forums
new posts
donate
UER Store
events
location db
db map
search
members
faq
terms of service
privacy policy
register
login




UER Forum > Archived UE Website Updates > Infiltration.org Malware warning (Viewed 1975 times)
SwitchSwag 


Location: Toronto
Gender: Male




Send Private Message | Send Email
Infiltration.org Malware warning
< on 3/1/2012 6:38 AM >
Posted on Forum: Infiltration Forums
 
Just noticed it today. I’m getting the malware warning. What’s up with that?!?


267324.jpg (63 kb, 600x284)
click to view



Reality is what you make it.
Breach 


Location: Louisville, KY
Gender: Male




Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 1 on 3/1/2012 3:31 PM >
Posted on Forum: UER Forum
 
http://safebrowsin.../infiltration.org/

The domain gimulta.ru if i recall correctly is a photo aggregate server for sites MGID.org and other traffic sites where misleading headlines are the norm to get you to click the links.
[last edit 3/1/2012 3:36 PM by Breach - edited 1 times]

"I set the bar high, it makes it easier to sneak under." -J.D. Jenkins
Valkyre 


Location: Niflheim
Gender: Male


Its not the end of the world, but you can see it from here.

Send Private Message | Send Email | Tumblr
Re: Infiltration.org Malware warning
<Reply # 2 on 3/22/2012 11:20 AM >
Posted on Forum: UER Forum
 
Yeah just went to infiltration and got the same thing too. Now it's completely shut / redirecting to another down site.

Once things get political, they want us to stop shooting and start dancing.
I don't dance.
bonnie&clyde 


Location: 510 & 415


Cleverly disguised as responsible adults

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 3 on 3/22/2012 3:22 PM >
Posted on Forum: UER Forum
 
My browser hasn't let me go to infiltration for a while. A bunch of warnings. The search sites have it labeled as a threat.

The question is not when are we gonna stop, It's who's gonna stop us?

Intrinsic 


Location: Collingwood
Gender: Male




Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 4 on 3/22/2012 4:11 PM >
Posted on Forum: UER Forum
 
My initial attempt brought me to a Russian site http://hand-poise.ru/way/cream.php

but refreshing the URL brought me to the site.

Someone should have Liz look into this. It is hosted on Dreamhost.
[last edit 3/22/2012 4:12 PM by Intrinsic - edited 1 times]

paulpa 

This member has been banned. See the banlist for more information.


Location: Canuckistan
Gender: Male


Part-time troll

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 5 on 3/23/2012 2:07 AM >
Posted on Forum: UER Forum
 
Malware confirmed

It is the "internet security 2010" virus.

I just manually eliminated it from my computer.

there are two things you will have to delete if you get it:

the program itself which you can find in:

c/programdata

search for isecurity.exe and delete it. (you will need to be in safemode to disable the autorun)

and the autorun which is a registry key. You would need to go into safemode for this one

press flag+r and run regedit.exe

follow this path:

HKEY_USERS\S-1-5-21-1644491937-682003330-725345543-281977\Software\Microsoft\Windows\Current Version\Run

the key you are looking for is named isecurity.exe
[last edit 3/23/2012 2:08 AM by paulpa - edited 1 times]

Valkyre 


Location: Niflheim
Gender: Male


Its not the end of the world, but you can see it from here.

Send Private Message | Send Email | Tumblr
Re: Infiltration.org Malware warning
<Reply # 6 on 3/23/2012 12:42 PM >
Posted on Forum: UER Forum
 
Posted by paulpa
Malware confirmed

It is the "internet security 2010" virus.

I just manually eliminated it from my computer.

there are two things you will have to delete if you get it:

the program itself which you can find in:

c/programdata

search for isecurity.exe and delete it. (you will need to be in safemode to disable the autorun)

and the autorun which is a registry key. You would need to go into safemode for this one

press flag+r and run regedit.exe

follow this path:

HKEY_USERS\S-1-5-21-1644491937-682003330-725345543-281977\Software\Microsoft\Windows\Current Version\Run

the key you are looking for is named isecurity.exe


You mean this virus is causing the issue related to the infiltration.org site? I recently answered this on yahoo answers too, to delete the virus haha.
Gon' do it myself if I got it.

Once things get political, they want us to stop shooting and start dancing.
I don't dance.
Crypton 


Gender: Male




Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 7 on 3/23/2012 12:46 PM >
Posted on Forum: UER Forum
 
Don't Panic, I got this.


It appears something on infiltration.org has a web input field that is not sanitized. That is, someone has embedded script includes on some user-generatable content on the site so now that script executes on the website.

