jceman 1 #1 December 13, 2008 The attached report came from Avast AV software while accessing the forums tonight -- the affected connection from the offending ad has been blocked and now I have to repeatedly refresh until it rotates out or I only get blank areas in the center of the page. (Head, foot and side banners still display). This was accompanied by a pop-up of a purported people finder. This is unacceptable. Faster horses, younger women, older whiskey, more money. Why do they call it "Tourist Season" if we can't shoot them? Quote Share this post Link to post Share on other sites
tdog 0 #2 December 13, 2008 Yes, it is linked to the Coors add. I got all sorts of popups and weird stuff... Quote Share this post Link to post Share on other sites
PhreeZone 20 #3 December 13, 2008 Which ad was it for? This info is needed to get it out of the ad rotation. This is an exploit of a PDF vulnerability. The site hosting the ads has been compromised in all likelihood.Yesterday is history And tomorrow is a mystery Parachutemanuals.com Quote Share this post Link to post Share on other sites
stratostar 5 #4 December 13, 2008 The fucking Coors light ad on the left side banner. Total BS!you can't pay for kids schoolin' with love of skydiving! ~ Airtwardo Quote Share this post Link to post Share on other sites
Squeak 17 #5 December 13, 2008 i had a JS/exploited shell.gen Trojan from this site, it was cleaned by my AV software every time i opened Dizzy. it also stopped any of the forum tables from appearing. I enabled add blocker and the Coors add disappeared and everything else returned to normalYou are not now, nor will you ever be, good enough to not die in this sport (Sparky) My Life ROCKS! How's yours doing? Quote Share this post Link to post Share on other sites
Amazon 7 #6 December 13, 2008 Yup the Coors add.. anytime the fjeking.com came up it caused anything on the forums window to lock. a repeated refresh would usually cause it finally to load. It gave me a popup wanting to install and I shut it down. I have now turned off the My Stuff and it got rid of the popups over there.... and everything is loading as it is supposed to. Quote Share this post Link to post Share on other sites
markovwgti 0 #7 December 13, 2008 same thing on basejumper.com Quote Share this post Link to post Share on other sites
PhreeZone 20 #8 December 13, 2008 Management is aware and they are trying to contact the people that can remove that ad.Yesterday is history And tomorrow is a mystery Parachutemanuals.com Quote Share this post Link to post Share on other sites
grannyinthesky 0 #9 December 13, 2008 Thanks, Turnomg pff My Stuff worked great."safety first... and What the hell..... safety second, Too!!! " ~~jmy POPS #10490 Quote Share this post Link to post Share on other sites
j_ung 0 #10 December 13, 2008 Ok, all ads should now be gone, or they will be in a few minutes. I do not know what happened, but I will post back Monday sometime with a complete explanation and a plan to make sure it never happens again. First guess -- and this is just from what I'v been told -- is that the network from which those ads come was compromised. I posted in the BF thread earlier from my phone, but I was not in a good reception area and it was problematic, to say the least. ddt has been working tirelessly all day from the west coast since around 7 am his time and we've finally managed to get with the Gossamer folks. I'm going to direct traffic from that thread here. Quote Share this post Link to post Share on other sites
j_ung 0 #11 December 13, 2008 The Bonfire thread: http://www.dropzone.com/cgi-bin/forum/gforum.cgi?do=post_lock;redo=post_view_flat;so=ASC;sb=post_latest_reply;root_id=3421639;post=3421883; Quote Share this post Link to post Share on other sites
j_ung 0 #12 December 13, 2008 In the meantime, please enjoy an ad-free rest of the weekend. Quote Share this post Link to post Share on other sites
CSpenceFLY 1 #13 December 14, 2008 QuoteIn the meantime, please enjoy an ad-free rest of the weekend. Ad a much faster Dropzone.com Quote Share this post Link to post Share on other sites
j_ung 0 #14 December 14, 2008 I'm getting reports on Rockclimbing.com that the following works for what the rogue ad leaves behind (if your own anti-viral didn't stop it). The trojan may be called Extra Antivir. Click below and scroll down just a bit. If that looks familiar to you, follow the instructions. http://www.bleepingcomputer.com/malware-removal/remove-extra-antivir Quote Share this post Link to post Share on other sites
Pokerstar 0 #15 December 14, 2008 Thanks to everyone for figuring this out so quickly! And, just one more reason not to drink COORS LIGHT.Fortunately, I'm adhering to a pretty strict, uh, drug, uh, regimen to keep my mind, you know, uh, limber. --- The Dude --- Quote Share this post Link to post Share on other sites
ltdiver 3 #16 December 14, 2008 QuoteThe Bonfire thread: http://www.dropzone.com/cgi-bin/forum/gforum.cgi?do=post_lock;redo=post_view_flat;so=ASC;sb=post_latest_reply;root_id=3421639;post=3421883; Hey, that link has been deleted. I'd like to read what others have experienced with this. My Mac was slow, but not compromised. Seems that Mac's using Safari weren't affected? ltdiver Don't tell me the sky's the limit when there are footprints on the moon Quote Share this post Link to post Share on other sites
j_ung 0 #17 December 14, 2008 QuoteThanks to everyone for figuring this out so quickly! And, just one more reason not to drink COORS LIGHT. Before today, I didn't think my opinion of Coors Light could be any lower. Those were the days. Quote Share this post Link to post Share on other sites
j_ung 0 #18 December 14, 2008 QuoteQuoteThe Bonfire thread: http://www.dropzone.com/cgi-bin/forum/gforum.cgi?do=post_lock;redo=post_view_flat;so=ASC;sb=post_latest_reply;root_id=3421639;post=3421883; Hey, that link has been deleted. I'd like to read what others have experienced with this. My Mac was slow, but not compromised. Seems that Mac's using Safari weren't affected? ltdiver No, it's still there. I locked it to keep the discussion contained in a single thread. There's a little info from users on Rockclimbing.com, too: http://www.rockclimbing.com/cgi-bin/forum/gforum.cgi?post=2037976; Quote Share this post Link to post Share on other sites
ltdiver 3 #19 December 14, 2008 QuoteQuoteQuoteThe Bonfire thread: http://www.dropzone.com/cgi-bin/forum/gforum.cgi?do=post_lock;redo=post_view_flat;so=ASC;sb=post_latest_reply;root_id=3421639;post=3421883; Hey, that link has been deleted. I'd like to read what others have experienced with this. My Mac was slow, but not compromised. Seems that Mac's using Safari weren't affected? ltdiver No, it's still there. I locked it to keep the discussion contained in a single thread. There's a little info from users on Rockclimbing.com, too: http://www.rockclimbing.com/cgi-bin/forum/gforum.cgi?post=2037976; May be there for you, but not for me. ltdiver Don't tell me the sky's the limit when there are footprints on the moon Quote Share this post Link to post Share on other sites
tdog 0 #20 December 14, 2008 QuoteIn the meantime, please enjoy an ad-free rest of the weekend. This site is like 100 times faster now! Quote Share this post Link to post Share on other sites
SuFantasma 0 #21 December 14, 2008 QuoteQuoteQuoteThe Bonfire thread: http://www.dropzone.com/cgi-bin/forum/gforum.cgi?do=post_lock;redo=post_view_flat;so=ASC;sb=post_latest_reply;root_id=3421639;post=3421883; Hey, that link has been deleted. I'd like to read what others have experienced with this. My Mac was slow, but not compromised. Seems that Mac's using Safari weren't affected? ltdiver No, it's still there. I locked it to keep the discussion contained in a single thread. There's a little info from users on Rockclimbing.com, too: http://www.rockclimbing.com/cgi-bin/forum/gforum.cgi?post=2037976; Thanks! Unfortunately, it's part of doing business in the Internet... thanks for working with us ... and thanks for a great website !Y yo, pa' vivir con miedo, prefiero morir sonriendo, con el recuerdo vivo". - Ruben Blades, "Adan Garcia" Quote Share this post Link to post Share on other sites
CSpenceFLY 1 #22 December 14, 2008 QuoteQuoteThanks to everyone for figuring this out so quickly! And, just one more reason not to drink COORS LIGHT. Before today, I didn't think my opinion of Coors Light could be any lower. Those were the days. I don't think you can blame this on Coors Light. Quote Share this post Link to post Share on other sites
j_ung 0 #23 December 14, 2008 QuoteQuoteQuoteThanks to everyone for figuring this out so quickly! And, just one more reason not to drink COORS LIGHT. Before today, I didn't think my opinion of Coors Light could be any lower. Those were the days. I don't think you can blame this on Coors Light. No, I certainly can't. I can blame myself, and that's about it. Quote Share this post Link to post Share on other sites
porpoishead 8 #24 December 14, 2008 one of my machines went for the ride..i was running firefox 3 but the ad blocker wasn't setup correctly it ended up with the extra-anti virus and 2 gay porn desktop icons the extra-anti virus looked like a windows boot up screen appearing like windows was rebooting and recommending you install the fake anti-virus for a fee kept doing the fake reboot every 5 minutes then it kept prompting error tabs from the task bar as if it were your windows security to get you to reconnect to the web to download and scan with the AGV anti-virus. the real antivirus program is AVG so I recognized it as fake right away..also during the fake windows reboots it would never prompt me to type my user password. so I figured it wasn't really windows. the gay porn desktop icons were a fucked up twist to the virus. they were read only so I couldnt figure out where they came from. i would delete them and they would pop back up within seconds. had me laughing my ass off. machine is clean now all updates and patches.. crazy stuff... coors light rocks!!! no love lost for the john waynes if you want a friend feed any animal Perry Farrell Quote Share this post Link to post Share on other sites
j_ung 0 #25 December 14, 2008 Okay, ads will be up sometime tomorrow, minus the culprit. I'm going to spend some more time following up on things, and then get some sleep. I'll be back online all day tomorrow to make sure things go smoothly. Quote Share this post Link to post Share on other sites