Welcome to our community

Be a part of something great, join today!

  • Hey all, just changed over the backend after 15 years I figured time to give it a bit of an update, its probably gonna be a bit weird for most of you and i am sure there is a few bugs to work out but it should kinda work the same as before... hopefully :)

Warning: Visiting this site may harm your computer

Google did this to my site, seemingly forever. I finally figured out that someone had inserted some code into my root dir (thank you ISP for protecting me, f#rs) but there was no evidence that it was doing anything besides pinging a bunch of foreign sites. I would like to personally thank Google for replacing Microsoft as computing's next big pain in the ass. I had to "hard reboot" my Google/Android phone today, for chrissake.
 
I will update this thread when I have something to update beyond what I have already stated... which is that I am 99.99% certain that I have removed the potentially harmful content that was causing the flag, submitted the site for review for google to remove the warning, and am waiting on them now...

There was something on this site. It may or may not have been malicious. It certainly wasn't kosher in its intent. It should be gone now. I am waiting for google's review process to complete and hopefully remove the safe browsing warning now.
 
Thanks for your patience, everyone.... Sorry for the inconvenience. It sucks that this stuff happens some times. There are assholes on the internet.

At any rate, looks like the review process has completed and you should no longer receive the warning.

If you experience any further issues, please post here so I can look into it in a timely manner.

Later,
Jason
 
Status of the latest badware review for this site: A review for this site has finished. The site was found clean. The badware warnings from web search are being removed. Please note that it can take some time for this change to propagate.

Later.
jason
 
It's good to see the site is now testing clean and the warnings should be removed soon, if not already.

i report spam posts everytime.You can try asking specific questions about Red in registration page.Bad idea?

Specific questions won't work. We can't even get many newcomers to follow the real names only policy that is presented in HUGE LETTERS on the registration page. And that still does not address the issue that many spam accounts circumvent any such checks by exploiting security holes in the forum software. Anyone familiar with the internal workings of the forum software can interface directly with the new user registration module and dodge most any custom checking we can implement, short of completely writing our own registration module, and hope no one hacks that. Reduser is a big site these days and e number of attacks and spam seems to be increasing.

This problem and so many others could be prevented if we had a genuine real names policy and a probation period before users could freely post. Other professional forums do this and they benefit from a very high signal to noise ratio.

I agree with the need for the real names policy, and we are slowly working toward that. However, probationary periods or moderator approved memberships have been avoided because the lack of security in that sense is probably better than RED losing customers if someone has a problem and wants to consult the forum, but needs to register... Then they find they cant post their question until after a probationary period or until a moderator reviews a request or something? Hmmm....

Another thing to keep in mind here is that long-time users are always linking files and inis case seem to be responsible, at least partially, with this situation. All the roadblocks for spammers and new users won't stop a legitimate user from accidentally or unknowingly linking a Trojan-infested image...
 
I agree with the need for the real names policy, and we are slowly working toward that. However, probationary periods or moderator approved memberships have been avoided because the lack of security in that sense is probably better than RED losing customers if someone has a problem and wants to consult the forum, but needs to register... Then they find they cant post their question until after a probationary period or until a moderator reviews a request or something? Hmmm....

Losing customers? Is Red really going to lose out on a camera sale because someone can't immediately post to the forum? That doesn't seem to add up.

In terms of a user wanting to consult directly with the forum to solve a technical problem or get a question answered, there are no restrictions on reading and searching posts if one is non-regestered. ~95% of all questions someone might have are already answered with in the posts on here by registered users.

Making new "Junior Members" wait till their ID is vetted isn't going to make the site less useable, it would likely cut down on the number of redundant threads. You're not really going to turn "customers" away if you have to wait ~24 hours to post after registering. You just might set a tone for the forum from the start that could improve things as a whole.

And which is more efficient... vetting new members from the start, or maintaing the Real Names thread and reminding members constantly that there is a Real Names policy on Red User? Your about to explode your user base when Scarlet and Epic come out, why not make it more manageable before that happens? Just suggestions.
 
