Timeshare Users Group Forums
TUG Links external to TUG BBS:    TUG Home| TUG Resort Databases| Marketplace | TUG Help | Advice | Join TUG  

Timeshare Users Group Bulletin Board
Go Back   Timeshare Users Group Forums > TUG > About TUG BBS
Log into the TUG BBS:

About TUG BBS The place to discuss this bulletin board, its features, etc. Discussion of all other aspects of TUG should be placed in About the Rest of TUG forum.

GLOBAL ANNOUNCEMENTS
Free Timeshare Exchanges on TUG! View current exchanges!

Free TUG Newsletter! Sign up today!

TUG Banner Travels the World! Follow the Banner!

 
Forum Jump


Reply « Previous Thread | Next Thread »
 
Thread Tools Search this Thread Display Modes
Old January 2, 2013, 01:08 PM   #151
emuyshondt
TUG Member
 
BBS Reg. Date: Apr 5, 06
Location: Austin, TX
Posts: 1,179

Resorts: Westin Ka'anapali Ocean Resort Villas, WKORV North, Westin St. John
Paco,

Any additional information on which virus it is (does it have a name I can google) and what all it does? My system scans are clean, but I want to make sure there's nothing hiding somewhere in my machine?

Henry
emuyshondt is offline   Reply With Quote
Old January 2, 2013, 02:37 PM   #152
TUGBrian
Administrator
 
TUGBrian's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Mar 24, 06
Location: Florida
Posts: 8,035
the only people ive seen report getting any sort of infection seem to describe the same "xp defender" fake antivirus download type.

although again, we cant find any source for it...no malicious code anywhere...and all the security scans (even 3rd party ones) show the site as clean.

Believe me its as frustrating on our end as it is yours.

Ill avoid putting more forum links in this weeks newsletter as well just in case.
TUGBrian is online now   Reply With Quote
Old January 2, 2013, 04:47 PM   #153
Makai Guy
Administrator
 
Makai Guy's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Jun 3, 04
Location: Aiken, SC, USA
Posts: 2,918

Resorts: Makai Club & Makai Club Cottages (Princeville, HI), Spicebush (Hilton Head)
Not sure how I missed this and failed to respond ..
Quote:
Originally Posted by emuyshondt View Post
Was anything specific found and cleaned up by the TUG administrators? Have they done anything beyond contacting Google and McAfee to get off their blacklist? I would like to know if there was some virus that has been fixed, and if so, what it was, so I can try to chase the issue down on my end. If I got infected, I want to make sure I find a way to disinfect my machine.
On 12/23 I found an image file that had some extraneous binary code added to it. This was an image file that is only viewed when a user is viewing a particular message in the BBS Help area, so it's not one that would have been visited much. I immediately replaced it with a clean copy of the image file. I don't know the nature of the injected code, just that it shouldn't have been there.
__________________
Doug Wilson, "The Makai Guy" - TUG BBS Administrator
My websites: North Shore Kauai and Yellowstone Photo Gallery
Makai Guy is offline   Reply With Quote
Old January 2, 2013, 07:35 PM   #154
pacodemountainside
 
pacodemountainside's Avatar
TUG Member
 
BBS Reg. Date: Jan 11, 08
Location: Aurora, Colorado
Posts: 1,412

Resorts: Wyndham VIP 315K, CWA 154, AVP Floating Week
Quote:
Originally Posted by emuyshondt View Post
Paco,

Any additional information on which virus it is (does it have a name I can google) and what all it does? My system scans are clean, but I want to make sure there's nothing hiding somewhere in my machine?

Henry
No, unfortunately this was all the info I have.

Interestingly, today I got same from 118.219.232.216. Just got another one with 121 that disappeared before I could copy while using spell checker!

Kinda like olde days when one had electrical problem with car. Lots of diagnosing and some luck finding!

