Author Topic: Infected file on GenesReunited  (Read 21714 times)

Offline Nick29

  • Deceased † Rest In Peace
  • RootsChat Marquessate
  • ********
  • Posts: 6,273
    • View Profile
Re: Infected file on GenesReunited
« Reply #117 on: Thursday 18 February 10 10:09 GMT (UK) »
I think what Steve was getting at yesterday was that email and web page links don't always take you where you think they are going to take you, and with many email packages (like Outlook), if you hover your mouse pointer over the link, it reveals where it's going to take you.  You can have a link that says Google but when you click on it, it takes you somewhere else (try it !).  I get several emails a week asking me to confirm my emails on banks and other online payment sites, and they all look quite authentic, but the links don't take you where you think they're going to.  

RIP 1949-10th January 2013

Best Wishes,  Nick.

Census information Crown Copyright, from www.nationalarchives.gov.uk

Offline smudwhisk

  • RootsChat Marquessate
  • *******
  • Posts: 3,864
  • Whiskey (1997-2018)
    • View Profile
Re: Infected file on GenesReunited
« Reply #118 on: Thursday 18 February 10 10:16 GMT (UK) »
Its possible it could be a false positive but if you re-read the thread you'll see that McAfee, Norton, Kaspersky and AVG have all been mentioned .... so perhaps less likely.  The chances are that people who haven't experienced the problem are also using these products ....

But then as some have been people experiencing it and not others, its not really surprising since the problem is with the adverts fed to the site and these change each time you go there ... so not everyone is going to get the same adverts.  And yes the same comment can be made about other sites IF people are experiencing the same issue with them ... adverts are generally fed randomly to sites.

(KENT) Lingwell, Rayment (BUCKS) Read, Hutchins (SRY) Costin, Westbrook (DOR) Gibbs, Goreing (DUR) Green (ESX) Rudland, Malden, Rouse, Boosey (FIFE) Foulis, Russell (NFK) Johnson, Farthing, Purdy, Barsham (GLOS) Collett, Morris, Freebury, May, Kirkman (HERTS) Winchester, Linford (NORTHANTS) Bird, Brimley, Chater, Wilford, Read, Chapman, Jeys, Marston, Lumley (WILTS) Arden, Whatley, Batson, Gleed, Greenhill (SOM) Coombs, Watkins (RUT) Stafford (BERKS) Sansom, Angel, Young, Stratton, Weeks, Day

Offline Nick29

  • Deceased † Rest In Peace
  • RootsChat Marquessate
  • ********
  • Posts: 6,273
    • View Profile
Re: Infected file on GenesReunited
« Reply #119 on: Thursday 18 February 10 10:26 GMT (UK) »
That really depends on who is supplying the advertising.  On RC it is Google, so if you post something with Ancestry in the message body, chances are that an Ancestry advert will appear.  On GR it may be a totally different agency supplying advertising from companies that have paid specifically to be there.

RIP 1949-10th January 2013

Best Wishes,  Nick.

Census information Crown Copyright, from www.nationalarchives.gov.uk

Offline downside

  • RootsChat Marquessate
  • *******
  • Posts: 4,208
  • Make my day
    • View Profile
Re: Infected file on GenesReunited
« Reply #120 on: Thursday 18 February 10 10:31 GMT (UK) »
There only seem to be 2 advertisers at the moment:

JobCentrePlus
BT

In the past they have had organusations like the RSPCA advertise on there.

They seem to be respectable organisations.

Sussex: Floate, West
Kent: Tuffee
Cheshire: Gradwell
Lancashire: Gradwell

UK Census information is Crown Copyright, from www.nationalarchives.gov.uk


Offline arthurk

  • RootsChat Marquessate
  • *******
  • Posts: 5,194
    • View Profile
Re: Infected file on GenesReunited
« Reply #121 on: Friday 19 February 10 10:38 GMT (UK) »
I know everyone is saying that GR is fine and I accept that BUT...

<snip>

So - what raised the Trojan message? It wasn't anything lurking on my PC and nothing else apart from GR raises the error.  I'm not sure how people can be as confident as they are that there's nothing amiss on the GR site  ???

It's refreshing to read a message from someone who seems to know what they're talking about, rather than just pontificating about something they haven't experienced and blaming users for this, rather than accepting the overwhelming evidence from those who have actually come across the problem themselves.

