View Full Version : Anyone else get virus warnings from rf.net today?
angrymissy
12-04-2006, 01:32 PM
<p><font size="2">When I loaded the index page today, my AV popped up warnings about a downloader trojan.</font></p><p><font size="2"> Then when the site was down earlier, I got another warning and IE seemed to be trying to download from <font face="Arial">81.95.146.133.</font></font></p><p><font face="Arial" size="2">Did this happen to anyone else or is my computer just fucked?</font></p>
suggums
12-04-2006, 01:33 PM
i didnt notice anything different, i hope i didnt get infected
<font color="Navy"><font size="2">That happened with me too, downloading from that IP address. No Anti-virus warnings though.</font></font>
<span class=post_edited>This message was edited by HBox on 12-4-06 @ 5:34 PM</span>
BrentfromTN1
12-04-2006, 01:34 PM
I got the same error/virus message today for a while as well. That is strange.
TheMojoPin
12-04-2006, 01:34 PM
<p>EXCELLENT.</p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p>Seriously, I didn't get that. I just got a "SERVICE IS UNAVAILABLE" message in my browser.</p>
Wallower
12-04-2006, 01:36 PM
<p>I didn't get that, but I did get the dreaded "Service Unavailable".</p><p>Mikeyboy! Don't let this happen next time you go in studio. We need to have our cake and step on it too.</p>
JustJon
12-04-2006, 01:36 PM
hmmm... that might explain some things. I'll have to look at that when I get home. I run AVG, so I don't get those popups.
EliSnow
12-04-2006, 01:36 PM
<font face="arial,helvetica,sans-serif" size="3">I got some virus warnings as well.</font>
Hottub
12-04-2006, 01:39 PM
I got a virus warning. Trying to get a "Downloader Trojan."
jetdog
12-04-2006, 01:39 PM
Yup, virus warning for me. Symantec says its quarentined, whatever that means.<br />
<font face="comic sans ms,sand" size="2">Yup, it's happening to me too. It is my Spyware Sweeper that is giving me the warnings though.</font>
Bulldogcakes
12-04-2006, 01:41 PM
<p>I got the Site unavailable, and I just ran a disk cleanup and had a shitload of bugs and cookies. To the point where my whole system slowed down. </p><p>I'm also getting some weird text (HTML code?) just before the site opens, and it opens much slower than it used to, even after the cleanup. Takes a good 4 seconds to get to the main page and open some threads. </p>
HeyGuy
12-04-2006, 01:42 PM
everytime I access a topic I have been getting a popup from my antivirus telling me they caught something and to reboot to permanatly delete it.
EliSnow
12-04-2006, 01:43 PM
<font face="arial,helvetica,sans-serif" size="3">I just got it again. </font>
angrymissy
12-04-2006, 01:44 PM
<p>I noticed really quickly that it was trying to DL from that listed IP, google turns up</p><p><a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-072610-0431-99&tabid=2"><font color="#0000cc">Downloader.Traus - Symantec.com</font></a></p><p>AV says that the its infecting index.htm which I suppose is being saved in my cache. Running full AV/Spyware check now</p><p>OMG DID WE GET HAX0RED??? OH NOEEEEEEESSSSSSS</p>
Fezticle98
12-04-2006, 01:47 PM
<p>Same thing here.</p><p>Fez's revenge?</p>
Hottub
12-04-2006, 02:01 PM
<p>I'm going to log off now.</p><p>Run NAV and Spysweeper.</p><p>I'll report back with what I come up with. Right now it is sluggish and I still get the occasional code at the top of the page.</p>
Marc with a c
12-04-2006, 02:03 PM
Anyone on suicide watch for stu and reilly? I hope they are okay after that.
PhishHead
12-04-2006, 02:15 PM
some newbie could have put a virus in their sig pic
Alice S. Fuzzybutt
12-04-2006, 02:21 PM
I actually had trouble accessing the site all weekend.