Managers are giving best shot and fortunately no one with good virus programs reporting being infested just inconvenienced!
__________________
Paco
pacodemountainside is offline   Reply With Quote
Old January 2, 2013, 09:22 PM   #155
Timeshare Von
 
Timeshare Von's Avatar
TUG Member
 
BBS Reg. Date: Mar 13, 06
Location: Milwaukee, WI
Posts: 4,629

Resorts: FF/Wyndham Myrtle Beach/Westwinds (77k), Lifetime in Hawaii (Oahu)
Thumbs up

My sign on tonight (just now) was the first in days (weeks?) that I didn't get the notice via Firefox. Maybe it has been fixed
__________________
Yvonne

Check out my travel journals and photos at: http://www.igougo.com/profile/viewer...emberID=347099
Timeshare Von is online now   Reply With Quote
Old January 2, 2013, 10:43 PM   #156
Makai Guy
Administrator
 
Makai Guy's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Jun 3, 04
Location: Aiken, SC, USA
Posts: 2,918

Resorts: Makai Club & Makai Club Cottages (Princeville, HI), Spicebush (Hilton Head)
FWIW, for Firefox users:

Firefox 17 apparently is not updating its internal cache of the Reported Site list properly when a site drops off the Google list. (See Mozilla bug 820283.) This is reported to be fixed in Firefox 18, due to be released the week of Jan 6.

Meanwhile, users of Firefox 17 can force Firefox to check the current list at Google every time, instead of relying on cached data, as follows:

Enter about:config in the Address/URL bar.
Press the big button to bypass the warning (if you haven't turned this off already).
Enter confirm in the Filter bar to limit display to just options containing 'confirm'.
Double-click on urlclassifier.confirm-age and change the value to 0.
__________________
Doug Wilson, "The Makai Guy" - TUG BBS Administrator
My websites: North Shore Kauai and Yellowstone Photo Gallery
Makai Guy is offline   Reply With Quote
Old January 2, 2013, 11:20 PM   #157
memereDoris
 
memereDoris's Avatar
TUG Member
 
BBS Reg. Date: Oct 4, 09
Location: Alberta, Canada
Posts: 106

Resorts: Island Seas, Taino Beach, Wyndham Royal Vista & Palm-Aire, Florida Bay Club, Grand Pacific Palisades, Waterside at Spinn
Quote:
Originally Posted by Makai Guy View Post
FWIW, for Firefox users:

Firefox 17 apparently is not updating its internal cache of the Reported Site list properly when a site drops off the Google list. (See Mozilla bug 820283.) This is reported to be fixed in Firefox 18, due to be released the week of Jan 6.

Meanwhile, users of Firefox 17 can force Firefox to check the current list at Google every time, instead of relying on cached data, as follows:

Enter about:config in the Address/URL bar.
Press the big button to bypass the warning (if you haven't turned this off already).
Enter confirm in the Filter bar to limit display to just options containing 'confirm'.
Double-click on urlclassifier.confirm-age and change the value to 0.
This fix worked and was actually very easy.
Thanks.
memereDoris is offline   Reply With Quote
Old January 3, 2013, 07:14 AM   #158
Beaglemom3
 
Beaglemom3's Avatar
TUG Member
 
BBS Reg. Date: Jun 6, 05
Location: Boston
Posts: 1,667

Resorts: Allen House-London, Harborside Inn-Martha's Vineyard, The Mariner House-Nantucket, Marriott Custom House Platinum x2
I have not received any warning of any kind, ever on Tug.

Not at all tech savvy here, but I have Windows 7 Premium Home and Webroot.

I stand in awe of all who know this stuff.







-
__________________
www.belikebrit.org Remember Brittany and her orphanage in Haiti.

Last edited by Beaglemom3; January 3, 2013 at 07:21 AM.
Beaglemom3 is offline   Reply With Quote
Old January 3, 2013, 07:47 AM   #159
Timeshare Von
 
Timeshare Von's Avatar
TUG Member
 
BBS Reg. Date: Mar 13, 06
Location: Milwaukee, WI
Posts: 4,629

Resorts: FF/Wyndham Myrtle Beach/Westwinds (77k), Lifetime in Hawaii (Oahu)
Quote:
Originally Posted by Timeshare Von View Post
My sign on tonight (just now) was the first in days (weeks?) that I didn't get the notice via Firefox. Maybe it has been fixed
Oops - I spoke too soon (or jinxed it). This morning, the red bar warning returned
__________________
Yvonne

Check out my travel journals and photos at: http://www.igougo.com/profile/viewer...emberID=347099
Timeshare Von is online now   Reply With Quote
Old January 3, 2013, 09:12 AM   #160
judyjht
 
judyjht's Avatar
TUG Member
 
BBS Reg. Date: Jun 6, 05
Location: Hingham, Massachusetts
Posts: 990

Resorts: Briarwood (Cape Cod) Weeks 33 & 34 Mariner's Pointe Resort, TN - Week 34
I followed those instructions posted by Makai Guy and it looks good so far - what a pain in the butt this has been! Thanks (I hope)!
__________________
"If you can think of it - I can find it!"

