• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

TalkBass PC Threat?

mrjim123

Supporting Member
May 17, 2008
4,453
11,011
Indy
Disclosures
Magnetically Aligned
Anybody see any warnings similar to this (my AVG anti virus program popped it up - I did not click on "More Information")?
 

Attachments

  • tb.JPG
    tb.JPG
    23 KB · Views: 226
I'm getting all sorts of warnings from my corporate Symantec Antivirus.

This has NEVER HAPPENED BEFORE ON TALKBASS.

It must be one of the banner ads.

I am getting warnings for

JS.Sykipot
Bloodhound.PDF!gen
Torojan.Malscript!html

I'm getting the Bloodhound.PDF!gen every day while on talkbass, with only talkbass open in a browser.


edit : I run Symantec with autoprotect (which is what catches it), I also run malwarebytes. Neither one finds any infection when full scans are performed.
 
This happened to me last night too. I believe I had just clicked on The Family Guy thread in the lobby (first new post which I believe led me to the second page). I'm at work now and don't want to risk the infection if something is there (or I'll have to clean it up!) or I'd post the url...
 
Ok, found the source of all the "trojans"... Google Adsense. We use google adsense (as do many many other internet sites) to fill unsold ad inventory. Some antivirus software reports google's javascript as a trojan. This is not the case, as the antivirus companies are now reporting it was a 'false positive':

[Invalid or Expired Link Removed]

http://support.kaspersky.com/kis2010/error?qid=208281219

Quote from the company: "Update: To fix Trojan.JS.Redirector.ar (false alarm ) update your Kaspersky virus database and it should fix the problem."
 
Ok, found the source of all the "trojans"... Google Adsense. We use google adsense (as do many many other internet sites) to fill unsold ad inventory. Some antivirus software reports google's javascript as a trojan. This is not the case, as the antivirus companies are now reporting it was a 'false positive':

[Invalid or Expired Link Removed]

http://support.kaspersky.com/kis2010/error?qid=208281219

Quote from the company: "Update: To fix Trojan.JS.Redirector.ar (false alarm ) update your Kaspersky virus database and it should fix the problem."

were you able to find anything on the bloodhound threat?
 
Ok, found the source of all the "trojans"... Google Adsense. We use google adsense (as do many many other internet sites) to fill unsold ad inventory. Some antivirus software reports google's javascript as a trojan. This is not the case, as the antivirus companies are now reporting it was a 'false positive':

[Invalid or Expired Link Removed]

http://support.kaspersky.com/kis2010/error?qid=208281219

Quote from the company: "Update: To fix Trojan.JS.Redirector.ar (false alarm ) update your Kaspersky virus database and it should fix the problem."

Thanks, Paul.
 
I'm getting the Bloodhound.PDF!gen every day while on talkbass, with only talkbass open in a browser.


edit : I run Symantec with autoprotect (which is what catches it), I also run malwarebytes. Neither one finds any infection when full scans are performed.

http://www.symantec.com/security_response/writeup.jsp?docid=2010-031521-1825-99

Bloodhound.PDF!gen
Risk Level 1: Very Low

Discovered: March 15, 2010
Updated: March 15, 2010 10:04:49 PM
Type: Trojan
Systems Affected: :eek: Linux, Solaris, Windows 2000, Windows 95, Windows 98, Windows NT, Windows Server 2003, Windows Vista, Windows XP

Bloodhound.PDF!gen is a heuristic detection of potentially malicious files, which may exploit vulnerabilities in Adobe Reader in order to perform further malicious actions.

Antivirus Protection Dates

* Initial Rapid Release version March 15, 2010 revision 034
* Latest Rapid Release version March 15, 2010 revision 034
* Initial Daily Certified version March 15, 2010 revision 040
* Latest Daily Certified version March 15, 2010 revision 040
* Initial Weekly Certified release date March 17, 2010

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild

* Wild Level: Low
* Number of Infections: 0 - 49
* Number of Sites: 0 - 2
* Geographical Distribution: Low
* Threat Containment: Easy
* Removal: Easy

Damage

* Damage Level: Low

Distribution

* Distribution Level: Low

So much for basking in an Ubuntu install: Linux malware
 
were you able to find anything on the bloodhound threat?

The only thing that I can think of is Google Adsense. Recently Google started sub-contracting with other ad networks, allowing "Google Certified 3rd Party Ad Networks" to display ads on the Adsense platform. Google maintains that each network is QC'ed and verified, but with over 100 3rd party ad networks putting ads through, I bet a few bad apples make it through.

I've set our Adsense account to disable all 3rd party ad networks, so only campaigns originated through Google Adwords will show on TalkBass (plus ads that we sell and verify in-house).

Let me know if you get any further alerts, and if so, as much detail as you can provide would be great (specific URL's etc).

Thanks!
 
i tried opening this link
https://www.talkbass.com/forum/showthread.php?p=875583

and got this warning by firefox
This Connection is Untrusted











You have asked Firefox to connect
securely to www.talkbass.com, but we can't confirm that your connection is secure.



Normally, when you try to connect securely,
sites will present trusted identification to prove that you are
going to the right place. However, this site's identity can't be verified.







What Should I Do?





If you usually connect to
this site without problems, this error could mean that someone is
trying to impersonate the site, and you shouldn't continue.











Technical Details



https://www.talkbass.com/forum/showthread.php?p=875583 uses an invalid security certificate.

The certificate is not trusted because it is self-signed.
The certificate is only valid for wwwbass.talkbass.com

(Error code: sec_error_untrusted_issuer)







I Understand the Risks





If you understand what's going on, you
can tell Firefox to start trusting this site's identification.
Even if you trust the site, this error could mean that someone is
tampering with your connection.



Don't add an exception unless
you know there's a good reason why this site doesn't use trusted identification.

am able to browse tb pages otherwise though
 
The URL of that link is incorrect - TalkBass needs to be accessed with http://www.talkbass.com/....etc and NOT https://www.talkbass.com/etc/etc

You're telling your browser to access TalkBass via secure encrypted connection when you use https (which you always want to do when submitting your credit card info, SS#, or any other info to any website), but for board posts it's unnecessary. And so we don't pay the $$$$ for a signed certificate, and therefore your browser gives you that warning when you use https.