Jump to content

Primary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Secondary: Sky Slate Blackcurrant Watermelon Strawberry Orange Banana Apple Emerald Chocolate Marble
Pattern: Blank Waves Squares Notes Sharp Wood Rockface Leather Honey Vertical Triangles
Photo

Malware warning by Google [Incident: 2014/08/21]


  • This topic is locked This topic is locked
62 replies to this topic

#21
BakaBaka11

BakaBaka11

    Potato Sprout

  • Members
  • 7 posts

Wonder if its the same thing that happened to me months ago.



#22
1Suspect

1Suspect

    Potato Spud

  • Members
  • 15 posts

[Equips-Tin-Foil-Hat]

 

Although impossible to prove, it's plausible that this was orchestrated by the people in charge of the recent Japanese anti-piracy push; Likely out of frustration due to their inability to do anything.

 

[/Unequips-Tin-Foil-Hat]



#23
Tgirl

Tgirl

    Fingerling Potato

  • Members
  • 51 posts

I'm one of the MT victims, but that site had a very old unused password so I think I'm fine. I changed my passwords right after that event anyways.  ....   Oh gosh.  This was quite a small scare. D:   The flashback of the MT hack is still fresh in my mind. 

 

I have a good anti-malware program so I will run my phone and computer through them just to be safe. (But Grumpy says this is a fairly new malware so....., maybe, that won't really help..?) 

 

Thanks for keeping us updated on this.  



#24
Ookami-San

Ookami-San

    Potato Sprout

  • Members
  • 1 posts

According to avgthreatlabs.com this website was infected with NeoSploit Exploit Kit.

 

http://www.avgthreatlabs.com/website-safety-reports/domain/batoto.net/#analytics



#25
Tsukumo Yuma

Tsukumo Yuma

    Potato Spud

  • Contributor
  • 44 posts

Does virus infect the computers of people who have been on this site?


Otaku Tower Scans needs Japanese to English Translators, if you are interested, please apply.
http://otaku-tower-scans.tumblr.com
YCD12K3.pngSig made by me!
tJs5ySh.gif

#26
Kannade

Kannade

    Baked Potato

  • Donator
  • 1,204 posts
  • Locationkonoha

I cleaned out the infection, but later decided to nuke the entire skin as there may be more lingering pieces.

[...]
 
I've been scouring the logs for last few hours...


Dang you work too hard grumpy senpai, I would have just scrapped the entire site and then I would have pretended babobo never existed #lazy

#27
Sir Flashâ„¢

Sir Flashâ„¢

    Baked Potato

  • Donator
  • 1,365 posts
  • LocationGaming & Streaming

Just to be safe I will turn my ad-guard back on for this site...


Musician King's SoundCloud: 


 
 

p4dJLo8.gif

SON, NIC, SHAKES!!

Spoiler


#28
samo

samo

    Potato

  • Members
  • 133 posts
  • Locationdunno...i'm lost

Will the deluxe skin be put back again at some point??? cause i really liked it.



#29
Bogo

Bogo

    Potato Spud

  • Members
  • 30 posts
  • Locationbetween boobs

so I guess im safe (?) used Sylo skin and bookmark  


Edited by Bogo, 21 August 2014 - 10:29 PM.

c570a2ea1bad7bbe.gif

DONT SCROLL! BE A MAN!!!

>englrish user<


#30
ragamuphin

ragamuphin

    Potato Sprout

  • Members
  • 3 posts

Just wanna say I was using Blood skin/theme and my chrome is set to open to last open tabs. When I opened chrome and had a tab open to batoto it started downloading something. The first time I cancelled it, the file was called 12. The second time it was called 7 and i couldn't stop it. It was a small "file" not an application or picture. I scrubbed my computer clean but I'm not sure it's gone. This happened like two days ago.


Edited by ragamuphin, 21 August 2014 - 11:18 PM.


#31
Tsukumo Yuma

Tsukumo Yuma

    Potato Spud

  • Contributor
  • 44 posts
For the past few days untill today, evertime I went to this site, it said something about...

Chrome would like to gain access to you confedential infromation, by pressing ok you agree to let chrome use this information to *something i dont remember* please click ok.
I press cancel.

I tried going to the site through fire fox, a bunch of adds popped up as soon as I went to the site, and that computer has been acting buggy ever since.

PS. I am not using it now, it is to buggy, and I don't want whatever it is that's doing that to get my passwords.

A bunch of anime and manga sites, even nico nico dougas american branch has been hit with malware and hacking, it is going on all over the net recently.

Edited by Tsukumo Yuma, 22 August 2014 - 12:20 AM.

Otaku Tower Scans needs Japanese to English Translators, if you are interested, please apply.
http://otaku-tower-scans.tumblr.com
YCD12K3.pngSig made by me!
tJs5ySh.gif

#32
Grumpy

Grumpy

    RawR

  • Administrators
  • 4,078 posts
  • LocationHere of course!

I got the message when visiting directly from chrome or firefox.

 

So do I have to worry about having been infected or not grumpy? (because like I said, I ignored the warning on chrome to visit before you fixed the issue) It seems from what you said, no, but I want to make sure.

