Author
Topic: Is there a virus on this website?  (Read 16888 times)
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« on: January 04, 2008, 02:52:23 pm »

Hello fellow members...

I am not sure if it's just me... but has anyone noticed an "active x" control pop-up on certain screens on this website?  It says that it wants to download some Microsoft data retrieving info software into my computer (something like that).   I've tried three different computers, and all have the same issue.  All the virus scanners on my computers all pop-up indicating a harmful virus was blocked.   

It sometimes on this website, and sometimes not... not sure if there's something or someone that was able to hack into this site...

Has anyone noticed this?

Thanks,

Michael 

  Smile from your heart.  ;D
kforse
  • Junior Member
  • **
  • Posts: 17
  • CPMS Member
« Reply #1 on: January 04, 2008, 03:36:46 pm »

Michael,

I have had no pop ups appear or any warnings from my McAfee Software.

Hope this helps.

Life is to short not to have fun
YuMan
  • Wiki Contributor
  • Junior Member
  • **
  • Posts: 75
  • Paper Money is Art!
« Reply #2 on: January 04, 2008, 03:45:26 pm »

Michael:
Yes, it was on last mid-night.  But I have McAfee internet security installed on my computer, it automatically let me to turn it down.  I didn't read it in detail but McAfee site advisor indicated that the site (or the link that I click) was phishing or scams and trying to steal some user information.  I can't remember exactly the link but the post I guess was between yesterday afternoon and mid-night.  Probably the link was hacked.

Now, it is okay for me.

Yuman

Yuman
twoinvallarta
  • Senior Member
  • ****
  • Posts: 445
  • Paper Money is Art!
« Reply #3 on: January 04, 2008, 05:09:46 pm »

Yep,Trend Micro caught it on my work comp.

hanmer
  • Full Member
  • ***
  • Posts: 188
« Reply #4 on: January 04, 2008, 05:38:32 pm »

I had an active X object try to load. The website that was loading in behind was saying "Your computer may be infected, blah, blah". When I closed the window it never came back. My Mcafee anti-virus did pick it up. This site puts a cookie on the computer when you log in. Those cookies can be traced by other sites and trigger the behavior described. Having never seen this happen here on this site, I wonder if the tracking cookie given at login has been changed. 

If you do have any concerns, delete your cookies and login again. Maybe choose 24 hours for the period to see if the  cookie expires as designed.

:)



:)
Manada
  • Very Senior Member
  • *****
  • Posts: 580
« Reply #5 on: January 04, 2008, 06:04:03 pm »

I use Kaspersky, and it just told me there is a malicious trojan script running on this forum. I have never seen this before.

But always, there remained the discipline of steel. - Conan the Barbarian
Punkys Dad
  • Very Senior Member
  • *****
  • Posts: 547
  • I keep my $1000 bill collection at Squid's place
« Reply #6 on: January 04, 2008, 06:21:00 pm »

I had an active X object try to load. The website that was loading in behind was saying "Your computer may be infected, blah, blah". When I closed the window it never came back. My Mcafee anti-virus did pick it up. This site puts a cookie on the computer when you log in. Those cookies can be traced by other sites and trigger the behavior described. Having never seen this happen here on this site, I wonder if the tracking cookie given at login has been changed. 

If you do have any concerns, delete your cookies and login again. Maybe choose 24 hours for the period to see if the  cookie expires as designed.

:)

Basically just got the same Active X pain. my PC Spyware just picked it up on this site. Got the same Pop-in virus claim, I did the same thing by closing it down then did a very thourough scan before coming back on. I use NOD32 Antivirus.

Teeny guy on my shoulder sez, It's only money mon
Fever
  • Guest
« Reply #7 on: January 04, 2008, 06:21:35 pm »

Yes, I was on the site about half an hour ago and when I left the site, my Norton Firewall blocked an high risk intrusion attempt.
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #8 on: January 04, 2008, 06:25:39 pm »

What URLs are generating this problem? Is it on ALL pages, or only some? Has anyone who has seen this been able to narrow down the source of the problem?

