OKC Talk Virus

It pains me to say this – but a very valuable and popular local message board has been hit with a nasty virus. The virus apparently hit my computer hard – I’m hearing others have had similar experiences. I’m hoping that the operator or a representative of the site will contact us and let us know when this matter is resolved. Until it is, I’m staying off the site. I do want to add this virus apparently hit a lot of message boards and I don’t think this should reflect badly on www.okctalk.com or its operators. Let’s hope they “get well” very soon.
UPDATE: I’ve talked with one of the moderators at OKC Talk and we will coordinate an alert to let folks know when it’s safe again. For now, all of you engage in rational discussion are welcome to chat here. Those of you who are hostile and crazy – go to www.okctalk.com right away and ignore this post (it’s just a conspiracy to silence OKC Talk and you can’t let that happen!)

Categorized under:

Thank you for joining our conversation on OKC Central. We encourage your discussion but ask that you stay within the bounds of our commenting and posting policy.

Comments

Yea, it’s not Pete’s fault. Stuff like this happens. We understand.

I can’t go anywhere near the site, though. I’ve never been so slammed by a computer virus like I did that one.

I got on there yesterday with no problems. I haven’t tried today– nor will I. I have a Mac, though. Hopefully I’m safe from the virus from my contact yesterday but I’ll be staying away at least until I see some of you say it’s okay.

I have a Mac too. They are wonderful. Traversed OKC Talk yesterday and throughout today without incident. After years of service calls ($$$) and anti virus upgrades, I chucked the PC’s and went for it. They cost more up front, but the lack of daily/weekly aggravation completely made up for it.

Go MAC!

What kind of symptoms did you have, Steve? I got slammed with a bunch of spyware today and couldn’t figure out where I got it. It’s been an absolute bastard to get rid of and I’ll probably just end up re-imaging

It literally crashed my computer. The IT folks had to rebuild it today. Glad it was my work laptop, and not personal computer.

If it’s the same one that hit me upon going to OKCTALK, it was ‘scareware’, trying to get you to buy a bogus rogue ‘AV Security Systems’ (or something like that) product w/ false system corruption messages and hijacking one’s ability to quickly get rid of it.
For those w/ same problem as we speak, turn you browser’s to ‘no proxy’, safe boot, download the malwarebytes (excellent free product) install from their site, if you don’t already have it, then run a scan and it will find all the files and reg entries you need to delete. when scan is done, delete the detected files/entries (about 24 or so) and reboot normally, you should be okay, but stay off the site until someone tells us it’s ‘clean’. !

P.S. I use AVAST (free) basic version, and this is the first thing that has got by it in years. several years. To be fair, this more in category of ‘malware’, so the malwarebytes, once installed, a person should run that often.

Macs at work & home, no problems with the site.

It hit me as well (using windows vista). The malware installs a fake security program on your system (“AV Security Suite”) and is extremely malicious. It prevents you from opening other programs (including task manager), opens a barrage of fake security warnings, and uses a proxy server to disable your internet access via internet explorer.

For any of y’all still having trouble, I followed the following instructions and my system is now back to normal: http://www.bleepingcomputer.com/virus-removal/remove-av-security-suite.

Mab’s fix is less involved than the one from bleepingcomputer, but it works. That’s how I ended up defeating it (mostly). I still have issues with clicking links and being misdirected to other sites.

I just posted this to OKCTalk. Frankly, all of you hit with this should be VERY angry…

“OKCTalk is still running the actual vBulletin platform at version 3.7.4. I can understand wanting to maybe wait to upgrade to the vB4 versions, but the version of vBulletin running now is a *year and a half old*. The fact this attack was successful against such an old version, without all the security fixes, should be no surprise. It’s too bad so many had to suffer for lack of basic maintenance. From my understanding of certain posts, Pete is paying good money for maintenance of his forum that he is NOT getting. Whoever is responsible should get these updates and do it immediately. Take the site offline and fix this. Too many without a high-level of security knowledge are getting burned badly.”

I think the world of http://www.okctalk.com and I want to see it back and healthy asap. But after seeing my computer hit HARD (my drive was so damaged by this thing I lost all my personal email folders and some of my other files as well), I really think it would be best for the site to be taken off-line until this matter is fixed. I can not emphasize enough that even if you think this thing is harmless, IT IS NOT. I was participating on the board for a week where we now know it was infected and it took a few days before it took my computer down. Until we are advised that the site is fixed, I urge ALL OF YOU to avoid http://www.okctalk.com. I promise I will be the first one to celebrate it’s return and will announce it here, on Twitter and on Facebook.

I was defending Pete to the hilt on this deal until its become clear that nobody cares enough to even update the members who make up OKCTalk. The last ‘Update’ was one week ago today. The site is listed in Google’s database of attack sites and brings up a warning message. Whether it’s URLJet, Pete, or whoever, the lack of communication is a slap in the face.

The site is still running the old vBulletin software (year and a half old) that made this attack possible and keeps the site (and its visitors) vulnerable to even more dangerous trojans.

Is anyone home at OKCTalk?

Steve, Is anyone currently working to solve the problem at OKCTalk? I really miss checking in there several times a day.

I’m glad there’s at least some kinda chit chat going on here. I’m not getting that message when I type up the website (which I do at work so that is now a NO NO). At least I can still access it from my cell phone. How come virus’ don’t attack them?

Nevermind. I take that back. The warning page came up yesterday and today the link to the still cam jpg file produced a page that said “account suspended”. If the guys who take pictures of the Devon Tower are reading this, please post them at http://www.skyscraperpage.com. Thanks a lot!

I hate to hear about this.
Luck to all who were bit.

Well, the account for OKCtalk was suspended. You can’t allow your site to be used as a carrier of malware, show a cavalier attitude, not aggressively work to stop the attack on your visitors – and not expect that. Pete’s post yesterday that he’s in Idaho at an Ironman competition and “can’t do much from here,” was really surprising.

I wouldn’t be a bit surprised if Pete’s looking to sell the site. He hasn’t really been engaged much at all, has complained about the expenses, allows the site to basically go unmoderated much of the time – and now this. If he did sell, it would most probably be to local ownership this time which I think would be the best thing for OKCTalk. It’s a wonderful site that just needs a little TLC.

the okctalk site is now suspended. my computer wouldnt let me on the site anyway since this virus started. oh well.

It looks like his host has suspended his account. Hopefully he gets things resolved quickly. I hate not being able to visit a site that is in my daily routine.

Noticed this morning when I went to OKCTalk that a message pops up that says the account is suspended & when I do a Google search for the site, it tells me it may harm my computer. I got the fake anti-virus trojan & I’m still trying to clean it off my laptop at home. Love OKCTalk but I’ve been avoiding it at home since getting the virus, just checking from work. Hope they get it resolved soon & back online. Thanks for the updates on this, Steve.

Ok, things are definitely different now… Couldn’t access the site from my cell phone at all this morning. Probably a good thing no matter what. If anyone who has posted here in these comments also posts pics of the Devon Tower at okctalk, or you know someone who posts them, let them know that they can register a username at http://www.skyscraperpage.com and post pics there. There’s also skyscrapercity but I like page much better. There’s users on those pages dying for photo updates. Can’t wait til okctalk is restored. I feel the same void in my stomach as I did when I was quitting smoking. Sad, I know…

I tried to access OKCtalk today and the there is a message that says “Account Suspended”.

Bigray in Ok

\Account Suspended\ is the message I’m getting when trying to access the site. Anyone else getting this?

Mission Accomplished

Yes, since this morning.

Guys, while I agree the site should have been taken down early on, I really think it’s unfair to be critical of Pete. (WHAT I SHOULD HAVE SAID HERE IS ‘UNFAIR TO JUMP TO CONCLUSIONS ABOUT PETE UNTIL WE KNOW THE FULL STORY”). Believe it or not, folks have lives. Pete has spent his own money to keep this forum up with, from what I can see, no personal benefit. He’s spent money, he’s done a lot of work, just to provide this city with a truly independent forum. If you’re unhappy with the lack of updates, etc., be part of the solution, thank Pete for all his work, and offer to send a donation to cover its costs.
Pete, if you read this, just know I APPRECIATE all that you’ve done for your hometown and I remain a fan of your work. I wish you well trying to get the site back up.

Steve, All I can say is – wow. Nobody is holding a gun to Pete’s head to run a forum he bought several years ago and done nothing to monetize. I HAVE tried to be part of the solution. Pete knows I have written him with several ideas. Why not ask me what I’ve done or not done before posting my comments and then basically blasting me? Turning ME into the bad guy.

