Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 21st, 2008, 10:13 PM
thedman thedman is offline
Infrequent Poster
 
Join Date: Jun 2006
Posts: 6
Default norton blocked attack - need to worry?

I was searching on Yahoo for info on gambling regulation and tried to go to an article on the Covenant Protestant Refrormd Church website

Norton A/V said 2 attacks blocked by software-clicks.com (Misleading Application Detection) and img-z.com (Fake Codec Webpage)

so I went directly to the home page and tried again

cprf.co.uk

this time Norton didn't do anything

the address bar changed to wificafe-search.com, then us-euro.biz, then the website sextoyfun.com loaded

can anyone advise what might have go on here and if I need to worry I've been infected

thanks for any advice
  #2  
Old November 22nd, 2008, 02:32 AM
GES/POR's Avatar
GES/POR GES/POR is offline
Very Frequent Poster
 
Join Date: Nov 2006
Location: Armacham
Posts: 1,476
Default Re: norton blocked attack - need to worry?

Do a default scan with MBAM and a full/deep scan with SAS, if it comes up clean then relax.
__________________
Vista 64
  #3  
Old November 22nd, 2008, 03:47 AM
Sm3K3R's Avatar
Sm3K3R Sm3K3R is offline
Frequent Poster
 
Join Date: Feb 2008
Posts: 310
Default Re: norton blocked attack - need to worry?

Run BitDefender online scan + install,update and run Spybot Search & Distroy in safe mode.
__________________
Over & Out!
  #4  
Old November 22nd, 2008, 09:54 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,090
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by Sm3K3R
Run BitDefender online scan + install,update and run Spybot Search & Distroy in safe mode.
I haven't used it in a while but if I recall correctly BitDefender's online scan setting has to be modified not to delete what it finds.
  #5  
Old November 23rd, 2008, 05:35 AM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: norton blocked attack - need to worry?

I've just loaded the church's homepage, without any redirects, and no exploits evident. I would guess that the link you clicked from the Yahoo search page (if that's what you did) was fake; misleading, and since following that episode you were redirected away from the real site, something quite possibly has infected you despite Norton announcing it was blocked.
I would take the scanning suggestions recommended above fairly seriously. Especially the MBAM and SAS ones; those two are darned good. No experience of the online scan so can't comment.
DrWeb's Cureit is also an excellent demand AV scanner. Good removal capabilities, if that is a factor.
It would probably be a good idea to run a disk clean before running the scanners.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #6  
Old November 23rd, 2008, 12:15 PM
shanep shanep is offline
AV Expert
 
Join Date: Sep 2008
Posts: 54
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by thedman
I was searching on Yahoo for info on gambling regulation and tried to go to an article on the Covenant Protestant Refrormd Church website

Norton A/V said 2 attacks blocked by software-clicks.com (Misleading Application Detection) and img-z.com (Fake Codec Webpage)

so I went directly to the home page and tried again

cprf.co.uk

this time Norton didn't do anything

the address bar changed to wificafe-search.com, then us-euro.biz, then the website sextoyfun.com loaded

can anyone advise what might have go on here and if I need to worry I've been infected

thanks for any advice

Hi thedman,

That alert is coming from the Intrusion Prevention Engine which scans inbound (and outbound) network traffic and prevents such nasties from even getting into your machine. There is nothing more for you to do.The attack was blocked from infecting your machine.

It should be noted that these attacks are not easy to reproduce. They may 1 in 5 times. Thats what the JScript is code to do to trick AV Scanners and other web reputation crawlers.

Shane
  #7  
Old November 23rd, 2008, 02:37 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: norton blocked attack - need to worry?

Shane,
I may be as thick as a whale omelet, but if the intrusion was successfully blocked, why did the browser redirect to a sex toys site when the url for the church (which I can verify works correctly) was entered?
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #8  
Old November 24th, 2008, 02:55 AM
shanep shanep is offline
AV Expert
 
Join Date: Sep 2008
Posts: 54
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by Tarq57
Shane,
..but if the intrusion was successfully blocked, why did the browser redirect to a sex toys site when the url for the church (which I can verify works correctly) was entered?

Just to clarify, when you "works correctly", are you saying that when you visit that URL on another PC it goes to the expected page, yet on this PC it redirects you to a sex toys site ?
  #9  
Old November 24th, 2008, 04:39 AM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: norton blocked attack - need to worry?

To clarify, it wasn't my computer affected; I tried the URL in the OP, cprf.co.uk as part of a troubleshoot for thedman. It worked with no indication of redirect, nothing suspicious in the webpage at all, and nothing leapt out at me from viewing the page info (using Firefox.)
The OP (thedman) apparently had the redirect when he attempted to open the same website following the intrusion attempt alerted to by Norton.
As specified in the OP.
Which would make me a little suspicious.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #10  
Old November 24th, 2008, 12:17 PM
thedman thedman is offline
Infrequent Poster
 
Join Date: Jun 2006
Posts: 6
Default Re: norton blocked attack - need to worry?

thanks for all the advice

it repeated everytime I tried it - 4x in all

if I tried the link directly to the article on gambling Norton picked it up

but if I tried the link to their homepage it redirected to sextoyfun

I then e-mailed the cprf to make them aware and they said they'd fix it - I've now checked again and it does seem fixed

I've done all the scans recommended and nothing has come up aaprt from hundreds of tracking cookies - these are low danger?

BTW, should MBAM and SAS be run in safe mode or normal windows mode?

thanks again
  #11  
Old November 24th, 2008, 02:16 PM
shanep shanep is offline
AV Expert
 
Join Date: Sep 2008
Posts: 54
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by thedman
I then e-mailed the cprf to make them aware and they said they'd fix it - I've now checked again and it does seem fixed

Thanks for the update. So does this mean that the site was indeed infected ?
  #12  
Old November 24th, 2008, 03:17 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: norton blocked attack - need to worry?

Quote:
Thanks for the update. So does this mean that the site was indeed infected ?
And if it was, I'm wondering why it wasn't evident from my computer?
Using Firefox2, with no script and adblock plus.(All other software kept very up to date.) Was still OK with scripting enabled.
Thedman, what browser do you use?
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #13  
Old November 25th, 2008, 06:20 AM
thedman thedman is offline
Infrequent Poster
 
Join Date: Jun 2006
Posts: 6
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by Tarq57
And if it was, I'm wondering why it wasn't evident from my computer?
Using Firefox2, with no script and adblock plus.(All other software kept very up to date.) Was still OK with scripting enabled.
Thedman, what browser do you use?
I use IE7

I think I may have confused people with the chronology

After having these problems and (retrying x4) I posted on here - then I e-mailed the site owner - and I got an e-mail response within a few hours to say they would change the password and reload the site

So maybe they fixed it before anyone on here tried it
  #14  
Old November 25th, 2008, 06:37 AM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: norton blocked attack - need to worry?

Quote:
So maybe they fixed it before anyone on here tried it
Maybe they did.
Wouldn't hurt to run a scan with MBAM, anyway, to be sure.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #15  
Old November 25th, 2008, 12:00 PM
GES/POR's Avatar
GES/POR GES/POR is offline
Very Frequent Poster
 
Join Date: Nov 2006
Location: Armacham
Posts: 1,476
Default Re: norton blocked attack - need to worry?

Quote:
Originally Posted by thedman
I've done all the scans recommended and nothing has come up aaprt from hundreds of tracking cookies - these are low danger?

BTW, should MBAM and SAS be run in safe mode or normal windows mode?

thanks again

Safe mode isnt needed, cookies are harmless but no need to keep em on board so remove em. Am glad your safe.
__________________
Vista 64
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:09 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums