The Rolex Forums   The Rolex Watch

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX


Go Back   Rolex Forums - Rolex Watch Forum > Miscellaneous Forums > Announcements/feedback & support

Reply
 
Thread Tools Display Modes
Old 9 December 2011, 04:45 PM   #31
LordNinja
"TRF" Member
 
LordNinja's Avatar
 
Join Date: Aug 2008
Real Name: Chris
Location: Boston
Watch: 116610,116233,OsQz
Posts: 1,109
Now, in chrome flavor.
Attached Images
File Type: png Screen Shot 2011-12-09 at 1.43.28 AM.png (39.3 KB, 106 views)
LordNinja is offline   Reply With Quote
Old 9 December 2011, 04:58 PM   #32
Dan Pierce
2024 Pledge Member
 
Dan Pierce's Avatar
 
Join Date: Dec 2006
Real Name: D'OH!
Location: Kentucky
Watch: Rolex-1 Tudor-3
Posts: 35,721
Now my mac is running fine, must have been the network at the airport I'm working at.
But I'm afraid to log on TRF so I'm using my DROID instead.
dP
Dan Pierce is offline   Reply With Quote
Old 9 December 2011, 07:52 PM   #33
316lad
"TRF" Member
 
Join Date: Oct 2011
Location: UK
Posts: 1,642
It's still problematic Dan - as of 09:51
With Safari blocking the site and then this...
Attached Images
File Type: jpg trfd2.jpg (57.2 KB, 102 views)
316lad is offline   Reply With Quote
Old 9 December 2011, 08:18 PM   #34
Alex1974
Member
 
Join Date: Nov 2011
Real Name: Alexander
Location: China
Posts: 89
Here we go :





Regards,
Alex
Alex1974 is offline   Reply With Quote
Old 9 December 2011, 08:51 PM   #35
HL65
TRF Moderator & 2024 DATE-JUST41 Patron
 
HL65's Avatar
 
Join Date: Dec 2007
Real Name: Ken
Location: SW Florida
Watch: One on my wrist.
Posts: 63,385
No issues here and I am also running Lion on my iMac.
__________________

SPEM SUCCESSUS ALIT
HL65 is offline   Reply With Quote
Old 9 December 2011, 09:01 PM   #36
OrangeSport
"TRF" Member
 
OrangeSport's Avatar
 
Join Date: Oct 2011
Real Name: Jason
Location: Essex, UK
Watch: 14060M
Posts: 2,943
Yep, getting the same message on Chrome. Have logged in on my Android instead...
__________________
OrangeSport is offline   Reply With Quote
Old 9 December 2011, 09:43 PM   #37
Lol-x
Facilitator
 
Lol-x's Avatar
 
Join Date: Nov 2005
Real Name: Steve
Location: Omnipresent
Posts: 33,228
No problems.
Make sure you are logged into www.rolexforums.com
__________________

Most folks are about as happy as they make up their minds to be. ~Abraham Lincoln
Nothing compares to the simple pleasure of a bike ride. ~John F. Kennedy

ROLEXploitation - yeah I'm a victim
Lol-x is offline   Reply With Quote
Old 9 December 2011, 09:59 PM   #38
Jimbits76
"TRF" Member
 
Join Date: Sep 2007
Location: UK
Posts: 9,407
Certainly an issue somewhere. I'm getting a pop up asking me to download a piece of software disguised as a microsoft security patch. It's coming from Ccsnaioborn or something!

J
Jimbits76 is offline   Reply With Quote
Old 9 December 2011, 10:01 PM   #39
Jimbits76
"TRF" Member
 
Join Date: Sep 2007
Location: UK
Posts: 9,407
BTW I'm running XP and IE8.

I'm also getting pop ups from Nemmess something or other...

J
Jimbits76 is offline   Reply With Quote
Old 9 December 2011, 10:04 PM   #40
ArcticMoose
"TRF" Member
 
ArcticMoose's Avatar
 
Join Date: Oct 2009
Location: The Sea
Posts: 1,894
I'm still getting the warning, Safari 5.1.2 on Lion, logged in to www.rolexforums.com.
ArcticMoose is offline   Reply With Quote
Old 9 December 2011, 10:09 PM   #41
Fiery
"TRF" Member
 
Fiery's Avatar
 
Join Date: Jul 2009
Location: Europe
Watch: Sub-C 116610LN
Posts: 2,649
Icon4 TRF has a trojan threat?

