Ship Simulator

English forum => Small talk => Topic started by: grampsmorris on December 24, 2009, 21:08:36

Title: Trojan Horse reported by Avast antivirus today
Post by: grampsmorris on December 24, 2009, 21:08:36
The following warning showed up this morning after Avast updated definitions. Do we have a problem or is this a false warning?

Thanks

Gordon
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 26, 2009, 00:21:52
[UPDATE]

I am changing this response. This mornong, Norton also started to warn about a problem.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 26, 2009, 00:27:57
Hopefully I don't get shunned for asking this, but I'm just curious:

Why has their software gotten less reliable and what might lead them to think that this is a dangerous site?

EDIT:

Also Terry, you might find this interesting: When I was having problems getting on the forum earlier this year, AVG Safe Search, and WOT both said this was a bad website, BUT I'm positive they were talking about the website I was being redirected to, as it appears. Just thought I'd give my two cents. :)
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 26, 2009, 00:37:40
I am changing this response. This morning, Norton also started to warn about a problem.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: matt5674 on December 26, 2009, 02:04:35
That same error came up every time I wanted to go to the home page of shipsim.com. The rest of the pages at the website are fine but not the Home. I think I will uninstall Avast to keep the connection fine, without false Viruses. Just a thought
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Master Captain on December 26, 2009, 02:06:33
probally no worries, no warnings from norton for me
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Kapn Jonah on December 26, 2009, 02:07:01
Nothing from Trend Micro or McAfee
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: matt5674 on December 26, 2009, 02:15:04
Must be Avast! only.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: v.h94 on December 26, 2009, 02:19:54
AVG say the same as Avast.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 10:37:36
Norton also say it and if i go to www.shipsim.com  then my explorer crash.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 26, 2009, 11:41:36
I have changed response. This morning, Norton also started to warn about a problem.

I strongly suggest that you do not currently go to the www{dot}shipsim{dot}com page, until we know what is happening.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: mvsmith on December 26, 2009, 15:32:21
When I tried shipsim.com a few hours ago, I got a yellow-band ActiveX warning that the site was trying to run Microsoft Data Collection Control. I immediately exited IE.
I’ve gone there a few times since, without getting the warning.
Strange.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 15:37:14
maybe the trojaner are installed on you pc, if i was you i will run a complete virus check on the pc and norton found a virus
when i did that i got the warning again, so do not allow the  ActiveX to run
Tore
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Captain Best on December 26, 2009, 16:08:55
I highly recommend to not use norton.

I've done several test with Norton and Avast Free Version.

and i've scanned some files on my old computer. and Avast detected Trojan while Norton said it were cleaned..

A cool program(a scan program) Malware Bytes free is a scanning program that scans through your computer and finds any infected files ;)

srry for off topic :D
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Shipaddict on December 26, 2009, 18:34:26
This has also happened to me, only today not before.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: J3nsen on December 26, 2009, 18:36:45
NOD32 Ver. 4 (last updated 26.12.2009)

Also finds Trojan.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: laganviking on December 26, 2009, 18:47:15
I have also received a spyware virus today. Not sure if it was from the shipsim website, but it was causing my computer to run slow and then freeze.

Best advice - start in safe mode - control panel - add/remove programmes and then remove it - mine was a programme called relevant information.

Also, task mgr and under processes just to make sure its not running!
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 26, 2009, 19:37:05
But before you all get into headless chicken mode, bear in mind that it could be one of the adverts in the banners that is causing the problem. That might be why it only shows up from time to time.

And it might still be a false positive.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: danielschunk on December 26, 2009, 19:58:30
Hello @ *,

Kaspersky Anti Virus alerts me, too:

Code: [Select]
26.12.2009 19:48:31 Gefunden: Trojan-Clicker.JS.Iframe.db Firefox http://met-art-com.koubei.com.mpnrs-com.theatticsale.ru:8080/mihanblog.com/mihanblog.com/baixing.com/google.com/travian.ae/
Is it critical?

Bye, Daniel
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: grampsmorris on December 26, 2009, 20:19:15
Thanks Terry and all of you folks. I feel better that it is not just me having the problem. I will not stay on the site for long and will check back from time to time. I hope we can get this resolved soon as I will miss the site.

