Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-08-2010, 10:27 AM   #1
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Another exploit on a GFY banner?

I just refreshed a page and got infected by one of those Windows security alert viruses. Remember that from a few months ago? I was only surfing GFY and on DroidDoes.com
a Verizon site I assume.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 10:51 AM   #2
Nikki_Licks
Confirmed User
 
Nikki_Licks's Avatar
 
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
Wonderful! I went through this last time...what a pain in the arse.

Thanks for the heads up
__________________
Amateur Content
ICQ: 292 356 077
Nikki_Licks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 11:01 AM   #3
GetSCORECash
Confirmed User
 
GetSCORECash's Avatar
 
Industry Role:
Join Date: Mar 2008
Location: Miami
Posts: 5,527
Thanks jim, luckly I'm not on IE.
__________________
| skype: getscorecash | ICQ: 59-271-063 |
New Sites: | SCORELAND2 | Roku Channel SCORETV.TV | 60PLUSMILFS |
| Big Tit Hooker | Tits And Tugs | Big Boobs POV | Karla James |
| Naughty Foot Jobs | Linsey's World | Busty Arianna Sinn | Get SCORE Cash |
GetSCORECash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 11:07 AM   #4
DBS.US
Geo Cities
 
DBS.US's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: North Captiva Island, Florida USA
Posts: 11,835
Next time, think Mac
__________________
Make a Free Chaturbate White Label site in 34 minutes and be making money tonight

DBS.US is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 11:10 AM   #5
erooup
Confirmed User
 
erooup's Avatar
 
Industry Role:
Join Date: Jul 2010
Posts: 512
For all those of you that want to see what is going on on the different sites you visit, I can highly recommend you try Fiddler
http://msdn.microsoft.com/en-us/libr...46(VS.85).aspx

It's also a great tool to track where and how the dodgy affiliates redirect their traffic. This tool have saved me hours of work, when catching and investigating fraud amont affilates.

Last edited by erooup; 08-08-2010 at 11:12 AM..
erooup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 11:19 AM   #6
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
No one else got infected yet? I use FireFox and this is the second time assuming I did pick that up here today. Thinking about switching to Chrome next to see if that is safer.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 11:35 AM   #7
area51 - BANNED FOR LIFE
So Fucking Banned
 
Join Date: Aug 2009
Posts: 3,164
you were more than likely already infected.
area51 - BANNED FOR LIFE is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 12:37 PM   #8
bolsex
Confirmed User
 
bolsex's Avatar
 
Industry Role:
Join Date: May 2002
Posts: 717
Avira detected and deleted it too when I opened a thread!
bolsex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 12:44 PM   #9
2MuchMark
Videochat Solutions
 
2MuchMark's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Canada
Posts: 49,507
Quote:
Originally Posted by DBS.US View Post
Next time, think Mac
__________________

Custom Coding | Videochat Solutions | Age Verification | IT Help & Support
www.2Much.net
2MuchMark is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:07 PM   #10
Nikki_Licks
Confirmed User
 
Nikki_Licks's Avatar
 
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
Quote:
Originally Posted by Jim_Gunn View Post
No one else got infected yet? I use FireFox and this is the second time assuming I did pick that up here today. Thinking about switching to Chrome next to see if that is safer.
Fire fox here and don't have any problems ;)
I also run Nod32....
__________________
Amateur Content
ICQ: 292 356 077
Nikki_Licks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:28 PM   #11
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Quote:
Originally Posted by bolsex View Post
Avira detected and deleted it too when I opened a thread!
Thanks for the confirmation. I use AVG but will switch to Avira next if that is the case. I am too entrenched in Windows to go MAC. But switching anti-virus and browsers after I clean this up is definitely in order.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:28 PM   #12
kektex
Confirmed User
 
Industry Role:
Join Date: Mar 2005
Location: elkektex at gmail
Posts: 1,813
Adblock + Noscript.
I know an affiliate webmaster shouldn't be recommending this but unfortunately it's the safest way to surf.
kektex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:29 PM   #13
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Quote:
Originally Posted by Nikki_Licks View Post
Fire fox here and don't have any problems ;)
I also run Nod32....
What is Nod32?
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:36 PM   #14
HAPPYPEEKERS
Confirmed User
 
HAPPYPEEKERS's Avatar
 
Industry Role:
Join Date: Feb 2004
Location: Margaritaville
Posts: 7,562
My micro trend picked it up as well.
__________________
Please Read All Of My Posts In A Sarcastic Tone So You Get The Full Effect!!



HappyPeekers - April
HAPPYPEEKERS is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 01:37 PM   #15
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
What specifically is it detecting -- what does it call it -- as much info as possible please including filename and/or registry key if present.

I recommend (in order of preference):

1. Linux (http://linux.org, http://ubuntu.com)
2. Mac
3. Firefox with NoScript (Ad block plus optional) + Microsoft Security Essentials + MalwareBytes Anti-Malware (to scan when infected)
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 04:44 PM   #16
Tjeezers
Webmaster
 
Tjeezers's Avatar
 
Industry Role:
Join Date: Mar 2007
Location: BP4L - NL/RO
Posts: 16,588
Quote:
Originally Posted by Jim_Gunn View Post
What is Nod32?
http://www.eset.com/
that will answer it
__________________
Enroll in the SWAG Affiliate Asian Live Cam Program and get 9 free quality linkbacks from my network!
Wanna see how old school I am? Look at this! All my Cam Review Sites are here.
Tjeezers is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 04:51 PM   #17
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Mods: Please take note of this thread with two confirmations. I wish that I could give more details about the infection. But I have anti-spyware running in safe mode now including Mal-Ware Bytes. It pops up the fake critical stop messages saying your pc is infected. Similar to the last banner exploit. I am real annoyed with FireFox and AVG for not catching this!
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 05:48 PM   #18
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
I just lost 2 days fixing the same damn virus with Avast, Avira, Spybot and super antispyware running.

Was only able to fix it booted of a repair disk from Avira. Every other repair never got to the root of the problem.

2 fucking days lost. I want to kill whoever did this.

Why the fuck can't this board scan and kill any issues before we get infected?

Last edited by suesheboy; 08-08-2010 at 05:55 PM..
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 05:54 PM   #19
SallyRand
So Fucking Banned
 
Industry Role:
Join Date: Jan 2008
Location: In A Galaxie Far, Far Away!
Posts: 3,487

Hate to write it but I told you so! And was promptly pilloried as a idiot by "certain" GFY members.

I posted a thread on this very matter here:

https://gfy.com/showthread.php?t=980103

which thread includes the domain, the host and the IP of the attacking source as well as several threads on which the attack was occurring.

Sally.
SallyRand is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 06:04 PM   #20
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Quote:
Originally Posted by SallyRand View Post
Hate to write it but I told you so! And was promptly pilloried as a idiot by "certain" GFY members.

I posted a thread on this very matter here:

https://gfy.com/showthread.php?t=980103

which thread includes the domain, the host and the IP of the attacking source as well as several threads on which the attack was occurring.

Sally.
Interesting read.

If they don't get this fixed fast they can color me gone.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 07:07 PM   #21
2012
So Fucking What
 
2012's Avatar
 
Industry Role:
Join Date: Jul 2006
Posts: 17,189
sally and papillon

what happened ?
2012 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 07:24 PM   #22
pornpf69
Too lazy to set a custom title
 
pornpf69's Avatar
 
Join Date: Jun 2004
Location: Brasil
Posts: 15,778
that is why I only come to GFY when I am on UBUNTU...
pornpf69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-08-2010, 09:30 PM   #23
Ron Bennett
Confirmed User
 
Join Date: Oct 2003
Posts: 1,653
Still no real details of the actual exploit ... is it really a serious threat? ... is it really coming through GFY's ad server?... or maybe is coming through from an embedded image in some posts / user signatures - that has been documented happening numerous times in the past.

Ron
__________________
Domagon - Website Management and Domain Name Sales
Ron Bennett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 08:12 AM   #24
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Quote:
Originally Posted by Ron Bennett View Post
Still no real details of the actual exploit ... is it really a serious threat? ... is it really coming through GFY's ad server?... or maybe is coming through from an embedded image in some posts / user signatures - that has been documented happening numerous times in the past.

