malware on site

  • Thread starter Thread starter Anonymous
  • Start date Start date
Dennis":kj9210ec said:
Thanks Roy, it looks like a rogue ad slipped through on Google's ad network... from what I've read online, this is a nasty little piece of malware.

Question: Did any of you get a pop-up message while visiting this site that said you had a computer virus and needed to scan your computer? (One that was not your installed anti-virus software.)

Sounds like you need to get rid of Google ad's, there are probably many others that have been hit and can't even post .

I have never seen a pop-up of any kind on this site.
 
I am using my business computer almost exclusively now. For the last three nights, when I open this site, my computer gets hit. Our companies' anti virus and malware software catches it as soon as the site opens. On my personal computers, I run malwarebytes. Its free and works great. I cant count the number of computers I have fixed with that software. Like everyone else has said, beware of the popups!!
 
Norton just blocked an attempt on my computer. I jumped from main forum of Farmall Cub, to for sale. I see the history in Norton. Looks like it blocked an attack from zarerd,,,, dot com.?? Dennis, I have the IP address stored in Norton History if you like.
 
59cub":2bs3gq70 said:
Norton just blocked an attempt on my computer. I jumped from main forum of Farmall Cub, to for sale. I see the history in Norton. Looks like it blocked an attack from zarerd,,,, dot com.?? Dennis, I have the IP address stored in Norton History if you like.

Please PM me any info you have collected.

Thanks,
Dennis
 
Wow :shock: :!:

I usually visit the forum in Opera v 11.60 on Windows Vista Business Edition with all patches. So far I have not seen this pop up or any popups on the forums. With luck Opera might be immune? I seldom use IE8, Safari, Chrome or FireFox on the forum mostly cause I like some of Opera's

I also use Malwarebytes, Spybot SD, SuperAntiSpyware in concert with System Mechanic Professional with System Shield and of course the basic Windows Defender. I haven't had a virus on my laptop as long as I have had it basically.
 
I was hit 2 nights ago while on the forum. Same thing, Win 7 Home Security. Took several hours to get my computer back up and running properly.
 
I'm not on my computer right now because I got it too. Said " XP antivirus 2012 alert. Internet explorer alert. Visiting this site may pose a security threat to your system". Well, it did. Not sure how to fix. I didn't click on anything to fix and now I can't open any programs at all. Later guys, this may take a while. :-( Grump
 
Is there going to be a warning posted or mass e-mail to warn other members and users of the problem until it is resolved. Could be a bunch of problems if it persists.

Would hate for it to affect anyone without the means to fix t.
 
im at work now , im sure LSU has pretty good defenses :wink: i can look and get whatever might help from my computer, i just dont know what/where to look for it. i'll have to bring it to someone to fix. coppersmythe..........................
 
Our laptop at home got hit with that windows 2012 blah blah crap a few nights ago. I was using it at home doing my normal tractor sites visits, nothing out of the ordinary, had no idea how it happened. Maybe now I do. Haven't been able to use it since, not computer savvy enought to do that on my own. I got it here at work waiting on our computer guy to come by sometime and look at it for me...
 
my secutity blocked a high severity intrusion attempt last nite at 8:53 while i was on this site--don't know if this will help ya dennis but this was what was blocked: (178.18.243.89 ) i have norton
 
Charlie,

What Norton product do you have? I have Symantic Anti-virus and I obviously need to do something different. :shock:
 
Charlie:

Out of curiosity I googled

178.18.243.89

and it resolves to somewhere in England... 178.18.243.89

A whois.net query resolves as

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

Ripe shows it as a German IP addy.
 
OK folks,

I've been over the site with a fine tooth comb and cannot find any evidence of malware/viruses on the site.

For those of you who have noticed strange things, be aware, that most viruses and mailware are delivered via "downloaded" files, email attachements, and some "drive by" infections on computers with un-patched computer files.
Once a virus or malware is loaded onto a computer, it will give bogus information and prompt the person to click or purchase some software or it may just interfere with the computers normal operation.

Blocked ads can be either a false positive from the anti-virus software or it is blocking the originating URL of the ad -- for whatever reason. It does not mean the ad has a virus and it will infect your computer by display on the screen. (I've checked with Google Adsense and they report no known malware or viruses invading their ad network and are vigilant in that quest; it is their bread and butter, so they are serious about keeping it clean.)

If you want, you can scan the site by using the multiple scanners located on this site: http://www.virustotal.com/index.html
Click the "Submit URL" tab and enter "farmallcub.com" in the box and scan the site for your assurance that the site is clean.

Regardless, be assured I take all potential threats as real and fully investigate them. However, with a whole internet full of sites (and I'm sure FarmallCub is not the only one you visit), plus email threats, it is a difficult job to try and find where these nasties originate from. I can only verify this site.

Please let me know if you have positive proof of any malicious activity from this site.

Thanks,
Dennis
 
I haven't been hit yet and I use

Apple products

[ Post made via iPhone ]
iPhone.png
 
Dennis,
Yep, I got hit on Wednesday afternoon and it basically locked up my computer. Fortunately it was a company computer, 8-months old, but it locked her up good. Our IT guy could not get in to my computer remotely, so I spent the day in Syracuse on Thursday letting them work on it. After a whole day, something that they used to remove the virus, or the virus itself, stripped some of the Windows files, and my computer was toast. They had to re-install Windows. So, I got a new laptop out of the deal (because they were tired of working on it and had new ones laying there).

Regardless. I know exactly where I was when I got hit. I was in the Cub Vine section, and it was about noon on Wednesday.
 
Don McCombs":39qsbjtn said:
What's the status of this situation?

Don and FarmallCub members,

I have been over this site multiple times looking for any malicious code and scanned it with server based scanners and third party scanners. I find ZERO evidence of any "Trojan" or virus software on FarmallCub.Com.

I have also triple checked with Google Adsense and they verified that their are ZERO reports of any compromised ads on their networks.

Now that being said, NEVER let down your guard and neither will I. Keep your systems patched with security updates, religiously -- set them to AUTOMATIC if you're a windows user. Keep a good anti-virus installed and updated (firewall too.) Never, ever, click on an email attachment unless you are 100% positive that it is safe -- that includes emails from friends and business (they can be "spoofed").

I also hate to say it, but Windows XP currently accounts for 75% of all virus infections... if you are using XP, be extra careful. You might want to ask Santa for a new Windows 7 or Apple computer. ;)

Dennis

PS: I personally spent the last five days cleaning a very nasty "rootkit" virus off my brothers computer.... he clicked on a file attachment.
 
Back
Top