G35Driver Feedback & Suggestions NO Car Questions! For posting Feedback, Suggestions or Questions regarding G35Driver website ONLY.

Trojan

Thread Tools
 
Search this Thread
 
Rate Thread
 
  #46  
Old 08-01-2010, 12:36 AM
ThePhoenix's Avatar
Registered User
Join Date: Apr 2010
Location: Seattle, WA
Posts: 1,152
Likes: 0
Received 1 Like on 1 Post
yea i would recommend when coming to G35Driver.com to come in directly using the

www.g35driver.com/forums

to bypass it
 
  #47  
Old 08-01-2010, 01:19 AM
bsw845's Avatar
Registered User
Join Date: Nov 2007
Location: NorCal
Posts: 128
Received 3 Likes on 3 Posts
Had it happen twice at work and once at home, luckily my virus software caught it all three times. Will go directly to the forums page from now on. Here's a screen shot of what my Norton 2010 IS says about the virus...

Any word??

 
  #48  
Old 08-01-2010, 04:35 AM
Bigtime's Avatar
Registered User
iTrader: (1)
Join Date: May 2009
Location: Where the girls are prettier (562), CA
Posts: 702
Received 2 Likes on 2 Posts
^ I got that same IP address in a message.

After completing a virus scan I go to G35driver forum home page and all of a sudden Java starts up and I get this message: "unable to access jarfile \\91.188.60.234\public\photo1.jpg"

What's going on here admins?
 
  #49  
Old 08-01-2010, 07:13 AM
or_G's Avatar
Registered User
iTrader: (13)
Join Date: Apr 2010
Location: So Cal
Posts: 1,003
Likes: 0
Received 2 Likes on 2 Posts
had a trojan blocked at friends comp today too..
 
  #50  
Old 08-01-2010, 08:23 AM
Robb M.'s Avatar
IB Staff
Join Date: Feb 2010
Location: Barrie, ON
Posts: 658
Received 41 Likes on 28 Posts
hey bsw845, can you please post a larger version of your screenshot for us.

Thanks!
 
  #51  
Old 08-01-2010, 08:34 AM
Robb M.'s Avatar
IB Staff
Join Date: Feb 2010
Location: Barrie, ON
Posts: 658
Received 41 Likes on 28 Posts
Thanks for your reports everyone. I don't profess to know wtf is going on, but I definitely think this is getting suspicious. I am re-filing a ticket with tech now.

This is a different report that what has previously been brought up in this thread, this seems somehow more serious/legit.

I would also suggest avoiding the homepage until we can figure this out.

cheers,
robb
 
  #52  
Old 08-01-2010, 10:31 AM
bsw845's Avatar
Registered User
Join Date: Nov 2007
Location: NorCal
Posts: 128
Received 3 Likes on 3 Posts
Originally Posted by Robb M.
hey bsw845, can you please post a larger version of your screenshot for us.

Thanks!
Here you go...

 
  #53  
Old 08-01-2010, 11:01 AM
spoolinupblue's Avatar
Registered User
iTrader: (3)
Join Date: Nov 2009
Location: Houston, TX
Posts: 291
Likes: 0
Received 2 Likes on 2 Posts
I just got it this morning with AVAST on my personal laptop.

I did get a screenshot this time

 
  #54  
Old 08-01-2010, 03:56 PM
or_G's Avatar
Registered User
iTrader: (13)
Join Date: Apr 2010
Location: So Cal
Posts: 1,003
Likes: 0
Received 2 Likes on 2 Posts
Originally Posted by bsw845
Here you go...


got the same thing..
some java thing..
 
  #55  
Old 08-01-2010, 10:27 PM
voltaireb's Avatar
Registered User
Join Date: Apr 2007
Posts: 11
Likes: 0
Received 0 Likes on 0 Posts
wepawet is a good website tool to identify if site is running malicious code. looks like a hidden iframe and redirect is in the code and the hosting g35driver site is vulnerable to remote attacks.

by querying g35driver.com at the wepawet site, some interesting info is discovered, basically a redirect is made to horyq.info website that hosts the malicious and obfuscated java code as mentioned by previous posts.

once the redirect occurs, 2 security vulnerabities are tested against your system and if not patched, the exploits are performed against your computer, basically against Adobe Reader/Acrobat, and Java Web Start:

1. doc.media.newPlayer Use-after-free vulnerability in the Doc.media.newPlayer method in Adobe Reader and Acrobat 8.0 through 9.2 CVE-2009-4324

2. JWS command-line injection Java Web Start Arbitrary command-line injection CVE-2010-0886

I would check with sysadmins to make sure the g35driver.com hosting site is using the latest security patches for its forum software. as stated at the bottom of the forum website, it looks like it's running vBulletin version 3.7.4, last i read just by googling "vbulletin 3.7.4 exploit" these versions are full of security holes that allow malicious activity.

????
 
  #56  
Old 08-01-2010, 11:50 PM
tiguy99's Avatar
Registered User
iTrader: (2)
Join Date: Feb 2007
Location: Chicago
Posts: 4,315
Received 30 Likes on 25 Posts
Originally Posted by or_G
got the same thing..
some java thing..
Same thing happened to my girlfriend's laptop...said it blocked a trojan when I logged on this site. WTF?
 
  #57  
Old 08-02-2010, 04:14 AM
or_G's Avatar
Registered User
iTrader: (13)
Join Date: Apr 2010
Location: So Cal
Posts: 1,003
Likes: 0
Received 2 Likes on 2 Posts
I got virused! Comp is screwed!
 
  #58  
Old 08-02-2010, 09:30 AM
spoolinupblue's Avatar
Registered User
iTrader: (3)
Join Date: Nov 2009
Location: Houston, TX
Posts: 291
Likes: 0
Received 2 Likes on 2 Posts
Originally Posted by or_G
I got virused! Comp is screwed!
Thats why when you are asked to install something you don't know...you say NO!...lol
 
  #59  
Old 08-02-2010, 10:26 AM
kvangil's Avatar
Registered User
Join Date: Dec 2006
Location: Aurora, IL
Posts: 1,281
Likes: 0
Received 1 Like on 1 Post
Originally Posted by or_G
I got virused! Comp is screwed!
Try to reboot to safe mode and do a Windows Restore to last week or anytime before the infection. Then download/install Malware Bytes' AntiMalware application and run that. It should remove the malware.
 
  #60  
Old 08-02-2010, 10:28 AM
kvangil's Avatar
Registered User
Join Date: Dec 2006
Location: Aurora, IL
Posts: 1,281
Likes: 0
Received 1 Like on 1 Post
Originally Posted by spoolinupblue
Thats why when you are asked to install something you don't know...you say NO!...lol
That's true, but this particular trojan/virus self-installs and does NOT prompt you to install or run/download anything. As soon as you hit the home page, if you do not have an up-to-date anti-malware running, it tries to kick off a Java app and then opens Acrobat or Windows Media Player. It then installs itself. Happens pretty quickly before you can close out IE or Firefox.
 

Last edited by kvangil; 08-02-2010 at 11:07 AM.


You have already rated this thread Rating: Thread Rating: 0 votes,  average.

Quick Reply: Trojan



All times are GMT -4. The time now is 01:47 AM.