G35Driver Feedback & Suggestions NO Car Questions! For posting Feedback, Suggestions or Questions regarding G35Driver website ONLY.

Trojan

Old Aug 1, 2010 | 12:36 AM
  #46  
ThePhoenix's Avatar
Registered User
Joined: Apr 2010
Posts: 1,152
Likes: 1
From: Seattle, WA
yea i would recommend when coming to G35Driver.com to come in directly using the

www.g35driver.com/forums

to bypass it
 
Reply
Old Aug 1, 2010 | 01:19 AM
  #47  
bsw845's Avatar
Registered User
Joined: Nov 2007
Posts: 128
Likes: 3
From: NorCal
Had it happen twice at work and once at home, luckily my virus software caught it all three times. Will go directly to the forums page from now on. Here's a screen shot of what my Norton 2010 IS says about the virus...

Any word??

 
Reply
Old Aug 1, 2010 | 04:35 AM
  #48  
Bigtime's Avatar
Registered User
iTrader: (1)
Joined: May 2009
Posts: 702
Likes: 2
From: Where the girls are prettier (562), CA
^ I got that same IP address in a message.

After completing a virus scan I go to G35driver forum home page and all of a sudden Java starts up and I get this message: "unable to access jarfile \\91.188.60.234\public\photo1.jpg"

What's going on here admins?
 
Reply
Old Aug 1, 2010 | 07:13 AM
  #49  
or_G's Avatar
Registered User
iTrader: (13)
Joined: Apr 2010
Posts: 1,003
Likes: 2
From: So Cal
had a trojan blocked at friends comp today too..
 
Reply
Old Aug 1, 2010 | 08:23 AM
  #50  
Robb M.'s Avatar
IB Staff
15 Year Member
Joined: Feb 2010
Posts: 660
Likes: 41
From: Barrie, ON
hey bsw845, can you please post a larger version of your screenshot for us.

Thanks!
 
Reply
Old Aug 1, 2010 | 08:34 AM
  #51  
Robb M.'s Avatar
IB Staff
15 Year Member
Joined: Feb 2010
Posts: 660
Likes: 41
From: Barrie, ON
Thanks for your reports everyone. I don't profess to know wtf is going on, but I definitely think this is getting suspicious. I am re-filing a ticket with tech now.

This is a different report that what has previously been brought up in this thread, this seems somehow more serious/legit.

I would also suggest avoiding the homepage until we can figure this out.

cheers,
robb
 
Reply
Old Aug 1, 2010 | 10:31 AM
  #52  
bsw845's Avatar
Registered User
Joined: Nov 2007
Posts: 128
Likes: 3
From: NorCal
Originally Posted by Robb M.
hey bsw845, can you please post a larger version of your screenshot for us.

Thanks!
Here you go...

 
Reply
Old Aug 1, 2010 | 11:01 AM
  #53  
spoolinupblue's Avatar
Registered User
iTrader: (3)
Joined: Nov 2009
Posts: 291
Likes: 2
From: Houston, TX
I just got it this morning with AVAST on my personal laptop.

I did get a screenshot this time

 
Reply
Old Aug 1, 2010 | 03:56 PM
  #54  
or_G's Avatar
Registered User
iTrader: (13)
Joined: Apr 2010
Posts: 1,003
Likes: 2
From: So Cal
Originally Posted by bsw845
Here you go...


got the same thing..
some java thing..
 
Reply
Old Aug 1, 2010 | 10:27 PM
  #55  
voltaireb's Avatar
Registered User
Joined: Apr 2007
Posts: 11
Likes: 0
wepawet is a good website tool to identify if site is running malicious code. looks like a hidden iframe and redirect is in the code and the hosting g35driver site is vulnerable to remote attacks.

by querying g35driver.com at the wepawet site, some interesting info is discovered, basically a redirect is made to horyq.info website that hosts the malicious and obfuscated java code as mentioned by previous posts.

once the redirect occurs, 2 security vulnerabities are tested against your system and if not patched, the exploits are performed against your computer, basically against Adobe Reader/Acrobat, and Java Web Start:

1. doc.media.newPlayer Use-after-free vulnerability in the Doc.media.newPlayer method in Adobe Reader and Acrobat 8.0 through 9.2 CVE-2009-4324

2. JWS command-line injection Java Web Start Arbitrary command-line injection CVE-2010-0886

I would check with sysadmins to make sure the g35driver.com hosting site is using the latest security patches for its forum software. as stated at the bottom of the forum website, it looks like it's running vBulletin version 3.7.4, last i read just by googling "vbulletin 3.7.4 exploit" these versions are full of security holes that allow malicious activity.

????
 
Reply
Old Aug 1, 2010 | 11:50 PM
  #56  
tiguy99's Avatar
Registered User
iTrader: (2)
Joined: Feb 2007
Posts: 4,315
Likes: 30
From: Chicago
Originally Posted by or_G
got the same thing..
some java thing..
Same thing happened to my girlfriend's laptop...said it blocked a trojan when I logged on this site. WTF?
 
Reply
Old Aug 2, 2010 | 04:14 AM
  #57  
or_G's Avatar
Registered User
iTrader: (13)
Joined: Apr 2010
Posts: 1,003
Likes: 2
From: So Cal
I got virused! Comp is screwed!
 
Reply
Old Aug 2, 2010 | 09:30 AM
  #58  
spoolinupblue's Avatar
Registered User
iTrader: (3)
Joined: Nov 2009
Posts: 291
Likes: 2
From: Houston, TX
Originally Posted by or_G
I got virused! Comp is screwed!
Thats why when you are asked to install something you don't know...you say NO!...lol
 
Reply
Old Aug 2, 2010 | 10:26 AM
  #59  
kvangil's Avatar
Registered User
Joined: Dec 2006
Posts: 1,281
Likes: 1
From: Aurora, IL
Originally Posted by or_G
I got virused! Comp is screwed!
Try to reboot to safe mode and do a Windows Restore to last week or anytime before the infection. Then download/install Malware Bytes' AntiMalware application and run that. It should remove the malware.
 
Reply
Old Aug 2, 2010 | 10:28 AM
  #60  
kvangil's Avatar
Registered User
Joined: Dec 2006
Posts: 1,281
Likes: 1
From: Aurora, IL
Originally Posted by spoolinupblue
Thats why when you are asked to install something you don't know...you say NO!...lol
That's true, but this particular trojan/virus self-installs and does NOT prompt you to install or run/download anything. As soon as you hit the home page, if you do not have an up-to-date anti-malware running, it tries to kick off a Java app and then opens Acrobat or Windows Media Player. It then installs itself. Happens pretty quickly before you can close out IE or Firefox.
 

Last edited by kvangil; Aug 2, 2010 at 11:07 AM.
Reply

Thread Tools
Search this Thread
Rate This Thread
Rate This Thread:
You have already rated this thread Rating: Thread Rating: 0 votes,  average.


All times are GMT -4. The time now is 12:57 PM.