Both IE8 and NOD32 throws an alert when visiting TRF. I've never had such issues before... NOD32 says:

*h*t*t*p*://nempesrsrioic.com/content/v1.jar

Java/TrojanDownloader.OpenConnection.AQ trojan


Does anyone else get such an alert? (I've put the asterisks in the URL)
__________________
"In an age of obsolescence and gimmickry, this simple classic virtue of a Rolex is indeed a rarity." (Rolex ad from 1974)
Fiery is offline   Reply With Quote
Old 9 December 2011, 10:15 PM   #42
kultschar
"TRF" Member
 
kultschar's Avatar
 
Join Date: Sep 2011
Location: End of the World
Watch: PP & Rolex
Posts: 1,970
Im getting malware warning on my Mac - Safari???
kultschar is offline   Reply With Quote
Old 9 December 2011, 10:17 PM   #43
drockadam
"TRF" Member
 
drockadam's Avatar
 
Join Date: Nov 2010
Real Name: Adam
Location: Ontario, Canada
Watch: Pepsi.
Posts: 5,749
I'm getting it on my laptop! I'll be signing off TRF until, this goes away.
__________________
- Adam
Instagram: @GMTSUBTIME
drockadam is offline   Reply With Quote
Old 9 December 2011, 10:29 PM   #44
Fiery
"TRF" Member
 
Fiery's Avatar
 
Join Date: Jul 2009
Location: Europe
Watch: Sub-C 116610LN
Posts: 2,649
I've added this to my HOSTS file (which is in \Windows\System32\drivers\etc, at least under WinXP):

127.0.0.1 nempesrsrioic.com

That made it go away :) I hope the mods will take care of getting rid of this threat.
__________________
"In an age of obsolescence and gimmickry, this simple classic virtue of a Rolex is indeed a rarity." (Rolex ad from 1974)
Fiery is offline   Reply With Quote
Old 9 December 2011, 10:42 PM   #45
316lad
"TRF" Member
 
Join Date: Oct 2011
Location: UK
Posts: 1,642
Still getting these two before running away quickly.

Hope it's nothing serious guys.

my system is OS X 10.6 Snow Leopard
Safari
Firefox

Pulling warning signs on both browsers.
Attached Images
File Type: jpg trfd.jpg (77.7 KB, 136 views)
File Type: jpg trfd2.jpg (57.2 KB, 135 views)
316lad is offline   Reply With Quote
Old 9 December 2011, 10:51 PM   #46
speedo
"TRF" Member
 
speedo's Avatar
 
Join Date: Feb 2010
Location: bp, hu, eu
Watch: dj 16234, 116610ln
Posts: 2,376
Same here. I receive a warning on my pc however it runs flawless on my iphone.
__________________
16234 jubilee dial, 116610 ln, grand seiko sbgm221g, omega speedmaster mark II, longines legend diver, breguet 3910, nomos club campus 38, swatch sistem51, mares nemo, seiko ripley, g-shock rangeman

instagram: modus_horologicus
speedo is offline   Reply With Quote
Old 9 December 2011, 10:53 PM   #47
MoBe
"TRF" Member
 
Join Date: Sep 2011
Location: Canada
Posts: 6,773
I`ve been getting trojan warnings from my Kaspersky Anti Virus software.
MoBe is offline   Reply With Quote
Old 9 December 2011, 10:56 PM   #48
roach7
"TRF" Member
 
Join Date: Jun 2007
Real Name: henry
Location: nyc
Watch: 16610lv
Posts: 1,829
and i thought i was the only one...

what's going on?
roach7 is offline   Reply With Quote
Old 9 December 2011, 11:00 PM   #49
GradyPhilpott
2024 ROLEX DATEJUST41 Pledge Member
 
GradyPhilpott's Avatar
 
Join Date: Sep 2008
Location: New Mexico
Watch: 116710 BLNR
Posts: 34,345
Google put up a warning on the site and I've had three (make that at least six now and counting) warnings from Norton that a trojan has been cleaned in rapid succession this morning, not including a couple last night.
__________________
JJ

Inaugural TRF $50 Watch Challenge Winner
GradyPhilpott is offline   Reply With Quote
Old 9 December 2011, 11:00 PM   #50
mtrunner
2024 Pledge Member
 
mtrunner's Avatar
 
Join Date: Jan 2008
Real Name: Gary
Location: Bozeman, MT
Watch: 126508 Paul Newman
Posts: 7,825
Not good. I am going to log off until this is is sorted out. Don't want to infect my work computer.
mtrunner is offline   Reply With Quote
Old 9 December 2011, 11:06 PM   #51
nauticajoe
"TRF" Member
 
nauticajoe's Avatar
 
Join Date: Feb 2010
Real Name: Joe
Location: PA
Posts: 14,774
Getting the same problem malware warning. Yikes!





Sent from my iPhone using Tapatalk
nauticajoe is offline   Reply With Quote
Old 9 December 2011, 11:19 PM   #52
HDHNTER
"TRF" Member
 
HDHNTER's Avatar
 
Join Date: Feb 2007
Real Name: Allen
Location: SC
Posts: 2,766
Malware warning for me as well.
__________________
Instagram @HDHNTER
HDHNTER is offline   Reply With Quote
Old 9 December 2011, 11:47 PM   #53
mitchy
"TRF" Member
 
mitchy's Avatar
 
Join Date: Apr 2010
Real Name: Mitch
Location: .
Watch: 116710LN
Posts: 2,495
me too, not good!!!
__________________
Time you enjoy wasting, was not wasted

John Lennon
mitchy is offline   Reply With Quote
Old 9 December 2011, 11:48 PM   #54
Mosco
"TRF" Member
 
Mosco's Avatar
 
Join Date: Dec 2008
Real Name: Greg
Location: Cincinnati
Watch: I like to...
Posts: 18,567
Works fine on my iPad...
__________________
Instagram - @CaliberSwiss

“A man who procrastinates in his choosing will inevitably have his choice made for him by circumstance.” - Hunter S. Thompson
Mosco is offline   Reply With Quote
Old 9 December 2011, 11:48 PM   #55
CashGap
"TRF" Member
 
CashGap's Avatar
 
Join Date: Nov 2010
Real Name: Blank
Location: Romo
Posts: 1,465
Warning - visiting this web site may harm your computer!

