Warning: EntropiaForum - Marked as unsafe

Discussion in 'About EntropiaPlanets' started by NotAdmin, Mar 20, 2010.

  1. xentric

    xentric noob

    It was fine for me. Now in the last 15 minutes I get a warning every page load and it would not even let me post a reply to 711 to tell him so.

    Win 7 64bit Firefox and Sophos here.

    I don't appear to be infected yet though.
     
  2. EntropiaForum - Marked as unsafe

    I'm using Firefox and I still get the Unsafe site message if I try to go to EntropiaForum.

    Pennsif
     
  3. safara

    safara Pamwe Chete

    This is what I am getting


    What is the current listing status for www.entropiaforum.com/forums?
    This site is not currently listed as suspicious.
    What happened when Google visited this site?
    Of the 14 pages that we tested on the site over the past 90 days, 3 page(s) resulted in malicious software being downloaded and installed without user consent. The last time that Google visited this site was on 2010-03-20, and the last time that suspicious content was found on this site was on 2010-03-20.Malicious software includes 3 trojan(s). Successful infection resulted in an average of 2 new process(es) on the target machine.
    Malicious software is hosted on 1 domain(s), including waycity.net/.
    2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including hyperconnect.com/, ads.is/.
    This site was hosted on 1 network(s) including AS36351 (SOFTLAYER).
    Has this site acted as an intermediary resulting in further distribution of malware?
    Over the past 90 days, www.entropiaforum.com/forums did not appear to function as an intermediary for the infection of any sites.
    Has this site hosted malware?
    No, this site has not hosted malicious software over the past 90 days.
     
  4. RAZER

    RAZER Custom title ... uh ...

    Well as far as I could see the problems were solved before the message from google and Firefox, but it looks like the blocking of the site got in a bit late.

    [​IMG]
     
  5. GeorgeSkywalker

    GeorgeSkywalker Explorer


    ?? not sure what you meant there..


    Anyway i thought i was safe because i use firefox. When I tried to go to EF now i got the above Error.


    Has the site been hacked? and does it hold malicious software?

    Is EP safe or will this be targeted next?


    (please answer in plain english no technical jargon - thanks :P )
     
  6. well seems like my desktop with IE got it when I accessed EF and my firewall is blocking access to a program called ctcnsftav.exe. It removed some program in my spyware program and quarantined it but its still trying to access . when i googled it it says its called program called virus soft which poses as removal program and it was what my program removed... now to remove the rest :(
     
  7. GeorgeSkywalker

    GeorgeSkywalker Explorer

    When i was reading EF earlier someone had mentioned about this problem on there.

    Also someone posted that they used adblock and noscript addons with firefox. So i've installed them onto my firefox.

    If you want to download them here's the link:

    https://addons.mozilla.org/en-US/firefox/browse/type:1/cat:12


    I dunno if they do any good or anything, just thought I'd share :P

    Not been back to EF since i installed these either thought i'd wait for a techy to post first ....
     
  8. Hmm same probleme here :S
     
  9. aridash

    aridash large throbbing member

    711 sure has a shity way of dealing with people trying to offer feedback, just dismissing them.

    conclusion from reading everything is that EF served up ads that infected alot of people.
     
  10. Zar

    Zar Nuthin but a Hound Dog

    Was on Ef early this morning and had the adobe error message a few times, shut down and left the house.

    Came back tonight and had to reboot my computer 3 times because it kept locking up. Virus scan found nothing, but I wondered if it was related to the issue on EF this morning. I have not gone back there yet, checked here first and am glad to see the info posted here.

    I am going to do a deep scan and make sure there is nothing that was missed, but it does seem to be acting better now.

    Good luck everyone
     
  11. Hey Ace. :)

    The block page people are seeing now is due to google detecting the malicious code that was on the page earlier today. When the search engine spiders from google (and others) visit a page and detect malicious code, it adds it to the data base of blocked sites. 711 has contacted google and asked them to re-test it....once they do that the block will disappear.
    That's basically it in a nutshell....someone else can correct me if I got it wrong or missed something... :)
     
  12. NotAdmin

    NotAdmin Administrator

    The issue seems to be solved now. Like others stated, apparently the tool used to serve banners and ads for EF somehow allowed for a malicious exploit to be run. I doubt this was an attack specifically targetted at EF, but rather something that affected quite a lot of sites.

    In any case, it's been handled, and this thread will be removed shortly, unless there's still people experiencing trouble. As said above, the current warnings are most likely "better safe than sorry" warnings displayed by Google or other parties, and they will dissappear as soon as the new scans performed will not find anything suspicious.

    In the mean time, please ensure you got your bases covered. Regularly update your OS, always have recent virus updates, and running some additional anti-malware software is always a good idea. Oh, and if you have not already done so, GET A GOLD CARD!
     

  13. Dunno if it's been solved... I was fine all along and now I got the same malware block running it with Google Chrome browser.
     
  14. NotAdmin

    NotAdmin Administrator

    Alright, then let's leave the thread open a bit longer.

    For those worried, EntropiaPlanets does not use OpenX, so this particular exploit will not hit us.
     
  15. I have the same problem right now 9:30 CT
    I did run the virus program thru and found 4 problem. I clean it and did try open EF again with same problem and a warning :(
     
  16. Zar

    Zar Nuthin but a Hound Dog


    I had no trojans or other issues found using the lastes dats, Nakwarebyte found nothing and I was unable to find anything.

    I have to correct myself that I did not shut down when I left, I just logged off and went into sleep mode. I rebooted and continued to have trouble, once I did a full power off the problems went away. I was not seeing anything suspicious in running processes but must have had something not releasing that was trying to do something until power off.

    Everything seems smooth now, I have not been back to EF yet, will probably try to go there a bit later since it appears if my be ok now.
     
  17. Lol @ there being a Thread on EF saying "Hey EF is hacked don´t go there"

    Can´t wait to go there and read some tips on how not to get hacke...oh shit my mouse is moving by itself and why is c: being formatted.
     
  18. 711 said that a bit earlier:

    So I guess we just gotta be patient and ignore that malware screen
     
  19. GeorgeSkywalker

    GeorgeSkywalker Explorer


    What i don't get is if 711 is still using openx and it's been exploited by hackers why would google say it's ok? when clearly it won't be ok. 711 would have to correct the root cause of the problem i.e. hackers exploiting openx then have google review it.

    So it seems to me this could go on for few days...
     
  20. NotAdmin

    NotAdmin Administrator

    The old OpenX version apparently had a bug. 711 upgraded to a newer version (safe from this particular exploit), removing the threat itself, but the messages now seen by users are due to an external site not having rechecked the site yet, and hence still showing a warning message.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.