Trains.com

Railpictures.net - malware

8325 views
22 replies
1 rating 2 rating 3 rating 4 rating 5 rating
  • Member since
    May 2003
  • From: US
  • 25,279 posts
Railpictures.net - malware
Posted by BaltACD on Friday, March 4, 2011 6:47 AM

The other evening I was surfing Railpicturs.net and called up a video of the Ringling Bros. Circus train on the FEC....in addition to the video I seemed to have picked up a trespasser on the right of way....a piece of Malware that entered through the Java connection and appears to have identified itself as 'Microsoft Antimalware'.

Upon entering my desktop system it put up a screen stating that there was Malware on the system and only the product that began and displayed a 'scan dialogue' on the screen could cure it.

I immediately shut the box down and began running the known anit-virus, anti-malware products that reside on my box...they identified and removed a number of items, however, there was one item that it would not remove....it was identified as

TrojanDownloader:Java/OpenConnection.gc

The box is now at a professional comupter service to have this rectified.

I have been experiencing a number of unrequested advertising pages from RailPictures.net when attempting to call up the full size pictures of my choosing.

I don't know if anyone else is experiencing similar things.

Never too old to have a happy childhood!

              

  • Member since
    September 2002
  • 762 posts
Posted by kolechovski on Friday, March 4, 2011 7:23 AM

You'd better forward a copy of this message to the staff there-they may not know about it yet and would like to find out.  Maybe they can research things better and find out where the offending ads are coming from.

  • Member since
    June 2004
  • From: Menasha, Wis.
  • 451 posts
Posted by Soo 6604 on Friday, March 4, 2011 7:52 AM

I always get pop-up advertising from that site, so I stopped going there.

  • Member since
    October 2006
  • From: Allentown, PA
  • 9,810 posts
Posted by Paul_D_North_Jr on Friday, March 4, 2011 8:42 AM

I believe I have, but since my anti-virus software identified, isolated, and suppressed it, it wasn't enough of a problem for me to take the trouble to write down the details of the name, etc.  It wasn't much worse than suppressing the pop-ups, anyway. 

Same thing has happened to me on some of the pages at the otherwise very useful  www.multimodalways.com website - I recognize the pattern of that bogus malware warning screen and cure, etc.  Too bad somebody can't "terminate with extreme prejudice" the originators of these problems - permanently !  Dead

- Paul North. 

"This Fascinating Railroad Business" (title of 1943 book by Robert Selph Henry of the AAR)
  • Member since
    December 2005
  • From: MP 175.1 CN Neenah Sub
  • 4,917 posts
Posted by CNW 6000 on Friday, March 4, 2011 8:45 AM

Soo 6604

I always get pop-up advertising from that site, so I stopped going there.

+1

Plus you had people entering model trains (HO, O, N, etc) in the loco and rolling stock roster.  Quite annoying when you're looking for 1:1 info.

Dan

  • Member since
    January 2003
  • From: Kenosha, WI
  • 6,567 posts
Posted by zardoz on Friday, March 4, 2011 10:05 AM

CNW 6000

 Soo 6604:

I always get pop-up advertising from that site, so I stopped going there.

 

+1

Plus you had people entering model trains (HO, O, N, etc) in the loco and rolling stock roster.  Quite annoying when you're looking for 1:1 info.

+2

FWIW: Sometimes these malware programs are coded such that even clicking on the "X" to close the applet window will cause the unwanted program to launch.  DO NOT "X" OUT OF THE PROGRAM!

Your best bet when you get a malware program is to do "Control-Alt-Delete", and from the task manager restart the entire PC. If the malware is preventing access to the task manager, then use the power button to turn off the PC (yes, even with programs running); although it is not good to do this on a regular basis, it is a far better alternative than risking giving the malware an opportunity to self-install.

If, after holding the power button in for 5 seconds the PC does not stud down, then go drastic and pull the plug. REPEAT: DO NOT "X" OUT OF A MALWARE APPLET!!!!

  • Member since
    May 2005
  • From: Pittsburgh, PA
  • 1,155 posts
Posted by tcwright973 on Friday, March 4, 2011 10:49 AM

I agree with Zardoz. It happened to me about a year ago and I ended up having to have everything erased, including the operating system. I was told by the technician to always just shut down immediately when these things pop up. Hitting the X-box or taking some other action actually launches it in a lot of cases.

Tom

Tom

Pittsburgh, PA

  • Member since
    July 2006
  • From: Southern California
  • 1,074 posts
Posted by Erie Lackawanna on Friday, March 4, 2011 11:15 AM

zardoz

 CNW 6000:

 Soo 6604:

I always get pop-up advertising from that site, so I stopped going there.

 

+1

Plus you had people entering model trains (HO, O, N, etc) in the loco and rolling stock roster.  Quite annoying when you're looking for 1:1 info.

 

+2

FWIW: Sometimes these malware programs are coded such that even clicking on the "X" to close the applet window will cause the unwanted program to launch.  DO NOT "X" OUT OF THE PROGRAM!

Your best bet when you get a malware program is to do "Control-Alt-Delete", and from the task manager restart the entire PC. If the malware is preventing access to the task manager, then use the power button to turn off the PC (yes, even with programs running); although it is not good to do this on a regular basis, it is a far better alternative than risking giving the malware an opportunity to self-install.

If, after holding the power button in for 5 seconds the PC does not stud down, then go drastic and pull the plug. REPEAT: DO NOT "X" OUT OF A MALWARE APPLET!!!!

 

I just want to echo that this is absolutely 100% perfect advice. I infected a computer once, not that long ago, by actually clicking on the "X."

Realizing how stupid I was (and paying to get the computer cleaned), I told the whole family these instructions. Wherver the malware was coming from, it tried to attack two other computers in the house. I both cases, by powering down immediately, we kept the malware from launching.

Charles Freericks
  • Member since
    December 2005
  • From: MP 175.1 CN Neenah Sub
  • 4,917 posts
Posted by CNW 6000 on Friday, March 4, 2011 11:19 AM

I run a program called MalWare Bytes which is free (google it) and pretty easy to use.  I also keep a backup copy of that program on a flash drive as some of the mw I've seen disables anything on the system when it arrives. 

I have had good experiences with shutting down, restarting and running in "safe mode" and running the MalWare Bytes from there.  It's caught infections that were launched and removed their tracking cookies too...but I'm comfortable taking that (and registry editing too) steps.

Has anyone contacted the owner of that site?

Dan

  • Member since
    January 2005
  • From: Duluth,Minnesota,USA
  • 4,015 posts
Posted by coborn35 on Friday, March 4, 2011 11:34 AM

CNW 6000

 

 Soo 6604:

 

I always get pop-up advertising from that site, so I stopped going there.

 

+1

 

Plus you had people entering model trains (HO, O, N, etc) in the loco and rolling stock roster.  Quite annoying when you're looking for 1:1 info.

What?

Mechanical Department  "No no that's fine shove that 20 pound set all around the yard... those shoes aren't hell and a half to change..."

The Missabe Road: Safety First

 

  • Member since
    May 2003
  • From: US
  • 25,279 posts
Posted by BaltACD on Friday, March 4, 2011 12:11 PM

I also have MalWareBytes loaded on my machine and ran it...it removed some stuff but not the 'real offender',

The computer tech that is working on the machine said he had not yet heard of the problem I was relating and he has worked on this box before with great success.

CNW 6000

I run a program called MalWare Bytes which is free (google it) and pretty easy to use.  I also keep a backup copy of that program on a flash drive as some of the mw I've seen disables anything on the system when it arrives. 

I have had good experiences with shutting down, restarting and running in "safe mode" and running the MalWare Bytes from there.  It's caught infections that were launched and removed their tracking cookies too...but I'm comfortable taking that (and registry editing too) steps.

Has anyone contacted the owner of that site?

Never too old to have a happy childhood!

              

  • Member since
    September 2007
  • From: Charlotte, NC
  • 6,099 posts
Posted by Phoebe Vet on Friday, March 4, 2011 12:53 PM

I also have MalWareBytes.  It was loaded on my computer by a tech support agent at Microsoft while he was troubleshooting a windows problem by remote control.  The problem was not a virus, but I decided that if Microsoft uses the program it must be pretty effective.

Dave

Lackawanna Route of the Phoebe Snow

  • Member since
    December 2005
  • From: MP 175.1 CN Neenah Sub
  • 4,917 posts
Posted by CNW 6000 on Friday, March 4, 2011 1:03 PM

coborn35
What?

I was looking for some prototype photos of particular locomotives (SDCAT & a special CNW Dash 9 - 8730) for modeling purposes and ended up finding lots of pictures of Athearn, Bachmann & Kato locomotives.  After 15 locomotives I clicked on were all models and with the amount of pop-ups & flash ads I stopped using the site.  LocoPhotos or Flickr are what I use now.

Dan

  • Member since
    February 2005
  • From: Vancouver Island, BC
  • 23,330 posts
Posted by selector on Friday, March 4, 2011 1:14 PM

Whenever I have encountered that dreaded self-initiating malware detection pop-up that immediately begins to list all the bad bogeymen on my hard drive, I just back-screen out and it goes away.

One time I found that I had a Trojan or virus called Spyaxe, and I couldn't get rid of it with Norton or anything else.  Not knowing better, I decided I had nothing to lose by trying a system restore to a previous set-point.  By that I mean I had never used it before, and didn't really know what I was about to ask the computer to do (this was years ago...).   When the computer restarted a few minutes later, it was free of the SpyAxe.  

Ever since that time, whenever I encounter a bug of any kind, something that makes me go "Hmmm..." because the computer seems to have modified its behaviour in an unwanted or prohibitive way, I just do a system restore.  Takes about five minutes all up, and it has always cured my woes.  Did it just five days ago.

And I agree, railpictures.net is an annoying site for that reason.  It has a lot of fantastic imagery, though.

MalwareBytes has a good reputation, and I used Superantispyware until just recently when I purchased a new PC.  AVG freeware and SuperAntiSpyware both worked very well.

Crandell

  • Member since
    January 2005
  • From: Duluth,Minnesota,USA
  • 4,015 posts
Posted by coborn35 on Friday, March 4, 2011 2:13 PM

CNW 6000

 

 coborn35:
What?

 

 

 

I was looking for some prototype photos of particular locomotives (SDCAT & a special CNW Dash 9 - 8730) for modeling purposes and ended up finding lots of pictures of Athearn, Bachmann & Kato locomotives.  After 15 locomotives I clicked on were all models and with the amount of pop-ups & flash ads I stopped using the site.  LocoPhotos or Flickr are what I use now.

No way. I doubt that is true. I have never EVER seen a model photo on railpictures.net. They would never allow one. Maybe your thinking of rrpicturearchives.net.

Mechanical Department  "No no that's fine shove that 20 pound set all around the yard... those shoes aren't hell and a half to change..."

The Missabe Road: Safety First

 

  • Member since
    January 2002
  • From: Canterlot
  • 9,575 posts
Posted by zugmann on Friday, March 4, 2011 2:14 PM

But they do have fake snow.... 

 

Laugh

It's been fun.  But it isn't much fun anymore.   Signing off for now. 


  

The opinions expressed here represent my own and not those of my employer, any other railroad, company, or person.t fun any

  • Member since
    June 2003
  • From: South Central,Ks
  • 7,170 posts
Posted by samfp1943 on Friday, March 4, 2011 2:37 PM

Bang HeadSome pretty accurate and interesting advice here.  I enjoy reading a lot of different sites, and in the past I have developed some pretty 'ugly' issues, as well as some vicious infections to my machines (boxes?)Bang Head some that have been fatal and some that were extracted- expensively!Oops.

Fortunately, I have a grandson that is pretty computer literate.  His thoughts about dealing with malware problems have revolved around several free systems to attack malware problems. He's installed 'Malware Bytes', 'Ad Aware', 'Threatfire', Avast Free Virus protection'.   The theory being that malware gremlins use diferent strategies to infect systems, and one system may get it, or might overlook the infector. Therefore by running several different protectors, your chances of stopping the malware are better. So far it has worked pretty well.

One thing to hold onto and protect is the Original Systems Installation Disk for your maching. If you wind up having to 'scrub' your hard drive to dump an infection, you can reinstall youtr original system.     To buy a new disk for a Windows Operating System, can be devilishly expensive and possibly hard to find. That original operating system disk is worth its weight in gold.My 2 Cents  

 

 


 

  • Member since
    April 2003
  • 305,205 posts
Posted by Anonymous on Friday, March 4, 2011 3:50 PM

CNW 6000

I run a program called MalWare Bytes which is free (google it) and pretty easy to use.  I also keep a backup copy of that program on a flash drive as some of the mw I've seen disables anything on the system when it arrives. 

I have had good experiences with shutting down, restarting and running in "safe mode" and running the MalWare Bytes from there.  It's caught infections that were launched and removed their tracking cookies too...but I'm comfortable taking that (and registry editing too) steps.

Has anyone contacted the owner of that site?

Malwarebytes is a very good stand alone tool to remove spyware/mareware.

A common misconception is that you need to pay for computer protection. 

However, there are quite a few good free software programs that you should consider for use.

