Aaron, Might want to think about a scan on the servers.

Having problems with our website? Can't seem to find what you are looking for? Ask your questions here.
User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Fri Jan 31, 2014 2:06 pm

OK so I know this is normally a client side thing and I know for a fact that my machine is not infected and I've just run another scan after killing all the IE process and there are none of the baddies listed on my machine.
One click on the main forum page and the complaint here shows up. It says I've caught a bunch of bad things.... Not so.

http://www.washingtonlakes.com/forum/vi ... =7&t=19632

When I try to X out of the pop up, it launches another IE process. Then win 8.1 asks if I want to allow the script to run...... It's trying to install a root kit or something.
Catching this stuff was my livelihood for many years. Best check your code, it's reaching out in an unfriendly manner.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Fri Jan 31, 2014 2:20 pm

First this pops up:
Image

Then this when you try to X out:

Image

Finally this is the real quarantine:

Image

The listed threats are well known and SC Endpoint is quite familiar with them. It's trying to load something else.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
Aaron
Owner/Engineer
Owner/Engineer
Posts: 1635
Joined: Wed Oct 05, 2011 9:08 pm
Location: Spokane, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by Aaron » Fri Jan 31, 2014 2:31 pm

I really don't know what to do here. An infection is an infection. It's not picky. Either we're infected, and everyone should see something going on, or we're not, in which case I'm inclined to blame the client. At the very least I would expect more than 1 or 2 complaints.

Can you reproduce this on another machine/device? Do you think it's only IE/Windows 8 related? I haven't used IE in... when was Chrome released?

- Aaron
Aaron
Owner/Software Engineer
Image

2009 Hewescraft 20' ProV
2009 Mercury Optimax 150
2012 Tohatsu 8hp 4-stroke
Minn Kota Terrova #80 i-Pilot
Humminbird 959ci HD DI
Baystar Hydraulic Steering
Traxstech Fishing System

User avatar
Aaron
Owner/Engineer
Owner/Engineer
Posts: 1635
Joined: Wed Oct 05, 2011 9:08 pm
Location: Spokane, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by Aaron » Fri Jan 31, 2014 2:33 pm

Alrighty then. It's IE related. I loaded the forum with IE and received the notice. I'll see what I can find. Just another reason to never ever ever use IE.
Aaron
Owner/Software Engineer
Image

2009 Hewescraft 20' ProV
2009 Mercury Optimax 150
2012 Tohatsu 8hp 4-stroke
Minn Kota Terrova #80 i-Pilot
Humminbird 959ci HD DI
Baystar Hydraulic Steering
Traxstech Fishing System

User avatar
needs2hunt
Warrant Officer
Posts: 140
Joined: Wed Sep 05, 2012 6:01 pm

Re: Aaron, Might want to think about a scan on the servers.

Post by needs2hunt » Fri Jan 31, 2014 2:36 pm

firefox ... FTW (for the win)...

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Fri Jan 31, 2014 2:40 pm

Aaron wrote:Alrighty then. It's IE related. I loaded the forum with IE and received the notice. I'll see what I can find. Just another reason to never ever ever use IE.
I would but, when MS pays my salary, they kind of expect us to use IE. For code testing we can use anything but...... If one of the big boys swings through, I don't like answering those kind of questions, right or wrong...... [sad]
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
Aaron
Owner/Engineer
Owner/Engineer
Posts: 1635
Joined: Wed Oct 05, 2011 9:08 pm
Location: Spokane, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by Aaron » Fri Jan 31, 2014 2:48 pm

My fear is that it's Banner ad related... coming through from one of the ad networks. My initial quick scan using Malwarebytes came up with nothing. Security Essentials shows nothing. That tells me there's...... nothing.

- Aaron
Aaron
Owner/Software Engineer
Image

2009 Hewescraft 20' ProV
2009 Mercury Optimax 150
2012 Tohatsu 8hp 4-stroke
Minn Kota Terrova #80 i-Pilot
Humminbird 959ci HD DI
Baystar Hydraulic Steering
Traxstech Fishing System

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Fri Jan 31, 2014 2:54 pm

Aaron wrote:My fear is that it's Banner ad related... coming through from one of the ad networks. My initial quick scan using Malwarebytes came up with nothing. Security Essentials shows nothing. That tells me there's...... nothing.

- Aaron
That is a distinct possibility. On the second pic have a look at the start of the url, definitely not one of yours. =)
I'd almost put money on it being the ADs. Necessary evil but an unpleasant one.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
MarkFromSea
Admiral
Posts: 1934
Joined: Mon Feb 16, 2009 1:38 pm
Location: Kirkland

Re: Aaron, Might want to think about a scan on the servers.

Post by MarkFromSea » Sat Feb 01, 2014 1:55 pm

Hewes had the same issue a few weeks back...
if you look at your captured picture of security essentials alert, the red one, the word "MIGHT" is misspelled."migth". that tells me that is not an alert from security essentials..but a fake... it's the Ruskies at it again.. it is red after all!

I haven't rcvd these messages... but have been experiencing some big slow downs on this old computer... Firefox quit working, deleted it.... that sped up chrome, which I'm now using.

I noticed in my processes, when the slow down returns, that a MS "something" cranks way up in CPU usage. Not related to here.... Some other forums I'm on report massive daily attacks... so much so.. one forum recently changed their software package out to run the forum... any way... it's happening all over more intensely.. it seems to me.. CHEERS! Keep your tip up and your line tight! Limits of clams last Tues! Easy pickins!
"Fish Hard and Fish Often!"

User avatar
Aaron
Owner/Engineer
Owner/Engineer
Posts: 1635
Joined: Wed Oct 05, 2011 9:08 pm
Location: Spokane, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by Aaron » Mon Feb 03, 2014 10:06 am

Anyone still seeing this as of this morning? I've received a few complaints via email about it, but I can no longer reproduce the problem. My hope is that is was in fact being delivered via a banner ad exploit and the publisher of the ad has cleaned their systems. I've done everything I can on my end to find and remove it, but everything we have comes up as clean.
Aaron
Owner/Software Engineer
Image

2009 Hewescraft 20' ProV
2009 Mercury Optimax 150
2012 Tohatsu 8hp 4-stroke
Minn Kota Terrova #80 i-Pilot
Humminbird 959ci HD DI
Baystar Hydraulic Steering
Traxstech Fishing System

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Mon Feb 03, 2014 10:25 am

Aaron wrote:Anyone still seeing this as of this morning? I've received a few complaints via email about it, but I can no longer reproduce the problem. My hope is that is was in fact being delivered via a banner ad exploit and the publisher of the ad has cleaned their systems. I've done everything I can on my end to find and remove it, but everything we have comes up as clean.
I had it pop up on me Sunday evening. Nothing this morning. It may be a failure to launch but I kill the thread anyway.
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
Big D
Moderator
Moderator
Posts: 1464
Joined: Wed Nov 05, 2008 8:20 pm
Location: Waterville

Re: Aaron, Might want to think about a scan on the servers.

Post by Big D » Mon Feb 03, 2014 7:15 pm

It showed on my work computer last night shortly after 3:00 am and on my home computer at about 9:00 am this morning.
The only way for me to get rid of it is killing the thread and doing a computer reboot.

User avatar
The Quadfather
Rear Admiral One Star
Posts: 3868
Joined: Tue May 08, 2007 2:27 pm
Location: Carkeek Park, North Seattle
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by The Quadfather » Mon Feb 03, 2014 11:06 pm

I've got the same thing, as Bodo's below screen shot. Maybe I will consider a different browser if that is what we are saying will fix the issue? MS doesn't write my checks. :-"

Bodofish wrote:First this pops up:
Image

Then this when you try to X out:

Image

Finally this is the real quarantine:

Image

The listed threats are well known and SC Endpoint is quite familiar with them. It's trying to load something else.

User avatar
strider43
Captain
Posts: 620
Joined: Mon Dec 06, 2010 12:29 pm
Location: Gold Bar, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by strider43 » Tue Feb 04, 2014 6:32 am

Wa Lakes was infected as I had the same problem at home last night. Got out and scanned my machine and it was clean, its the website.

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Tue Feb 04, 2014 6:34 am

strider43 wrote:Wa Lakes was infected as I had the same problem at home last night. Got out and scanned my machine and it was clean, its the website.
Pretty sure it's the AD Banners. Aaron scanned all the servers. 3rd Party content, what can ya do......
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
AJ's Dad
Commodore
Posts: 992
Joined: Fri Apr 03, 2009 6:34 am
Location: Millwood Wa.

Re: Aaron, Might want to think about a scan on the servers.

Post by AJ's Dad » Tue Feb 04, 2014 6:51 am

I just had this happen 5 minutes ago when I tried to login. I just ran the cc cleaner and the malwarebytes last night.

User avatar
hewesfisher
Admiral
Posts: 1886
Joined: Sat Apr 28, 2007 8:20 am
Location: Spangle, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by hewesfisher » Tue Feb 04, 2014 7:01 am

Bodofish wrote:Pretty sure it's the AD Banners. Aaron scanned all the servers. 3rd Party content, what can ya do......
I know what I'd do.... :-"
Phil

'09 Hewescraft 20' ProV
150hp Merc Optimax
8hp Merc 4-stroke
Raymarine DS600X HD Sounder
Raymarine a78 MultiFunctionDisplay
Raymarine DownVision
Raymarine SideVision
Baystar Hydraulic Steering
Trollmaster Pro II
Traxstech Fishing System
MotorGuide 75# Thrust Wireless Bow Mount

User avatar
Aaron
Owner/Engineer
Owner/Engineer
Posts: 1635
Joined: Wed Oct 05, 2011 9:08 pm
Location: Spokane, WA

Re: Aaron, Might want to think about a scan on the servers.

Post by Aaron » Tue Feb 04, 2014 7:21 am

Made a slight change to the AD code this morning. Let me know if it makes any difference.
Aaron
Owner/Software Engineer
Image

2009 Hewescraft 20' ProV
2009 Mercury Optimax 150
2012 Tohatsu 8hp 4-stroke
Minn Kota Terrova #80 i-Pilot
Humminbird 959ci HD DI
Baystar Hydraulic Steering
Traxstech Fishing System

User avatar
Bodofish
Vice Admiral Three Stars
Posts: 5407
Joined: Sun Apr 29, 2007 12:59 pm
Location: Woodinville
Contact:

Re: Aaron, Might want to think about a scan on the servers.

Post by Bodofish » Tue Feb 04, 2014 11:47 pm

So far so good! I've been bouncing back and forth between forums and haven't had it pop up yet. [thumbsup]
Build a man a fire and he's warm for the night. Light a man on fire and he's warm the rest of his life!

User avatar
AJ's Dad
Commodore
Posts: 992
Joined: Fri Apr 03, 2009 6:34 am
Location: Millwood Wa.

Re: Aaron, Might want to think about a scan on the servers.

Post by AJ's Dad » Thu Feb 06, 2014 6:34 am

I have had no issues the last 2 days.

Post Reply