Welcome to
Mod The Sims
Online: 2732
News:
Have an account? Sign in:
pass:
If you don't have an account, why not sign up now? It's free!
Other sites: SimsWiki

Hi, Unregistered! Still using Blue Game Style? Try out the new MTS theme, now in beta. Show me!
Closed Thread  Replies: 51 (Who?), Viewed: 25534 times.
Search this Thread
Old 14th Jul 2011, 11:41 PM DefaultAvast catching something on MTS? #1
matildarose
Original Poster

Lab Assistant

Join Date: Jan 2006
Posts: 216
Thanks: 1719 in 14 Posts
8 Achievements


Something odd keeps happening now when I access the site that didn't happen this afternoon. Avast keeps having to block an ad(?) which, in turn, stops the flash parts of the site from loading. I was able to navigate through a link to a thread get to the forum. Here's some info, with caps added by me:

Infection Details
URL: DONOTCLICKJUSTINCASEtp://fontcraft.com/2b1n-bad/banner.htmlDONOTCLICKJUSTINCASE
Process: file://C:\Program Files\Mozilla Firefox\firefox.exe
Infection: html:Iframe-inf

I have not actually looked at the url given- I have no idea what it links to. While it could be a false positive, I want to make sure to note it in case anyone else is having the same problem. Not even blocking all the entries in noscript helps. Hopefully, I can at least post this!


Please read this post!dialog
Last edited by Delphy : 15th Jul 2011 at 5:33 PM.
Old 14th Jul 2011, 11:47 PM #2
Delphy
Delphinius The Great



Join Date: May 2004
Posts: 8,709
Thanks: 69925 in 16 Posts
26 Achievements

View My Journal


Is this happening RIGHT NOW? Becuase I took the site offline to deal with that, and cleaned it all up, and I can't see it happening again right now.

Please tell me the specific page you are seeing it on.

Tumblr - Yes, I have a blog. :)

<Corsix> Why 'mod the sims 2' when you can mod 'mod the sims 2'?

Story books are full of fairy tales, of Kings and Queens, and the bluest skies.
Old 14th Jul 2011, 11:47 PM #3
matildarose
Original Poster

Lab Assistant

Join Date: Jan 2006
Posts: 216
Thanks: 1719 in 14 Posts
8 Achievements


Quote:
Originally Posted by Delphy
Is this happening RIGHT NOW? Becuase I took the site offline to deal with that, and cleaned it all up, and I can't see it happening again right now.

Please tell me the specific page you are seeing it on.


Haha, it's stopped now. That was quick! It seems you fixed it right as I was typing my message.
Old 15th Jul 2011, 12:10 AM #4
SeeMyu
Fluctuating Feathers



Join Date: Mar 2010
Posts: 1,405
Thanks: 16985 in 40 Posts
27 Achievements

View My Journal


This may be different, but everytime I load this forum or some other random threads.. Avast pops up saying Malicious URL Blocked



Screenshots
Click image for larger version

Name:  Capture.PNG
Views: 0
Size:  34.0 KB  

"Writing is all about disregarding the fact that you don't know what you're doing, never will, and are convinced that every other writer does." - Lauren DeStefano
It's Pronounced See-Mew
Old 15th Jul 2011, 12:22 AM #5
Whiterudder
BUTTS!



Join Date: Jul 2005
Posts: 14,791
Thanks: 28215 in 60 Posts
30 Achievements

View My Journal


Try clearing your caches - this is the same problem that D addressed a few minutes ago.

"On the page, punctuation performs its grammatical function, but in the mind of the reader it does more than that. It tells the reader how to hum the tune." - Lynn Truss, Eats, Shoots and Leaves
Old 15th Jul 2011, 1:27 AM Default'MAL/HTMLGen-A' found at this website? #6
Beccapixie10
Alchemist

Join Date: Apr 2009
Posts: 2,906
Thanks: 2227 in 16 Posts
11 Achievements


Every time I navigate to a new page on MTS (and sometimes randomly when I'm looking at a page), my antivirus (Sophos Endpoint Security & Control) is giving me the message "Access has been blocked to "indilatimes.gv.vg/showthread.php"as 'MAL/HTMLGen-A' has been found at this website". Before this morning, nothing had been happening. It apparently blocking access to this site has no effect on anything displaying or working, that I've found yet, but it is only happening on this site, so I'm guessing it's something on the site's end. I use Firefox and haven't changed anything since last night, when this message wasn't appearing. Anyone know what might be causing this?
Old 15th Jul 2011, 1:31 AM #7
SeeMyu
Fluctuating Feathers



Join Date: Mar 2010
Posts: 1,405
Thanks: 16985 in 40 Posts
27 Achievements

View My Journal


Hmm, this is odd. I cleared my cache, but Avast keeps notifying me that the URL is malicious =/

I get it on all of the community forums also if that helps

"Writing is all about disregarding the fact that you don't know what you're doing, never will, and are convinced that every other writer does." - Lauren DeStefano
It's Pronounced See-Mew
Old 15th Jul 2011, 1:39 AM #8
simsample
'Death, death, death' Until the sun cries morning



Join Date: Feb 2005
Posts: 16,822
Thanks: 7915 in 83 Posts
18 Achievements

View My Journal


Try clearing your caches- I was seeing something similar a while ago, but according to Delphy's Twitter he has fixed it, and it's fine for me now.

