Infected Fotkis?? or is the entire site infected?

Nonie

Well-Known Member
Thanks! Now how do i get it off of my computer. I use the Firefox browser and have all kinds of protection, but that thing still shows up when i go to IE fotki. Do I need to get the spybot thing, too??

What Internet protection are you using? When I used to have Norton Antivirus, I found I had to have Spybot too because while Norton Antivirus would catch malware/trojans, it could only quarantine them but not delete them. Spybot on the hand would get rid of them. So together they formed a great team.

Since upgrading to Norton Internet Security, I haven't had to use Spybot at all. I still have it on my PC but it's kinda on vacay since I haven't had any issues at all.
 

dimopoulos

Crazy Greek
Staff member
So that everyone has a clear understanding of what is going on.

1. The forum does not have any viruses or malware. We do not allow HTML code and as a result nobody apart from the admin team can install any scripts that can harm your computers. The base installation of the forum is clean.

2. We only display ads from Google. That is it. The only other ad we display is the Clover one but that one is just a banner and nothing else. If you see the HTML code of any page you will notice that the Clover ad is served by http://ads.niden.net which is my domain.

3. Google Webmaster Tools reports no malware. That tool surfs the whole forum so if there was something it would have been reported. Additionally http://www.radabg.com/url/longhaircareforum.com/ reports no malware

4. I have noticed that there are several warnings in Firefox's debug console regarding ads being served by doubleclick.net. Doubleclick.net has been purchased by Google so they fall in the same pool. Doubleclick has been in the past accused of issuing tracking cookies so that might be the case.

5. I have checked this topic with 5 browsers in 2 computers and 2 different antivirus programs (AVG and Norton). Nada :(

If you get any warning whatsoever please help the situation by actually pointing me to the correct topic. A screenshot, the URL of the page with the problem or something like that would help a ton.

We had a similar issue in the past (pages issuing warnings) which resulted in a picture that was cross-linked from this site to a site that had been reported as a fishing one. The picture was in a user's signature.

Thanks!
 

Nonie

Well-Known Member
okay, how do we do a screenshot (for quick reference purposes)???

If you press the key on your computer that says PRTSC (Print Screen) it makes a copy of your screen as it is that very moment. If you then go to Windows Paint program or MS Word, and then right-click anywhere on the page and select PASTE from the menu that pops up, or just hold down the keys CTRL and V together, you will paste a copy of your screen you just captured as it is. You can then save that on your PC and attach it to a ticket and submit to Admin.

I just saved a screenshot of this page before I submitted. See attachment.
 

Attachments

  • Screenshot.jpg
    Screenshot.jpg
    97.3 KB · Views: 17

dimopoulos

Crazy Greek
Staff member
Some more information about this

One member sent a screenshot regarding the matter. Now admittedly there were 3 sites open at her computer so we cannot be certain. However the screenshot sent was from Norton's blocker.

The attack was from a Trojan Mebroot.
The source IP was hosted by theplanet.com
The source IP was hosted in Texas
The target IP was in NJ.
The URL identifier was: google.analytics.com.uwyovhxythol.info

As you note from the above:

a) that is not Google's domain and neither the one for Google analytics.
b) our servers are hosted in California and not in Texas or in theplanet.com


So this leads to the conclusion that the LHCF is not the attacker.

However, there might be a signature or a picture somewhere that might causing this. I am investigating everyone's signature so as to find where this thing is coming from. I have noticed that there is a similar complaint on a different board so we are not the only ones that are experiencing this problem.

If you have any screenshots that you can share while looking at the problem please do. I am more interested in the URL you were trying to visit than the warning itself.

Thanks!
 

Ms Kain

Active Member
As you note from the above:

a) that is not Google's domain and neither the one for Google analytics.
b) our servers are hosted in California and not in Texas or in theplanet.com


So this leads to the conclusion that the LHCF is not the attacker.

I'm confused. :perplexed I thought we were talking about the Fotki website having a virus, not LHCF. Did someone say that LHCF had a virus or are you saying that LHCF is somehow affiliated with Fotki.com?
 

SimplyBlessed

Well-Known Member
Ok so I have Windows Live Onecare which I do not really care for but I do like that it does Tune-ups for me, disk defrag, etc...

If I were to install Avast and Malwarebytes would they conflict with my Windows Live OneCare??

Also is it neccessary to install BOTH Avast and Malwarebytes??
 

Dragon_Of_Vaeros

New Member
I got it too. Never would have thought it was from here. I might have to take a break from posting. I had to restore my pc a few minutes ago!!! :(
 

FebeeSigns

New Member
My computer is pretty protected. I have AVG as well as ZoneAlarm that personally asks me if I want to block such applications and incoming traffic. It's a really yummy firewall. Despite also getting the fotki messages I have no trouble on my computer
 

kittikat24

New Member
My PC isn't protected (virus protection expired and we never updated)
so yes, I went on fotki, and my pc started freakin' out!!
Honestly, I won't be goin' on fotki for a loonnggg time now... :(
 

chebaby

Well-Known Member
the thing is i never go to fotki. im just not interested lol. but something made me click on it today and well, the rest is history.
 
Top