Forgot Password
Pentax Camera Forums Home
 

Reply
Show Printable Version 2 Likes Search this Thread
12-05-2017, 02:48 PM   #1
Veteran Member
enoeske's Avatar

Join Date: Jul 2009
Location: Surprise, Az
Photos: Gallery
Posts: 2,136
reports of a virus here

u/rollingrawhide on reddit just posted this which I find disturbing if true? Any verification regarding his/her claim?

Trojan virus warning for pentaxforums.com : photography

I visited the said forums a few weeks ago and I've been an infrequent visitor for a number of years.

Tonight I visited and instantly got a warning from multiple Anti-virus/Anti-Malware products which I have installed.

It seems that the site owner has installed the crypto-loot virtual currency mining trojan virus. It's a bit of Javascript thats available to site owners if they want it, then they get a share of any virtual currency mined by their visitors.

It basically means they use the CPU power of visitors to mine virtual currency. In this case the virtual currency is Monero.

I didnt know who to tell about it, but I figured reddit would get the word out.

This is a very new virus apparently, similar to coinhive which has been around longer. Nevertheless, I dont want someone else profiting from my hard earned computer hardware and perhaps you dont either!

Just a heads up if you're a visitor there.

12-05-2017, 02:59 PM - 1 Like   #2
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,595
Hmm, I'm not aware of anything like this, but we do work with some third party networks so I will check all our scripts just in case. I know that a lot of toolbars these days have these kinds of malware, so that's something worth checking as well.

Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
12-05-2017, 03:10 PM   #3
Site Supporter
Site Supporter
Digitalis's Avatar

Join Date: Mar 2009
Location: Melbourne, Victoria
Photos: Gallery
Posts: 11,694
Extraordinary claims require extraordinary proof, in the R/ post there is no evidence of this malware just an allegation that pentaxforums is involved.Usually with threats of this nature multiple sites are affected - not just one which is suspicious to me. But then again it is 8:30AM here and I haven't had my second coffee yet...

This kind of malware would be pretty useless against anyone with a javascript blocker worth its salt....or JS turned off in their browser. And in any case If such Malware were present here i'm sure the administrators would do the right thing and remove it.
12-05-2017, 05:08 PM   #4
Seeker of Knowledge
Loyal Site Supporter
aslyfox's Avatar

Join Date: Aug 2016
Location: Topeka, Kansas
Photos: Gallery | Albums
Posts: 24,581
QuoteOriginally posted by Digitalis Quote
Extraordinary claims require extraordinary proof, in the R/ post there is no evidence of this malware just an allegation that pentaxforums is involved.Usually with threats of this nature multiple sites are affected - not just one which is suspicious to me. But then again it is 8:30AM here and I haven't had my second coffee yet...

This kind of malware would be pretty useless against anyone with a javascript blocker worth its salt....or JS turned off in their browser. And in any case If such Malware were present here i'm sure the administrators would do the right thing and remove it.
I agree, in Adam and other administrators we trust

12-05-2017, 05:22 PM   #5
Moderator
Site Supporter
Loyal Site Supporter
MarkJerling's Avatar

Join Date: May 2012
Location: Wairarapa, New Zealand
Photos: Gallery | Albums
Posts: 20,406
I've posted on Reddit that Adam is not aware of anything but that he is looking into it.
12-05-2017, 05:26 PM   #6
Site Supporter
Site Supporter
foxandcrow's Avatar

Join Date: Sep 2017
Location: Colorado
Posts: 1,994
I have malwarebytes installed on my computer and it has blocked something called crypto-loot.com. , I don't remember where I was on the forum. This happened over the last week or so. It has not happened over the last few days.
12-05-2017, 05:40 PM   #7
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,595
I have done a pretty thorough check of our third-party content and have removed a bunch of old banners that I didn't recognize, but apart from that nothing stood out. You guys should be safe. Will ask our server team to see if there has been any suspicious activity on the server, and keep an eye out for any reports over the coming days in case there's something else I may have missed.


Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
12-05-2017, 06:16 PM   #8
Loyal Site Supporter
Loyal Site Supporter




Join Date: Jun 2009
Location: Tumbleweed, Arizona
Photos: Gallery | Albums
Posts: 5,707
QuoteOriginally posted by foxandcrow Quote
I have malwarebytes installed on my computer and it has blocked something called crypto-loot.com. , I don't remember where I was on the forum. This happened over the last week or so. It has not happened over the last few days.
That's exactly what the post over at reddit was complaining about. That said, there are several places in the stack or food chain that this can originate from.

12-06-2017, 08:57 AM   #9
Site Supporter
Site Supporter
foxandcrow's Avatar

Join Date: Sep 2017
Location: Colorado
Posts: 1,994
Crypto-loot.com

I'm no techy but just Google crypto-loot.com and you can see lots of info on it.
12-06-2017, 02:04 PM   #10
Veteran Member
SSGGeezer's Avatar

Join Date: Jun 2017
Location: Indiana, U.S.
Photos: Gallery | Albums
Posts: 4,845
The person reporting this is probably infected locally. Running multiple AV and anti-malware running concurrently is a recipe for false positives also. You are killing your performance if you are running multiples. If you can't show the link and the actual signature from seeing the malware in the wild, you shouldn't spread FUD.
12-06-2017, 03:55 PM - 1 Like   #11
Administrator
Site Webmaster
Adam's Avatar

Join Date: Sep 2006
Location: Arizona
Photos: Gallery | Albums
Posts: 51,595
QuoteOriginally posted by SSGGeezer Quote
The person reporting this is probably infected locally. Running multiple AV and anti-malware running concurrently is a recipe for false positives also. You are killing your performance if you are running multiples. If you can't show the link and the actual signature from seeing the malware in the wild, you shouldn't spread FUD.
I get a free mcafee subscription through my ISP, and it covers all the PCs in a household. But after many months of blindly installing this on all my computers, I realized how big of a CPU and memory hog it is. Who knows how much data it sends back, too. I even had to remove it for a neighbor whose computer simply couldn't be used as a result of all of the disk usage- it would crash a few minutes after logging in. Mcafee also blocks things such as spybot (anti-malware I've been using for a while) because the developers of mcafee see them as competitors. So, in a sense, anti-viruses can be viruses themselves. Be careful what you install on your computer! Your due diligence can outperform an automated tool any day.

Adam
PentaxForums.com Webmaster (Site Usage Guide | Site Help | My Photography)



PentaxForums.com server and development costs are user-supported. You can help cover these costs by donating or purchasing one of our Pentax eBooks. Or, buy your photo gear from our affiliates, Adorama, B&H Photo, KEH, or Topaz Labs, and get FREE Marketplace access - click here to see how! Trusted Pentax retailers:
Reply

Bookmarks
  • Submit Thread to Facebook Facebook
  • Submit Thread to Twitter Twitter
  • Submit Thread to Digg Digg
Tags - Make this thread easier to find by adding keywords to it!
currency, dont, reddit, site, trojan, virus, visitor, visitors

Similar Threads
Thread Thread Starter Forum Replies Last Post
CAUTION: pentax_takumar_lens_repair_manual.rar VIRUS FilmORbitz Pentax SLR Lens Discussion 12 11-19-2017 12:38 AM
Anyone here using NOD 32 anti virus software? A new message is appearing here. jpzk General Talk 10 06-01-2017 09:07 PM
Question Virus? RHN12 Site Suggestions and Help 7 12-10-2015 07:29 AM
Virus detected when accessing forum home page simonkit Site Suggestions and Help 7 09-12-2010 01:56 AM
Real Virus Warning!! Tom S. General Talk 3 09-26-2008 07:19 AM



All times are GMT -7. The time now is 01:49 PM. | See also: NikonForums.com, CanonForums.com part of our network of photo forums!
  • Red (Default)
  • Green
  • Gray
  • Dark
  • Dark Yellow
  • Dark Blue
  • Old Red
  • Old Green
  • Old Gray
  • Dial-Up Style
Hello! It's great to see you back on the forum! Have you considered joining the community?
register
Creating a FREE ACCOUNT takes under a minute, removes ads, and lets you post! [Dismiss]
Top