Jump to content

Souleater

Experienced Members
  • Posts

    15
  • Joined

  • Last visited

Posts posted by Souleater

  1. Always latest version (chrome autoupdates itself in the background on every computer on the world)

     

    I ticked all entries for chrome but not datqbases and passwords.

    Also flash player under multimedia is ticked.

    No chrome closes completely, no more running processes which could cause this issue.

     

    I am using 2 users / profiles in chrome

  2. I am using CCleaner and just Google Chrome.

    Sometimes I play online flashgames and it seems CCleaner doesnt delete the flash cookies (latest flash version)

    Always when I load the game website after using CCleaner it seems the cookies are still existing.

    But when I delete all data in Chrome directly using the settings then they are gone.

     

    I am using Win7 Home Premium 64bit

  3. That surprises me.

    Many times when I tried to contact the forum website I never had a warning but I had the error

    "Fatal error: require_once() [function.require]: Failed opening required './initdata.php' (include_path='.:/usr/local/php53/pear') in /home/ccleaner/public_html/index.php on line 23"

    BUT

    I also tried

    http://www.piriform....leaner/download

    and that connected immediately without any problem

    but when I clicked on the Support button on that page and chose the "Community Forum"

    I again got

    "Fatal error: require_once() [function.require]: Failed opening required './initdata.php' (include_path='.:/usr/local/php53/pear') in /home/ccleaner/public_html/index.php on line 23"

    I assumed it was only the forum website that had a coding error.

     

    Are you saying that there was an exploit affecting both

    http://www.piriform.com

    and

    http://forum.piriform.com

     

    just affecting the forum software, there were php files changed

  4. Some files / dirs were not deleted when I deinstalled some software and there are some more paths / dirs / files which can be deleted like:

     

     

    C:\ProgramData\PC Tools\DownloadManager (old installers)

    C:\ProgramData\Adobe\Setup (old installers from adobe)

    C:\Program Files (x86)\Windows Sidebar\Gadgets

    C:\Users\...l\AppData\Local\Downloaded Installations (also some unnecessary old installers)

    C:\Users\...\AppData\LocalLow (same?)

     

    there could be some more maybe

  5. So everyone understands it:

     

    someone hacked the forum and got access to the file system.

    They changed some files and included an iframe.

     

    The iframe loaded the new blackhole exploit kit v2.

    And this loaded (on my machine where I saw this) some payload, it loaded also a jar file.

    Google chrome blocked it for me directly.

    The php error was due to the changed files and just fooled you. There was more than only this error message, the iframe, but you could not see it.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.