View Full Version : Looks like the site is infected and admins don't have idea about it.


Samsara
03-29-2010, 10:56 PM
I am a new user, reached this site searching Google and here how it comes:


http://www.access-programmers.co.uk/forums/archive/index.php/t-105344.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105357.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105358.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105359.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105366.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105369.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105370.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105371.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105375.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105379.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105393.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105399.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105400.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105401.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105402.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105405.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105406.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105407.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105417.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105433.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105440.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105442.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105444.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105451.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105452.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105459.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105468.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105469.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105472.html
http://www.access-programmers.co.uk/forums/archive/index.php/t-105484.html


My Antivirus is prompting me to access this page.

Samsara
03-29-2010, 11:11 PM
Ok resolved now. But just to prove the truth of my statement above, I am attaching the Screenshot what I kept getting for hours.

Samsara
03-30-2010, 09:21 AM
It's Back again, click any of the links above.

georgedwilkinson
03-30-2010, 09:29 AM
No problems with the links. Looks like the problem is on your end.

rainman89
03-30-2010, 09:31 AM
Looks like you might have a browser hijacker

SOS
03-30-2010, 09:31 AM
Yep, not the site's problem - your problem.

Samsara
03-30-2010, 02:26 PM
Ok, Here is the source code of the page which I am receiving and it clearly states "Access Programmers Forum" and I am behind firewall and have updated AVG antivirus, further if the browser is hijacked it should be for all other sites as well but I am not experiencing any problems browsing other site.



<html>


<head>


<meta http-equiv="content-type" content="text/html; charset=UTF-8" />


<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>


<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jqueryui/1.7.2/jquery-ui.min.js"></script>


<script type="text/javascript" src="http://static.cpalead.com/jquery/interface/compressed/iutil.js"></script>


<script type="text/javascript" src="http://static.cpalead.com/jquery/interface/compressed/fisheye.js"></script>


<script type="text/javascript" src="http://static.cpalead.com/jquery/plugins/jquery.bt.min.js"></script>


<script type="text/javascript" src="http://static.cpalead.com/jquery/plugins/jquery.hoverIntent.minified.js"></script>


<!--[if IE]><script type="text/javascript" src="http://static.cpalead.com/jquery/plugins/excanvas.compiled.js"></script><![endif]-->


<script type="text/javascript">var widgetJSON = {"brandwwwdomain": "www.cpalead.com","brandcode": "cpalead","datadomain": "data.cpalead.com","pub": "49339","subid": "119.153.195.168","country": "PK","gateid": "54648","gateid64": "NTQ2NDg=","gatetype": "0","iconmaxwidth": "59.25","iconitemwidth": "59.25","protectfile": "","promptemail": "0","accesstime": "0","fontcolor": "#000000","backgroundurl": "http://www.cpalead.com/images/gatewaytemplate/bookskin.jpg","download": "NDkzMzl8NTQ2NDh8","lefttime": "for <strong><u>0</u></strong> hour(s) only","allowance": "0","alert": "1","alerttext": "Premium Content Unlocked!","leadtext": "","cacheurl": "aHR0cDovL3d3dy5hY2Nlc3MtcHJvZ3JhbW1lcnMuY28udWsvZm 9ydW1zL2FyY2hpdmUvaW5kZXgucGhwL3QtOTQwMTYuaHRtbA%3 D%3D","trafficretainer": "1","closebutton": "0","redirectenabled": "0","redirecturl": "","smsdata": "AHuOTR7mb44%3D"};</script><script type="text/javascript" src="http://static.cpalead.com/widget/widget-1.0.min.js"></script><script type="text/javascript">function clickSurvey(campid, slotid) {window.open('http://'+widgetJSON.datadomain+'/offer.php?id='+campid+'&pub='+widgetJSON.pub+'&subid='+widgetJSON.subid+'&gateid='+widgetJSON.gateid+'&cacheurl='+widgetJSON.cacheurl+'&slotid='+slotid+'');}$(document).ready(function() {$('#menu').Fisheye({maxWidth: 59.25,items: 'a',itemsText: 'span',container: '.menuContainter',itemWidth: 59.25,proximity: 70,alignment : 'left',valign: 'bottom',halign : 'center'})});</script></head><body style="margin: 0px; background: transparent url(http://static.cpalead.com/images/blank7.gif); overflow: hidden;" onload="checkLeads();"><style type="text/css">.menu {text-align: center;height: 50px;position: relative;}a.menuItem{text-align: center;color: #fff;font-weight: bold;text-decoration: none;width: 40px;position: absolute;display: block;top: 0;}.menuItem img{cursor: pointer;border: none;margin: 0 auto 5px auto;width: 100%;}.menuItem span{display: none;positon: absolute;}.menuContainter{background-color: transparent;height: 40px;width: 200px;left: 500px;position: absolute;}.offerlink{cursor: pointer;color: #000000;text-decoration: none;}.banner_text{padding-top:30px;font-family:Arial;color:#000000;font-weight: bold;font-size:22px;}.instruction_text{padding-top: 15px;padding-bottom:10px;padding-left: 5px;padding-right:5px;font-family:Verdana;font-size:12px;font-weight:bold;color:#56E310;}.offer_div{padding-left:80px;padding-right:80px;text-align:left;color:#000000;font-family:Verdana;font-size:15px;}</style><div id="offer_wrap" align="center" style="z-index: 1000000000; display: none; position: absolute; width: 100%;"><div id="offer_frame" align="center" style="-moz-box-shadow:0px 0px 7px #ffffff; background-color: #ffffff; width: 85%; height: 537px;-moz-border-radius-topleft:10px; -moz-border-radius-topright:10px; -moz-border-radius-bottomleft:5px; -moz-border-radius-bottomright:5px;"><div style="height: 32px; background-color: #ffffff; -moz-border-radius-topleft:10px; -moz-border-radius-topright:10px;"><div style="float: right; width: 32px; height: 32px;"><a onclick="closeOffer('blind');" style="cursor: pointer;"><img src="http://static.cpalead.com/images/close-32.png" border="0" width="32" height="32" style="width: 32px; height: 32px;" /></a></div><div id="title" style="font-weight: bold; font-size: 18px; color: #000000;">My Title</div></div><iframe id="offer_iframe" width="100%" height="500" src="about:blank" frameborder="0" allowtransparency="true" style="visibility: hidden; overflow-x: auto; overflow-y: auto;"></iframe><div style="height: 5px;"></div></div></div><div id="help_wrap" align="center" style="display: none; z-index: 1000000010; position: absolute; width: 100%;"><div id="help_frame" align="center" style="background: transparent url(http://static.cpalead.com/images/help/helpSkin.png) no-repeat scroll center top; width: 700px; height: 437px;"><div style="color: #5d5d5d; height: 37px; background-color: transparent;"><div style="float: right; width: 34px; height: 37px; margin-right:24px;"><a onclick="closeHelp('blind');" style="cursor: pointer;"><img src="http://static.cpalead.com/images/help/closeButton.jpg" border="0" width="34" height="37" style="width: 34px; height: 37px;" /></a></div><div id="help_title" style="font-family:Tahoma,Verdana,Arial,Helvetica,sans-serif; font-weight: bold; font-size: 18px; color: #5d5d5d; padding-top:4px;">My Title</div></div><iframe id="help_iframe" width="100%" height="388" src="about:blank" frameborder="0" allowtransparency="true" style="background: transparent; visibility: hidden; overflow-x: auto; overflow-y: auto;"></iframe><div style="height: 5px;"></div></div></div><div id="top_menu" style="height: 110px;"></div><div id="cpalead_gateway" align="center" style="border: 0px solid gray; background: transparent url(http://static.cpalead.com/images/gatewaytemplate/bookskin.jpg) no-repeat scroll center top; height: 264px;"><div id="banner_text" class="banner_text" align="center">Access Programmers Forum</div><div align="center" id="thank_you" style="display: none; font-family: Arial; color: #000000; font-weight: bold; font-size: 14px;"></div><div align="center" id="survey_page" style="width: 539px; "><div class="instruction_text" align="center">We are trying our best to maintain the quality of this site. To view the content of this page, please verify that you are human by filling one of the surveys below.</div><div id="survey_list" class="offer_div"><font>Sorry, There are no surveys available to your <br> country at this time. Please try back later</font><BR></div></div><div id="survey_warn" style="padding-top: 30px; width: 332px; display: none; color: #000000; font-family: Verdana; font-size: 11px; "> </div></div><div id="help_button" align="center"><a onclick="showHelp('scale', 'Widget Help', 'http://www.cpalead.com/widget-help.php?id=NTQ2NDg%3D&pub=49339&clicked='+has_clicked);" style="cursor: pointer;"><img src="http://static.cpalead.com/images/help/help_new.png" border="0"></a></div><script type="text/javascript">


__compete_code = 'e2431fed6403dd2c4115d396d31a4d73';


(function () {


var s = document.createElement('script'),


d = document.getElementsByTagName('head')[0] ||


document.getElementsByTagName('body')[0],


t = 'https:' == document.location.protocol ?


'https://c.compete.com/bootstrap/' :


'http://c.compete.com/bootstrap/';


s.src = t + __compete_code + '/bootstrap.js';


s.type = 'text/javascript';


s.async = 'async';


if (d) { d.appendChild(s); }


}());


</script>





</body>


</html>

SOS
03-30-2010, 02:40 PM
Well, considering that none of mine has that (and I'm posting on the same site you are) then it would seem to be YOUR computer problem (regardless of whether you have a firewall and AVG anti-virus, you could have spamware installed unknowingly or a rootkit virus).

Any ideas on why I would not have that and you would? :confused:

SOS
03-30-2010, 02:43 PM
Ok, Here is the source code of the page which I am receiving and it clearly states "Access Programmers Forum"

By the way just that it clearly states "Access Programmers Forum" does not mean a thing. Anyone can spoof a page easily enough. That is no proof whatsoever.

Vassago
03-30-2010, 03:54 PM
Go get Malwarebytes Anti-malware. It's a free program that you can download and use to scan your PC for malicious rootkits or hijackers. Your screenshot is a common symptom of such rootkits. They even inject scripts into sites as they are displayed on your browser, so the source code above is no indication that the site has an issue.

FYI, I have Symantec Endpoint and get none of the issues you are experiencing, nor do I get any warnings that the site is infected. It's more than likely on your end as has been pointed out.

The_Doc_Man
03-30-2010, 07:00 PM
My Kaspersky KIS 2010 doesn't say anything when I visit the site. Which, given the rather nervous nature of KIS 2010, is actually saying a lot!

Samsara
03-31-2010, 01:59 PM
After searching for one day, finally I found it. Recently Google Adsense has started displaying 3rd party, other network ads due to Geo Targeting, somehow these networks include CPAlead for Asian IPs and that's why I am experiencing it and many other people are not. It totally blocks the content showing it's a "premium content" unless you take a survey.

Anyways, I found ways to block it and see if it works. Just want to request Admins to filter out these Ads from AdSense account so that the content can be seen behind these splash pages.

Atleast they can add cpalead.com to "competitive sites filter" in the Adsense account or by adding Javascript code in the archive pages head section as suggested below.

http://74.125.153.132/search?q=cache:KSBMWRxJvsUJ:https://adblockplus.org/forum/viewtopic.php%3Ff%3D2%26t%3D4620+CPAlead&cd=3&hl=en&ct=clnk

http://www.blockcpalead.com/

http://answers.yahoo.com/question/index?qid=20081106132659AAUp3kD

georgedwilkinson
03-31-2010, 06:30 PM
Man, I hate those surveys viruses.

SOS
03-31-2010, 09:50 PM
<smug mode on> Guess I was right all along eh? <smug mode off> :D

Banana
04-01-2010, 04:07 AM
FWIW...

Someone is posting on newsgroup telling others to not visit AWF due to malwares. (http://groups.google.com/group/microsoft.public.access/browse_thread/thread/fb461897b29f1442/674dd2a9b7d07cbf?lnk=gst&q=access-programmers.co.uk#674dd2a9b7d07cbf)

Vassago
04-01-2010, 09:23 AM
I moved the thread to the Site Suggestions section so Jon is more likely to notice it. Jon, is this something that can be looking into with Google Ads? Like I said, I haven't experienced it personally, but at work they use blocking software and at home I use Firefox. Maybe it's only affecting users of IE?

Jon
04-01-2010, 10:44 AM
I've added the following to my Competitive Ad filter in Adsense:

cpalead.com

Let me know if you still get their ad showing.

Thanks for moving this thread to the Site Suggestions area Vassago. Clever idea.

Vassago
04-01-2010, 10:53 AM
I've added the following to my Competitive Ad filter in Adsense:

cpalead.com

Let me know if you still get their ad showing.

Thanks for moving this thread to the Site Suggestions area Vassago. Clever idea.

Thanks for the filter! Hopefully this will sort it out. Banana, can you ask the user in the other forum to try again and see if he still receives the error?

Banana
04-01-2010, 10:56 AM
Actually Jon already posted there. :)

Vassago
04-01-2010, 11:12 AM
Actually Jon already posted there. :)

Well okay then... :p

Khalid_Afridi
04-01-2010, 11:39 AM
Alas! so very are hijacked at last:o:mad::( I was very happy here sometime ago.

Vassago
04-01-2010, 11:53 AM
Alas! so very are hijacked at last:o:mad::( I was very happy here sometime ago.

Huh? :confused: I'm sorry, I didn't understand this at all. Can you try and explain better? I understand English is not your first language.

Khalid_Afridi
04-01-2010, 11:55 AM
don't try to understand

Banana
04-01-2010, 11:58 AM
Also, to be clear:

The site wasn't hijacked. What actually happened was that one of advertiser was crappy and probably broke the etiquette if not Google AdSense's Terms of Service by disrupting browser's behavior so they can be in your face. Jon removed that nasty advertisers from the "allowed list".

This is very different thing from being hijacked or getting malware installed. It may look like that way but it's not really that simple. Now, that could have been avoided if Jon chose to not allow external sources in the source but ads were added as means to support the site, for better or worse.

Vassago
04-01-2010, 11:58 AM
don't try to understand

Okay...? :rolleyes:

Khalid_Afridi
04-01-2010, 12:02 PM
I know Banana :) I was just kidding.
It's good that jon removed that nasty advertisers.

Banana
04-01-2010, 12:03 PM
Jon -

Just curious - does Google give you enough control to deny any ads that requires JavaScript or Java? I bet that if you could restrict ads to only JavaScripts or forbid any scripting, that would be less of an issue?

Jon
04-01-2010, 12:40 PM
You have very limited control. You can only block by advert url.

Banana
04-01-2010, 12:48 PM
Too bad. It would certainly make things lot easier if you could block scripting ads. Any advertisers that tries to use those should be nailed to the wall, IMNSHO. :)

Samsara
04-01-2010, 11:02 PM
Here you can see exactly what's happening.

http://www.youtube.com/watch?v=SOIhYkLmylA

Jon
04-02-2010, 02:11 AM
Ooooo that is a nasty bit of code. Google will surely ban them.

Vassago
04-02-2010, 08:39 AM
I still have yet to experience this. Just for kicks, I uninstalled all ad blocking and used IE at home, and surfed around the site and forum. I didn't get a single ad like the one in the video. Do you have all IE updates? Maybe it's a hole they plugged with a more recent update that's affecting you?

The_Doc_Man
04-03-2010, 05:20 AM
I use Kaspersky KIS 2010 at home with all sorts of filters and blockers. I'm not advertising the KIS product. KIS is able to block a lot of this stuff, but the truth is that MOST of the good packages can do this. It is a matter of how we install it and what features we are willing to turn on.

On the other hand, I'll add this note. While working on my day job for the U.S. Department of Defense, I used to teach Windows Security for System Administrators. Per a study by the SANS Institute not that long ago, failing to patch systems on a regular basis was in the top 3 reasons why a system would be affected by security threats. Others included use of firewalls and use of comprehensive security software. 'Comprehensive' in that context was anti-virus scanner with e-mail tie-ins; ad-ware blocker; spy-ware blocker; and active threat detection capability such as heuristics, file-system tie-ins, and program behavior checkers in general.

Many good packages from Symantec, McAfee, and Kaspersky Labs have at least 75% of those features built-in. To my way of thinking, any computer professional who doesn't have one of the advanced systems is either daft or is so new to the game as to not have yet been enlightened. Here's hoping my comments will be viewed as constructive. That is how they were intended.