Don Stugots
12-04-2006, 02:22 PM
<strong>Marc with a c</strong> wrote:<br />Anyone on suicide watch for stu and reilly? I hope they are okay after that.<p> thanks for worring about me sweety. it was rough but i made it. i did some work and then drove home. i hope Reilly is ok. </p>
<span class=post_edited>This message was edited by STUGOTS1 on 12-4-06 @ 6:28 PM</span>
reillyluck
12-04-2006, 02:25 PM
<strong>Marc with a c</strong> wrote:<br />Anyone on suicide watch for stu and reilly? I hope they are okay after that. <p>i managed to stick with my old habit in the meantime. myspace.com</p><p> </p><p>thanks for caring Marc!!! you notice Stu mentioned NOTHING about if i was ok though...lol </p>
angrymissy
12-04-2006, 02:27 PM
maybe this has something to do with the crap on the top of the page
reillyluck
12-04-2006, 02:27 PM
<strong>angrymissy</strong> wrote:<br />maybe this has something to do with the crap on the top of the page <p>i seen that too. happening since yesterday</p>
Don Stugots
12-04-2006, 02:28 PM
<strong>reillyluck</strong> wrote:<br /><strong>Marc with a c</strong> wrote:<br />Anyone on suicide watch for stu and reilly? I hope they are okay after that. <p>i managed to stick with my old habit in the meantime. myspace.com</p><p> </p><p>thanks for caring Marc!!! you notice Stu mentioned NOTHING about if i was ok though...lol </p><p> you sure about that? i would double check my facts if i was you madame. </p>
reillyluck
12-04-2006, 03:40 PM
<strong>STUGOTS1</strong> wrote:<br /><strong>reillyluck</strong> wrote:<br /><strong>Marc with a c</strong> wrote:<br />Anyone on suicide watch for stu and reilly? I hope they are okay after that. <p>i managed to stick with my old habit in the meantime. myspace.com</p><p> </p><p>thanks for caring Marc!!! you notice Stu mentioned NOTHING about if i was ok though...lol </p><p> you sure about that? i would double check my facts if i was you madame. </p><p><img src="/messageboard/tiny_mce/plugins/emotions/images/lol.gif" border="0" width="20" height="20" /> ahhh....how i love thee!</p><p> </p>
furie
12-04-2006, 03:47 PM
http://i5.photobucket.com/albums/y178/furie1335/pics/logo_apple.jpg
JustJon
12-04-2006, 04:00 PM
folks, those who got the message, are you on firefox or ie?
PhishHead
12-04-2006, 04:02 PM
I did not get it on Firefox at home, but got it multiple times at work on IE
Hottub
12-04-2006, 04:11 PM
IE of course. The hackers love that browser.
reillyluck
12-04-2006, 04:14 PM
i was on IE jon.
JustJon
12-04-2006, 04:16 PM
ok, so somehow an activex thinger is the culprit
<p><font face="comic sans ms,sand" size="3">I am running Slimbrowser and I get the test at the top and the Spysweeper popup once in a while but not always.</font></p>
<p>I always have to close out my browser and open it again whenever I go to the Chat Room because it causes multiple fuck ups. </p><p>Could it have anything to do with recent problems on the board or are they two seperate entities? </p>
cougarjake13
12-04-2006, 04:25 PM
<p>its not there anymore but for the last day or two at the top of the messageboard topics page there was a bunch of code about three lines long from left to right</p><p>it all looked like mumbo jumbo to me but it did kinda look like java scrpit of some kind</p><p>and then i got the service unavailable page</p>
I've been getting the exact same thing for the past two days, cougarjake.
FUNKMAN
12-04-2006, 04:29 PM
yes... so i put a condom over my monitor
MadMatt
12-04-2006, 04:30 PM
<strong>PhishHead</strong> wrote:<br />I did not get it on Firefox at home, but got it multiple times at work on IE <p>Multiple times at work using Ie 6 and Symantec (NAV07). Running IE 6 and AVS at home, so no messages.</p>
<span class=post_edited>This message was edited by MadMatt on 12-4-06 @ 8:32 PM</span>
PhishHead
12-04-2006, 04:53 PM
<p>this is the message i get at the very top of the website on firefox:</p><p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 01:51:23 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!-- whois.cfm --> <!-- includes/queries/qry_checkmemberoptions.cfm --> </p>
Reephdweller
12-04-2006, 05:04 PM
Yeah since yesterday when I load the site spysweeper has been going nuts. None of my AV apps Norton or AVG reported any viruses though.
Snoogans
12-04-2006, 05:07 PM
justjon owes everyone a new computer
JustJon
12-04-2006, 05:39 PM
ok, think I got it, running a second scan to make sure. if you see the text on top or the popup again, let me know.
Don Stugots
12-04-2006, 05:40 PM
<strong>suggums</strong> wrote:<br />i didnt notice anything different, i hope i didnt get infected<p> The Virus is spreading, XM 202<br /> </p>
reillyluck
12-04-2006, 05:41 PM
<strong>JustJon</strong> wrote:<br />ok, think I got it, running a second scan to make sure. if you see the text on top or the popup again, let me know. <p>http://i16.photobucket.com/albums/b9/sccrbunny16/cabbage.gifhttp://i16.photobucket.com/albums/b9/sccrbunny16/cabbage.gifhttp://i16.photobucket.com/albums/b9/sccrbunny16/cabbage.gifhttp://i16.photobucket.com/albums/b9/sccrbunny16/cabbage.gif</p><p>yeah jon. Its ya birfday....we gonna party like its ya birfday!!!</p>
Hottub
12-04-2006, 05:53 PM
<p>Still here.</p><p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 02:51:48 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Set-Cookie: SHOWHOWMANY=25;expires=Thu, 27-Nov-2036 02:51:48 GMT;path=/ Content-Type: text/html; charset=UTF-8 <!-- inbox.cfm --><!-- includes/header.cfm --><!-- includes/siteheader.cfm --></p>
<p>I hate this place!</p><p>I've been here for 5 years!</p><p>Nothing works here!</p><p>I hate this place!</p><p>I've been here for 5 years!</p><p>Nothing works here!</p><p>I hate this place!</p><p>I've been here for 5 years!</p><p>Nothing works here! </p>
angrymissy
12-04-2006, 06:37 PM
<p>AHHHHHH GVAC POST # 6666</p><p><img src="http://i9.photobucket.com/albums/a63/angrymissy/Image1.gif?t=1165289873" border="0" alt="image" width="361" height="330" /></p>
JustJon
12-04-2006, 06:56 PM
<strong>Hottub</strong> wrote:<br /><p>Still here.</p><p> </p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 02:51:48 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Set-Cookie: SHOWHOWMANY=25;expires=Thu, 27-Nov-2036 02:51:48 GMT;path=/ Content-Type: text/html; charset=UTF-8 *-- inbox.cfm -**-- includes/header.cfm -**-- includes/siteheader.cfm -*<p> </p><p> Did you clear your cache?</p>
FUNKMAN
12-04-2006, 06:57 PM
i sprayed lysol but no change
reillyluck
12-04-2006, 07:02 PM
<strong>angrymissy</strong> wrote:<br /><p>AHHHHHH GVAC POST # 6666</p><p><img src="http://i9.photobucket.com/albums/a63/angrymissy/Image1.gif?t=1165289873" border="0" alt="image" width="361" height="330" /></p><p><img src="/messageboard/tiny_mce/plugins/emotions/images/lol.gif" border="0" width="20" height="20" /></p>
Fez4PrezN2008
12-04-2006, 07:15 PM
Hey guys, I am pretty sure I found the problem. Blame it on these <a href="http://www.homestarrunner.com/systemisdown.html">guys</a>...
reillyluck
12-04-2006, 07:33 PM
<strong>Fez4PrezN2008</strong> wrote:<br />Hey guys, I am pretty sure I found the problem. Blame it on these <a href="http://www.homestarrunner.com/systemisdown.html">guys</a>... <p>Thats gotta be the problem!! <img src="/messageboard/tiny_mce/plugins/emotions/images/lol.gif" border="0" width="20" height="20" /></p><p>is it me or am i the only reads fez4prez's posts imagining him to sound like Triumph? its funny. </p>
Fez4PrezN2008
12-04-2006, 07:36 PM
<p>That's good reillyluck....good for me to poop on !! I KEED I KEED ...</p>
foodcourtdruide
12-04-2006, 07:36 PM
I got this virus warning. It got me in trouble at work!
