What the heck? Attack Site?

Page 4 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

TheVrolok

Lifer
Dec 11, 2000
24,254
4,090
136
Just got the warning myself. Anyone know what the "attack" is supposed to be? Anything we should be scanning for?
 
Last edited:

Slacker

Diamond Member
Oct 9, 1999
8,623
33
91
Avast gave me a warning about a blocked trojan, I am using firefox.

3/27/2010 3:35:05 PM "h t t p : // storesigma. c o m/cgi-bin/ids.h t m l [L] JS: Prontexi-AI [Trj] (0)

(deleted some characters so the link wouldnt parse)
^ didnt work so i added spaces to the com and html parts
 
Last edited:

goog40

Diamond Member
Mar 16, 2000
4,198
1
0
The fake antivirus installed itself without any prompts on my computer on IE8 last night. I was wondering where it came from. Had to reboot into safe mode to remove the registry entries and delete some files. It also changed the proxy setting in the registry so that IE and Chrome couldn't load any pages after I rebooted, but FF still worked fine. Today while running another scan with Malware-Bytes, AVG picked up that a PDF file in my cache was infected.
 

TheVrolok

Lifer
Dec 11, 2000
24,254
4,090
136
The fake antivirus installed itself without any prompts on my computer on IE8 last night. I was wondering where it came from. Had to reboot into safe mode to remove the registry entries and delete some files. It also changed the proxy setting in the registry so that IE and Chrome couldn't load any pages after I rebooted, but FF still worked fine. Today while running another scan with Malware-Bytes, AVG picked up that a PDF file in my cache was infected.

Any memory of what the registry entries were? Would be nice to get some info on whatever is trying to be installed.

Registry proxy settings are:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy"=dword:00000001
"ProxyEnable"=dword:00000001
"ProxyHttp1.1"=dword:00000000
"ProxyServer"="http://ProxyServername:80"
"ProxyOverride"="<local>"
 
Last edited:

skull

Platinum Member
Jun 5, 2000
2,209
327
126
Can anyone see the source code? When I get the reported attack page message I hit ignore. Then view source and it justs shows the warning. I'm running firefox in linux.
 

Interitus

Platinum Member
Jan 28, 2004
2,143
9
81
I laughed a little when "Attack Site" came up on the Fermi article.

But yes, I get these too. Haven't found anything bad yet after scanning though.
 

goog40

Diamond Member
Mar 16, 2000
4,198
1
0
Any memory of what the registry entries were? Would be nice to get some info on whatever is trying to be installed.

Registry proxy settings are:

I believe this is what was installed:

http://deletemalware.blogspot.com/2010/01/how-to-remove-antivirus-soft-fake.html

The program that was set to run on startup was [random]ftav.exe

It doesn't let you run any .exe or open the task manager once its running, so you have to boot into safe mode in order to edit the registry so that it doesn't start up with Windows.
 

pyonir

Lifer
Dec 18, 2001
40,852
312
126
Same setup but with NoScript also. No problems...so far.

I have NoScript installed also...but didn't mention that. When going to the pages people are reporting they see it...google analyticsz still doesn't show up in my NoScript list...so I assumed it was being blocked by ABP. Either way, people should install NoScript if they have FF.
 

daw123

Platinum Member
Aug 30, 2008
2,593
0
0
Avast gave me a warning about a blocked trojan, I am using firefox.

3/27/2010 3:35:05 PM "h t t p : // storesigma. c o m/cgi-bin/ids.h t m l [L] JS: Prontexi-AI [Trj] (0)

(deleted some characters so the link wouldnt parse)
^ didnt work so i added spaces to the com and html parts

Ditto with me; Avast has blocked a trojan several times. I'm using IE8.
 

TruePaige

Diamond Member
Oct 22, 2006
9,874
2
0
Glad to see some good responses and that it got attention from some of the higher ups.

Thanks for contributing guys! I'm sure they'll resolve it soon. Nice to have tips for further protection for the members here.

Even with NoScript though I am pretty sure you can get the attack site message in Firefox, since Firefox was parsing the domain you were going to directly, before anything loads, and seeing it marked.
 

JEDIYoda

Lifer
Jul 13, 2005
33,986
3,320
126
PEBKAC?? You're probably infected if your browser didn't detect it. Running FF 3.6.2 on Linux from 2 different distros with ADblock warn of it. Same with Win7 on FF

There is no truth in what you are saying.
The fact is not all anti virus programs are created equal.
17 posts and your telling someone they are probably infected...not likely!!
 

Matthiasa

Diamond Member
May 4, 2009
5,755
23
81
Avast gave me a warning about a blocked trojan, I am using firefox.

3/27/2010 3:35:05 PM "h t t p : // storesigma. c o m/cgi-bin/ids.h t m l [L] JS: Prontexi-AI [Trj] (0)

(deleted some characters so the link wouldnt parse)
^ didnt work so i added spaces to the com and html parts

Thats what I had detected as well.
 

0roo0roo

No Lifer
Sep 21, 2002
64,795
84
91
please don't tell us to go into forum issues and lock this thread.
no one surfs forum issues for kicks.
 

pyonir

Lifer
Dec 18, 2001
40,852
312
126
Even with NoScript though I am pretty sure you can get the attack site message in Firefox, since Firefox was parsing the domain you were going to directly, before anything loads, and seeing it marked.

Yes, you still get the attack site message when going to the NVidia review on the homepage. But I ignored the warning, went to the article and had no problems at all. analyticsz still didn't show up in my NoScript list (just the normal google-analytics did, but I have that blocked anyway). I went to the article before it was reported as an attack site, when you all were having issues, and no warnings or problems came up. So FF, ABP and NoScript is working if anyone is really worried about getting attacked/infected.
 

JEDIYoda

Lifer
Jul 13, 2005
33,986
3,320
126
Yes, you still get the attack site message when going to the NVidia review on the homepage. But I ignored the warning, went to the article and had no problems at all. analyticsz still didn't show up in my NoScript list (just the normal google-analytics did, but I have that blocked anyway). I went to the article before it was reported as an attack site, when you all were having issues, and no warnings or problems came up. So FF, ABP and NoScript is working if anyone is really worried about getting attacked/infected.

no issues here iether.
 
Oct 27, 2007
17,009
1
0
Why is AT using some dodgy ad agency that can inject bad code into the page? Just use Google for your ads like everyone else FFS.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |