiral
- Posts: 1886
- Joined: Sat Apr 28, 2007 8:20 am
- Location: Spangle, WA
Re: Aaron, Might want to think about a scan on the servers.
I know what I'd do....Bodofish wrote:Pretty sure it's the AD Banners. Aaron scanned all the servers. 3rd Party content, what can ya do......

Phil
'09 Hewescraft 20' ProV
150hp Merc Optimax
8hp Merc 4-stroke
Raymarine DS600X HD Sounder
Raymarine a78 MultiFunctionDisplay
Raymarine DownVision
Raymarine SideVision
Baystar Hydraulic Steering
Trollmaster Pro II
Traxstech Fishing System
MotorGuide 75# Thrust Wireless Bow Mount
'09 Hewescraft 20' ProV
150hp Merc Optimax
8hp Merc 4-stroke
Raymarine DS600X HD Sounder
Raymarine a78 MultiFunctionDisplay
Raymarine DownVision
Raymarine SideVision
Baystar Hydraulic Steering
Trollmaster Pro II
Traxstech Fishing System
MotorGuide 75# Thrust Wireless Bow Mount
Re: Aaron, Might want to think about a scan on the servers.
Made a slight change to the AD code this morning. Let me know if it makes any difference.
- Bodofish
- Vice Admiral Three Stars
- Posts: 5407
- Joined: Sun Apr 29, 2007 12:59 pm
- Location: Woodinville
- Contact:
Re: Aaron, Might want to think about a scan on the servers.
So far so good! I've been bouncing back and forth between forums and haven't had it pop up yet. ![ThumbsUp [thumbsup]](./images/smilies/msp_thumbsup.gif)
![ThumbsUp [thumbsup]](./images/smilies/msp_thumbsup.gif)
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!
Re: Aaron, Might want to think about a scan on the servers.
I have had no issues the last 2 days.