View Full Version : CineForm website unsafe??


Harry Simpson
May 1st, 2010, 11:13 PM
I've tried to get onto the Cineform website several times tonight - on my laptop it just froze up and I had to turn the laptop off. On the desktop my virus protection immediately blocked the site as unsafe.

Any idea what's going on?

Harry

David Newman
May 1st, 2010, 11:27 PM
I'm seeing it too. Investigating.

Chris Soucy
May 1st, 2010, 11:55 PM
It appears that something on the site is initiating an immediate Java upgrade install which, dependant on the security level set on you're system, may trigger an alarm.

Whether the Java update is cosher is another question entirely, Nortons didn't flag it, but I kyboshed it anyway.

Think you may have added some new graphics which require the latest update is all.


CS

David Newman
May 2nd, 2010, 12:13 AM
Thanks Chris,

That is useful info. I have downloads the whole website and scanned it locally and found nothing.

Rich Perry
May 2nd, 2010, 02:20 AM
The cineform website has a virus,
On loading if allowed it downloads a PDF which contains the following content:

"Abvolt spit abortively abongo puneet. Playboy abhorrently phone dawn elizabeth abashedness abyssinian. Topography lisa playboy abhorrently phone dawn elizabeth abashedness abyssinian abhorrently. "

Oh, this happened while using google chrome and the PDF downloaded was called
3bbb9d.pdf

Rich Perry
May 2nd, 2010, 02:41 AM
I did not get any issues on iexplorer or google chrome the second time I went to the site today or even when clearing cookies (but I had already approved the unsafe site) perhaps it's something akin to the described article below:

Virus spreading via PDF | OIT Website (http://oit.ncsu.edu/news-releases/virus-spreading-pdf)

David Taylor
May 2nd, 2010, 07:49 AM
Network Solutions is our host. Apparently they have other sites they host that have also been targeted. They have escalated it and are working on a solution. I'll post again when they've resolved it.

Harry, thank you for first reporting it, and to others who have chimed in....

David Dwyer
May 3rd, 2010, 02:39 AM
This website has been reported as unsafe
techblog.cineform.com

We recommend that you do not continue to this website.
Go to my home page instead

This website has been reported to Microsoft for containing threats to your computer that might reveal personal or financial information.

More information

This website has been reported to contain the following threats:

Malicious software threat: This site contains links to viruses or other software programs that can reveal personal information stored or typed on your computer to malicious persons.

Learn more about phishing
Learn more about malicious software
Report that this site does not contain threats
Disregard and continue (not recommended)



Yeah I was trying to download the latest update and I got the above - Nice of Windows 7! Atleast I know it works

Martin Guitar
May 3rd, 2010, 11:33 AM
It happened to my company's website as well maybe 3 months ago.

Basically it attacked every HTML files and XML files on our website. Our IT guy wrote a script to remove those javascript code snippet from all infected files. There was a lot of infections.

We cleaned it with the script and changed all our passwords and everything was ok...then it came back 2 weeks after so we had to do a re-provisioning of our server. (backing up and formatting the whole thing, re-installing os)

It really sucks.

Steve Pesenti
May 3rd, 2010, 04:02 PM
After reaching the Cineform site I noticed the suspicious Java install message pop up too. Did not click on it and Norton also flagged it had resolved an attack. However, despite this I then appeared to get a redirect virus in my browser. Ran a scan with Malwarebytes' Anti-Malware found at Malwarebytes (http://www.malwarebytes.org) and it seems to have fixed the problem.

Burk Wagner
May 6th, 2010, 07:55 PM
Still virus-ridden May 6 10 pm EST

David Newman
May 6th, 2010, 10:35 PM
I think I might be finally fixed. Please report.

Trond Saetre
May 7th, 2010, 12:52 AM
No error message, no java update pop-up, no antivirus messages when visiting cineform website May 7, 06:50UTC

Website appears to be as it is supposed to be.

Tim Hall
May 7th, 2010, 01:52 AM
I did not get any issues on iexplorer or google chrome the second time I went to the site today or even when clearing cookies (but I had already approved the unsafe site) perhaps it's something akin to the described article below:

Virus spreading via PDF | OIT Website (http://oit.ncsu.edu/news-releases/virus-spreading-pdf)

I also approved the site after it was reported unsafe by my AV, now I'm worried :/ It didn't seem to try and download any PDFs, so it should be fine right?!

Robert Young
May 7th, 2010, 01:53 AM
Confirmed!
Both the Tech Blog page and the CF site seem squeeky clean now.
I never did approve the site when it was misbehaving, and now I don't get the unsafe site screen.
What a nusiance for you guys...

David Newman
May 7th, 2010, 08:54 AM
We spent two many precious hours on it, and it turn out not to be in any of our pages, but in the server side components. Network Solutions found it last night.

Reber Clark
May 7th, 2010, 11:05 AM
I think I might be finally fixed. Please report.

All clear here as well.

David H. Wilson
May 7th, 2010, 01:32 PM
It's fine now from this perspective. Avast was blocking the site before.

Stephen Armour
May 7th, 2010, 02:15 PM
Slick, clean, fast. Glad Network Solutions took care of your prob. It's getting harder every day to keep those yo-yo's at bay. It's almost as bad as our porous borders and hamstrung guards.

Thanks for being open and transparent about it. That's refreshing to see.

Robert Young
May 7th, 2010, 06:55 PM
Slick, clean, fast. Glad Network Solutions took care of your prob. It's getting harder every day to keep those yo-yo's at bay. It's almost as bad as our porous borders and hamstrung guards.

Thanks for being open and transparent about it. That's refreshing to see.
Network Solutions has been having a lot of commotion lately.
One of our sites they host was part of a network wide shutdown for FTP upload for a while, then they reset all the site passwords. They never really explained it, but I can guess...

Larry Secrest
October 29th, 2013, 02:24 PM
I've tried to download NeoHDV, too long to explain why I need it, but basically my OS drive died, I've updated to a SSD and I need to reinstal NeoHDV to be able to read some older videos encoded in NEO.
The download is always aborted by AVAST that tells me there is a virus.
No, I'm not going to disable my anti virus software, why should I do that when I'm downloading.
So since this is something that happened in the past to Cineform, I'm wondering if it's not happening again.
That happened to me yesterday, October 28th, 2013
Thanks for looking into this, David or somebody else at Cineform.
Larry

David Newman
October 29th, 2013, 07:43 PM
It is a false positive in Avast, it happens with some of the updates, I filed a false report with Avast. Either disable Avast or wait for them to fix it.