Threat detected !!

Submitted: Sunday, Sep 05, 2010 at 21:54
ThreadID: 81158 Views:5885 Replies:13 FollowUps:16
This Thread has been Archived
Have been getting a threat detection notice from AVG!!

Danger: AVG Active Surf-Shield has detected active threats on this page and has blocked access for your protection.
The page you are trying to access has been identified as a known exploit, phishing, or social engineering web site and therefore has been blocked for your safety. Without protection, such as that in the AVG Security Toolbar and AVG, your computer is at risk of being compromised, corrupted or having your identity stolen. Please follow one of the suggestions below to continue.

URL: sdztsdz.co.cc/x/index.php?s=8afbd7f3844f428845fda616ee61a85f
Name: Eleonore Exploit Kit (type 1617)

Am going to bail out for tonight !!

Ian
Back Expand Un-Read 0 Moderator

Reply By: Member - John (Vic) - Sunday, Sep 05, 2010 at 22:58

Sunday, Sep 05, 2010 at 22:58
Do a search of the archives.
AVG has done this sort of thing before from memory.

VKS737 - Mobile 6352 (Selcall 6352)

Lifetime Member
My Profile  Send Message

AnswerID: 429485

Reply By: Dave(NSW) - Sunday, Sep 05, 2010 at 23:22

Sunday, Sep 05, 2010 at 23:22
I'm using AVG and don't have a problem.
Cheers Dave..
GU RULES!!

Lifetime Member
My Profile  My Blog  Send Message

AnswerID: 429486

Follow Up By: Member - Doug T (NT) - Sunday, Sep 05, 2010 at 23:33

Sunday, Sep 05, 2010 at 23:33
Is yours the free version or the full version as mine is and paid for.

/.
gift by Daughter

Lifetime Member
My Profile  My Blog  Send Message

0
FollowupID: 700234

Follow Up By: Dave(NSW) - Monday, Sep 06, 2010 at 00:20

Monday, Sep 06, 2010 at 00:20
Yeah Doug, mines the full paid for version I also run Malwarebytes.
Cheers Dave.
GU RULES!!

Lifetime Member
My Profile  My Blog  Send Message

0
FollowupID: 700238

Follow Up By: Member - DickyBeach - Monday, Sep 06, 2010 at 06:51

Monday, Sep 06, 2010 at 06:51
I'm the same as Dave(NSW) - paid version of AVG (updated nightly) and also Malwarebytes (also nightly) and have not (yet?) received any warnings.
Fingers crossed,

DB
0
FollowupID: 700242

Reply By: Member - Doug T (NT) - Sunday, Sep 05, 2010 at 23:31

Sunday, Sep 05, 2010 at 23:31
So if you get a warning , take notice and don't open the website.
Mine blocked it.

Image Could Not Be Found
gift by Daughter

Lifetime Member
My Profile  My Blog  Send Message

AnswerID: 429487

Reply By: Maîneÿ . . .- Sunday, Sep 05, 2010 at 23:33

Sunday, Sep 05, 2010 at 23:33
I'm using AVG Free (ver 9.0) and don't appear to have any problem :)

Fortunately Google Chrome won't let me open the webpage 'sdztsdz . co' and advises me "it appears to host malware" so something is not as it usually is?

Maîneÿ . . .
AnswerID: 429488

Reply By: Member - Marc Luther B (WA) - Sunday, Sep 05, 2010 at 23:40

Sunday, Sep 05, 2010 at 23:40
I already found out the hard way that ones identity can be stolen in Facebook, now here as well. What is going on.

I have a fully paid subscription to AVG now, and although no such warning, I will stay away for a while to avoid the chance of it happening again.
Why travel overseas, you could travel Australia your entire life, and not see it all.

Lifetime Member
My Profile  My Blog  Send Message

AnswerID: 429489

Follow Up By: Member - Leon A (SA) - Sunday, Sep 05, 2010 at 23:46

Sunday, Sep 05, 2010 at 23:46
I don't think the warning is from this site as there is nothing in any of the posts to suspect there is.
0
FollowupID: 700235

Reply By: Member - Serendipity(WA) - Sunday, Sep 05, 2010 at 23:42

Sunday, Sep 05, 2010 at 23:42
I am using a Apple Mac so you guys just ignore those warnings - everything is alright. ; )

Lifetime Member
My Profile  My Blog  Send Message

AnswerID: 429490

Follow Up By: Maîneÿ . . .- Sunday, Sep 05, 2010 at 23:48

Sunday, Sep 05, 2010 at 23:48
Serendipity,
an explanation as to why we should ignore it would be nice :)

Is it because you use a Mac and don't virus's and we (PC users) are in some danger and your laughing at our expense ?