While it is quite correct that this piece of malware is not itself on the Genes Reunited website, it is almost certain that there is nevertheless a problem on the site which is causing people to be directed to a site which does contain some kind of malware. I have experienced this on two different computers which, like Angela's, have been thoroughly scanned and do not have any nasties on them.

This seems to have happened to so many people on (and only on) Genes Reunited that the laws of probability indicate that the problem is there rather than on individual computers. What seems to be happening is that when people click on a page, either on the site itself or in an email linking to the site, they are being misdirected to an external page containing (in my case) a rogue scanner. (Although my security software has been preventing the page from loading, it logged the IP address, which I have checked out at WHOIS.)

That it is not happening to everybody does not mean that there is not a problem, or that the problem is not originating at GR. It seems to be happening on a fairly random basis, and it may be that it only affects some browsers. It has also so far only happened to me when I have been logged in.

It's also unlikely that this is a false positive, since several different security products are detecting it as a threat. Moreover, the description from people who do not have security software blocking the page fits with that of a rogue scanner - they are being told that they have lots of nasties on their computer and need to download software to deal with it.

I have sent GR several emails about this, and like many others received their standard reply about removing adverts. However, the problem occurred again after they had supposedly removed these adverts, and although I emailed them again to point this out and describe how the problem occurred and gave them the IP address etc, it was clear that they did not read this as all I received was another copy of the standard reply. I wrote again asking them to read what I had written, but two days later am still awaiting a reply.

I have not returned to Genes Reunited since this last happened to me a couple of days ago, as I do not have any confidence that they have dealt with the problem properly and that the site is now safe.

Arthur
Researching among others:
Bartle, Bilton, Bingley, Campbell, Craven, Emmott, Harcourt, Hirst, Kellet(t), Kennedy,
Meaburn, Mennile/Meynell, Metcalf(e), Palliser, Robinson, Rutter, Shipley, Stow, Wilkinson

Census information is Crown Copyright, from www.nationalarchives.gov.uk

Offline Annette7

  • RootsChat Marquessate
  • *******
  • Posts: 8,009
    • View Profile
Re: Infected file on GenesReunited
« Reply #122 on: Friday 19 February 10 12:07 GMT (UK) »
Hear, hear Arthur

I agree with everything you say.   I too am staying away from Genes.

Annette
Scopes (One-Name Study - Worldwide)
Suffolk - Grist, Knights, Bullenthorpe, Watcham
Scotland - Spence, Horne, Cowan, Moffat
London -  Monk

Don't walk behind me, I may not lead.   Don't walk in front of me, I may not follow.   Just walk beside me and be my friend.

Census Information is Crown Copyright, from www.nationalarchives.gov.uk

Offline alyson123

  • RootsChat Veteran
  • *****
  • Posts: 630
    • View Profile
Re: Infected file on GenesReunited
« Reply #123 on: Friday 19 February 10 12:35 GMT (UK) »
Ditto
Lea/Lee ........Gnosall, Armitage Hednesford Kings Bromley,  Hednesford, Staffordshire.
Richardson..... Hanbury, Hednesford, Checkley Marchington .....Staffordshire
Corbett ....... Dawley, Wellington, Madeley......Shropshire, Willenhall & Hednesford,Staffs
Pyle/Pile ........Hensingham, Workington, Whitehaven, Cumberland
Pyle/Pile....... Newcastlle on Tyne, County Durham & Northumberland
Doran ...... Whitehaven, Cumberland and Ireland
Savage ........ County Down, Killough and Belfast, Irela

Offline maidmarianoops

  • RootsChat Marquessate
  • *******
  • Posts: 4,184
  • somewhere over the rainbow
    • View Profile
Re: Infected file on GenesReunited
« Reply #124 on: Friday 19 February 10 12:49 GMT (UK) »
another to look out for is a Hallmark card sent to you that contains a virus

sylvia
notts/derbys clark
      "        "      stenson
        "       "    nicholson
       "     "        jarvis
                         castledine
    rhodes

 
Census information Crown Copyright, from www.nationalarchives.gov.uk

Offline snowyw

  • RootsChat Aristocrat
  • ******
  • Posts: 1,102
    • View Profile
Re: Infected file on GenesReunited
« Reply #125 on: Friday 19 February 10 12:52 GMT (UK) »
Well said Arthur!!

Sue
I'm not young enough to know everything.


Census information Crown Copyright, from www.nationalarchives.gov.uk