Ron
I am accessing GFY from a different pc now using No Script & Adblock Plus in FF for protection while I try and get rid of the "Windows Security" malware on my laptop. I do recall what thread I was reading however. It was 'Best Android Phone". maybe some one else can check that one and see if any more alerts pop up on your secured browser.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 08:27 AM   #25
Nathan
Confirmed User
 
Industry Role:
Join Date: Jul 2003
Posts: 3,108
Wonder why so many including myself have no problems....

Then again, I have never used anti virus apps and never had a problem... Makes you wonder....
__________________
"Think about it a little more and you'll agree with me, because you're smart and I'm right."
- Charlie Munger
Nathan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 09:37 AM   #26
Nikki_Licks
Confirmed User
 
Nikki_Licks's Avatar
 
Join Date: May 2005
Location: Behind The Lens
Posts: 6,323
Quote:
Originally Posted by Tjeezers View Post
http://www.eset.com/
that will answer it
Thanks, apologies for the late reply, Jim ;)

http://www.eset.com/search-brand?CMP...FcZh2godlm4chg
__________________
Amateur Content
ICQ: 292 356 077
Nikki_Licks is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 11:50 AM   #27
BarryP
Confirmed User
 
BarryP's Avatar
 
Industry Role:
Join Date: Oct 2002
Posts: 145
So far I am unable to duplicate this. What browser/version and AV are you guys running?
__________________
Who will be the next MissGFY?!
Attention Industry Females & Solo Girls - Register Now for MissGFY Q4


GoFuckYourself.com
Have a Suggestion? Issue? Interested in Advertising? Contact me!
Barryp AT adult.com | icq 559539603
BarryP is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 12:12 PM   #28
Roald
SecretFriends.com
 
Roald's Avatar
 
Industry Role:
Join Date: May 2001
Location: IMC Headquarters
Posts: 27,889
Quote:
Originally Posted by Nathan View Post
Wonder why so many including myself have no problems....

Then again, I have never used anti virus apps and never had a problem... Makes you wonder....
I blame tubes!

oh wait ;)))
__________________


WE ARE BUYING PAY SITES! CONTACT ME



ClubSweethearts | ManUpFilms | SinfulXXX | HOT * AdultPrime * HOT


Paying webmasters since 1996! Contact: r.riepen @ sansylgroup.com | telegram: roaldr
Roald is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 01:17 PM   #29
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Quote:
Originally Posted by BarryP View Post
So far I am unable to duplicate this. What browser/version and AV are you guys running?
Thanks for looking into it. I don't know how the hell so many others are not affected by this instead of just three or four of us Windows users. It was something in the "Best Android Phone' thread this time. I got an immediate infection like I had no protection at all. I use Win XP SP3, FF 3.6.3 and AVG antivirus. Plus I run Windows Defender and Ad-Aware too.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 01:23 PM   #30
candyflip
Carpe Visio
 
candyflip's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,064
I have blocked all ads and scripts while surfing GFY. Sucks for people paying to advertise, but the last exploit that loaded here cost me two days of fucking around to get my PC back.
__________________

Spend you some brain.
Email Me
candyflip is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 01:52 PM   #31
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Quote:
Originally Posted by candyflip View Post
I have blocked all ads and scripts while surfing GFY. Sucks for people paying to advertise, but the last exploit that loaded here cost me two days of fucking around to get my PC back.
Same here! On a business board like this I actually like to see the ads and banners so I can see who is spending money, and doing business and what they are promoting. I just finally removed (I hope) the exploit after a half dozen scans & reboots later and wasting the better part fo two days using a few tools including Malware Bytes, AVG anti-virus, TDSS rootkit killer,& Spybot Search & Destroy as well as manually going through my Windows/System 32 folder to remove all the newer .exe & dlls that had a date created yesterday. I am now using FF with No Script & Adblock Plus. I really have no idea why my system is so easily infected when I run an updated Win XP SP3, updated AVG anti-virus, Spybot-SD resident real time protection, Windows Defender and Ad-Aware.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 02:36 PM   #32
SallyRand
So Fucking Banned
 
Industry Role:
Join Date: Jan 2008
Location: In A Galaxie Far, Far Away!
Posts: 3,487
:2cents

I am running Firefox 3.6.8, which is the latest version, Adaware, Spybot, AVG, Malwarebytes, Windows Defender, Zone Alarm and frequently run Windows Security Essentials. I update frequently, some daily. Using Windows Vista Home Premium With SP on this box. Same programs on my laptops.

There are some recent updates to Adobe which close some holes well-known to attackers. I also keep my firewall settings way up there.

I never use IE.

I think perhaps if you take a look at my first thread on the matter, to which I linked in this thread and then compare it to the threads mentioned by other users, you might be able to pin down the source of the attacks or at least get close to the perp.

'den when you find him/her we keel 'dem an' we don' need no stinking badges!

LOL!

Sally.

Last edited by SallyRand; 08-09-2010 at 02:38 PM..
SallyRand is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 05:33 PM   #33
DirtyJs
So Fucking Banned
 
Join Date: Sep 2006
Location: Illinois
Posts: 307
they need to host the ads locally so that people can't change them out on the fly.
DirtyJs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-09-2010, 08:19 PM   #34
Jim_Gunn
Confirmed User
 
Industry Role:
Join Date: Feb 2003
Location: Where The Teens Are
Posts: 5,702
Wow, this malware is really insidious. I thought I had caught it all since the notifications that lock up your screen and task manager are gone. But now hours later it tried launching an installer out of system restore and luckily AVG caught it. I also saw that it had added custom proxy settings to FF & IE/Chrome. Plus there were several suspicious scheduled tasks added to the windows scheduler that most people don't even pay attention to. The malware itself is not active yet sending me messages and locking up my screen but a scan with malware bytes just caught new infections I am deleting all restore points & temp files and running the anti- virus, spyware and & rootkit apps again before I reboot my laptop.
Jim_Gunn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2010, 04:59 AM   #35
SallyRand
So Fucking Banned
 
Industry Role:
Join Date: Jan 2008
Location: In A Galaxie Far, Far Away!
Posts: 3,487
:mad Yet Another Attempted Attack

occurred on this thread:

https://gfy.com/showthread.php?t=981873

Info on IP and associated site and hosting:

67.220.140.58

67.220.140.58 - Geo Information
IP Address 67.220.140.58
Host 67.220.140.58
Location US US, United States
City Stockton, CA 95219
Organization DENIRO MARKETING, LLC.
ISP WBS CONNECT, LLC
AS Number AS14576
Latitude 38°01'99" North
Longitude 121°38'06" West
Distance 10357.98 km (6436.15 miles)

I KEEL DEEZ MOTHYFUCKER AN I DON' NEED NO STEENKEENG BADGES!

Figure it out people!

Sally.
SallyRand is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2010, 05:16 AM   #36
erooup
Confirmed User
 
erooup's Avatar
 
Industry Role:
Join Date: Jul 2010
Posts: 512
Quote:
Originally Posted by Jim_Gunn View Post
Wow, this malware is really insidious. I thought I had caught it all since the notifications that lock up your screen and task manager are gone. But now hours later it tried launching an installer out of system restore and luckily AVG caught it. I also saw that it had added custom proxy settings to FF & IE/Chrome. Plus there were several suspicious scheduled tasks added to the windows scheduler that most people don't even pay attention to. The malware itself is not active yet sending me messages and locking up my screen but a scan with malware bytes just caught new infections I am deleting all restore points & temp files and running the anti- virus, spyware and & rootkit apps again before I reboot my laptop.
ALWAYS disable your system restore as step #1, when removing malware.
erooup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2010, 06:11 AM   #37
rogueteens
So fucking bland
 
rogueteens's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: England
Posts: 8,005
I had a virus warning from GFY last night too, unfortunately i didnt keep the details.
__________________
Free traffic and backlinks from one of the fastest growing adult pinsites on the net - SAUCY PICTURES!
Easily my best performing webcam sponsor - CLICK HERE!!
rogueteens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-11-2010, 06:18 AM   #38
Nicky
Too lazy to set a custom title
 
Nicky's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: Sweden
Posts: 30,070
I got this shit yesterday, took a nice 2-3 hours of my time to go safe mode and delete everything in registry etc and then run nod32 and spyware doctor.
__________________

gfynicky @ gmail.com
Nicky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.