This is what I use on my computers at home:

Firewall:  Zone Alarm Free Firewall 

http://www.zonealarm.com/security/en-us/anti-virus-spyware-free-download.htm

Anti-Virus: Microsoft Security Essentials  http://www.microsoft.com/security_essentials

Registry Cleaner:  CCleaner  http://www.ccleaner.com

Malware:  Malwarebytes  http://www.malwarebytes.org

Another good free registry cleaner can be found at:  http://www.eusing.com  Eusing will not conflict with CCleaner.

 

  • Member since
    July 2009
  • From: San Francisco East Bay
  • 1,360 posts
Posted by MikeF90 on Friday, March 4, 2011 5:31 PM

I've run Win2K and XP for over ten years and have NEVER had a malware infection. Lucky, maybe. Cautious, definitely!  Some tips not mentioned above:

- use a hardware firewall if you have a high speed internet connection. Software firewalls mainly belong on laptops and those systems forced to use dial up access. Test your firewall using GRC's Shields Up service.

- use Firefox as your primary web browser. The Noscript and Adblock add-ons are updated frequently and add great protection against evolving malware threats. Never, ever use IE6 or older for web surfing!!

- consider using a Linux distribution instead of Windoze, especially if your computer needs are basic - web surfing and email (recommend Ubuntu, Fedora, OpenSUSE). For sensitive applications like online banking, use the distro in 'live' mode which runs directly from CD and doesn't need to touch your hard drive. Computer geeks can install Linux dual boot or in a virtual environment.

- turn off Autorun! This Windows 'feature' deserves several threads alone on computer forums. The idea that Windows will try to run anything inserted into your DVD drive or USB port is insane.

 

  • Member since
    August 2006
  • From: South Dakota
  • 1,592 posts
Posted by Dakguy201 on Saturday, March 5, 2011 3:29 AM

BaltACD

I don't know if anyone else is experiencing similar things.

I picked up the same problem from that site in the last week of February. 

  • Member since
    December 2005
  • From: Cardiff, CA
  • 2,930 posts
Posted by erikem on Saturday, March 5, 2011 12:26 PM

MikeF90

- use Firefox as your primary web browser. The Noscript and Adblock add-ons are updated frequently and add great protection against evolving malware threats. Never, ever use IE6 or older for web surfing!!

Firefox does a good job of blocking the pop-ups on the railpictures website and I haven't bothered to unblock any of the pop-ups. There are also some good add-ons such as Adblocker and NoScript that will further improve security.

The latest version of Internet Explorer has a pop-up blocker as well, but don't have any experience with it.

- consider using a Linux distribution instead of Windoze, especially if your computer needs are basic - web surfing and email (recommend Ubuntu, Fedora, OpenSUSE). For sensitive applications like online banking, use the distro in 'live' mode which runs directly from CD and doesn't need to touch your hard drive. Computer geeks can install Linux dual boot or in a virtual environment.

A even more secure approach would be running Solaris on SPARC (or MacOS or Linux on PowerPC) as anything but Java malware would be incompatible with the processor.

One caution about Linux (or any other UNIX). Getting it set up properly does require a bit of knowledge of how the system works, although many flavors of Linux (e.g. Ubuntu) do have a very straightforward access to security settings. As you pointed out, the "Live CD's" have the advantage of not touching the hard drive.

- Erik

  • Member since
    May 2003
  • From: US
  • 25,279 posts
Posted by BaltACD on Saturday, March 5, 2011 4:14 PM

Mine contracted it's problem on Feb 26

Dakguy201

 BaltACD:

I don't know if anyone else is experiencing similar things.

 

I picked up the same problem from that site in the last week of February. 

Never too old to have a happy childhood!

              

  • Member since
    March 2002
  • 9,265 posts
Posted by edblysard on Saturday, March 5, 2011 6:36 PM

Add one to the list of ruined computer...$200.00 later still waiting for the reformat disc to arrive from the computer company so I can have the entire hard drive wiped clean and reformat it.

The blue screen virus arrived either from RailPictures, (my geek is pretty sure thats where it came from)  or in a chain e-mail, all of which will  now be deleted...from now on, if someone continuies to send me chain e-mail, I will simply block them from my machine.

 

Railpictures has twice infected my machine, once with a "pop up" virus and this time with the blue screen virus, as described in the opening post.

My computer geek told me the same thing, if you think it has happened to you, do not X out, eithr pull the plug, or the alt control delete routine.

If you get it, be prepared to lose all data on your machine.

23 17 46 11

Join our Community!

Our community is FREE to join. To participate you must either login or register for an account.

Search the Community

Newsletter Sign-Up

By signing up you may also receive occasional reader surveys and special offers from Trains magazine.Please view our privacy policy