I will choose a path that's clear- I will choose free will
RUSH Headlong Flight Performing Arts Award Star Rush OC
Please check out my profile policies before PMing me! Thanks.
Old 15th Jul 2011, 1:43 AM #9
Whiterudder
BUTTS!



Join Date: Jul 2005
Posts: 14,791
Thanks: 28215 in 60 Posts
30 Achievements

View My Journal


I've seen several people reporting that is issue is still occurring now, so I'm gonna take the site down until D can give us another check-up in the morning (not all users have decent virus protection, and we don't want to be a source of infections). If you've complained previously and want to tell me it's fixed now and there's no need for maintenance, speak now or hold your peace 'til tomorrow.

"On the page, punctuation performs its grammatical function, but in the mind of the reader it does more than that. It tells the reader how to hum the tune." - Lynn Truss, Eats, Shoots and Leaves
Old 15th Jul 2011, 8:07 AM #10
Delphy
Delphinius The Great



Join Date: May 2004
Posts: 8,709
Thanks: 69925 in 16 Posts
26 Achievements

View My Journal


I can't find any evidence server-side that this is still occuring, nor can I reproduce it. I'm going to need specific URLs where this is happening.

Thanks

Tumblr - Yes, I have a blog. :)

<Corsix> Why 'mod the sims 2' when you can mod 'mod the sims 2'?

Story books are full of fairy tales, of Kings and Queens, and the bluest skies.
Old 15th Jul 2011, 8:47 AM #11
LadyAngel
Scholar

Join Date: Sep 2009
Posts: 1,042
Thanks: 13745 in 106 Posts
17 Achievements

View My Journal


I'm getting this warning even when clicking on my username to view my stuff:





I have to point out that I could view everything fine yesterday...perhaps it's a problem with Avast rather than the site?

Sim Fans UK is looking for creators to fill their downloads section, can you help? We also have a requests message board for members. :)
Old 15th Jul 2011, 8:59 AM #12
jenniferpink
Lab Assistant

Join Date: Dec 2007
Posts: 201


I also think it might be a problem with Avast, I'm getting the same messages.
Old 15th Jul 2011, 9:15 AM #13
SugoiZiua
Test Subject

Join Date: Jul 2011
Posts: 5


I have an other antivirus (Antivir), and it does not detect anything when I'm on MTS. I also have a professional version of Malwarebytes, It blocks absolutely all pages that seem questionnable.
Before I had Avast and it often make "jokes" like that.
Old 15th Jul 2011, 9:19 AM #14
Delphy
Delphinius The Great



Join Date: May 2004
Posts: 8,709
Thanks: 69925 in 16 Posts
26 Achievements

View My Journal


Okay for those that are willing, I need some help.

1. Go to http://www.modthesims.info/sitemap.php OR any URL *except* this thread you are reading now.
2. If you see the Avast popup, go to step 3.
3. Press Ctrl-U (firefox) Ctrl-Shift-U (safari, other browsers) or right click -> view source.
4. Within the source code, please search for either fontcraft.com or indila.
5. If you get any hits, take a screenshot of the source code and post it here.

Additionally, a Firefox Firebug Net panel output showing the call to indilatimes.gv.vg would be much appreciated.

Thanks

Tumblr - Yes, I have a blog. :)

<Corsix> Why 'mod the sims 2' when you can mod 'mod the sims 2'?

Story books are full of fairy tales, of Kings and Queens, and the bluest skies.
Old 15th Jul 2011, 9:21 AM #15
Alma70
Field Researcher

Join Date: Nov 2006
Posts: 407


I have Avast free version and I don't get any warnings but then I use Adblock Plus so I don't get any ads at all unless I turn it off...
Old 15th Jul 2011, 9:28 AM #16
Delphy
Delphinius The Great



Join Date: May 2004
Posts: 8,709
Thanks: 69925 in 16 Posts
26 Achievements

View My Journal


Alma70: This is nothing to do with ads, despite the thread category.

Tumblr - Yes, I have a blog. :)

<Corsix> Why 'mod the sims 2' when you can mod 'mod the sims 2'?