Judith S. Peacock
judyjht is offline   Reply With Quote
Old January 5, 2013, 01:27 PM   #161
Blues
 
Blues's Avatar
TUG Member
 
BBS Reg. Date: Jun 6, 05
Location: Monterey County CA
Posts: 1,286

Resorts: HGVC, The Ridge Tahoe
Hadn't gotten it for a few days, but got the Firefox warning again this AM (Jan 5, 2013). Firefox 17.0.1. Haven't tried Makai's fix yet.

-Bob
Blues is offline   Reply With Quote
Old January 5, 2013, 02:53 PM   #162
TUGBrian
Administrator
 
TUGBrian's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Mar 24, 06
Location: Florida
Posts: 8,035
We are still experiencing what appears to be some sort of malware or exploit impacting the TUGBBS FORUMS. It seems to only impact a small number of visitors, but still to be sure, we would suggest not browsing the TUGBBS FORUMS unless you have a current/updated active virus scanner/protection software loaded on your computer. note this does NOT impact the member only section of the site, tug2.com is unaffected by this issue.

I myself have been able to get an unprotected laptop I own infected with this virus from surfing the forum...sadly it simply appears the forum is "redirecting" random users to some other location and the virus is not actually loaded on the TUGBBS...just the exploit that redirects people.

Hopefully we can come up with a solution with our host here soon.

I sincerely apologize for any of you that have had to deal with this. I will point out that I was able to restore my laptop using the native system restore tool to the previous days restore point and suffered no ill effects from the virus. I would urge all of you to make sure that you have system restore enabled on your windows machines...its way easier than trying to clean these viruses in other ways for sure!

Last edited by Makai Guy; January 5, 2013 at 11:36 PM. Reason: corrected "suggest browsing' to "suggest not browsing"
TUGBrian is online now   Reply With Quote
Old January 5, 2013, 04:10 PM   #163
Htoo0
TUG Member
 
BBS Reg. Date: Sep 6, 05
Location: Oklahoma
Posts: 1,155
Although I get the warning each time I come to the site this is only the second time my antivirus actually 'caught' something. Probably won't help but here it is.

Infection Details
URL: http://qahihahur.longmusic.com/lrf2x7zxw...
Process: C:\Program Files (x86)\Mozilla Firefox\f...
Infection: URL:Mal
Htoo0 is offline   Reply With Quote
Old January 5, 2013, 10:54 PM   #164
sptung
 
sptung's Avatar
TUG Member
 
BBS Reg. Date: Dec 5, 10
Location: Northern California
Posts: 853
The only way to clean the server is to build the server os from scratch and reload data onto the server. Alot of these malware just cannot be gotten rid of. I get the malware warning everyday on my laptop when I visit TUGbbs . No warning on the IPAD or my Droid phone. Wonder if they are now infected!
sptung is offline   Reply With Quote
Old January 7, 2013, 06:48 PM   #165
Tia
TUG Member
 
BBS Reg. Date: Jun 6, 05
Location: western Colorado
Posts: 1,867
Crossing fingers as this is the first time I have come to TUG in days and not gotten the warning page!

It's back spoke too soon
__________________
Still learning after all this time......

Last edited by Tia; January 8, 2013 at 07:40 AM. Reason: it's back
Tia is offline   Reply With Quote
Old January 8, 2013, 07:07 AM   #166
emuyshondt
TUG Member
 
BBS Reg. Date: Apr 5, 06
Location: Austin, TX
Posts: 1,179

Resorts: Westin Ka'anapali Ocean Resort Villas, WKORV North, Westin St. John
Quote:
Originally Posted by TUGBrian View Post
I myself have been able to get an unprotected laptop I own infected with this virus from surfing the forum...
Which virus is it? What does it do to your system? I am asking about the virus that infected my machine, not the redirecting code you had on TUG that caused my machine to catch the bug.
emuyshondt is offline   Reply With Quote
Old January 8, 2013, 08:46 AM   #167
mpumilia
TUG Member
 