GvacNoMore
12-04-2006, 07:49 PM
<p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 04:47:40 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Set-Cookie: CFID=4177541;domain=.ronfez.net;expires=Thu, 27-Nov-2036 04:47:40 GMT;path=/ Set-Cookie: CFTOKEN=db02a36314546a90-50F04337-CAB0-3D96-C2D17C869486603E;domain=.ronfez.net;expires=Thu, 27-Nov-2036 04:47:40 GMT;path=/ Set-Cookie: SHOWHOWMANY=25;expires=Thu, 27-Nov-2036 04:47:40 GMT;path=/ Content-Language: en-US Content-Type: text/html; charset=UTF-8 </p><p> </p><p> </p><p> Still there...clean cache and all. </p>
<span class=post_edited>This message was edited by GvacNoMore on 12-4-06 @ 11:51 PM</span>
hunnerbun
12-04-2006, 08:09 PM
<p>I just got this on the homepage:</p><p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 05:03:14 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Content-Language: en-US Content-Type: text/html; charset=UTF-8 <!-- includes/header.cfm --><!-- includes/siteheader.cfm --> _uacct = "UA-135237-1"; urchinTracker(); </p><p> </p><p>No virus warnings but the board has been running pretty slow for me the past couple of days too. </p>
FUNKMAN
12-04-2006, 08:43 PM
<p>i cleared the cash and change out of my pockets but no change</p><p><img title="" alt="" src="http://www.ronfez.net/messageboard/tiny_mce/plugins/emotions/images/bye.gif" border="0" /></p><p>what a pain in the balls i am</p>
Kevin
12-04-2006, 08:45 PM
<strong>Fez4PrezN2008</strong> wrote:<br /><p>That's good reillyluck....good for me to poop on !! I KEED I KEED ...</p>Its I JOKE I JOKE I KEED I KEED. <p> </p>
HeyGuy
12-05-2006, 04:55 AM
<p>the site seemed to be down all night. I just got it again when I went to my prefrences on here. my virus scan caught like 5 or 6 viruses quickly and then I got this message at the top of the screen</p><p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 13:50:27 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Content-Type: text/html; charset=UTF-8 <!-- preferences.cfm --><!-- includes/header.cfm --><!-- includes/siteheader.cfm --></p><p> and it also popped up the message below</p><p>This website wants to run the following add on: Microsoft data access - remote data services dat...' if you trust the website and the add on and want to allow it to run click here...</p><p>I did not click because I dont trust it. So whats the deal?</p>
EliSnow
12-05-2006, 05:21 AM
<p><font face="arial,helvetica,sans-serif" size="3">I'm still getting the warnings today. This is what we get when mikey hangs out in the studio with the boys.</font></p>
Hottub
12-05-2006, 05:23 AM
<p>This website wants to run the following add on: Microsoft data access - remote data services dat...' if you trust the website and the add on and want to allow it to run click here...</p><p>I did not click because I dont trust it. So whats the deal?</p><p><br /></p><p>Same here. BTW, I am running IE.</p>
angrymissy
12-05-2006, 05:54 AM
<strong>Campo</strong> wrote:<br /><p>the site seemed to be down all night. I just got it again when I went to my prefrences on here. my virus scan caught like 5 or 6 viruses quickly and then I got this message at the top of the screen</p><p>HTTP/1.1 200 OK Connection: close Date: Tue, 05 Dec 2006 13:50:27 GMT Server: Microsoft-IIS/6.0 X-Powered-By: ASP.NET MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: last_visit=now Cache-Control: no-cache, must-revalidate Content-Type: text/html; charset=UTF-8 *-- preferences.cfm -**-- includes/header.cfm -**-- includes/siteheader.cfm -*</p><p> and it also popped up the message below</p><p>This website wants to run the following add on: Microsoft data access - remote data services dat...' if you trust the website and the add on and want to allow it to run click here...</p><p>I did not click because I dont trust it. So whats the deal?</p><p>Yeah, I also was getting the "This website wants to run the following add on: Microsoft data access - remote data services dat...' if you trust the website and the add on and want to allow it to run click here..." throughout the day yesterday, luckily I did not run it. I got more virus warnings today as well.</p><p> Running IE7 and Norton AV</p>
JustJon
12-05-2006, 10:04 AM
<p>Sorry about the downtime folks. The best way to deal with the virus bullshit was a rebuild of the server. If I had done it, it would have happened tonite, but FMJeff was kind enough to offer to do it this morning and it just took longer than expected and ran thru a good portion of show time. But we believe the changes made during the rebuild will stop this from happening again.</p>Thanks Jeff.
angrymissy
12-05-2006, 10:17 AM
So how do we find out who the leet haxor was
angrymissy
12-05-2006, 10:20 AM
<p>Crap.</p><p>Norton AV just detected an intrusion attempt from 69.45.86.81 Port 5004</p>
Tenbatsuzen
12-05-2006, 10:22 AM
<p>The entire site has been flipping out my work computer.</p><p> </p><p> </p>
Don Stugots
12-05-2006, 10:22 AM
<strong>angrymissy</strong> wrote:<br /><p>Crap.</p><p>Norton AV just detected an intrusion attempt from 69.45.86.81 Port 5004</p><p> quick kill it!!</p>
angrymissy
12-05-2006, 10:23 AM
It blocked it. Does anyone know what port that is?
