The Google Malware Alert

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Bill Dozer
    www.twitter.com/BillDozer
    • 07-12-05
    • 10894

    #1
    The Google Malware Alert
    Some posters have reported the Malware Alert from Google for the NFL pages of www.SBRforum.com. Apparently using any Google product, like Chrome & Google Search, will prompt the message. All of our internal virus scans as well as other external malware detectors show we are clean but that really doesn't matter because Google owns the internet. To give an idea of how this happens, the last time we saw a warning it was against the posting forum, and it was because someone hot linked an image from a third party infected website. Anyway, we took down all third party embedded video, facebook widget and ads for the moment and Google Scan says we are safe again. Unfortunately we need the same scan to be reflected in Google Search results not just thr internal scan they do for webmasters. So, we wait for them to update to reflect our update and re-index us.

    In the meantime, we have no reason not to believe visiting NFL Matchups page is A-OK. Apologies for the roadblock on NFL Thurs.
  • BlurredOut
    SBR Sharp
    • 01-22-12
    • 430

    #2
    thanks for the heads up malware is not a fun thing
    Comment
    • Bill Dozer
      www.twitter.com/BillDozer
      • 07-12-05
      • 10894

      #3
      Google is getting better all the time and making the net better. They are one of those monopolies I think we are better off with... at least at the moment. Hopefully they get better at detecting this stuff too. Embedding a non-clickable image in the forum can't be as dangerous as the offending site itself... All sites need to be careful which I guess is a good thing.
      Comment
      • TheCentaur
        SBR Hall of Famer
        • 06-28-11
        • 8108

        #4
        It wasn't google it was me lots of bad beats in the poker room lately. Sorry
        Comment
        • ACoochy
          SBR Posting Legend
          • 08-19-09
          • 13949

          #5
          Dozer is good peoples...
          Comment
          • Bill Dozer
            www.twitter.com/BillDozer
            • 07-12-05
            • 10894

            #6
            Looks like it is good now. It may have to update at all the Goog data centers.
            Comment
            • cloudagh
              SBR Sharp
              • 04-08-07
              • 486

              #7
              I did see this also. Thanks for letting us know what is what.
              Comment
              • dj_destroyer
                SBR MVP
                • 07-28-10
                • 3856

                #8
                Originally posted by Bill Dozer
                Google is getting better all the time and making the net better. They are one of those monopolies I think we are better off with... at least at the moment. Hopefully they get better at detecting this stuff too. Embedding a non-clickable image in the forum can't be as dangerous as the offending site itself... All sites need to be careful which I guess is a good thing.
                Definitely an awesome company... I think these guys really get it.
                Comment
                • TheMoneyShot
                  BARRELED IN @ SBR!
                  • 02-14-07
                  • 28690

                  #9
                  Originally posted by Bill Dozer
                  Google is getting better all the time and making the net better. They are one of those monopolies I think we are better off with... at least at the moment. Hopefully they get better at detecting this stuff too. Embedding a non-clickable image in the forum can't be as dangerous as the offending site itself... All sites need to be careful which I guess is a good thing.
                  A girl I know works for Google. She's a higher ranking employee. The personal data they obtain would blow your mind. She said if the government wants to see data about a particular individual... they must release it. It's so extensive at times... Google's formula knows more about you than you know about yourself.
                  Comment
                  • yahoonino
                    SBR MVP
                    • 08-10-07
                    • 2651

                    #10
                    bill , you are the man,,
                    Comment
                    • riffraff24
                      SBR Hall of Famer
                      • 04-20-11
                      • 7234

                      #11
                      Buy Macs. Problem solved.
                      Comment
                      • dante1
                        BARRELED IN @ SBR!
                        • 10-31-05
                        • 38658

                        #12
                        Originally posted by riffraff24
                        Buy Macs. Problem solved.

                        I can no longer use anything but Mac.
                        Comment
                        • riffraff24
                          SBR Hall of Famer
                          • 04-20-11
                          • 7234

                          #13
                          Originally posted by dante1
                          I can no longer use anything but Mac.
                          Same here. Every time I get on a PC I feel like i'm back in the 80s
                          Comment
                          • FuzzyDunlop
                            SBR MVP
                            • 01-15-11
                            • 2422

                            #14
                            Originally posted by Bill Dozer
                            Looks like it is good now. It may have to update at all the Goog data centers.
                            Working in Digitial Security, I've seen this take up to 3 weeks.
                            Comment
                            • lolbear
                              SBR Wise Guy
                              • 09-10-09
                              • 756

                              #15
                              google scares me
                              Comment
                              • FilL IVY League
                                SBR High Roller
                                • 10-27-12
                                • 180

                                #16
                                Originally posted by TheMoneyShot
                                A girl I know works for Google. She's a higher ranking employee. The personal data they obtain would blow your mind. She said if the government wants to see data about a particular individual... they must release it. It's so extensive at times... Google's formula knows more about you than you know about yourself.
                                Google don't know anything they merely save information, it is those that have access to that info that knows a thing or two, "So know you know, and knowing is half the battle"! G I Joe american heroe
                                Comment
                                • Iwinyourmoney
                                  SBR Posting Legend
                                  • 04-18-07
                                  • 18368

                                  #17
                                  Comment
                                  • slacker00
                                    SBR Posting Legend
                                    • 10-06-05
                                    • 12262

                                    #18
                                    I'm still getting the virus message. Any update on this?
                                    Comment
                                    • capitalist pig
                                      SBR Hall of Famer
                                      • 01-25-07
                                      • 5001

                                      #19
                                      I got the attack again last night after clicking on recommened books tab, I screen shot it but there seems to be so many things going wrong here at the moment I didnt send it in again.

                                      later
                                      Comment
                                      • nosniboR11
                                        SBR Posting Legend
                                        • 09-02-08
                                        • 10042

                                        #20
                                        in the meantime, some posters have had thousands stolen from them and sbr basically laughs
                                        Comment
                                        • SBR Lou
                                          BARRELED IN @ SBR!
                                          • 08-02-07
                                          • 37863

                                          #21
                                          Originally posted by capitalist pig
                                          I got the attack again last night after clicking on recommened books tab, I screen shot it but there seems to be so many things going wrong here at the moment I didnt send it in again.

                                          later
                                          Are you using Firefox? I can reproduce a message logged in through Google but it doesn't actually say anything's wrong. Appears to just be cache from before.

                                          Screenshots are always a plus.
                                          Comment
                                          • tad0matic
                                            SBR Wise Guy
                                            • 10-09-10
                                            • 621

                                            #22
                                            I got the message for the first time today, but after I closed chrome and tried it again there was no malware message. I'm posting this in the chrome browser.
                                            Comment
                                            • slacker00
                                              SBR Posting Legend
                                              • 10-06-05
                                              • 12262

                                              #23
                                              Originally posted by SBR Lou
                                              Are you using Firefox? I can reproduce a message logged in through Google but it doesn't actually say anything's wrong. Appears to just be cache from before.

                                              Screenshots are always a plus.
                                              I get the message using IE.
                                              Comment
                                              • JR007
                                                SBR Hall of Famer
                                                • 02-21-10
                                                • 5279

                                                #24
                                                thanks
                                                Comment
                                                • capitalist pig
                                                  SBR Hall of Famer
                                                  • 01-25-07
                                                  • 5001

                                                  #25
                                                  Click on sbr odds, brings it up for a flash then page goes blank and say IE can not connect to that web page. It was doing the same thing yesterday using Google Chrome.

                                                  Category: Intrusion Prevention
                                                  Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
                                                  12/24/2012 8:59:46 AM,High,An intrusion attempt by qgwzzddnkyv.antongorbunov.com was blocked.,Blocked,No Action Required,Web Attack: FakeAV Download 2,No Action Required,No Action Required,"qgwzzddnkyv.antongorbunov.com (31.7.57.194, 80)","qgwzzddnkyv.antongorbunov.com/index.php?c=RaENOjEayDF925cOxP3ACC60zajg AjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBd yf5LI5bynvIuWgPy46nXyoM=","VALUED-C0DCCC42 (xxx.xxx.x.x, xxxx)",31.7.57.194 (31.7.57.194),"TCP, www-http"
                                                  Network traffic from <b>qgwzzddnkyv.antongorbunov.com/index.php?c=RaENOjEayDF925cOxP3ACC60zajg AjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBd yf5LI5bynvIuWgPy46nXyoM=</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.

                                                  later
                                                  Comment
                                                  • SBR Lou
                                                    BARRELED IN @ SBR!
                                                    • 08-02-07
                                                    • 37863

                                                    #26
                                                    Hi cap,

                                                    Where are you clicking SBR Odds from - the posting forum or somewhere else?
                                                    Comment
                                                    • capitalist pig
                                                      SBR Hall of Famer
                                                      • 01-25-07
                                                      • 5001

                                                      #27
                                                      Originally posted by SBR Lou
                                                      Hi cap,

                                                      Where are you clicking SBR Odds from - the posting forum or somewhere else?
                                                      Posting forum

                                                      later
                                                      Comment
                                                      • SBR Lou
                                                        BARRELED IN @ SBR!
                                                        • 08-02-07
                                                        • 37863

                                                        #28
                                                        Thanks Cap. The rotator that was serving the iframe that seems to be triggering these alerts has been disabled while we investigate.
                                                        Comment
                                                        Search
                                                        Collapse
                                                        SBR Contests
                                                        Collapse
                                                        Top-Rated US Sportsbooks
                                                        Collapse
                                                        Working...