Story books are full of fairy tales, of Kings and Queens, and the bluest skies.
Old 15th Jul 2011, 9:50 AM #17
treeag
Theorist

Join Date: Feb 2006
Posts: 2,341
Thanks: 79719 in 49 Posts
25 Achievements

View My Journal


I'm using ESET NOD32 and I get warnings too.



Old 15th Jul 2011, 9:52 AM #18
Alma70
Field Researcher

Join Date: Nov 2006
Posts: 407


Quote:
Originally Posted by Delphy
Alma70: This is nothing to do with ads, despite the thread category.


Ok, still don't get any warnings from Avast tho... =P
Old 15th Jul 2011, 10:02 AM #19
HappyMonster
Test Subject

Join Date: Oct 2010
Posts: 10


I also get warnings from avast, as soon as I enter the site. Also everytime I open a new page.
Old 15th Jul 2011, 10:04 AM #20
Liv
Lab Assistant

Join Date: Jan 2008
Posts: 211
Thanks: 1827 in 9 Posts
8 Achievements


http://img35.imageshack.us/img35/347/98732036.jpg - linked because of its size.
I have Avast as well.

:]
Formerly Liv94.
Old 15th Jul 2011, 10:11 AM #21
Pleun
Test Subject

Join Date: Sep 2009
Posts: 35


Well, having avast as well, i figured i'd have a look, but my avast isn't responding to anything here. So i can't be of more help then reporting that it's not having any problems. I've even tried changing settings, trying the highest sensitivity levels, but it remained quiet.
Old 15th Jul 2011, 10:17 AM #22
Delphy
Delphinius The Great



Join Date: May 2004
Posts: 8,709
Thanks: 69925 in 16 Posts
26 Achievements

View My Journal


treeag, thanks for the source code shot! That's enabled me to track down the last remnants of this - inside the Blue Skies specific theme. This would only affect people using that particular theme.

Should be fixed now.

Tumblr - Yes, I have a blog. :)

<Corsix> Why 'mod the sims 2' when you can mod 'mod the sims 2'?

Story books are full of fairy tales, of Kings and Queens, and the bluest skies.
Old 15th Jul 2011, 10:21 AM #23
Liv
Lab Assistant

Join Date: Jan 2008
Posts: 211
Thanks: 1827 in 9 Posts
8 Achievements


It works fine now

:]
Formerly Liv94.
Old 15th Jul 2011, 11:52 AM #24
Digitalchaos
Instructor

Join Date: Apr 2005
Posts: 512
Thanks: 1603 in 21 Posts
9 Achievements


EDIT: Does not seem to be limited only to Blue Skies Theme ... I switched to Mint Tea (and still had the issue)
EDIT2: This time I got refences to fontcraft.com (but not indilatimes.gv.vg) -- at the top of the page (the source for the banner.html might explain why we are seeing both in the page's source)
Quote:
<iframe src='http://fontcraft.com/2b1n-bad/banner.html' width='1' height='1' frameborder='0'></iframe>
EDIT3: banner.html's source contains only: <iframe src='http://indilatimes.gv.vg/showthread.php?t=10070085' width='1' height='1' frameborder='0'></iframe>

ModTheSims Url: http://www.modthesims.info/imts2.php
Malicious/Blocked Url: http://indilatimes.gv.vg/showthread.php?t=10070085
No references to: fontcraft.com

Still getting Avast saying the site was blocked due to the above malicious URL

Quote:
Running Opera (with caches cleared)
Version: 11.50
Build: 1074
Platform: Win32
System: Windows 7
XHTML+Voice: Plug-in not loaded
Browser identification: Opera/9.80 (Windows NT 6.1; U; en) Presto/2.9.168 Version/11.50
Screenshots
Click image for larger version

Name:  MTS_AVAST_indilatimes_malware_warning_source_code.jpg
Views: 0
Size:  242.8 KB  

All TS2 Downloads Link
All TS3 Downloads: Link
All Other downloads: Link
Skyrim SKSE 1.6.x gamepad key support: Link
Last edited by Digitalchaos : 15th Jul 2011 at 12:42 PM. Reason: moving affected themes edit to new post (so people will get notified about it being new ... some themes are not affected and can be a temporary solution)
Old 15th Jul 2011, 11:54 AM #25
Alundra
Field Researcher

Join Date: Nov 2005
Posts: 256


I've cleared my cache and now can't get to the site because everything keeps getting shut down after loading. It's taken a few tries to get here. Here's a screenshot taken a couple of minutes ago:

http://i53.tinypic.com/id8uom.jpg

You can see the time on it too. My time format is in Australian time, the date is laid out the way Americans do it lol (I lived in the states for 6 years and came back to Aus confused ). Good luck on fixing it :D.

Jade Elizabeth (Alundra)
Just call me Al
See Hunaki La
Closed Thread


Section jump:


Powered by MariaDB Some icons by http://dryicons.com.