Virus blocked by my antivirus software twice in two days when accessing this site

Status
Not open for further replies.

Mac

Ultra Member
ECF Veteran
Jun 5, 2009
2,477
15,159
All up in your grill..
I don't know what the deal is but last night and then this morning my antivirus stopped me from opening ecf and said a virus was blocked.

AVG calls it "exploit blackhole exploit kit"

Closed everything logged in again and now ecf works fine. This makes me nervous. Any idea what's causing it? ecf was the only page open and I was not running any other software.
 

carpedebass

Ultra Member
ECF Veteran
Verified Member
Jul 10, 2011
2,168
1,500
54
The Alamo City
I don't know what the deal is but last night and then this morning my antivirus stopped me from opening ecf and said a virus was blocked.

AVG calls it "exploit blackhole exploit kit"

Closed everything logged in again and now ecf works fine. This makes me nervous. Any idea what's causing it? ecf was the only page open and I was not running any other software.

Same thing happened on my work machine running Windoze. I figured it's probably benign, but annoying none the less.
 

rolygate

Vaping Master
Supporting Member
ECF Veteran
Verified Member
Sep 24, 2009
8,354
12,402
ECF Towers
We think there might have been an issue with the previous software version, we've just upgraded everything and things seem to be OK now. Also we have recently changed advert supply channels to one managed by Google, this seems to have some issues with tracking cookies which are being reported as a virus or as spyware.

So things are a bit complicated right now, but hopefully in a couple of days will have settled down so that we can tell what the situation is. Thanks for the heads-up, let's see what happens.

Note to others: normally, you will only experience any issue even on an infected website if:

1. You are using Internet Explorer
2. Your antivirus is not very good
3. You have outdated software on your PC

Macs and Linux are not normally targeted as there are not enough of them to make it worthwhile.

You MUST keep your apps updated - out of date Java, Flash, Adobe PDF Reader etc WILL make you vulnerable and IT IS YOUR FAULT if malware can lodge on your PC due to the obsolete software versions you are using.

Update Java using the JavaRa app, it's by far the best way.
Update Flash and see if you can remove any old versions or installers.
Don't use Adobe PDF Reader. Just don't. Use something like PDF-Xchange Viewer, it's 10 times faster and 10 times less vulnerable.
And if you use IE you know you are asking for trouble - so everything else MUST be 100% right.
 

Mac

Ultra Member
ECF Veteran
Jun 5, 2009
2,477
15,159
All up in your grill..
We think there might have been an issue with the previous software version, we've just upgraded everything and things seem to be OK now. Also we have recently changed advert supply channels to one managed by Google, this seems to have some issues with tracking cookies which are being reported as a virus or as spyware.

So things are a bit complicated right now, but hopefully in a couple of days will have settled down so that we can tell what the situation is. Thanks for the heads-up, let's see what happens.

Note to others: normally, you will only experience any issue even on an infected website if:

1. You are using Internet Explorer
2. Your antivirus is not very good
3. You have outdated software on your PC

Macs and Linux are not normally targeted as there are not enough of them to make it worthwhile.

You MUST keep your apps updated - out of date Java, Flash, Adobe PDF Reader etc WILL make you vulnerable and IT IS YOUR FAULT if malware can lodge on your PC due to the obsolete software versions you are using.

Update Java using the JavaRa app, it's by far the best way.
Update Flash and see if you can remove any old versions or installers.
Don't use Adobe PDF Reader. Just don't. Use something like PDF-Xchange Viewer, it's 10 times faster and 10 times less vulnerable.
And if you use IE you know you are asking for trouble - so everything else MUST be 100% right.

Thank you Roly, for the quick response. Yes my antivirus snagged it and shut it down before it happened. AVG is really not bad at all to be free software. But alone it's not enough to use ie imo. I am far from an expert but have been pretty lucky using their free software and their (paid for) pc analyzer. I run other programs and do other maintanence and have so far avoided the majority of spyware and pretty much any viruses the web has to offer. But I am careful. My concern of course was seeing it pop up here as that is new for me. I will let you know if I run across anything else like this.
 

carpedebass

Ultra Member
ECF Veteran
Verified Member
Jul 10, 2011
2,168
1,500
54
The Alamo City
I'm noticing another oddity. When I click to read the first unread message, I get some kind of message asking me if I'm sure I want to navigate away from the current page. Doesn't happen every time, but some editor script is running or something.

EDIT....and suddenly I can't type worth a dang! :laugh:
 

tiburonfirst

They call me 'Tibs"
ECF Veteran
Verified Member
Feb 23, 2010
26,882
260,281
while the forum was being worked on ms security essentials blocked swf/blacole.d and js/blacole.a for me; not had a problem since earlier today.
but the above-mentioned editor script has popped up a few times when i hit the 'post reply' button ......



spoke too soon - swf/blacole.d was just blocked ......
 
Last edited:

tiburonfirst

They call me 'Tibs"
ECF Veteran
Verified Member
Feb 23, 2010
26,882
260,281
Exploit:SWF/Blacole.D(?)
Encyclopedia entry
Published: Oct 27, 2011

Aliases
Not available

Alert Level (?)
Severe

Antimalware protection details
Microsoft recommends that you download the latest definitions to get protected.
Detection initially created:
Definition: 1.115.678.0
Released: Oct 27, 2011
 

rolygate

Vaping Master
Supporting Member
ECF Veteran
Verified Member
Sep 24, 2009
8,354
12,402
ECF Towers
Yeah :)

As far as i can see you only get problems if you have outdated software on a PC, and maybe if you use IE as well.

If you have a software update manager, and block IE in your firewall (ex: Online Armor), then it is unlikely you will have any problem. A good AV like Avast will probably stop any issues even if you use IE and have old software versions.
 
Status
Not open for further replies.

Users who are viewing this thread