As a computer security professional, I know that if somebody is not in a position (for whatever reason) to run a site properly, one has no business running it. This isn’t about people having lives, it’s about priorities. If the site is so low on priorities that one can allow his visitors to be compromised…..never mind…..I could go on, but I can tell logic and good security practice isn’t going to win over your telling him that all is fine and you appreciate him so much. Wow.

I just checked my email – nothing from Steve Lackmeyer. Thanks again for getting in touch with me before choosing to kill the messenger and coddle the person who chose to allow site visitors to be infected for a WEEK before he was FORCED off by the hosting company. I was only speaking the truth.

Mike, forgive me if my comments came out as blasting you. That was not my intent. Also, if you’ve tried to contact me, well, please realize that I’ve lost much of my email this past week from my computer crashing – from the OKC Talk virus. I don’t mean at all to be bashing you anymore than I want to blast Pete.
Note that I was out pretty early on pointing out this problem and urging people to stay off the site. I’m trying to be even-handed here, and I’m a bit uncomfortable with an ongoing critique of Pete without him being able to respond. Again, I don’t mean to be bashing you, I personally think your concerns and complaints are well founded. I just want to give Pete the benefit of the doubt before he’s completely raked over the coals.
For all we know, they might have been locked out of the site management system and couldn’t pull the plug. I just don’t know ..
Mike, YOU ARE NOT THE BAD GUY. I’ve always valued your contribution to this site and I really hope this apology will be accepted. (gotta love online communication)

OMG what is going on at okctalk? That site TOTALLY F’ed up my computer. They finally suspended the site, but not after one nasty virus got loose.

What is going on with that site? They finally took the site down, but not until after giving my computer a HORRIBLE virus. What a nightmare.

And to the faux “RonRonnie,” LOL that gave me a good laugh.

Steve, Apology accepted. It’s forgotten. You mentioned how, “you gotta love online communication.” That’s the truth. There is an excellent book out that I just finished this past weekend called, “The Shallows: What the Internet Is Doing To Our Brains” by Nicholas Carr. (He has the blog ‘Rough Type’.) There is an excellent audio interview that pretty much covers the crux of his thinking at The Mercatus Center site at George Mason University. They have an excellent podcast called, “Surprisingly Free.” Nick Carr was a guest about three weeks ago and you can listen online or download to your mp3 player. I can’t recommend it highly enough.
http://surprisinglyfree.com/2010/06/07/nicholas-carr-on-what-the-internet-is-doing-to-our-brains/

He’s no radical or anything, loves the Internet as much as the next guy and appreciates all it has to offer. You knew there was a “but” coming and you’re right. Excellent stuff. It will certainly make you think and if you listen to the interview you’ll see how this fits into your comment about “online communication” and our failure to understand the other in this thread. Which, by the way, I am sorry for the role I played.

Well, I posted a response to Pete right before the whole account was suspended. He was saying that he was unable to do anything was a bunch of crap. I went on to list steps that he should do immediately. Seriously, I don’t think Pete is really that smart. He seems dumb. Hate to say it, but he doesn’t know how to update, upgrade, and keep on top of things. It doesn’t take much. He screwed up. We should rally for the removal of Pete and have someone else to take over. Sell OKCTalk? Nah. Just pass it onto someone who actually know how to do these things. Btw, I found this place on Google.

It’s not going to affect me anymore. I get a message saying my account has been suspended and have no idea why.

So then I go to the skyline cam today and even it is offline. Steve, are you sure this isn’t a Devon conspiracy?! ;)

Roadhawg,

It is not YOUR account that has been suspended. The account is that of the OWNER of the website…

Thunder,

Pete has graduated from two major universities. What have you got under your belt? I’m not judging, I’m just telling you that you need to reserve your frustrations and take a chill pill. There are other sites, although, not as interactive about current happenings here in OKC. Obviously, this one or if it’s the Devon Tower you’re concerned about then go to skyscraperpage or skyscrapercity and register a username and pray that someone is uploading pics there. I’ve got a hole in my stomach too but I’m not blaming anyone. I’ll just be happy when it comes back on line, if ever.

So did everyone who visited okctalk.com in the past few weeks, geta virus on their computer? was their a certain post you clicked to get it?