<p>"This board is sho' goin' crazy!"</p><p><img src="http://members.aol.com/otpacker/images/Dudley1.gif" border="0" width="95" height="100" /></p>
FUNKMAN
12-05-2006, 10:51 AM
<strong>JustJon</strong> wrote:<br /><p>Sorry about the downtime folks. The best way to deal with the virus bullshit was a rebuild of the server. If I had done it, it would have happened tonite, but FMJeff was kind enough to offer to do it this morning and it just took longer than expected and ran thru a good portion of show time. But we believe the changes made during the rebuild will stop this from happening again.</p>Thanks Jeff. <p>Thanks Jon and Jeff!!! Appreciate all your efforts!</p><p>Funk</p>
<strong>JustJon</strong> wrote:<br /><p>Sorry about the downtime folks. The best way to deal with the virus bullshit was a rebuild of the server. If I had done it, it would have happened tonite, but FMJeff was kind enough to offer to do it this morning and it just took longer than expected and ran thru a good portion of show time. But we believe the changes made during the rebuild will stop this from happening again.</p>Thanks Jeff. <p> </p><div style="text-align: center"><img src="/messageboard/tiny_mce/plugins/emotions/images/clap.gif" border="0" width="170" height="172" /></div>
<p>I just had trouble logging in. I got a message saying there was a server problem. <br /> </p><p>I tried again and had no problem, but the site is running slow. </p>
SatCam
12-05-2006, 02:34 PM
why is this website run using windows and IIS?????????????????????????????????????????
keithy_19
12-05-2006, 03:11 PM
<p>The internet for me is running all wacky. By the way, can someone link me for a decent pop up/virus program that's free? </p>
King Imp
12-05-2006, 04:15 PM
<p>So, what was the final verdict? Was it in fact a harmful virus, or just some spyware being detected as such? </p><p> </p>
keithy_19
12-05-2006, 04:21 PM
<p>Please, we all know who is responsible.</p><p>Angrymissy! She obviously brought up the problem to shift blame away from herself! I watch enough Murder She Wrote to realize your schemes missy!</p>
FMJeff
12-05-2006, 07:18 PM
<strong>SatCam</strong> wrote:<br />why is this website run using windows and IIS????????????????????????????????????????? <p>It's not...anymore. </p><p>I'm not 100% sure what it was. I didn't have time to research the hack. It is most likely something written into an ini or registry entry somewhere that wasn't ready apparent for IIS. Certainly nothing in the code, that would've been a little obvious, and it was on the home page, which suggests it was in the headers perhaps. </p><p>Only a handful of people come to mind who posses the level of technical knowledge to pull something like that off, one in particular who just recently asked to come back to rf.net and will certainly never be welcome, ever. </p><p> </p>
mendyweiss
12-06-2006, 05:45 AM
<strong>FMJeff</strong> wrote:<br /><strong>SatCam</strong> wrote:<br />why is this website run using windows and IIS????????????????????????????????????????? <p>It's not...anymore. </p><p>I'm not 100% sure what it was. I didn't have time to research the hack. It is most likely something written into an ini or registry entry somewhere that wasn't ready apparent for IIS. Certainly nothing in the code, that would've been a little obvious, and it was on the home page, which suggests it was in the headers perhaps. </p><p>Only a handful of people come to mind who posses the level of technical knowledge to pull something like that off, one in particular who just recently asked to come back to rf.net and will certainly never be welcome, ever. </p><p> </p><p>The Jews ?</p>
Don Stugots
12-06-2006, 05:48 AM
<strong>mendyweiss</strong> wrote:<br /><strong>FMJeff</strong> wrote:<br /><strong>SatCam</strong> wrote:<br />why is this website run using windows and IIS????????????????????????????????????????? <p>It's not...anymore. </p><p>I'm not 100% sure what it was. I didn't have time to research the hack. It is most likely something written into an ini or registry entry somewhere that wasn't ready apparent for IIS. Certainly nothing in the code, that would've been a little obvious, and it was on the home page, which suggests it was in the headers perhaps. </p><p>Only a handful of people come to mind who posses the level of technical knowledge to pull something like that off, one in particular who just recently asked to come back to rf.net and will certainly never be welcome, ever. </p><p> </p><p>The Jews ?</p><p> without a doubt, it was reeshy. we all know that old people can use computers. </p>
JustJon
12-06-2006, 05:49 AM
Sory about this morning's downtime. Silly little bug where the server installed updates, rebooted itself and the brand spanking new web server wasn't configured to bring itself back up when it restarted. Won't happen again.
sr71blackbird
12-06-2006, 02:51 PM
I got it too. I am getting scared to come here.. Like Taco Bell!
FUNKMAN
12-06-2006, 04:20 PM
<strong>JustJon</strong> wrote:<br />Sory about this morning's downtime. Silly little bug where the server installed updates, rebooted itself and the brand spanking new web server wasn't configured to bring itself back up when it restarted. Won't happen again. <p>no prob jon. the site was the only thing to go down on me today...</p><p>beggars can't be choosers</p>
I am soooo fuckin' horny right now.
vBulletin® v3.7.0, Copyright ©2000-2025, Jelsoft Enterprises Ltd.