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
Gary_T
  • Very Senior Member
  • *****
  • Posts: 1,081
  • CPMS radar member 1551
« Reply #9 on: January 04, 2008, 06:30:32 pm »

I had a problem when I tried to reply to the grading poll question.

Gary_T
comox
  • Junior Member
  • **
  • Posts: 37
« Reply #10 on: January 04, 2008, 06:34:38 pm »

I had it happen to me twice when I went into 4 miscut 20s on Ebay. It said a Trojan horse had been detected. It happened about 8am EST this morning.

Gordo
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #11 on: January 04, 2008, 06:46:06 pm »

I'm not seeing anything strange. Can you guys please take screenshots of all these alerts and email them to me? bwjm@cdnpapermoney.com. Please include the page you were at (ie: full URL) when you got the message.
Thanks!

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #12 on: January 04, 2008, 09:34:01 pm »

There is a hit and miss on this virus...  in most cases, when you logout or have not logged in, that's where this virus hits...

When you scroll your cursor or mouse over the links... you will see the following:
http://www.cdnpapermoney.com/forum/index.php?PHPSESSID=7bbc149d80fd07cccaf0b2b2631e9276
(the website address when you drag your cursor over buttons or links will show on the bottom left side of the Internet Explorer window). 

I have no idea what that PHPSESSID is... but, what I know is that it's on all the address links after the Canadian papermoney website's address.  Whenever you click any of the links to any subjects ... your computer seizes up a bit, the "active x control" pops up on the window, and states:  "This website want to run the following add on:  'Microsoft  Data Access-Remote, Data Services Dat...' from Microsoft Corp.  If you trust the website and add on and want to allow it to run, click here..."   While this is running, the virus scanners pops up to indicate a known virus is blocked, and when you try to close the window... sometimes your computer freezes...

I WOULD ADVISE, DO NOT CLICK THIS...  as it's going to install something on your computer which can be permanent... and perhaps can track what your passwords, etc., are on PayPal, your banking website, etc... 

I hope this helps. 

Michael
« Last Edit: January 04, 2008, 09:43:24 pm by coinsplus »

  Smile from your heart.  ;D
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #13 on: January 04, 2008, 09:57:38 pm »

I found this website, trying to search this "Microsoft Remote Access Data Services.." 

This is an EXCELLENT little article showing the real website vs... a fake website:

http://msmvps.com/blogs/hostsnews/archive/2007/09/13/can-you-spot-the-fake.aspx

So Brent, I think this website has been attacked by some scrupulious person... and there's some debugging that someone's going to do...

Michael
« Last Edit: January 04, 2008, 10:00:15 pm by coinsplus »

  Smile from your heart.  ;D
Northwest5
  • Full Member
  • ***
  • Posts: 180
« Reply #14 on: January 04, 2008, 10:35:17 pm »

Yes, this has also haeppened to me twice over the last few days.  Very frustrating.  I tried to open the polls last nite when it hit me again.  The earlier time when I clicked to access/open the forum it would just not open at all.  I restarted the computer and then it did open without trouble.  I will look more closely next time and get details.
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #15 on: January 05, 2008, 12:42:41 am »

OK, I got it to happen once in Internet Explorer, but it has never happened in Firefox. I also cannot seem to reproduce it in Internet Explorer, which is annoying.
As far as I can tell, none of the source files for the website have been modified, but I haven't been able to properly examine this thing in action yet.

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #16 on: January 05, 2008, 02:57:22 am »

OK, I see the stupid thing, but I can't figure out where it's coming from. It's got to be in the source code somewhere, but everything I've looked at seems fine.

What pages are generating this problem? Is it only when you're viewing a topic? Does it happen when viewing a forum, or the main page? PMs?

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #17 on: January 05, 2008, 04:16:54 am »

Hi Brent,

It's EVERYWHERE!!!  It's on the mainpage of cdnpapermoney.com, the forum links to each section, when you post a reply, click the home page, click the help button, and so on....  Not sure if it's affecting PM.   

  Smile from your heart.  ;D
hanmer
  • Full Member
  • ***
  • Posts: 188
« Reply #18 on: January 05, 2008, 09:44:54 am »

Hard to recreate the error. I got it twice in a row doing some testing. Both times it happened when I clicked the General bread crumb shortcut at the top of the page. It happened while I was logged in and not logged in on the same link both times. Not sure it's in the code, or a MIME setting in the webservers settings. MIME is a communication that occurs between a web server and browser (IE mostly). This is where the webserver tells the browser what software is required to "see" pages or open specific file types embedded in pages (mpg, avi, pdf). If this is a hosted site, then it is possible that something changed for another site on the server, but the settings were applied across all sites instead of just the site that requires that Active X object.
It is unlikely a virus, but since there are no active x objects on this site, anti-virus software is flagging it as a threat. My next step is to actually install it to see what happens.

:)


:)
hanmer
  • Full Member
  • ***
  • Posts: 188
« Reply #19 on: January 05, 2008, 12:29:20 pm »

I installed the active x object as requested. I've not seen any issuses with the computers (running this on 2 seperate laptops).
I also have not seen any foreign connections appear when I'm using the internet. After the install of active x object, I  updated and ran the following software and all indicated no threats found.

Symantec anti-virus v 10 Enterprise Edition
Spybot Searce and Destroy
Ad Aware Personal

It's either been fixed, or the active x object was not harmful (in my opinion).

:)

:)
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #20 on: January 05, 2008, 12:54:25 pm »

Please note: I DO NOT recommend installing this activex control.

From what I have seen, there is definitely malware being returned on random page requests for this website. I do not know where it's coming from, despite spending hours poring over source code.

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
eldiablo666
  • Guest
« Reply #21 on: January 06, 2008, 09:18:42 am »

Hello,

I just became a member and there seems to be problems where ever I go on the site. I had a virus detected (trojan) when trying to become a member but my software took care of it, but when I tried to get into the recent posts my computer hung.   I rebooted and went back in and found this post and again got the virus detected and systems hung. I went back and finally got to post this.  Is this something to do with this specific site right now since I did access the site about 1 week ago as a guest and no problems . I am a little concerned that it is popping up so frequently and causing my computer to hang.
Any info appreciated.
Is is best to stay away from the site until this gets resolved.

ELDIABLO666
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #22 on: January 06, 2008, 10:45:07 am »

Use Firefox and you should not have this problem: www.getfirefox.com.

I am investigating, but this is going to take some time. Please be patient.

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #23 on: January 07, 2008, 10:52:38 am »

How about now? Is anyone getting that damned thing now?

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
CMNWEALTH
  • Junior Member
  • **
  • Posts: 33
  • One Chromosome between Insane and Genious !
« Reply #24 on: January 07, 2008, 11:07:19 am »

I noticed it for the first time yesterday (Internet Explorer)- Active X controls were trying to load when I clicked a page yesterday so I ran for the Hills. Today seems alright - fullscan on my computer and she's healthy as a horse !!!  ;D
comox
  • Junior Member
  • **
  • Posts: 37
« Reply #25 on: January 07, 2008, 11:16:10 am »

Everything seems to be fine in this end of the world. 8)

Gordo
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #26 on: January 07, 2008, 01:35:35 pm »

Hi Brent,

It seems that the website address, still has that weird PHPSESSID.

http://www.cdnpapermoney.com/forum/index.php?PHPSESSID=19e35906acd129334213a4c0807399f5&topic=6703.msg33425#new

It's a hit or miss on this... it seems that it randomly does this everytime you go into the link or refresh the screen... 

Normally, it should be:

http://www.cdnpapermoney.com/forum/index.php?topic=6703.0 or this:

http://www.cdnpapermoney.com/forum/index.php?topic=6703.msg33426#msg33426

Not sure if this can be corrected.

« Last Edit: January 07, 2008, 01:37:27 pm by coinsplus »

  Smile from your heart.  ;D
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #27 on: January 07, 2008, 01:41:19 pm »

Disregard the PHPSESSID thing. That's just tracking your session so the server knows it's still you making each request. I would expect that if you enable cookies or something, you should be able to avoid that. If not, no big deal.