Maîneÿ . . .
0
FollowupID: 700236

Follow Up By: Member - Serendipity(WA) - Monday, Sep 06, 2010 at 00:45

Monday, Sep 06, 2010 at 00:45
Sorry Mainey

I did not mean any offence - just gentle competition humour like toyota - nissan or Ford - holden.






Lifetime Member
My Profile  My Blog  Send Message

0
FollowupID: 700239

Reply By: Member No 1- Monday, Sep 06, 2010 at 08:53

Monday, Sep 06, 2010 at 08:53
I think you have a trojan

if you follow that link it wont take you to AVG but somewhere else and then you will have all sorts of problems

kids have done it many times on my computer...one that comes to mind is

had to do with an antivirus programme promising the world...it puts up a pop up and tells you that your machine is infected and to go to a site and down load the latest and bets Anti Virus programe for free...now what would you do if you were 9yrs old and have just stuffed up Dads Computer.........you'd go and down load the programme and make things better .....wouldnt you...then you go and hide at grandma's place....
AnswerID: 429504

Follow Up By: Member No 1- Monday, Sep 06, 2010 at 08:56

Monday, Sep 06, 2010 at 08:56
I use Shield Deluxe...far better than Computer Associates


but be warned ...it deletes KeyGens..lol
0
FollowupID: 700254

Reply By: olcoolone - Monday, Sep 06, 2010 at 09:41

Monday, Sep 06, 2010 at 09:41
It seems there are a lot of experts and nobody knows whats going on.

The web site "sdztsdz.co.cc/x/index.php?s=8afbd7f3844f428845fda616ee61a85f" is a know site for carrying malware in it's links, so when you click on a link it may download a small bit of software that can be used to get information or snap shoots about the user and send it back to the host.

I would strongly suggest if you if you current security software doesn't pick it up you may want to get some real security software......free is not always best!

And no real security software give you false alarms just so you have to buy are upgrade.

Remember cyber crims are getting smarter and smarter and so is software to detect it, it's just a shame that other people out there don't think so and allow their computers to become infected...... some think of it as a common cold, it will go away soon.....maybe they should think of it as cancer, you don't know you have it until most times it's to late and damage has been done.

AnswerID: 429511

Follow Up By: olcoolone - Monday, Sep 06, 2010 at 09:46

Monday, Sep 06, 2010 at 09:46
By the way this is what they are on about.

Safe Browsing
Diagnostic page for sdztsdz.co.cc

What is the current listing status for sdztsdz.co.cc?
Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.

What happened when Google visited this site?
Of the 3 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-09-04, and the last time suspicious content was found on this site was on 2010-09-04.
Malicious software includes 14 trojan(s).

This site was hosted on 2 network(s) including AS42560 (BA), AS6851 (BKCNET).

Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, sdztsdz.co.cc did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?
Yes, this site has hosted malicious software over the past 90 days. It infected 9 domain(s), including trendsone.com/, mostamazingplayers.blogspot.com/, telugumovieonline.net/.

How did this happen?
In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:
Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.
0
FollowupID: 700260

Reply By: B1B2 - Monday, Sep 06, 2010 at 10:32

Monday, Sep 06, 2010 at 10:32
I had copied a blog to a portable hard drive from this site to read later. When I used it on my wifes laptop it came up with a 'Trojan' alert. I deleted the file and all was ok.
I must keep my virus protection up to date.

Cheers,
Bill
AnswerID: 429513

Reply By: Dave(NSW) - Monday, Sep 06, 2010 at 11:47

Monday, Sep 06, 2010 at 11:47
I'm not trying to be smart or funny but what has the site mentioned got to do with EO, is it a link to something or what.
Cheers Dave. (who's not to bright on computers LOL)
GU RULES!!

Lifetime Member
My Profile  My Blog  Send Message

AnswerID: 429517

Follow Up By: Maîneÿ . . .- Monday, Sep 06, 2010 at 18:56

Monday, Sep 06, 2010 at 18:56
Dave,
The site is located at: http: //sdztsdz.co.cc/x/l.php?s=m7MASX

This website is not directly relevant to EO or even local 4wd

Why has Ian placed the post placed here? - I've no real clue
Maybe he was lonely and wants to tell us where he is playing
he definitely had a few interested people looking at his post :-)

Maîneÿ . . .
0
FollowupID: 700318

Follow Up By: Ianw - Monday, Sep 06, 2010 at 21:33

Monday, Sep 06, 2010 at 21:33
The threat warning occurred while opening pages on THIS SITE !! That is why it is posted here ! It happened on 2 occasions when opening different threads on the forum so I notified the moderators and bailed out for the night. I don't like taking risks with computer security.