To be honest, it should not take this long. I have worked full time online for 14+ years and have built, maintained, and moderated many forums including Vbulletin forums. Total time to copy a corrupted forum and have it running normal again somewhere else? 24 hours. A few hours to setup and upload everything plus allowing the new IP to propagate.
Pete SHOULD have the vbulletin files on his personal computer and he SHOULD have the database or at least be able to get it from the host. Once he has those it is not hard to set the forum back up either on a new server or host. It’s been 7+ days now. I take that as a sign that Pete either is lacking the skill, time, or desire to fix it.
Just my personal opinion, but I do have 14 years experience with forums so take it for what you will.
I’m hoping that Pete is hard at work on it and it will be back up soon so that we can all get back to discussing actual OKC matters :)

Pete Brzycki, OkcTalk’s owner, has an OkcTalk facebook page.

According to a post he made there a couple of hours ago (June 30): “Sorry everyone but we had to pull the site down for a couple of days to do some maintenance. Hope to have it back up in a day or two and will post again when things are ready to go.”

I was able to access OKCtalk today. I do not know if the virus is gone, but I did not have any problems with the site like I had before. Hopefully, the problem has been taken care of.

Bigray in Ok

Pete has a message on the board now saying the virus has been removed and he has upgraded the security software. The site came back online today around noon.

Bigray in Ok

It is screwed up this morning — again.

“…something has gone terribly wrong” — That’s the message posted on okctalk now. Bummer!

I want my construct-o-cam back… :-(

Steve is on to something,a nd people should heed the advice.

As he notes, there is no intent to disparage the site owner. Simply accepting the site sadly had/has major issues.

Waiting until there is an all clear, something like a Google clean bill of health after a recheck, visiting a site with known issues doesn’t make sense.

Hey Steve…..I too was hit so hard it literally blew our computer out of the water. But, I support Pete completely. I have soon so many people (me included) use this talk forum for fun and entertainment and then when there is a problem some people go for the throat. I feel confident Pete and his crew will have this thing up and going soon….thanks again Pete if you are reading this….I also lost some of my favorite files off my computer when we had it cleaned off….Thanks Steve for your help and support….

Yes, General, my computer was hit just as bad. Guys, I promise, I’m keeping touch with a moderator at OKC Talk and as soon as it’s truly safe and stable, I’ll let you know.

Jmark, if you’re an Oklahoman subscriber, you can watch live video streaming of the tower construction at http://www.newsok.com/okcskyline

Completely laid waste my laptop. I’ve done system restores, multiple online solutions of varying intricacy, and the computer’s still not the same. Windows Updates no longer starts up on schedule and the AV Security Suite thing may still be there, I don’t know.

My hard drive is probably Swiss cheese by now.

Been there, done that, and yeah, even with an entirely new hard drive, this laptop is not running like it did before. What I can’t figure out is why these hackers can’t turn their attention to the websites belonging to con artists, terrorists, murdering dictators, the people behind every bad reality show on TV, Jay Leno and BP (and by BP, of course I mean “Bad People”)

Steve
That was quite a list (from Leno to Terrorists) and you wonder why Homeland Security “delayed” your latest book? (I kid)

Hopefully all of the threads will still be in tact when everything is back up and running. Would hate to lose the famous South OKC thread! :-) I haven’t noticed anything wrong with my laptop, but then I hadn’t been on OKCTalk in a couple of weeks, so maybe I dodged a bullet.

It will be interesting to see if anyone is able to divine out the culprit offending file…I still have not had any problems of any kind…I use a Windows XP Pro PC for downloading from the OKCTalk website…anyone else have any investigatory ideas on what pedigree of sh** hit the fan?

Today is July 4th, and OKCtalk.com is still down. I have posted a question about this on the OKCtalk.com facebook page, and also I have personally messaged Pete on facebook concerning this issue. It is ridiculous that this is taking too much time, and the forum she be re-uploaded by now. Amen?

I hear ya Jonathan – we paid too much money to have to wait this long for the site to be restored, right? I mean, gosh, how much do we pay each month to Pete to provide this website to the community without ads or pop-ups?
(oh wait – we’ve not paid a dime, have we?)

For what it’s worth, my history website got hacked a couple years ago and it took a month or so before we had it back online. These things take time to fix, especially when it’s a non-profit venture.

BTW–Peter left a message on FB that the site would be back up and running soon…they have cleared the virus…but are having some issues with reloading the updated basic program that runs it…pretty normal computer/internet stuff…just an annoyance…probably will not miss too much over the long 4th weeekend.

We’re baaaaack! The fully cleaned and upgraded site is fully functional.

We’re still working on a few things but the site is safe and stable.

Thanks for your patience… Visit the site for more information.

I got this note from Peter on Facebook. I just thought I’d share it with you.

Leave a comment

(required)

(required)


*