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
Gary_T
  • Very Senior Member
  • *****
  • Posts: 1,081
  • CPMS radar member 1551
« Reply #28 on: January 07, 2008, 02:02:37 pm »

Quote
I noticed it for the first time yesterday (Internet Explorer)- Active X controls were trying to load when I clicked a page yesterday so I ran for the Hills. Today seems alright - fullscan on my computer and she's healthy as a horse !!! 

 My computer was as healthy as a horse too but a trojan horse! My computer was running rough yesturday I did a virus scan and there was a virus called SHeur.AIGJ in there but I'm not sure were I got it from.

 
Quote
I noticed it for the first time yesterday (Internet Explorer)- Active X controls were trying to load when I clicked a page yesterday

Yesterday was the same for me and after 11:30 or so I couldn't open the forum at all.Seems fine now.

I will be installing firefox very soon.

Gary_T
only4teeth
  • Forum Moderators
  • *
  • Posts: 496
  • CPMS Member 1489
« Reply #29 on: January 07, 2008, 03:00:09 pm »

Working good on my end Brent.

Thanks!
« Last Edit: January 07, 2008, 05:43:59 pm by only4teeth »
Punkys Dad
  • Very Senior Member
  • *****
  • Posts: 547
  • I keep my $1000 bill collection at Squid's place
« Reply #30 on: January 07, 2008, 03:02:34 pm »

I ran both IE first and then Firefox right after on this site. So far everything seems to be running okay here. Thanks Brent, that's why you get the big bucks  ;)

Keeping my fingers crossed. PD

Teeny guy on my shoulder sez, It's only money mon
buxvet
  • Senior Member
  • ****
  • Posts: 389
  • Is there anybody in the ceremony is about to begin
« Reply #31 on: January 09, 2008, 12:09:20 am »

I got all screwed up from this too. I'm not as tech savy as some of you. I ran a couple of spyware programs and seem to be OK now. I just stayed away for a few days.
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #32 on: January 09, 2008, 11:08:34 am »

Yesterday night, that active x thing was popping up constantly.  I couldn't get pas at either sites, cdnpapermoney.com or cdnpapermoney.com/forum/

Seems that things are okay now...

  Smile from your heart.  ;D
Gary_T
  • Very Senior Member
  • *****
  • Posts: 1,081
  • CPMS radar member 1551
« Reply #33 on: January 09, 2008, 12:33:39 pm »

The exact same thing here, but that firefox install is on the list.

Gary_T
nova7415
  • Full Member
  • ***
  • Posts: 242
  • Errors are the best as there are only 1 of a kind
« Reply #34 on: January 10, 2008, 01:54:11 am »

About 4 days ago, while on the Forum, this "active X" virus got through my firewall and slowed my computer down considerably ::). After I ran my Norton protection program, it found the virus and removed it. However, for the next few days I noticed quite a lag on my computer, but as of today everything is back to normal :). I can't understand what motivates these hackers to create these worms, virus's and such ???. Does someone pay them to infect certain sites or is it pure vandalism >:(
bugsy
  • Forum Moderators
  • *
  • Posts: 267
  • Money Doesn't Grow On Trees But is Made From Them?
« Reply #35 on: January 11, 2008, 10:19:39 am »

I to have had nothing but trouble along the same lines as all others. I have a trojan virus now that my ad-aware or other programs will not get rid of. Does anyone have any other programs or ideas that will help get this off of my comp. I have removed many things with ad-aware lately but this one just restarts my computer when ever the program detects it? Any info would be greatly appreciated. I have now switched to firefox for browsing!! Thanks Very Much...