Ian
0
FollowupID: 700339

Follow Up By: Maîneÿ . . .- Monday, Sep 06, 2010 at 22:49

Monday, Sep 06, 2010 at 22:49
Ian,
so you were directed to "http: //sdztsdz.co.cc/x/l.php?s=m7MASX" direct from this site?

You then advised the Mods so they, I'm positive, would have advised David of the potential threat to ALL of us using the forum and I'm just as sure some action would be taken to deactivate all threats

Maîneÿ . . .
0
FollowupID: 700346

Follow Up By: Ianw - Monday, Sep 06, 2010 at 22:57

Monday, Sep 06, 2010 at 22:57
No I wasn't directed to that site. The warning came up while viewing this site. At no time did I go to the other site. One would hope that David would take all threats seriously and move to investigate.

Ian
0
FollowupID: 700348

Follow Up By: Maîneÿ . . .- Monday, Sep 06, 2010 at 23:04

Monday, Sep 06, 2010 at 23:04
What I don't understand is the message you have received is:
"Danger: AVG Active Surf-Shield has detected active threats on this page and has blocked access for your protection.
The page YOU ARE TRYING TO ACCESS has been identified as a known exploit, phishing, or social engineering web site and therefore has been blocked for your safety.

URL: sdztsdz.co.cc /x/index.php?s=8afbd7f3844f428845fda616ee61a85f "

Ian, it clearly states you were directed to the site: "sdztsdz . co......."

Maîneÿ . . .
0
FollowupID: 700351

Follow Up By: Ianw - Monday, Sep 06, 2010 at 23:16

Monday, Sep 06, 2010 at 23:16
I spose that has to be correct, but AVG prevented that page from opening. AVG scans sites before it allows them to be opened, and in this case did its job.
At no time did I try to go to that site. All I did was open a thread on this forum. It come up with the warning. I tried another thread and the warning came up again. So I bailed out.

Ian
0
FollowupID: 700352

Reply By: Maîneÿ . . .- Monday, Sep 06, 2010 at 12:08

Monday, Sep 06, 2010 at 12:08
Norton Security

WARNING

sdztsdz.co.cc
Summary
•Computer Threats: 10
•Identity Threats: 0
•Annoyance factors: 0
Total threats on this site: 10

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=m7MASX

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=sound&d

Threat Name: HTTP Eleonore Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=samba2

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=sound&b

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=sound&9

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=sound&4

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=sound&7

Threat Name: HTTP Phoenix Toolkit Executable Download
Location: http: //sdztsdz.co.cc/x/l.php?s=flash9ALL

Viruses
Threats found: 2

Threat Name: Trojan.Pidief
Location: http: //sdztsdz.co.cc/x/img1.php?s=i900

Threat Name: Trojan.Pidief
Location: http: //sdztsdz.co.cc/x/img1.php?s=i708

(for security reasons I've separated all the above Internet address's)

Something to consider, is nothing I can see relevant to EO
BUT... I'm sure someone will go further and check it out

Maîneÿ . . .
AnswerID: 429520

Reply By: Ianw - Monday, Sep 06, 2010 at 18:34

Monday, Sep 06, 2010 at 18:34
Well people, I pay for a product to protect me. If I am stupid enough to ignore it when it warns of a problem then I guess I deserve anything that happens, eh? I took notice of the warning and passed it on to other users. I cannot do more than that. Ignore it at your own peril !

Cheers

Ian
AnswerID: 429541

Follow Up By: Member - John (Vic) - Monday, Sep 06, 2010 at 20:24

Monday, Sep 06, 2010 at 20:24
Was the warning from this site is the question being asked??

If so maybe it would be a good idea to pass the detail the David so he can have a look.

VKS737 - Mobile 6352 (Selcall 6352)

Lifetime Member
My Profile  Send Message

0
FollowupID: 700330

Follow Up By: Ianw - Monday, Sep 06, 2010 at 21:36

Monday, Sep 06, 2010 at 21:36
Yes the warning came while opening threads on this forum. It happened twice, I did notify moderators and users and then bailed out for the night.

Ian
0
FollowupID: 700340

Reply By: fisho64 - Tuesday, Sep 07, 2010 at 01:41

Tuesday, Sep 07, 2010 at 01:41
Have a look at it from another angle.

At my work we plug external hard drives/thumb drives into each others. We all use different virus programs. Occasionally someones will pop with "virus found" when plugging in when no one elses does.

Being a little cynical me-thinks that sometimes it is easier for a virus program supplier to make up a threat as some more gullible will be thinking

"my program is better than yours as its found something yours hasnt".

Thats not to say though that there isnt a possible threat here or anywhere.

However the message

"identified as a known exploit, phishing, or social engineering web site"

seems to ring true in every description of Exploroz (other than the poor spelling of fishing!)
AnswerID: 429584

Sponsored Links

Popular Products (9)