Everyone gets that message independent of the virus actually being present. It's a warning that it might be there placed by Google.

 

Wonder if its the same thing that happened to me months ago.

...What happened months ago? We never had any similar issue in the past.

 

[Equips-Tin-Foil-Hat]

 

Although impossible to prove, it's plausible that this was orchestrated by the people in charge of the recent Japanese anti-piracy push; Likely out of frustration due to their inability to do anything.

 

[/Unequips-Tin-Foil-Hat]

Uh... no. All they would have to do is send an email. Sounds a lot easier than hacking a site.

 

According to avgthreatlabs.com this website was infected with NeoSploit Exploit Kit.

 

http://www.avgthreatlabs.com/website-safety-reports/domain/batoto.net/#analytics

That's interesting that avg saw something... But that virus description is so vague that it practically applies to any kind of js injections...

 

Does virus infect the computers of people who have been on this site?

I believe that is the intent.

 

Just to be safe I will turn my ad-guard back on for this site...

Ad block/guard is unrelated to this issue. It won't protect you by using it, nor affect it in anyway unless you manually add the bad site url into its rules. This is not caused by the ads.

 

Will the deluxe skin be put back again at some point??? cause i really liked it.

If it does... I'll have to reinstall completely.

 

Just wanna say I was using Blood skin/theme and my chrome is set to open to last open tabs. When I opened chrome and had a tab open to batoto it started downloading something. The first time I cancelled it, the file was called 12. The second time it was called 7 and i couldn't stop it. It was a small "file" not an application or picture. I scrubbed my computer clean but I'm not sure it's gone. This happened like two days ago.

Hmm... That shows a virus-like behavior. But the days don't line up...

 

For the past few days untill today, evertime I went to this site, it said something about...

Chrome would like to gain access to you confedential infromation, by pressing ok you agree to let chrome use this information to *something i dont remember* please click ok.
I press cancel.

I tried going to the site through fire fox, a bunch of adds popped up as soon as I went to the site, and that computer has been acting buggy ever since.

PS. I am not using it now, it is to buggy, and I don't want whatever it is that's doing that to get my passwords.

A bunch of anime and manga sites, even nico nico dougas american branch has been hit with malware and hacking, it is going on all over the net recently.

I have never heard of such behavior until now. I would also suggest you to run a full virus scan on your computer.

If you are talking about the java install malware that was infecting large number of ad networks (also ones we don't use), it has been resolved for us already, and has been a while since it has.



#33
Tsukumo Yuma

Tsukumo Yuma

    Potato Spud

  • Contributor
  • 44 posts
I am not talking about that virus, I am talking about a newer one going around.
And I did run a full virus scan, but it picked up nothing at all, all the files, aplications, and the browsers, they all came back saying they were clean.

I googled the problem, and other viruses, I found something about a virus that is one going around that was barelly detected by only one virus scan software, but no way to get rid of it.

As I said, there have been large scale malware and hackings going on even within just this week.

Edited by Tsukumo Yuma, 22 August 2014 - 12:59 AM.

Otaku Tower Scans needs Japanese to English Translators, if you are interested, please apply.
http://otaku-tower-scans.tumblr.com
YCD12K3.pngSig made by me!
tJs5ySh.gif

#34
Grumpy

Grumpy

    RawR

  • Administrators
  • 4,078 posts
  • LocationHere of course!

Well... a rather strange development in google safe browsing...

http://www.google.com/safebrowsing/diagnostic?site=chinkoki.com/

Listing that site as no longer suspicious when that is the site which was injecting the virus on us...



#35
sidzero

sidzero

    Potato Spud

  • Members
  • 22 posts
  • LocationNowhereland

I like this skin better anyway.



#36
ragamuphin

ragamuphin

    Potato Sprout

  • Members
  • 3 posts

 

Hmm... That shows a virus-like behavior. But the days don't line up...

 

I don't remember the exact days.I believe the first time it happened 3-5 days ago, and the next time it was 2-4 days ago. It started downloading with no prompt, managed to stop the first from finishing,etc.



#37
Sogno-

Sogno-

    Russet Potato

  • Members
  • 469 posts
Thanks for the tldr; helps out us computer noobs :P

lol roll lol


#38
keane14

keane14

    Potato Sprout

  • Members
  • 1 posts
Does having notscript(chrome version of noscript), http switch board and ublock mean that I'm safe from this?

#39
Last Phantom

Last Phantom

    Potato Spud

  • Members
  • 11 posts
  • LocationNew Zealand

Wait, so the malware can get through IE? Damn... Chrome completely blocked me out of Batoto, so I used IE to get past...

...

Time to fire up the old Norton... I hate Norton.


600full-my-profile.jpg600full-my-profile.jpg600full-my-profile.jpg


#40
themis

themis

    Potato Sprout

  • Members
  • 2 posts

I don't know if this has anything to do with it, and I will freely admit not reading all the previous posts... but last week Every title page of kuroshituji was directing me to update my viewer. It would auto roll to the ad page if you didnt click over to the next page fast enough. It hasnt happened this week, but then again I'm UTD on that series now. :)

 

Oh yeah I was on Firefox at the time.


Edited by themis, 22 August 2014 - 03:42 AM.