Just became member to inform admins url is infected. | FerrariChat

Just became member to inform admins url is infected.

Discussion in 'New Member Introductions' started by DinoSR8LM, Dec 10, 2010.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
  2. El Wayne

    El Wayne F1 World Champ
    Staff Member Lifetime Rossa Owner

    Aug 1, 2002
    18,069
    San Marino, CA
    Full Name:
    L. Wayne Ausbrooks
    Thanks - the site admin is aware that there might be an issue and is working on a solution.
     
  3. agup48

    agup48 Two Time F1 World Champ

    Apr 15, 2006
    28,633
    Phoenix
    Full Name:
    AG
    Wow, Rosso subbed too!

    Welcome to Ferrarichat! :)
     
  4. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    Thanks for the prompt response L. and thanks for the welcome Ashwin.
     
  5. FarmerDave

    FarmerDave F1 World Champ
    Consultant

    Jul 26, 2004
    15,780
    Full Name:
    IgnoranteWest
    You are doing it right sir! There are folks who have contributed less to this community in years of participation, than you have already done.

    Welcome!
     
  6. ylshih

    ylshih Shogun Assassin
    Honorary Owner

    Mar 21, 2004
    20,405
    Northern CA
    Full Name:
    Yin
    As mentioned we're aware of a possible problem. When you say "that was a quick fix", do you mean you're not seeing it on the site in general? This problem might not be site general, but thread specific. Do you remember if you were looking at a specific thread and which thread it was?
     
  7. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    It was any link to Ferrarichat.com, even alone which redirects to ferrarichat.com/forum. I'm not being denied access anymore by my security.
     
  8. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,368
    Houston, Texas
    Full Name:
    Bubba
    My filter has been going off all week, I thought it was from the click thrus or something.

    My IT guy says "everythings ok, and that's a good looking girl there, on that sailboat".....LOL!
     
  9. ylshih

    ylshih Shogun Assassin
    Honorary Owner

    Mar 21, 2004
    20,405
    Northern CA
    Full Name:
    Yin
    What filter/virus scanner do you use?
     
  10. REMIX

    REMIX Two Time F1 World Champ

    I use NOD32 and nothing is popping up.

    RMX
     
  11. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    63,954
    Southlake, TX
    Full Name:
    Rob Lay
    Sorry, I have very little access right now.

    U subscribed Rossa just to tell us this?

    A Trojan by same name was showing up in about half of Dr. Strangleloves "cards". He fixed those, but old images remain that are infected. They should be harmless as posted attached images.

    That site maybe picked up on those old images, but we're confirming.
     
  12. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    #12 DinoSR8LM, Dec 10, 2010
    Last edited: Dec 10, 2010
    Yes I subscribed so that it would be taken seriously and not ignored as a random post by a guest. I also could not access the site except for by phone and paypal provides a phone number and an email.
     
  13. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    63,954
    Southlake, TX
    Full Name:
    Rob Lay
    Do you work for Kasperky? No one pays $50 to tell a random website they are on a softwares block list. Please explain more.
     
  14. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,368
    Houston, Texas
    Full Name:
    Bubba
    #14 BigTex, Dec 10, 2010
    Last edited: Dec 10, 2010
    I have no idea..:D :D....our server is in Kansas City and my desktop has (thinking) AVG?????

    And I see MalwareBytes on my desktop also...
     
  15. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    Thanks for the welcome, are you for real. The site is far from random, Ferrari is quite specific and for the record I don't work for Kasperky or Kapersky. I could ask you why you have such little access when you're aware of a trojan hackers use? Especially on a forum set up for Ferrari owners. I was hoping the little $50 donation would help, but now I'd rather have a refund.
     
  16. rob lay

    rob lay Administrator
    Staff Member Admin Miami 2018 Owner Social Subscribed

    Dec 1, 2000
    63,954
    Southlake, TX
    Full Name:
    Rob Lay
    Yep, I was right.
     
  17. thecarreaper

    thecarreaper F1 World Champ
    Silver Subscribed

    Sep 30, 2003
    18,054
    Savannah
    Avast, Malwarebytes, and Superantispyware all come up clean. But thank you for the warning.
     