I remember FCKEditor was notorious for that, under certain conditions, you could bypass authentication within the filemanager and have at it the entire website content and modify the code as you wish.



Malware confirmed

It is the "internet security 2010" virus.

I just manually eliminated it from my computer.

there are two things you will have to delete if you get it:

the program itself which you can find in:

c/programdata


... or just don't download shit you don't know.

paulpa 

This member has been banned. See the banlist for more information.


Location: Canuckistan
Gender: Male


Part-time troll

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 8 on 3/23/2012 2:54 PM >
Posted on Forum: UER Forum
 
Posted by Crypton
Don't Panic, I got this.


It appears something on infiltration.org has a web input field that is not sanitized. That is, someone has embedded script includes on some user-generatable content on the site so now that script executes on the website.

I remember FCKEditor was notorious for that, under certain conditions, you could bypass authentication within the filemanager and have at it the entire website content and modify the code as you wish.




... or just don't download shit you don't know.


it was an automatic download when I clicked through the link. effects were immediatly afterwards.

Crypton 


Gender: Male




Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 9 on 3/23/2012 3:02 PM >
Posted on Forum: UER Forum
 
Posted by paulpa


it was an automatic download when I clicked through the link. effects were immediatly afterwards.


Don't use IE.

paulpa 

This member has been banned. See the banlist for more information.


Location: Canuckistan
Gender: Male


Part-time troll

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 10 on 3/23/2012 6:14 PM >
Posted on Forum: UER Forum
 
Posted by Crypton


Don't use IE.


firefox, most recent.

did not even appear in the downloads. it came in the background.

paulpa 

This member has been banned. See the banlist for more information.


Location: Canuckistan
Gender: Male


Part-time troll

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 11 on 3/23/2012 6:16 PM >
Posted on Forum: UER Forum
 
Posted by Valkyre


You mean this virus is causing the issue related to the infiltration.org site? I recently answered this on yahoo answers too, to delete the virus haha.
Gon' do it myself if I got it.


the only way for me to know for sure is to infect myself again.

wish me luck...

Crypton 


Gender: Male




Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 12 on 3/23/2012 6:43 PM >
Posted on Forum: UER Forum
 
NoScript.

Valkyre 


Location: Niflheim
Gender: Male


Its not the end of the world, but you can see it from here.

Send Private Message | Send Email | Tumblr
Re: Infiltration.org Malware warning
<Reply # 13 on 3/24/2012 12:54 AM >
Posted on Forum: UER Forum
 
I'm pretty positive I don't have the Internet Security 2012 (whatever the hell version) in my PC.

Also the site is totally down now. The re-direction failed and it can't find the site. Dayum, I had just bought my infiltration tee from there, and it hasn't arrived yet! Should I panic or not?

Once things get political, they want us to stop shooting and start dancing.
I don't dance.
paulpa 

This member has been banned. See the banlist for more information.


Location: Canuckistan
Gender: Male


Part-time troll

Send Private Message | Send Email
Re: Infiltration.org Malware warning
<Reply # 14 on 3/24/2012 2:32 AM >
Posted on Forum: UER Forum
 
Posted by Valkyre
I'm pretty positive I don't have the Internet Security 2012 (whatever the hell version) in my PC.

Also the site is totally down now. The re-direction failed and it can't find the site. Dayum, I had just bought my infiltration tee from there, and it hasn't arrived yet! Should I panic or not?


http://www.isup.me/infiltration.org

It is definately up... I am on it and it is now malware free, I have ZERO tracking cookies coming from the site right now.

I believe t-shirts are done by a third party (Order Hut).

Valkyre 


Location: Niflheim
Gender: Male


Its not the end of the world, but you can see it from here.

Send Private Message | Send Email | Tumblr
Re: Infiltration.org Malware warning
<Reply # 15 on 3/24/2012 4:06 AM >
Posted on Forum: UER Forum
 
Posted by paulpa


http://www.isup.me/infiltration.org

It is definately up... I am on it and it is now malware free, I have ZERO tracking cookies coming from the site right now.

I believe t-shirts are done by a third party (Order Hut).


Alright, site is working now, for sure.
Well if my tee doesn't arrive by next week, then something's fishy!

Once things get political, they want us to stop shooting and start dancing.
I don't dance.
UER Forum > Archived UE Website Updates > Infiltration.org Malware warning (Viewed 1975 times)



All content and images copyright © 2002-2024 UER.CA and respective creators. Graphical Design by Crossfire.
To contact webmaster, or click to email with problems or other questions about this site: UER CONTACT
View Terms of Service | View Privacy Policy | Server colocation provided by Beanfield
This page was generated for you in 234 milliseconds. Since June 23, 2002, a total of 741714732 pages have been generated.