    Jeff

Always looking for more Rotator Notes!!!
Elwoodbluesca
  • Wiki Contributor
  • Very Senior Member
  • *****
  • Posts: 514
  • Metro Coin & Banknote Company - Toronto Coin Expo
    • Metro Coin & Banknote Company
« Reply #36 on: January 11, 2008, 11:23:42 am »

Hey Jeff,

I do not think there is an easy solution to this problem. I ended up backing up my hard on another drive, reformatting the hard drive, and then reinstalling the operating system. No data was lost, but the hassle of going through all of this was not fun. Now everything is 100%

www.metrocbc.com - Metro Coin & Banknote Company
www.torontocoinexpo.ca - Toronto Coin Expo
President - Canadian Paper Money Society #1605
Director - J. Douglas Ferguson Foundation
rocken
  • Full Member
  • ***
  • Posts: 233
« Reply #37 on: January 11, 2008, 11:43:20 am »

I have had no problems for a few days but my AVG software didn't detect a trojan .
I would like to know the name of it? ???

Gary_T
  • Very Senior Member
  • *****
  • Posts: 1,081
  • CPMS radar member 1551
« Reply #38 on: January 11, 2008, 12:09:19 pm »

My AVG found a trojan virus and it was called SHeur.AIGJ


Gary_T
friedsquid
  • Very Senior Member
  • *****
  • Posts: 2,879
  • CPMS 1593
« Reply #39 on: January 11, 2008, 12:38:55 pm »

I also have AVG (the freebie) one and it detected it, put it in the vault and then I deleted it.
FRIEDSQUID



Always looking for #1 serial number notes in any denomination/any series
bugsy
  • Forum Moderators
  • *
  • Posts: 267
  • Money Doesn't Grow On Trees But is Made From Them?
« Reply #40 on: January 11, 2008, 12:52:04 pm »

I did the AVG as well and it said it found 176 files with a trojan??? Not real sure what it all means, it said it removed all but 1 of them? I will try it out and see how it runs this afternoon. I'm not a comp wizard so I just have been doing what I was told? I do not have a anti-virus program, maybe it is time to purchase one that is new and up to date??? Any thoughts on what else to try or what to buy if it comes down to that, Thanks for all the help!!

  Jeff

Always looking for more Rotator Notes!!!
BWJM
  • Very Senior Member
  • *****
  • Posts: 5,018
« Reply #41 on: January 11, 2008, 12:59:37 pm »

AVG is a good way to go. If you're that infected though, getting cleaned up may be a challenge. Anti-virus protection is an absolute essential in today's world. It's like wearing a seat-belt while in a car.

BWJM, F.O.N.A.
Life Member of CPMS, RCNA, ONA, ANA, IBNS, WCS.
President, IBNS Ontario Chapter.
Treasurer, Waterloo Coin Society.
Show Chair, Cambridge Coin Show.
Fellow of the Ontario Numismatic Association.
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #42 on: January 13, 2008, 03:44:24 pm »

I think the virus was back on this website earlier today...

The website originator who ever is trying to attack the site has the following website address which was being hosted on this site:
-http://gomyron.com/MTgxNjQ=/2/6411/ax=1/ed=1/ex=1// (don't copy this website and try to open it)  

I was able to obtain this website address when my windows explorer started seizing up... disconnected from the wireless internet connection... and that address was shown on my address bar, instead of the www.cdnpapermoney.com/forum/
« Last Edit: January 13, 2008, 03:47:59 pm by coinsplus »

  Smile from your heart.  ;D
Gary_T
  • Very Senior Member
  • *****
  • Posts: 1,081
  • CPMS radar member 1551
« Reply #43 on: January 13, 2008, 04:28:33 pm »

I've had no problems since I installed the firefox browser.


Gary_T
admin
  • Administrator
  • *****
  • Posts: 78
« Reply #44 on: January 14, 2008, 02:09:27 pm »

The problem seems to have been an issue on my master account. All of the domains on my server were doing this (not just CdnPaperMoney). You guys actually found it long before I was aware of it, but I believe it's been fixed as of Sunday (Jan 13th) afternoon. Guess I should drop in more often.

I'm sorry of the troubles.

Paul
coinsplus
  • Moderator
  • *****
  • Posts: 763
  • Yabba Dabba D'OH$$$
    • More about me.
« Reply #45 on: January 14, 2008, 11:58:17 pm »

Nice to hear from you Paul!  Glad to know that things are okay with the site.

Michael

  Smile from your heart.  ;D
 

Login with username, password and session length