BBS Reg. Date: Jul 16, 10
Location: Pine Bush, New York
Posts: 589

Resorts: Smuggler's Notch
I am still getting the warning but chanced going on the site today. What is going on?
mpumilia is offline   Reply With Quote
Old January 8, 2013, 11:26 AM   #168
csxjohn
 
csxjohn's Avatar
TUG Member
 
BBS Reg. Date: Apr 25, 12
Location: North East Ohio
Posts: 1,635

Resorts: Alhambra at Poinciana, Tropic Shores
I went to the other side of tug this morning on my daughter's computer and avast told me a harmful url was blocked. I don't have any details but did not come directly to the forums.
__________________
Support live, local music!
csxjohn is offline   Reply With Quote
Old January 8, 2013, 06:26 PM   #169
TUGBrian
Administrator
 
TUGBrian's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Mar 24, 06
Location: Florida
Posts: 8,035
it was the one listed earlier that masks itself as the "security scan" downloaded to your computer.

we are going to try to reimage the server this week in the hopes that it will clear this issue, as all of our attempts to find it have failed.
TUGBrian is online now   Reply With Quote
Old January 8, 2013, 06:57 PM   #170
lcml11
Guest
 
BBS Reg. Date: Oct 15, 12
Posts: 869
Quote:
Originally Posted by TUGBrian View Post
it was the one listed earlier that masks itself as the "security scan" downloaded to your computer.

we are going to try to reimage the server this week in the hopes that it will clear this issue, as all of our attempts to find it have failed.
Wish you luck. Hope it works.
lcml11 is offline   Reply With Quote
Old January 8, 2013, 07:19 PM   #171
KauaiMark
 
KauaiMark's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Jun 6, 05
Location: San Jose, CA
Posts: 692

Resorts: Marriott's Kauai Beach Club
Still with the Google warnings...

Still getting warnings when accessing the BBS but not the TUG2.com main pages

..Mark (risking getting here by ignoring the warning, and Kasperski's not squawking about it)
...Mark


-----------------------------------------------------------------------
Safe Browsing
Diagnostic page for tugbbs.com/forums

What is the current listing status for tugbbs.com/forums?

This site is not currently listed as suspicious.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.

What happened when Google visited this site?

Of the 129 pages we tested on the site over the past 90 days, 2 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-01-07, and the last time suspicious content was found on this site was on 2012-12-23.

Malicious software includes 1 exploit(s). Successful infection resulted in an average of 7 new process(es) on the target machine.

Malicious software is hosted on 1 domain(s), including hivanopi.longmusic.com/.

This site was hosted on 1 network(s) including AS32244 (LIQUID).

Has this site acted as an intermediary resulting in further distribution of malware?

Over the past 90 days, tugbbs.com/forums did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?

No, this site has not hosted malicious software over the past 90 days.

Next steps:

Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.
-------------------------------------------------------------------------
__________________
____________________________________
Mark Perry
TUG Volunteer
KauaiMark is offline   Reply With Quote
Old January 9, 2013, 09:33 AM   #172
HatTrick
Guest
 
BBS Reg. Date: Aug 30, 08
Posts: 796

Resorts: HGVC Kalia & Waikoloa
Alert Received This Morning

HatTrick is offline   Reply With Quote
Old January 9, 2013, 12:16 PM   #173
TUGBrian
Administrator
 
TUGBrian's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Mar 24, 06
Location: Florida
Posts: 8,035
as a stopgap I have had our host block that URL that is being reported as the malware redirect...at least until we get this sorted out I hope at least this will be an effective stopgap measure.

although what baffles me is that if tug can get "flagged" for malware just for redirecting a small %of people to a virus site, why cant they blacklist the virus site?
TUGBrian is online now   Reply With Quote
Old January 9, 2013, 01:03 PM   #174
lcml11
Guest
 
BBS Reg. Date: Oct 15, 12
Posts: 869
Quote:
Originally Posted by TUGBrian View Post
as a stopgap I have had our host block that URL that is being reported as the malware redirect...at least until we get this sorted out I hope at least this will be an effective stopgap measure.

although what baffles me is that if tug can get "flagged" for malware just for redirecting a small %of people to a virus site, why cant they blacklist the virus site?
I would have thought since their staff verified it that would have been done within seconds of there finding it.
lcml11 is offline   Reply With Quote
Old January 9, 2013, 01:07 PM   #175
TUGBrian
Administrator
 
TUGBrian's Avatar
TUG Lifetime Member
 
BBS Reg. Date: Mar 24, 06
Location: Florida
Posts: 8,035
clearly not if people are still being redirected there and getting infected.
TUGBrian is online now   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 11:56 AM.


Powered by: vBulletin Version 3.8.7
BBS Software Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Editorial Content Copyright ©1993 - 2013, Timeshare Users Group
Customized for TUG by Makai Guy.