michele
May 4 2006, 09:07 PM
I've just received a strange e-mail from UM:
QUOTE
From: webmaster@unexplained-mysteries.com
Subject: Administration www.unexplained-mysteries.com ( Unexplained Mysteries Discussion Forums )
Date: 4 May 2006 22:57:24 GMT+02:00
To: webmaster@ufopsi.com
Return-Path: <webmaster@unexplained-mysteries.com>
Delivered-To: webmaster@ufopsi.com
Received: from Postfix filter 42a77884ce2a0a03efc6bb50a6dcdb21 (smtpin14l.fasthosts.co.uk [127.0.0.1]) by smtpin114.livemail.co.uk (Postfix) with SMTP id 30387168068 for <webmaster@ufopsi.com>; Thu, 4 May 2006 21:57:25 +0100 (BST)
Received: from davidinnes02.servermatrix.host (fa.f0.5446.static.theplanet.com [70.84.240.250]) by smtpin114.livemail.co.uk (Postfix) with ESMTP id 107E4168068 for <webmaster@ufopsi.com>; Thu, 4 May 2006 21:57:24 +0100 (BST)
Received: from localhost ([127.0.0.1] ident=[U2FsdGVkX1+Ffb0z6jyOMXnnIvuFFN1UXkbkZYugl/k=]) by davidinnes02.servermatrix.host with smtp (Exim 4.52) id 1Fbksx-0005nI-Fw for webmaster@ufopsi.com; Thu, 04 May 2006 20:57:19 +0000
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Priority: 3
X-Mailer: IPB PHP Mailer
X-Antiabuse: This header was added to track abuse, please include it with any abuse report
X-Antiabuse: Primary Hostname - davidinnes02.servermatrix.host
X-Antiabuse: Original Domain - ufopsi.com
X-Antiabuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-Antiabuse: Sender Address Domain - unexplained-mysteries.com
X-Source:
X-Source-Args:
X-Source-Dir:
Message-Id: <20060504205724.107E4168068@smtpin114.livemail.co.uk>
X-Original-To: webmaster@ufopsi.com
Please, take a part in our new cup.
Just register in the programm below:
What was that?

P.S. If you are under Windows, I'd not click on the url.
Edited the link so as no-one clicks it.
__Kratos__
May 4 2006, 09:39 PM
Alright, this has been happening since last night but I didn't want to say anything till all my scans and checks cleared my computer or another site first but now that I'm up and all is well with my computer and I tested UM again right now... I'm being hit with trojans from the UM site and earlier today it was pop up windows.

9 virus detections in the last hour just from AVG.
I've got some screen shots to show the off-site it's being loaded from and a couple shots of AVG detecting the virus with the name.
Screen Shot 1Screen Shot 2Screen Shot 3Screen Shot 4
Lottie
May 4 2006, 09:39 PM
To anyone who has received an email from UM don't open the link just delete it please.
frogfish
May 4 2006, 09:40 PM
for some reason, when I entered the site, that same virus or whatever it was tried to infect me...I encountered a starnge virus..
__Kratos__
May 4 2006, 09:42 PM
QUOTE(frogfish @ May 4 2006, 04:40 PM) [snapback]1174759[/snapback]
for some reason, when I entered the site, that same virus or whatever it was tried to infect me...I encountered a starnge virus..
I've got the same problem. I started a thread in here about it just a bit ago. Take some screen shots to help Saruman and update your virus programs.
Saru
May 4 2006, 09:58 PM
If you have received an e-mail from this web site please delete it.
I can confirm that this site has been hacked, someone is using it to mail out some form of spam.
This is going to take some sorting out.
Celumnaz
May 4 2006, 09:58 PM
Getting the same thing. Sophos going off about trojans. Took about 5 min to load up this page to the point I could type this.
Not having this problem on any other site. Java keeps loading up and wants me to input some script or something when I load UM.
Nadal
May 4 2006, 10:01 PM
Well...I'm leaving until this gets sorted out. This might explain a LOT of problems with my computer.
Michelle
May 4 2006, 10:02 PM
I got a nasty virus, too!
I was about to throw this old computer into the trash!
Celumnaz
May 4 2006, 10:03 PM
Disabled Java and now it loads faster.
Viruses were in temp .htm files. None of them look very bad... just totally annoying...
Saru
May 4 2006, 10:08 PM
The 'virus' that someone had implanted in our forum skin has now been removed. I'm doing my best to get to the bottom of this, and can only apologise profusely for any problems this may have caused.
Michelle
May 4 2006, 10:10 PM

Tell that to someone like me who is a computer idiot. It took me forever to figure out.
DR. YO
May 4 2006, 10:16 PM
I have 18 infected files........ HELP !!!!!!!!!!!!! Everytime I log on, the site crashes.

What's going on?
__Kratos__
May 4 2006, 10:20 PM
QUOTE(DR. YO @ May 4 2006, 05:16 PM) [snapback]1174815[/snapback]
I have 18 infected files........ HELP !!!!!!!!!!!!! Everytime I log on, the site crashes.

What's going on?
Use your virus program to catch them. If you don't have one, you can get a free verison of AVG off the net.
Michelle
May 4 2006, 10:22 PM

I wasn't talking back to the SaRu Man....I responding to Cel's post.
Please forgive me...
DR. YO
May 4 2006, 10:23 PM
QUOTE(__Kratos__ @ May 4 2006, 06:20 PM) [snapback]1174820[/snapback]
Use your virus program to catch them. If you don't have one, you can get a free verison of AVG off the net.

I did.............but everytime I log on to UM it crashes. I delete all infected files, but it comes back as soon al I log on to UM.
__Kratos__
May 4 2006, 10:27 PM
QUOTE(DR. YO @ May 4 2006, 05:23 PM) [snapback]1174826[/snapback]
I did.............but everytime I log on to UM it crashes. I delete all infected files, but it comes back as soon al I log on to UM.

If you have Firefox on your computer, you can use that until the problem is solved.

That's what I'm using right now and it seems to be working just fine.
frogfish
May 4 2006, 10:27 PM
Its seems much better now...My Norton and Webroot stopped the virus and deleted it.
There WAS a person posting suspicious links in a welcome thread yesterday...
frogfish
May 4 2006, 10:30 PM
DR. YO
May 4 2006, 10:31 PM
My cpu just crashed again as i was attempting to log on. And again my antivirus detected 11 infected files. Everytime I log on I get several infected files.
When i go to other sites my cpu is fine. I hope I'm not the only one.
DR. YO
May 4 2006, 10:32 PM
QUOTE(__Kratos__ @ May 4 2006, 06:27 PM) [snapback]1174827[/snapback]
If you have Firefox on your computer, you can use that until the problem is solved.

That's what I'm using right now and it seems to be working just fine.
I'm using eTrust.
Zking
May 4 2006, 10:33 PM
Damn, I opened it (looks at website) Does your usually say website is not responding, because fi it does then Im screw if it dosent, well then I guess I got lucky. I do so hope that this get fixed, and if their is anyway I can help (although I doubt that) I would glad ot be of service. I heard of this virus though, it's kinda like that IM virus that was going around, you know the one that wuld send it too all of your firends. I cant believe someoen would hack this site though, it seems so horrible.
BurnSide
May 4 2006, 11:25 PM
The issue has fortunately been resolved. Someone hacked the site through a vunerability in the security of the site and attached a virus to it, along with sending out these emails.
Do not open these emails, delete them immediately.Saruman has pinned a topic regarding the malicious acts,
HERE.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.