Welcome Guest ( Log In | Register )




Advertise Here


2 Pages V   1 2 >  
Closed TopicStart new topic
> Trojans on Genelle's sites (in list), Stelaartois hacker back again
Guest_wagdoll_*
post Feb 4 2007, 09:38 PM
Post #1





Guests






I had a littlecountryplace page with the stelaartois trojan and went to report it to butterflies n roses where as it was in their PTP got hit by it there too on the report page. toybox was reported earlier as having this back again, assume all Genelle's sites have it again, they are usually all hit together and there's too many of them to go run through Jutaky's checker individually.

CODE
(Level: 0) Url checked:
http://littlecountryplace.com
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified
Go to the top of the page
 
+Quote Post
the lil crusader
post Feb 4 2007, 10:37 PM
Post #2


GPF Addict
*****

Group: Senior Members
Posts: 5713
Joined: 11-December 02
From: my own little world, but it's okay - they know me there
Member No.: 6094



It's on Kerosene Cucumber too:

QUOTE(IframeChecker)
No zeroiframes detected!
Check took 4.15 seconds

(Level: 0) Url checked:
http://www.thekerosenecucumber.com
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (iframe source)
http://www.stelaartois.ru/index2.php
Zeroiframes detected on this site: 0
No ad codes identified

(Level: 1) Url checked: (script source)
http://www.kissdesign.net/calendriers/025/code.js
Blank page / could not connect
Go to the top of the page
 
+Quote Post
sophieca
post Feb 5 2007, 02:16 AM
Post #3


GPF Addict
*****

Group: Senior Members
Posts: 20827
Joined: 24-March 02
Member No.: 937



Does someone have a list of Genelles' sites ?

Is she fixing this ?

Thanks (IMG:style_emoticons/default/aa.gif)
Go to the top of the page
 
+Quote Post
Guest_wagdoll_*
post Feb 5 2007, 05:23 AM
Post #4





Guests






I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.

This post has been edited by wagdoll: Feb 5 2007, 06:04 AM
Go to the top of the page
 
+Quote Post
Guest_wagdoll_*
post Feb 5 2007, 11:39 PM
Post #5





Guests






I just checked thetoyboxonline and littlecountryplace and they are both now clean. I have not checked the rest of the sites.
Go to the top of the page
 
+Quote Post
taf
post Feb 6 2007, 12:25 AM
Post #6


Established Member
**

Group: Senior Members
Posts: 346
Joined: 7-September 03
From: Melbourne, 3001
Member No.: 15282



QUOTE(wagdoll @ Feb 6 2007, 04:39 PM) [snapback]4639642[/snapback]
I just checked thetoyboxonline and littlecountryplace and they are both now clean. I have not checked the rest of the sites.


thank you Wagdoll for the warning,
I am happy to say I am only a member at one site of Genelle's - mother earth- which she acquired during the allen fan club transfer, but she seems never to send mails on it, including my gold ads, LOL.
Go to the top of the page
 
+Quote Post
sophieca
post Feb 7 2007, 03:14 AM
Post #7


GPF Addict
*****

Group: Senior Members
Posts: 20827
Joined: 24-March 02
Member No.: 937



Thanks for the list wagdoll, going to check them now, if they are still infected, I'll add them to the alphabetical list otherwhise I'll leave it at that but as they seem to be a regular target, we'll keep an eye on it

hummingbirdsnroses.com fixed - nothing on homepage
PrancingPenguin fixed - nothing on homepage
CountryRedneck fixed - nothing on homepage
SugarLandCash fixed - nothing on homepage
SweetClickers fixed - nothing on homepage
CatMails fixed - nothing on homepage
ButterfliesNRoses fixed - nothing on homepage
MotherEarthMails fixed - nothing on homepage
BigDaddyMails fixed - nothing on homepage
PoolHallPTR fixed - nothing on homepage
TheToyBoxOnline fixed - nothing on homepage
purringemail.com fixed - nothing on homepage
KeroseneCucumber fixed - nothing on homepage
thelittlestpenguins.com fixed - nothing on homepage
Foxden Googled this one but couldn't find which one was the right one
LittleCountryPlace fixed - nothing on homepage
Pactech hosting fixed - nothing on homepage
drunkenpenguins fixed - nothing on homepage

Go to the top of the page
 
+Quote Post
Candyred32
post Feb 19 2007, 03:11 PM
Post #8


Established Member
**

Group: Senior Members
Posts: 478
Joined: 23-November 03
From: Winder, Georgia USA
Member No.: 19060



QUOTE(wagdoll @ Feb 5 2007, 06:23 AM) [snapback]4639153[/snapback]
I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.