It's good to see the site is now testing clean and the warnings should be removed soon, if not already.

(snip)



Another thing to keep in mind here is that long-time users are always linking files and inis case seem to be responsible, at least partially, with this situation. All the roadblocks for spammers and new users won't stop a legitimate user from accidentally or unknowingly linking a Trojan-infested image...
I think this is the reasonable response. S.H.I.T. is going to happen... pick it up or throw some dirt over it and just move along. No need to attach a colostomy bag to everyone.
 
limited visibility for new member posts

limited visibility for new member posts

However, probationary periods or moderator approved memberships have been avoided because the lack of security in that sense is probably better than RED losing customers if someone has a problem and wants to consult the forum, but needs to register... Then they find they cant post their question until after a probationary period or until a moderator reviews a request or something?

You could make the "probationary period" one in which new member posts are immediately visible to the RED customer support team, and maybe selected members of the community; that would give at least some help to newcomers without much delay, yet still limit the impact of random spam. I understand this solves a different problem than the one you apparently had yesterday, but it still might be worthwhile.
 
That Google warning leaves me wondering if my anti-virus software will find any of those trojans they say they'd downloaded. Has anyone scanned their computer to find if this happened with them?

I just initiated a scan of my system to find out for myself, at least.
 
Trojans

Trojans

I cannot and will not state that the Trojan files detected by one of my anti virus sweeps yesterday was traced back to the issues being reported.
However, all of these appeared shortly after I visited the RED site:


Trojan:Win32/Ircbrute

File:C:\Documents and Settings\Brian F Kobylarz\Local Settings\Temp\0.8539636011040775.exe



Trojan:Win32/Meredrop

File:C:\Documents and Settings\Brian F Kobylarz\Application Data\gdvzfrt.exe
C:\Documents and Settings\Brian F Kobylarz\Application Data\ouwvzww.exe
Note: Did not document additional infected file before removing Meredrop



PWS:Win32/Zbot

File:C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP 1539\A0288896.exe



Trojan:Win32/Ircbrute

File:C:\Windows\system32\sysdevop.exe
Regkey:HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\System Development Operations
Note: Did not document additional infected files before removing this Trojan


Again, I am not assuming these culprits are what were triggering alarms for everyone else, but the timing makes them very suspect.
I just visited the same sites as yesterday - if the Trojans re-appear on my system and Jason is confident that he killed off anything on the RED site, I'll need to dig deeper.
I'll rescan overnight and post in the morning only if I need to play whack-a-mole. Otherwise, a real thank you to Jason for being right on top of this.
 
From our experience (my roommate and I), the malware and trojans got installed from an initial program off of the root reduser.net page. Not a link or an image link. Still trying to deal with it, perhaps malware bytes or another paid program will help. It really sucks and I am wary of any forums now. My hunch is that it was a flash related virus - I totally agree with Steve Jobs when he says flash is insecure and should be replaced.

I've switched to Ubuntu / Firefox to be safe for now.
 
Any Luck with sorting this out. It's really frustrating both Safari and Mozilla are blocking every thread.
 
Any Luck with sorting this out. It's really frustrating both Safari and Mozilla are blocking every thread.

The problem was solved. Are you still getting the warning? I am using Safari and it's been clear sailing since Sunday.

Also, please visit the Real Names thread to update yours.
 
*.tssd.exe Virus - Antivir Solution Pro

*.tssd.exe Virus - Antivir Solution Pro

My computer got hit hard too. I've been trying to fix it for several days. It took over my machine as soon as I logged onto www.reduser.net. But, I didn't think it was from reduser.net until I read this post.

Scan for a file in the following format on your computer:
*tssd.exe" The file will be named: (bunch of random characters)+tssd.exe.

I found the info at http://www.2-spyware.com/remove-antivir-solution-pro.html

Good luck, I spent hours working on this problem.
 
Back
Top