Page 4 of 5 FirstFirst 12345 LastLast
Results 31 to 40 of 44

Thread: Weird Computer Question

  1. #31
    Join Date
    Jul 2006
    Location
    Connecticut, USA
    Posts
    2,478

    Default

    Hey gene-

    i have that hitman pro. I am running:

    AVG (paid version) for internet security. Malwatre bytes, Search and destroy, Hitman pro and now TDSSKiller (which was talked about on a forum specifically for this problem) and *every single* one of those programs finds ZILCH!!! Nada!! nuttin!!

    Obvioulsy, today it is back. i tried it this morning and got redirected. 1 and 1 "Tech Support" is about as useful as talking to a brick wall. the "barely speak my language" tech support person just kept reading scripts to me and finally after 46 minutes, send she will investigate the problem and email me. LOL...yeah, ok.

    I *REALLLLY* need to figure this out. its bad!!!

    -Marc
    http://www.laserist.org/images/ildalogos/ILDA-logo_colored-beams_Corporate_150w.jpg

    ILDA- U.S. Laser Regulatory Committee

    Authorized Dealer for:

    • Pangolin Laser Software and Hardware
    • KVANT Laser Modules & Laser Systems
    • X-Laser USA
    • CNI Lasers
    • Cambridge Technology & Eye Magic Professional Scanning Systems

    FDA/CDRH Certified Professional LuminanceRGB Laser Light Show Systems


  2. #32
    Join Date
    Aug 2008
    Location
    UK
    Posts
    5,704

    Default

    I'm sure this is google related or malware specifically on your site. If it was general browser malware then other searches for people would result in re-directs to the search heaven site, whereas this seems to be specific to your site.

  3. #33
    Join Date
    Dec 2008
    Location
    swansea, UK
    Posts
    198

    Default

    I just clicked a link to your website now from a google search, and it redirected me briefly through searchhaven to the following:
    http://tdsstdstds.org/in.cgi?30&parameter=ct+lasers (note people, do NOT click this link as the domain tdsstdstds.org is bad!!!

    doing a google diagnostics search came up with this; http://google.com/safebrowsing/diagn...dsstdstds.org/ (safe to click)

    this was using google.co.uk, and my browser is chrome. i thought maybe some other people may be able to use this info to help you out! can't you look at the HTML code of your site (as it looks on your host server) and see if there are any malicious additions to it? but thats my novice guess. im sure flecom/etc knows a lot more than me

    good luck!!

    Tom

  4. #34
    Join Date
    Apr 2006
    Location
    Miami, FL
    Posts
    3,590

    Default

    Quote Originally Posted by White-Light View Post
    I'm sure this is google related or malware specifically on your site. If it was general browser malware then other searches for people would result in re-directs to the search heaven site, whereas this seems to be specific to your site.
    ya but if you examine the google page its redirecting to www.ctlasers.com, nothing weird... and the searcheven site is stealing the referrer string and using it as part of their "search"

    this is definitely a 1and1 thing... you could look for another host? PM me if you want to go via that route

  5. #35
    Join Date
    Aug 2009
    Location
    Auburn, Washington
    Posts
    824

    Default

    I don't know enough about source code to decipher this, but after I got redirected (again today) I opened the redirected page's source code in Firefox.

    I can't save the page with the same info showing, but here is a screencap of what the page source code showed me. Maybe this will be of some help.

    The bottom 2 highlighted lines are interesting.

    Gene
    Attached Images Attached Images

  6. #36
    swamidog's Avatar
    swamidog is offline Jr. Woodchuckington Janitor III, Esq.
    Join Date
    Nov 2006
    Location
    santa fe, nm
    Posts
    1,545,835

    Default

    i wonder if a compromise has taken place on your virtual server....
    suppose you're thinkin' about a plate o' shrimp. Suddenly someone'll say, like, plate, or shrimp, or plate o' shrimp out of the blue, no explanation. No point in lookin' for one, either. It's all part of a cosmic unconciousness.

  7. #37
    Join Date
    Apr 2006
    Location
    Miami, FL
    Posts
    3,590

    Default

    Quote Originally Posted by swamidog View Post
    i wonder if a compromise has taken place on your virtual server....
    ya thats pretty much my best guess... i went through some things on the site with Marc and I am fairly certain someone got in either via Word Press or the OSCommerce shopping cart (latter is more likely I think)

    bastards

  8. #38
    Join Date
    Jul 2006
    Location
    Connecticut, USA
    Posts
    2,478

    Default

    with the help of frank (THANK YOU Frank!!)

    i *did* find some weird shit on the server. i deleted it out of one of the directories, and lets hope that this may have fixed it!!

    if you guys could clean out your cache and temp internt files and try again, it would be GREATLY appreciated!

    Do a search (google, bing) and click my name under the search results and *pray* that i dont have the re-direct in there.

    Thanks again everyone for your help and advice! you guys seriously are the best!

    -Marc
    http://www.laserist.org/images/ildalogos/ILDA-logo_colored-beams_Corporate_150w.jpg

    ILDA- U.S. Laser Regulatory Committee

    Authorized Dealer for:

    • Pangolin Laser Software and Hardware
    • KVANT Laser Modules & Laser Systems
    • X-Laser USA
    • CNI Lasers
    • Cambridge Technology & Eye Magic Professional Scanning Systems

    FDA/CDRH Certified Professional LuminanceRGB Laser Light Show Systems


  9. #39
    swamidog's Avatar
    swamidog is offline Jr. Woodchuckington Janitor III, Esq.
    Join Date
    Nov 2006
    Location
    santa fe, nm
    Posts
    1,545,835

    Default

    cool! you've just saved me some work. i'm currently downloading a copy of marc's site to go through the source code.

    i'll keep a cache for a couple of days. if it looks like the problem is gone, i'll just dump it. if not, let me know and i'll start grepping through it for anything weird.

    Quote Originally Posted by flecom View Post
    ya thats pretty much my best guess... i went through some things on the site with Marc and I am fairly certain someone got in either via Word Press or the OSCommerce shopping cart (latter is more likely I think)

    bastards
    suppose you're thinkin' about a plate o' shrimp. Suddenly someone'll say, like, plate, or shrimp, or plate o' shrimp out of the blue, no explanation. No point in lookin' for one, either. It's all part of a cosmic unconciousness.

  10. #40
    Join Date
    May 2008
    Location
    nerdtown, USA
    Posts
    1,165

    Default It's definitely not Google.

    I checked and it's not Google's doing. It's sending the browser to ctlasers.com same as always. Unfortunately the server is going somewhere weird. It is either:

    - a DNS poisoning attack
    - a domain hijack
    - a misconfigured/rooted server

    but it's definitely not Google; the Google cache still has the real site.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •