Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft Security Essentials detected virus on FR
Me

Posted on 05/29/2013 8:25:46 PM PDT by The Cajun

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-110 next last
To: Rage cat
Nope, don't have any of that turned on.

Still a little puzzling, but I am convinced it was an actual positive hit of that particular Trojan.

61 posted on 05/29/2013 9:37:31 PM PDT by The Cajun (Sarah Palin, Mark Levin, Ted Cruz, Trey Gowdy......Nuff said.)
[ Post Reply | Private Reply | To 58 | View Replies]

Comment #62 Removed by Moderator

To: Rage cat

I had this issue with essentials as well Rage....I dumped it when I upgraded to Win 7 a few years ago...

I think essentials scans the page sees the code and mismatches it to a trjan.


63 posted on 05/29/2013 9:37:47 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 58 | View Replies]

To: GGpaX4DumpedTea

I hate those things.....rather have a log in the woods...


64 posted on 05/29/2013 9:41:43 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 62 | View Replies]

To: GGpaX4DumpedTea

I needed a Norden bombsight for one like that in China a few times.

Scenes from the movie “Dam Busters” kept flashing thru my mind.


65 posted on 05/29/2013 9:44:15 PM PDT by llevrok (How hot does the water need to get before the frog should jump out?)
[ Post Reply | Private Reply | To 62 | View Replies]

To: Rage cat
It’s in wallpaper_crayon_face_homer.jpg

The site that hosts that image, "wowlpapers", is listed as a malicious site by one of the virustotal URL scanners. I will try to get a mod to delete the post.

66 posted on 05/29/2013 9:50:53 PM PDT by TChad
[ Post Reply | Private Reply | To 27 | View Replies]

To: TChad

Booted from DSL livecd so I would have a safe non persistent OS to do the transfer on. DLed the file on the pencil thread and submitted it to virscan.

It got a positive hit for the j frame virus on four search engines.
A-squared
Microsoft
Rising
Sunbelt.


67 posted on 05/29/2013 9:56:33 PM PDT by Rage cat
[ Post Reply | Private Reply | To 66 | View Replies]

To: Rage cat

There are two mylife posts to that thread. We are talking about the Homer Simpson post, right?


68 posted on 05/29/2013 9:58:16 PM PDT by TChad
[ Post Reply | Private Reply | To 67 | View Replies]

To: TChad

The one that had the pic with the crayons sticking out of his nose and ears.


69 posted on 05/29/2013 10:00:05 PM PDT by Rage cat
[ Post Reply | Private Reply | To 68 | View Replies]

To: Rage cat

I clicked Report Abuse and asked the mod to delete it. If the post is still there you might do the same.


70 posted on 05/29/2013 10:01:44 PM PDT by TChad
[ Post Reply | Private Reply | To 69 | View Replies]

To: TChad

Total waste of time..

The site is clean, and whatever code is in that jpeg, it does not match my security data base.

The host site did not ring any bells either. Scanned it...

You guys are doing the same things I did for years with these faulty scanners...Your putting out fires that were never really hot.


71 posted on 05/29/2013 10:06:11 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 70 | View Replies]

To: The Cajun

Joe Walsh - Life's Been Good

72 posted on 05/29/2013 10:11:19 PM PDT by Liberty Valance (Keep a simple manner for a happy life :o)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Cold Heat

Even if the scans are just false positives, they still waste Freepers’ time. Might as well delete the post.


73 posted on 05/29/2013 10:12:14 PM PDT by TChad
[ Post Reply | Private Reply | To 71 | View Replies]

To: TChad

Well...sure....no harm no foul, but what always happens is that every user who now knows about this will have to run a full scan, which I did for years and it takes about 18 hours cuz I have a lot of crud in storage...

I like to look tha variant up and see if they have the code and a clue to where it is....then I look for it.

This one for example can be found at the end of the page code or where ever they stuck it. It’s at the tail end....looks like this.....

[infected_site]/in.cgi?[number_for_infection_campaign] .


74 posted on 05/29/2013 10:17:52 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 73 | View Replies]

To: TChad
Anyway.....it's a redirect to a Chinese site where it gets some massaging and instructions...I can't recall the name but they have it, and it's been around since 2007.

I think they use it to log the IP, sell the list and the hackers will use it to gain a back door. They could use it for most anything...depending on what their flavor of the day is.

Always look at your logs and see if your computer contacted a site with the .cn. If you know you did not go there, chances are you have a Trojan that has, but any decent screen should pick this bugger up.

I just think that essentials, found on most any XP up to win vista system has a particular issue matching code to the malware list and if in doubt it flags it as malware.

75 posted on 05/29/2013 10:25:13 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 73 | View Replies]

To: Cold Heat
every user who now knows about this will have to run a full scan,

There is no point in doing a full scan just for viewing that jpg, but I bet that many Freepers visit the sites that host hotlinked images to get more information about the thread. I often do.

76 posted on 05/29/2013 10:28:08 PM PDT by TChad
[ Post Reply | Private Reply | To 74 | View Replies]

To: Liberty Valance
Kind of like this'en
77 posted on 05/29/2013 10:31:10 PM PDT by The Cajun (Sarah Palin, Mark Levin, Ted Cruz, Trey Gowdy......Nuff said.)
[ Post Reply | Private Reply | To 72 | View Replies]

To: The Cajun
Exactly!

Jolie Blon - Jo-El Sonnier

78 posted on 05/29/2013 10:34:17 PM PDT by Liberty Valance (Keep a simple manner for a happy life :o)
[ Post Reply | Private Reply | To 77 | View Replies]

To: TChad

Well I sure did....lol

I think it may be of somebodys list, not Microsoft because they have no record of it, but somebody may have it fagged because it hosts Islamic stuff.....I did not see anything of interest....a lending site for muslims...and some other portals that I might check out if I have time, but the home page is just wallpapers.

Could be the Islamic nature of it caused someone somewhere to flag it which caused the essentials scan to issue a warning.

Other than that, and that just a guess, I have found nothing..


79 posted on 05/29/2013 10:34:55 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 76 | View Replies]

To: Cold Heat

Gawd.....fagged=flagged....lol....I’m in trouble now......


80 posted on 05/29/2013 10:37:31 PM PDT by Cold Heat (Have you reached your breaking point yet? If not now....then when?)
[ Post Reply | Private Reply | To 79 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-110 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson