republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
12942
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3 · 4
AuthorAll Replies

chris_j11

join:2003-01-10
canada

virus/spyware: divxturka.net

i've been visiting this website for months and no problem
last night, i got a warning from chrome that the website was malicious
i continued on and end up with "SecurityTools" spyware

initially i remember Java 6 gui floating on top of the site and all the sudden - virus/spyware

how did i get it and how to prevent it
i still want to use the website


Rocky67
Pencil Neck Geek
Premium
join:2005-01-13
Orange, CA
Reviews:
·AT&T Yahoo

You got it because you ignored a warning. You can prevent it in future by not continuing to ignore warnings. Meanwhile, you might want to visit »Security Cleanup
--
Pain is weakness leaving the body



La Luna
Survived Ashraful
Premium
join:2001-07-12
Warwick, NY
kudos:3
Reviews:
·Vonage
·Optimum Online

reply to chris_j11

said by chris_j11:

how did i get it and how to prevent it
i still want to use the website
You got it by "continuing on". Why would you do that? And why would you want to continue using a malicious website?

You can prevent it by staying away and by not ignoring warnings in the future.
--
The Alien in the White House

15,737 DEADLY TERROR ATTACKS SINCE 9/11

neftv

join:2000-10-01
Broomall, PA

reply to chris_j11
I have the paid version of Malwarebytes operating on the taskbar and it blocks that domain.


chris_j11

join:2003-01-10
canada

reply to chris_j11
yes, i did ignore the warning
i didn't think to much of it since i've been using the website for a few months now and i just got the virus last night

can i still visit the website w/o getting virus
firefox + noscript + adblock + flashblock + microsoft security essential?


neftv

join:2000-10-01
Broomall, PA
Reviews:
·SIP Global Phone
·QuantumVoice
·Verizon FiOS

I wonder if you could use something like Comodo Firewall or something similar which has a sandbox and running IE in the sandbox trying to get to that site.
Maybe that site became infected recently too. My Malwarebytes just wants to block that site.



BlitzenZeus
Burnt Out Cynic
Premium
join:2000-01-13
kudos:2
Reviews:
·Frontier FiOS

reply to chris_j11
If your browser is running as a full admin you should know better. You need to run it as a limited user, or have UAC(Vista/Win7) enabled properly to prevent things like this.

The plugins are commonly targeted for exploits, and so are the browsers so it's good to make sure those are up to date.

No anti-software is perfect, and they can only detect a finite number of patterns, which can also lead to false positives. So you cannot depend on them to protect you from your own actions.
--
My hourly rates:
$25 per hour.
$35 per hour if you want to watch.
$45 per hour if you want to help.
$75 per hour if you tried to fix it, and failed.
Security through obscurity is for the ignorant who don't deserve security.



beck
Premium,MVM
join:2002-01-29
On The Road
kudos:1
Reviews:
·Stablehost.com
·AllureHost

reply to chris_j11

said by chris_j11:

yes, i did ignore the warning
i didn't think to much of it since i've been using the website for a few months now and i just got the virus last night

can i still visit the website w/o getting virus
firefox + noscript + adblock + flashblock + microsoft security essential?
This sounds like a serious addiction problem.
--
Some people are like slinkies - not really good for much.
But they bring a smile to your face when pushed down the stairs.


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17

reply to chris_j11
»Security Cleanup FAQ »Mandatory Steps Before Requesting Assistance



TheJoker
Premium,VIP,MVM
join:2001-04-26
Alexandria, VA
kudos:5

reply to chris_j11
One thing I'd like to point out, is that from the user standpoint, there is essentially no such thing as a trusted site. Sites get hacked; they may have been vulnerable and someone may have inserted a malicious script onto the site, or it simply may have ads provided by a second party, and an ad might be infected. Many people have been infected when that happens on legitimate sites because they trusted them, and continued on despite warnings from a browser or even their security software. Help sites that assist users with problems have been infected, and even the NY Times has had users infected through a malicious ad. You should never add a site to your Trusted Sites list unless functionality there is broken with it being there, and I'd recommend browsing with FireFox with the AdBlock Plus and NoScript add-ons installed, and be very stingy with NoScript in the sites that you do allow.
--
Proud ASAP member since 2005
Microsoft MVP/Consumer Security 2009-2010


fenix_jn

join:2006-12-28
Miami, FL

reply to chris_j11
Kaspersky allowed the site to load BUT it did freak out when I tried to access: hxxp://www.uppdapa.co.cc/prot.php which is visible if you look at the source code.

Yes you can still use your site but keep NoScript on


mysec
Premium
join:2005-11-29
kudos:4

reply to chris_j11

said by chris_j11:

initially i remember Java 6 gui floating on top of the site and all the sudden - virus/spyware

how did i get it

If you didn't click to install something, then it installed by remote code execution (drive-by download).

and how to prevent it

Most of these exploits install an executable file. so to have execution prevention of some type will block the download of the payload:




i still want to use the website

Not too advisable without protection better than what you have now.


----
rich

Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

1 edit

reply to chris_j11
I went there on Vista Ultimate on Firefox 3 using the Proxomitron, Avast5, WinPatrol, and OA++ and I got NO warnings, no infections. I looked around at some forums and threads. The ONLY problem I had was that is an EXTREMELY SLOW site. It was very slow to load initially (almost 30 seconds) and then each page took FOREVER to load. But other than that, I sure didn't see any malware there.

So, either the malware comes from an ad there which Proxo filters out or only IE gets infected. If Java is involved, I have an older version of Java 1.6.0_5 yet I didn't get any Java window there.

--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


redwolfe_98
Premium
join:2001-06-11
kudos:1

reply to chris_j11
i went to the website but i didn't see anything when i went there.. i am using firefox 3.6.8 with "noscript" and "adblock plus"..

i am guessing that the problem involved an "iframe" which was blocked by "noscript", which was why i didn't see anything when i went to the website..

i didn't try lowering my security-settings to see what would happen..

in the original post, i am curious about "chrome's" giving a warning for the website (?)..



ashrc4
Premium
join:2009-02-06
australia

2 edits

reply to chris_j11

said by chris_j11:

i've been visiting this website for months and no problem
i still want to use the website
The site contains illegal content/cracks/links to malware.
Even if you could traverse the site your more than likely going to infect your self with some of the content.
End of advice.
--
Paradigm Shift beta test pilot. So far nothing to report.
Now is the not right time to stop folding.


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

2 edits

reply to chris_j11

NOD32 Flagged
JS/TrojanDownloader.HackLoad.AA trojan
the site is going in my Hosts file.

 
Pinging divxturka.net [127.0.0.1] with 32 bytes of data:
 
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms 
 


Drunkula
Premium
join:2000-06-12
Denton, TX
Reviews:
·Verizon FiOS

reply to chris_j11
»www.google.com/safebrowsing/diag···urka.net

Odd. Google Safebrowsing doesn't currently have it listed as suspicious though it has before... Sounds like they need an update!
--
There are 10 types of people that understand binary numbers. Those that do - and those that do not...



siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17

URL void shows the same, so much for reputation based sites
»www.urlvoid.com/scan/divxturka.net


GuruGuy

join:2002-12-16
Atlanta, GA

reply to chris_j11

said by chris_j11:

i've been visiting this website for months and no problem
last night, i got a warning from chrome that the website was malicious
i continued on and end up with "SecurityTools" spyware

initially i remember Java 6 gui floating on top of the site and all the sudden - virus/spyware

how did i get it and how to prevent it
i still want to use the website
Warning from "Chrome". Were you using the Google Chrome Browser when this occurred?
--
GuruGuy

NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
kudos:4

reply to chris_j11
Patient: "It hurts when I do "that"".
Doctor: "Don't do "that""!.

page: 1 · 2 · 3 · 4

Friday, 01-Jun 21:01:56 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics