Threats Detected on PB Forum Site

For everything that's not in any way related to PureBasic. General chat etc...
IdeasVacuum
Always Here
Always Here
Posts: 6426
Joined: Fri Oct 23, 2009 2:33 am
Location: Wales, UK
Contact:

Threats Detected on PB Forum Site

Post by IdeasVacuum »

Avast is intercepting a threat-a-day on the PB Forum Website, which tries to re-direct to a spoof Flash Download site.
IdeasVacuum
If it sounds simple, you have not grasped the complexity.
Zach
Addict
Addict
Posts: 1677
Joined: Sun Dec 12, 2010 12:36 am
Location: Somewhere in the midwest
Contact:

Re: Threats Detected on PB Forum Site

Post by Zach »

NOD32 hasn't picked up anything, sure its not a local infection spoofing the site or something?
PB
PureBasic Expert
PureBasic Expert
Posts: 7581
Joined: Fri Apr 25, 2003 5:24 pm

Re: Threats Detected on PB Forum Site

Post by PB »

No problem with Avira, and also Firefox isn't reporting the site as malware.
I compile using 5.31 (x86) on Win 7 Ultimate (64-bit).
"PureBasic won't be object oriented, period" - Fred.
User avatar
Samuel
Enthusiast
Enthusiast
Posts: 755
Joined: Sun Jul 29, 2012 10:33 pm
Location: United States

Re: Threats Detected on PB Forum Site

Post by Samuel »

I have Avast as well, but I have never received a threat detection on the forums. You may want to do a system and boot-time scan on your computer.
User avatar
Kuron
Addict
Addict
Posts: 1626
Joined: Sat Oct 17, 2009 10:51 pm
Location: Pacific Northwest

Re: Threats Detected on PB Forum Site

Post by Kuron »

Block the ads if they are still here. See if it still picks up a threat with the ads blocked?
Best wishes to the PB community. Thank you for the memories. ♥️
tj1010
Enthusiast
Enthusiast
Posts: 716
Joined: Mon Feb 25, 2013 5:51 pm

Re: Threats Detected on PB Forum Site

Post by tj1010 »

If it was a local infection, what if their AV doesn't have a signature for it yet? What if [your av here] doesn't have a signature for it yet?

My best recommendations are Kaspersky offline(free), security essentials Offline(free), or Avast beta anti-rootkit(free) or GMER(free) which it is based on.. Malwarebytes(free) is also a respectable solution but not good against the rootkit likely hiding any modern malware..

I've been meaning to make my own peboot based offline startup scanner for windows MBR, VBR, NT init binary hash, and registry scanner which pretty much detects anything except BIOS kits which for the most part don't exist yet..

Even something that just shows offline what is in startup registry keys finds everything but boot loader malware and init binary infectors, which both are an extreme minority..
User avatar
Bananenfreak
Enthusiast
Enthusiast
Posts: 519
Joined: Mon Apr 15, 2013 12:22 pm

Re: Threats Detected on PB Forum Site

Post by Bananenfreak »

Is this an ad? My adblocker doesn´t block it...

Avira got no Problem with nothing, it smells like weed.
Image
IdeasVacuum
Always Here
Always Here
Posts: 6426
Joined: Fri Oct 23, 2009 2:33 am
Location: Wales, UK
Contact:

Re: Threats Detected on PB Forum Site

Post by IdeasVacuum »

I think the reason others may not have seen this issue (yet?) is it's sporadic nature, or perhaps your AV deals with it faster/silently. Security Essentials never knew it was happening. It is always intercepted by Avast (they would know if it was the local system rather than the web server?) and FireFox often traps it, but not often enough. It is indeed to do with the ads running at the bottom of the page, which 99 times out of 100 are innocent. There is however something malicious there somewhere. When Avast kills it, the advert becomes a (large font) short piece of text: 'Document.write()'
IdeasVacuum
If it sounds simple, you have not grasped the complexity.
c4s
Addict
Addict
Posts: 1981
Joined: Thu Nov 01, 2007 5:37 pm
Location: Germany

Re: Threats Detected on PB Forum Site

Post by c4s »

In another thread you've said that you're still on Windows XP. So be extra careful if you really don't want to upgrade.
If any of you native English speakers have any suggestions for the above text, please let me know (via PM). Thanks!
tj1010
Enthusiast
Enthusiast
Posts: 716
Joined: Mon Feb 25, 2013 5:51 pm

Re: Threats Detected on PB Forum Site

Post by tj1010 »

IdeasVacuum wrote:I think the reason others may not have seen this issue (yet?) is it's sporadic nature, or perhaps your AV deals with it faster/silently. Security Essentials never knew it was happening. It is always intercepted by Avast (they would know if it was the local system rather than the web server?) and FireFox often traps it, but not often enough. It is indeed to do with the ads running at the bottom of the page, which 99 times out of 100 are innocent. There is however something malicious there somewhere. When Avast kills it, the advert becomes a (large font) short piece of text: 'Document.write()'
It's only a problem if the browser is running as a privileged user or it hits you with a privilege-elevation exploit before MS releases an update to patch said exploit..

MSE signatures are typically days behind others, and the offline version has the same database.
Zach
Addict
Addict
Posts: 1677
Joined: Sun Dec 12, 2010 12:36 am
Location: Somewhere in the midwest
Contact:

Re: Threats Detected on PB Forum Site

Post by Zach »

I use Adblock Edge, so I never see ads on most sites.

But if its sporadic and its linked to the ads, that would not surprise me. Most ads are rotating banner systems and serve from a small pool of selected ads. Probably one of the advertisers (or the company itself) up to shenanigans.
IdeasVacuum
Always Here
Always Here
Posts: 6426
Joined: Fri Oct 23, 2009 2:33 am
Location: Wales, UK
Contact:

Re: Threats Detected on PB Forum Site

Post by IdeasVacuum »

In another thread you've said that you're still on Windows XP.
I'm also on Win7 x64 and Win8.1 x64 (separate machines). The reason I re-tried many other AVs was of course XP's impending doom. Avast, which I really disliked before, is now really nice.
IdeasVacuum
If it sounds simple, you have not grasped the complexity.
IdeasVacuum
Always Here
Always Here
Posts: 6426
Joined: Fri Oct 23, 2009 2:33 am
Location: Wales, UK
Contact:

Re: Threats Detected on PB Forum Site

Post by IdeasVacuum »

I have tried various ad blockers, yet never heard of Adblock Edge, just so many out there. I don't mind the ads, so long as that is all they are. I assume Fred has ads on the Forum to glean some extra income - if I found an ad really really interesting I would click-through.

It might be the case though that these are more than 'naughty advertisers'. I think it is quite possible that there is malware on the server itself.
IdeasVacuum
If it sounds simple, you have not grasped the complexity.
tj1010
Enthusiast
Enthusiast
Posts: 716
Joined: Mon Feb 25, 2013 5:51 pm

Re: Threats Detected on PB Forum Site

Post by tj1010 »

IdeasVacuum wrote:I have tried various ad blockers, yet never heard of Adblock Edge, just so many out there. I don't mind the ads, so long as that is all they are. I assume Fred has ads on the Forum to glean some extra income - if I found an ad really really interesting I would click-through.

It might be the case though that these are more than 'naughty advertisers'. I think it is quite possible that there is malware on the server itself.
Edge is Plus without whitelist ads. I use Plus under FF and Chrome.

If we're judging AVs by detection rate, then we should go by typical virustotal results on fresh malware samples. It's usually Dr.Web and Avira who detect first. For real-time protections Norton IS and Kaspersky IS are typically better design though.

I just use sandboxie and MSE, both 100% free.. MSE has a delay in detection but does signatures just as good as the others, just use it offline sometimes because of rootkits..
IdeasVacuum
Always Here
Always Here
Posts: 6426
Joined: Fri Oct 23, 2009 2:33 am
Location: Wales, UK
Contact:

Re: Threats Detected on PB Forum Site

Post by IdeasVacuum »

Yeah, I am a long-time User of MSE and I think it's adequate, but of course it is not updated for XP any more. One thing I didn't point out and that is that the PB Forum is the only website where this issue occurs, out of the many sites I regularly visit (most of which also have ads of course).
IdeasVacuum
If it sounds simple, you have not grasped the complexity.
Post Reply