Suggestions:
Return to the previous page and pick another result.
Try another search to find what you're looking for.
Or you can continue to http://www.rolexforums.com/ at your own risk. For detailed information about the problems we found, visit Google's Safe Browsing diagnostic page for this site.

For more information about how to protect yourself from harmful software online, you can visit StopBadware.org.

If you are the owner of this web site, you can request a review of your site using Google's Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.
CashGap is offline   Reply With Quote
Old 10 December 2011, 12:14 AM   #56
Cru Jones
2024 ROLEX DATEJUST41 Pledge Member
 
Cru Jones's Avatar
 
Join Date: Mar 2010
Location: Paris, France
Posts: 34,473
my message:

"Symantec Endpoint Protection - [SID: 24225] - Web Attack: Blackhole Toolkit Website 5 detected."
Cru Jones is online now   Reply With Quote
Old 10 December 2011, 12:16 AM   #57
dalip
"TRF" Member
 
dalip's Avatar
 
Join Date: Sep 2009
Real Name: Dalip
Location: Mumbai and Perth
Watch: Rolex PAM Omega
Posts: 18,656
Working fine on all my devices....all Mac. Seems to be selective. It is being looked into.
__________________



------------------------------------------------------------
"The liar's punishment is not in the least that he is not believed, but that he cannot believe anyone else." George Bernard Shaw
dalip is offline   Reply With Quote
Old 10 December 2011, 12:22 AM   #58
77T
2024 ROLEX DATEJUST41 Pledge Member
 
77T's Avatar
 
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 40,691
Thanks to the Mods - please let the hosting company for TRF know that the problem still exists.

New diagnostics report this morning has narrowed the source of malware to 2 domains: ccsnaioebom.com and ysybciderbmcp.com

The problem appears to be on some, but not all, of the virtual name servers at Go Daddy?

Or the Hosting/MNS provider, Liquid Web, may have some issues and is redirecting?

Either way it appears the malicious script(s) is/are not self-executing at this time. However this could change today or in the future. I noticed the number of exploits and Trojans since last nights report. It is now up to 23 exploits, 10 Trojans and 5 scripting exploits - any new ones may or may not become self-executing.

BTW, the "gift" results in an average of 4 new processes running on your PC/Mac. These could be benign like a kid wanting to show his mad coding skills to a bot net controller - or worse like a card skimmer bot waiting for you to use a credit card number for an online purchase.

Sorry for the long posts, just sharing in the spirit of teamwork. Not trying to alarm anyone. Thus far these exploits have been passive which means you'd be prompted to take an action that would insert malware on your machine - but disguised as a legitimate function.
__________________


Does anyone really know what time it is?
77T is offline   Reply With Quote
Old 10 December 2011, 12:26 AM   #59
dalip
"TRF" Member
 
dalip's Avatar
 
Join Date: Sep 2009
Real Name: Dalip
Location: Mumbai and Perth
Watch: Rolex PAM Omega
Posts: 18,656
Useful post. Thanks.
__________________



------------------------------------------------------------
"The liar's punishment is not in the least that he is not believed, but that he cannot believe anyone else." George Bernard Shaw
dalip is offline   Reply With Quote
Old 10 December 2011, 12:31 AM   #60
77T
2024 ROLEX DATEJUST41 Pledge Member
 
77T's Avatar
 
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 40,691
Quote:
Originally Posted by Fiery View Post
Both IE8 and NOD32 throws an alert when visiting TRF. I've never had such issues before... NOD32 says:

*h*t*t*p*://nempesrsrioic.com/content/v1.jar

Java/TrojanDownloader.OpenConnection.AQ trojan


Does anyone else get such an alert? (I've put the asterisks in the URL)
Yes last night one of the exploits was a jar loader - the disguised message was "Java needs to update files for this site". The exploit was a Java Archive file that had a bundle of multiple executables that would stay resident in background while collecting data on the target machine.

This is usually a keystroke logger specifically designed to log any 16 digit number followed by a 4 digit number and associated name data. After a few days of collection and tracking your activity, the bot code snippet wakes us and reports the contents of the logger to the botnet controller.
__________________


Does anyone really know what time it is?
77T is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Coronet

Takuya Watches

Bobs Watches

Asset Appeal

My Watch LLC

OCWatches

DavidSW Watches


*Banners Of The Month*
This space is provided to horological resources.





Copyright ©2004-2024, The Rolex Forums. All Rights Reserved.

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX

Rolex is a registered trademark of ROLEX USA. The Rolex Forums is not affiliated with ROLEX USA in any way.