Trojans in some of the forum discussion topics

Discuss about anything here that doesn't fit in the other categories. Just don't spam.
Post Reply
chessmastery2001
Posts: 7
Joined: Jan 18th, '07, 05:21

Trojans in some of the forum discussion topics

Post by chessmastery2001 » Dec 8th, '08, 02:37

FYI Administrators: Some of the forum topics will download trojans (backdoor, vundo). Upon opening a discussion forum topic the page sends out an signal to another site to download the trojan.

groink
Posts: 2016
Joined: Dec 8th, '03, 03:58
Location: Pearl City, Hawaii
Been thanked: 1 time

Post by groink » Dec 8th, '08, 03:27

It appears to be random - embedded in the advertisements. But yes, it is true that the trojans are there. I just right now received a warning from my security software:

HTTP Acrobat PDF Suspicious File Download
http:/xxx.xxx.xxx.xxx/zzyu298298/pdf.php?id=7655

Removed the IP for security reasons. The IP address is owned by valuepromo.net. The network traffic coming from the IP address matches a signature of a known attack.

--- groink

AkumaX
Global Moderator
Global Moderator
Posts: 634
Joined: Apr 20th, '06, 00:50
Contact:

Post by AkumaX » Dec 8th, '08, 03:56

attempts to open up embbeded pdf file in your browser:

here's what i got:

http://76.74.***.***/zv00108/pdf.php?id=31455&vis=1

search "zv00108" and "pdf" in google for some more info

aliensporebomb
Posts: 34
Joined: Apr 24th, '07, 21:15

I figured as much

Post by aliensporebomb » Dec 8th, '08, 04:23

Looks like drive by downloads being sent by compromised websites.

In most cases it's spammers or the like trying to use your PC as part of a spam
generation network or russian botnet folks trying to assimilate your pc.

I work in I.T. and highly recommend downloading www.malwarebytes.org's application
to rid yourself of this malicious garbage.

chessmastery2001
Posts: 7
Joined: Jan 18th, '07, 05:21

Post by chessmastery2001 » Dec 8th, '08, 08:37

Yar, I'm also in studying in the fields of IT Security. Malwarebytes is a good software, but I recommend adding Spybot Search & Destory + NOD32.

MoerkJ
Administrator
Administrator
Posts: 1315
Joined: Dec 6th, '03, 08:40
Location: Germany

Post by MoerkJ » Jan 9th, '09, 00:14

I'm bringing this up because there seem to be some users who still have these problems. The source of the problem could be a infected or hijacked ad-network server which randomly sends these pdf files or an already virus-infected computer on the user's side.

So, if you have problems like reported above you should first scan your computer for virusses or malware. Second you should disable auto-opening of pdf-files in your browser. Just change your browser application settings for MIME-type "application/pdf" from open with ... to save to file. This way you can decide yourself if you want to accept an incoming pdf file or not.

There have been several discussions about this on the web. But so far I couldn't find out the root of the problem and if it still exists. :|

releanoyed
Posts: 35
Joined: Sep 27th, '06, 04:29
Location: Lawrence Kansas

Google Malware warnings on D-Addicts

Post by releanoyed » Jan 19th, '09, 00:08

This is a first for me, but starting today whenever I try to look at a page on d-addicts.com google spits up a Malware warning. (I'm using the Safari browser)It looks like it may be linked to the banner ads. One of the site it lists as positive for malware is ebannerz.net but that isn't the only page that gets listed as the source of the problem, most that are listed are just jumbles of numbers and letters. Anybody else running into this problem?

User avatar
Keiko1981
Administrator
Administrator
Posts: 7571
Joined: Apr 9th, '06, 11:27
Location: Sweden
Has thanked: 5 times
Been thanked: 82 times
Contact:
Sweden

Post by Keiko1981 » Aug 29th, '09, 14:06

It could be either me or some of the ads at DA.
3 times in 2 days I've gotten a pop-up message (I've never clicked this message - used Alt + F4) saying that I need to scan my computer it take. If I'm not fast enough it automatically takes me to a page where you see what ones HDs, CD/DVD reader.
The website's address is the following:

Code: Select all

http://live-virus-scanner7.com
When this happened the last time, a few minutes ago I had only Gmail (inbox), a Sweding-English dictionary:

Code: Select all

http://lexin2.nada.kth.se/sve-eng.html
and D-Addicts open.
I got this message as exactly as I was leaving "Torrents" page, and went to the "Home" page.
And yesterday I got it when did log out.
Earlier today I did scan my computer with AVG 8, no viruses found, all warnings were tracking cookies, I deleted them. Yesterday I did also run CCleaner.

aimlesswanderer
Posts: 165
Joined: Feb 4th, '07, 03:53
Location: Sydney, Australia

Post by aimlesswanderer » Aug 30th, '09, 16:44

I had something dodgy install itself a few months ago from here. After scans with half a dozen scanners I found and removed a few dodgy files.

Now I use Chrome, and it sometimes warns me that threats are on certain pages, though none here so far. More security = good.

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest