Malware on Okshooters?

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.

poopgiggle

Sharpshooter
Special Hen
Joined
Feb 20, 2009
Messages
2,781
Reaction score
0
Location
Tulsa
I was able to replicate the warning. It's still there as of like an hour ago.

It's trying to run some windows console commands so, being that I have a mac, I'm hard-pressed to care very much.
 

dru

Sharpshooter
Special Hen
Joined
Jan 22, 2008
Messages
1,604
Reaction score
19
Location
Yukon
Windows Security Essentials detected VirTool:JS/Obfuscator and cleaned it off my machine. That bit of code is designed to hide another piece of malware. There's definitely some bad juju that's infected the forum software.

I just had the same issue. Windows SE claims it was successfully removed but still concerning to me
 

BReeves

Sharpshooter
Supporting Member
Special Hen Supporter
Joined
Feb 18, 2010
Messages
2,733
Reaction score
1,603
Location
Catoosa
It's trying to download and install Windows Security 2010 or 2011 which is nothing but a scam to get your credit card number. I don't run any resident AV software and was able to shut it down before it completed, then ran Malwarebytes to clean up what got through. I discovered if I went to the OKSHOOTERS home page then to the forum via the link it didn't try to install it. I deleted my shortcut in Favorites, created a new one after accessing the forum via the home page and that seemed to solve the problem.
 

Kelly Drown

Sharpshooter
Special Hen
Joined
Mar 18, 2016
Messages
1,623
Reaction score
2
Location
Tulsa, Oklahoma
I'm checking into this but at the moment I'm unable to reproduce it and I'm not getting any warnings or anything. (Chrome or IE)

Looks like this is a new pattern file just released so there's a small chance it could be hitting on legitimate code erroneously. I've seen this quite a number of times over the years. The worst was when McAfee accidentally quarantined a legitimate core system file for windows and shutdown a few hundred systems for us.

I'll see if I can trace it down.
 

poopgiggle

Sharpshooter
Special Hen
Joined
Feb 20, 2009
Messages
2,781
Reaction score
0
Location
Tulsa
so there's a small chance it could be hitting on legitimate code erroneously.

This isn't the case.

Try using a private browsing window in FF or Chrome. That trips it every time for me.

BReeves said:
It's trying to download and install Windows Security 2010 or 2011 which is nothing but a scam to get your credit card number. I don't run any resident AV software and was able to shut it down before it completed, then ran Malwarebytes to clean up what got through. I discovered if I went to the OKSHOOTERS home page then to the forum via the link it didn't try to install it. I deleted my shortcut in Favorites, created a new one after accessing the forum via the home page and that seemed to solve the problem.

I have been trying to get it to infect a VM since last night but it won't do it. Which version of IE are you using?
 

Latest posts

Top Bottom