Genelle also owns GroovyPaidEmails.biz
Go to the top of the page
 
+Quote Post
trekkiesg
post Mar 15 2007, 06:44 AM
Post #9


Active Member
*

Group: New Signups
Posts: 127
Joined: 29-November 05
Member No.: 67980



stellaartois is back...

littlecountryplace.com - infected
thelittlestpenguins.com - infected
thetoyboxonline - infected

had to refresh a few times but the nasty is definitely there.
not sure about the others.

have alerted her about this + alerted her about this thread
Go to the top of the page
 
+Quote Post
anyyan
post Mar 22 2007, 01:28 AM
Post #10


Expert Member
****

Group: Senior Program Owners
Posts: 4151
Joined: 29-January 03
From: One World, One Dream
Member No.: 7590



stelaartois.ru 5x5 iframe freasing browser and download ActiveX still on thelittlestpenguins.

I came across it on Sparky's PTP. Reported to Tipsy.

Not sure of other sites.
Go to the top of the page
 
+Quote Post
Guest_cubster_*
post Mar 22 2007, 01:45 AM
Post #11





Guests






It is definetely still on thetoyboxonline.
Go to the top of the page
 
+Quote Post
sophieca
post Mar 22 2007, 03:35 AM
Post #12


GPF Addict
*****

Group: Senior Members
Posts: 20827
Joined: 24-March 02
Member No.: 937



I had it too on the penguin PTP one, anyone knows the quickest way to inform Genelle ?
Go to the top of the page
 
+Quote Post
trekkiesg
post Mar 22 2007, 05:50 PM
Post #13


Active Member
*

Group: New Signups
Posts: 127
Joined: 29-November 05
Member No.: 67980



this is the reply I got from them.
So they are aware of the issue and are working on it:


QUOTE
---------- Forwarded message ----------
From: support@thetoyboxonline.com <support@thetoyboxonline.com>
Date: Mar 16, 2007 9:41 PM
Subject: Re: Other

Hi,

We are looking into this. Thank you for alerting us to this situation.


Kathy


Quoting trekkiesg:

>
> name: trekkiesg
>
> username: n/a
>
> bquestion_type: stellaartois on your sites
>
> message_type: hi Genelle,
>
> your sites are infected with the Stellaartois trojan.
>
> you might want to check through them. I did not check all the sites,
> only this one, littlecountryplace, thelittlestpenguins, all of
> which are affected.
>
> There is a thread at Getpaidforum so you can update us there:
> http://getpaidforum.com/forums/index.php?showtopic=478263
Go to the top of the page
 
+Quote Post
Guest_OurPTR2_*
post Mar 23 2007, 07:15 AM
Post #14





Guests






There are now three stellaartois showing on thelittlestpenguins.com.
Go to the top of the page
 
+Quote Post
mcf
post Mar 23 2007, 05:19 PM
Post #15


GPF Addict
*****

Group: Senior Members
Posts: 6398
Joined: 1-June 03
Member No.: 11327



QUOTE(wagdoll @ Feb 5 2007, 07:23 AM) [snapback]4639153[/snapback]
I was also wondering these things Sophie. Last time it happened I did go through her sites with Jutaky's detektor and grabbed site lists from the code. I wrote to her using generic email addresses for several of the sites (support@ and webmaster@) but didn't receive any replies so I have no idea if she even got my messages. I can't visit sites that have this on them to send them a support form, so I have no way to let them know unless an address like that works, and I don't know if the address works unless they reply.

I believe these are amongst Genelle's sites, that she owns or runs or hosts. Apologies for any errors.

hummingbirdsnroses.com
PrancingPenguins
CountryRedneck
SugarLandCash
SweetClickers
CatMails
ButterfliesNRoses
MotherEarthMails
BigDaddyMails
PoolHallPTR
TheToyBoxOnline
purringemail.com
KeroseneCucumber
thelittlestpenguins.com
Foxden
LittleCountryPlace
Pactech hosting
drunkenpenguins

I don't think that is a complete list.

I believe heavenlyemail and destinysdollars are now on pactech hosting and also getting hit when Genelle's get hit recently, although they are not owned by her.

How can she manage so many site ? Guess the answer is "not".
Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic


1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Advertise Here
Lo-Fi Version Time is now: 16th May 2012 - 05:02 PM

GPTBoycott.com

Get Paid to Read email | TommyDSports | Website Marketing Services


Hosting Provided by: HostingLagoon