  18. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    #18 DinoSR8LM, Dec 10, 2010
    Last edited: Dec 10, 2010
    You're welcome. I also have malwarebytes and didn't detect it. Try this http://usa.kaspersky.com/downloads/free-home-trials/internet-security

    This is what I got:

    Kaspersky
    Internet Security 2011
    Access denied
    The requested URL cannot be provided

    The requested object at the URL:

    http://www.ferrarichat.com/forum/
    showthread.php?t=302489

    Threat detected:

    object is infected by HEUR:Trojan.Script.Iframer

    more info: http://www.securelist.com/en/descriptions/HEUR:Trojan.Script.Iframer
     
  19. mseals

    mseals Two Time F1 World Champ
    Lifetime Rossa Owner

    Sep 9, 2007
    24,468
    Kuwait
    Full Name:
    Mike Seals
    So, apparently, it the malware was located in this thread:

    http://www.ferrarichat.com/forum/showthread.php?t=302489

    in the Lambo section...

    Mike
     
  20. DinoSR8LM

    DinoSR8LM Karting

    Dec 3, 2010
    166
    Actually that was just the last link I tried before copying, I was denied access for any link on the site up until I signed in this morning.
     
  21. ylshih

    ylshih Shogun Assassin
    Honorary Owner

    Mar 21, 2004
    20,405
    Northern CA
    Full Name:
    Yin
    OK, this may be a bit technical, but hopefully it will explain what we think is happening and explain what to look for.

    It turns out that about 50% of the cards that DrS played up through September 2010 were infected with a JPG trojan exploit that was prevalent in the 2004-2005 time frame. This exploit was patched by Microsoft fairly quickly so only very old AND unpatched Windows XP installs would have been vulnerable. The actual scenario, an infected JPG viewed in a web browser, was apparently not actually a vulnerability as no virus scanners detected this as a problem up until August 2010.

    As of August 2010, a new exploit circulated and had been identified. This is called an IFRAME exploit and it involves putting trojan code in Iframes (executable HTML scripts) embedded in JPG or GIF files. As we've been able to reconstruct it, it appears that first MSE (Microsoft Security Essentials) and now Kaspersky find the combination of JPG file and IFRAME script to match the new exploit, even though the trojan embedded in the cards was designed for the old exploit.

    This scenario was first analyzed for an MSE detection seen in September 2010 and as soon as DrS was advised of the problem, he cleaned up all his cards. However, the JPG's that he posted in threads up to that point were still present. Since 1) vBulletin doesn't store attachments by filename, it seemed impossible to scrub the old threads, 2) the only alert was generated by MSE up to then, and 3) it seemed that the detection of the exploit was actually a false positive; we left it at as a problem that would expire on its own as old threads don't get bumped that often.

    So, if an alert occurs as a result of trying to view an old thread/post (prior to September 2010) that contains a DrS card, then it falls into what we think is a false positive bucket. However, if an alert occurs under a scenario that doesn't match what has been described, then it may be another problem (perhaps a true Iframe exploit that got uploaded to the site). This would require further investigation and should be reported.
     
  22. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,368
    Houston, Texas
    Full Name:
    Bubba
    Hi gang!!

    Boy, (this is an old HP running XP..)

    My AVG vault was full that was part of my trouble..I found:

    Trojan horses: Downloader.Generic_C.BRX
    Hiloti.BY
    Hiloti.CA
    Generic20.YST also Generic18.AZBB and ABME and Generic2.ABZP and Generic4.AXMN
    Those guys are busy....LOL!
    Java/Classloader

    Malwarebytes called Generic2.ABZP "Adware"

    I ran both of those and killed it all....I think....am I going to live now???
     
  23. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,368
    Houston, Texas
    Full Name:
    Bubba
    #23 BigTex, Dec 10, 2010
    Last edited: Dec 10, 2010
    My bright young man I have managing all my software licenses explained it's all those cute pictures people send you in email that has a lot of that stuff hidden in them.

    I guess working like Dr. S cards.

    Thanks.

    Reading up on Trojan.Hiloti now, that sounds like a bad thing to have.....:D :D :D
    The reason I don't do any on line banking!!
     
  24. Sandy Eggo

    Sandy Eggo F1 Rookie
    BANNED

    Jun 4, 2009
    3,636
    Encinitas, CA
    Full Name:
    Rick
    LOL...stop surfing the pr0n sites. :D
     
  25. BigTex

    BigTex Seven Time F1 World Champ
    Owner Rossa Subscribed

    Dec 6, 2002
    79,368
    Houston, Texas
    Full Name:
    Bubba
    That's the thing......this is a work machine and I'm sure anyone that wants to can 'check in" on the traffic in Kansas City........

    So I just stay here for the most part. :D :D :D

    I read Slate for Doonesbury, check the surfcams at surfhouse1967, and the weather radar but that's about it.......
     

Share This Page