Gordon
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 26, 2009, 20:20:19
Hello @ *,

Kaspersky Anti Virus alerts me, too:

Code: [Select]
26.12.2009 19:48:31 Gefunden: Trojan-Clicker.JS.Iframe.db Firefox http://met-art-com.koubei.com.mpnrs-com.theatticsale.ru:8080/mihanblog.com/mihanblog.com/baixing.com/google.com/travian.ae/
Is it critical?

Bye, Daniel
Why are you going there? To see if you can catch something? How daft...  :doh:
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Minime on December 26, 2009, 20:38:52
so terry, if I have all the ads blocked, with adblock, it's less likely that I'll see this virus?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 20:42:36
so terry, if I have all the ads blocked, with adblock, it's less likely that I'll see this virus?

well DO NOT GO TO THE SHIPSIM MAINSITE befor all are safety and checked

Terry are on it and V-step know about it so be safe and smart, kip out of the site
Tore
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Minime on December 26, 2009, 20:44:34
haven't been there for a couple of days, wouldn't dream of going there now, a virus is the last thing I want to deal with today.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: gibby12 on December 26, 2009, 20:47:16
i have the mainsite as my homepage when i got to the enternet i better change it. and last night right before i exited out of ship sim my pc said the homepage had a trojan in it.


P.S i have AVG  
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 20:48:36
haven't been there for a couple of days, wouldn't dream of going there now, a virus is the last thing I want to deal with today.

batter to be smart yes  :2thumbs:
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 20:49:22
i have the mainsite as my homepage when i got to the enternet i better change it. and last night right before i exited out of ship sim my pc said the homepage had a trojan in it.


P.S i have AVG  

change it to the forum site then or something else
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: gibby12 on December 26, 2009, 20:50:22
i tried to change it to the forum site bu it takes me straight to the home site :-\
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Minime on December 26, 2009, 20:56:28
i tried to change it to the forum site bu it takes me straight to the home site :-\
just change it to google.com, that should be safe, or any other site.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 20:56:45
go to the front page of the forum
click on the homepage house on the menu line and those the add or change the home page, those add this as the only homepage and then it fixed
Tore
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: gibby12 on December 26, 2009, 20:58:58
k ill give it it try and remember i have vista
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 21:03:28
k ill give it it try and remember i have vista
its the same on IE 6 7 and 8 for all os wp, vista and win 7
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: gibby12 on December 26, 2009, 21:06:15
its the same on IE 6 7 and 8 for all os wp, vista and win 7
i got it thx tore  :thumbs:
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TJK on December 26, 2009, 21:07:19
i got it thx tore  :thumbs:

my pleasure my friend
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Captain Cadet on December 27, 2009, 12:43:26
The site may have been edited with a other computer and it may had put a vies in and it took a wire for it to be remove.
or someone had open up a e male and went they were editing the site and may have had a vires.
the list is long.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Aad The Pirate on December 27, 2009, 14:33:33
Ahoy to all,
There's something strange happening.
When I go to the shipsim homepage by using my bookmarks or when I enter the address directly into my browsers address line no strange behaviour at all.
Only when I try to reach the site from a hotlink in this forum I got a virus warning the moment the Shipsim homepage closes (see attachment)
Best regards
Aad

BTW, the hotlink in the preview was for testing only
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 27, 2009, 20:25:07
having just looked at the source 'code' for the homepage, there isn't any references to any third party sites except youtube.

Is it possible to embed nasties in a video?

Other than that the only references are on vsteps server. I can't see anything to get upset about. That said,  this is my opinion only and not defacto.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 27, 2009, 21:09:34
having just looked at the source 'code' for the homepage, there isn't any references to any third party sites except youtube.

Is it possible to embed nasties in a video?

Other than that the only references are on vsteps server. I can't see anything to get upset about. That said,  this is my opinion only and not defacto.
Thank you for doing that Stuart, except something I might add:

VSTEP Shipsim(dot)com uses PHP, which, is NOT visible when looking at the source code. For example, this script, written in PHP:

<?php
echo "Hello everyone who reads this"
?>

When you look at the source code, will only appear as:

Hello everyone who reads this

Which is the same with almost all PHP tags. For all we know, there is much in there we don't know about.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 27, 2009, 21:18:22
So??? it just means it is server side processing rather than client side.

It is irrelevant what is going on internally in the server- only its output is relevant. And I can see nothing dodgy in it.

There is also talk of third party adverts on the homepage- can you see any, as I can't....?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 27, 2009, 21:39:58
If someone was able to edit the original Index.php who knows what's happening.

I don't see any either, this is very confusing. If I get the chance I could run Windows in a virtual machine on Linux and see if it installs any viruses...Maybe
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 27, 2009, 21:50:20
But the output is benign. What you see on the screen is what is received from the server; if there were any nasties on the server it would manifest itself in the apparent static html
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 27, 2009, 21:57:34
I'd suggest that it is best to stop trying to second guess. For now, follow my advice and don't go to that page.

I find it absolutely astonishing that so many people are "going for a look", having been told very clearly that there might be a problem.

Sheesh....

PS Nothing wrong with any of the Super Packs. I've downloaded and checked each and every one of them.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 27, 2009, 22:06:09
As I have already said all that needs to be said here, i.e. "Don't go to that page until we know what is going on", I will lock this thread.

Any further threads on this subject will be deleted.

Thanks.

Please note the words in the posting guidelines about what is acceptable in the Technical Support area.
http://80.95.161.114/shipsim/forum/index.php/topic,11578.0.html

I will be enforcing that from now onwards, as people are finding it hard to find facts amongst the chatter these days.

Thanks.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 27, 2009, 23:25:15
The problem on www.shipsim.com has now been fixed and you should no longer receive the warnings from your antivirus program.

Sorry for the disruption.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 27, 2009, 23:26:19
Thanks to whoever fixed it! ;D

Terry, are you allowed to tell us what the actual problem was?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: --tractorman-- on December 27, 2009, 23:26:32
What was the problem? Just out of interest..

Edit, damn you firestar :P
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 27, 2009, 23:48:13
Hmm... For those of us who have seen the page and possibly have downloaded something sinister, it would not be unreasonable to be told what that might be...
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: grampsmorris on December 28, 2009, 03:03:53
Thanks Terry for all the help. I'm sorry it stirred up such a hornets nest, but glad it has been fixed.

Keep the missions coming please.

Gordon
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Jayshum on December 28, 2009, 03:17:53
Out of curiosity, how long was the site infected? My PC has recently been blue-screening, and won't stay on for more than 10 minutes before freezing. I've been trying my hardest to get it working, to no avail. Just wondering if this could be related (as it's only happened very recently)?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 28, 2009, 03:20:12
My car wouldn't start this morning and my toaster burned my breakfast. could it be related?  ;D


Jayshun, sorry. I'm *not* extracting the urine out of you...

I tried to find out earlier on what was wrong- as I also have concerns about my laptop after visiting the site. But like Superman, Terry comes in, saves the world and hops it without so much as a by your leave.  ;)
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 28, 2009, 03:50:09
I have other things to do in my life.... Such as some research on the nasty that was involved.

FYI: (1) The site was not infected. One page only was affected, that being the main page at www.shipsim.com, which I told people repeatedly to not visit.

(2) The page had embedded code in it, as I stated earlier. It tried to get the "Fragus downloader" trojan installed. But if you had either updatedWindows in the past 6 weeks or else got any of the Antivirus programs installed (Norton, MacAfee, Kapersky, Panda, etc etc etc) they would have caught this straight away, provided it had been updated in the past 8 weeks or so.

It might have tried to install an ActiveX control instead (see below).

If you for some strange reason don't have antivirus installed, the Tojan would then download any of hundreds of nasties.

The first one would probably have been an ActiveX that permits someone else to remotely control your PC. But your A/V should have stopped that. In fact, so far as I can see, the default settings in Internet Explorer would have prevented that or at lleast asked your permission to proceed with the installation of the ActiveX control.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 28, 2009, 03:55:34
Thanks Doc.

Any ideas at current, how it got there?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Jayshum on December 28, 2009, 10:29:05
Stuart, if you've gone without a PC for any length of time, one that you you work on for atleast 5 hours everyday, as well as talk and stay in touch with friends on (due to having very little money), you'd know that your sense of humour would right now seem a little anger-inducing. As you're probably a child, I'll pass on that and move on!

Terry, sorry if I came across in any other manner than inquisitive. As I said, 2 weeks without my computer is driving me nuts, and affecting my work. To be honest, this post offered me a slight glimmer of hope. So with this, I go back to 'no shipsim, occasional visit to boring forum' mode.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Kapn Jonah on December 28, 2009, 18:33:27
Stuart?! A Child!? Your nuts Jayshum!  :o :o :doh: :doh:
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 28, 2009, 18:49:52
Terry, sorry if I came across in any other manner than inquisitive. As I said, 2 weeks without my computer is driving me nuts, and affecting my work. To be honest, this post offered me a slight glimmer of hope. So with this, I go back to 'no shipsim, occasional visit to boring forum' mode.

No, you didn't do that. Not sure why you thought you did. I was grumping at Stu, who assumes that merely because I post here 24/7 I must have no other life...  :evil:

But, have you checked that all the fans are working in your PC? It really does sound like a blocked airway or fan failure. If you start the PC and go to the BIOS settings (usually either DEL or F1 will get you there just after it starts), you should see a PC Health screen (or some such title). Take a look at the temparatures and see if any of them is rising by much.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on December 28, 2009, 23:33:39
Stuart, if you've gone without a PC for any length of time, one that you you work on for atleast 5 hours everyday, as well as talk and stay in touch with friends on (due to having very little money), you'd know that your sense of humour would right now seem a little anger-inducing. As you're probably a child, I'll pass on that and move on!
Damn. I've been found out.

Stuart?! A Child!? Your nuts Jayshum!  :o :o :doh: :doh:
Thank you Capt. J.


No, you didn't do that. Not sure why you thought you did. I was grumping at Stu, who assumes that merely because I post here 24/7 I must have no other life...  :evil:
Oh I AM sorry, Dr. T. I thought you had thicker skin than that... I thought the ability to recognise comments for their humorous intent was something you inherited from your great grandfather, eh M'Lord.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Wave Music on December 28, 2009, 23:51:06
Damn. I've been found out.

I wonder then how old I am?  :o
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 29, 2009, 00:33:48
Wave Music doesn't follow ages in the same numeric way everyone else does. He uses a different system on his planet, based more on location than time. ;D

It's a mess to understand, don't even ask Wave Music, I doubt he can explain it in a way for you guys to understand without your brains imploding immediately. Also, don't ask Wave Music for a picture of himself or his planet. It's a disaster... :o
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on December 31, 2009, 10:19:19
Oh I AM sorry, Dr. T. I thought you had thicker skin than that... I thought the ability to recognise comments for their humorous intent was something you inherited from your great grandfather, eh M'Lord.

Indeed I do, serf. That's why my comment had the usual wicked grin icon by it. Still, I forgive you. You may arise from your prostrate position.

Hey, everyone! Grab the boards. The serf's up. YAY!
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Wave Music on December 31, 2009, 11:40:28
Wave Music doesn't follow ages in the same numeric way everyone else does. He uses a different system on his planet, based more on location than time. ;D

It's a mess to understand, don't even ask Wave Music, I doubt he can explain it in a way for you guys to understand without your brains imploding immediately. Also, don't ask Wave Music for a picture of himself or his planet. It's a disaster... :o

I thought that joke exhausted some months ago.  Oh well...
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on December 31, 2009, 16:31:44
Hard to joke about something like that. O_-
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Wave Music on December 31, 2009, 16:55:46
Actually, yes.  :-X
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on January 01, 2010, 14:48:39
Has ANYONE heard any more on this? >:(


EDIT: Having just purchased a new version of Norton (I know, I know... there are better products- like 'nothing')

The wikipedia entry for Norton is a little worrying in terms of its service, (I spent considerable time today trawling through its help forum looking for help- lots of complaints there about service).

Most worrying is the section on how they 'ignore' certain spytools from the FBI... Does that also meen MI6, MOSSAD, DGSE, FSB etc as well? How about the man in the moon?

Having just spent £50 on this programme that even its own website firewall test has reported as flawed, I'm not best pleased. I have written- in my usual, subtle way- to their customer services. I await their response with baited breath (if a hacker hasn't got into their pop server and deleted it  ::))

I know avs have been discussed before, but I'd be interested to know anyone elses opinion on this...


EDIT: Oh and theres the c: [stroke] fauxviris [stroke] carny ride [dot] exe   issue which it appears Norton2007 doesn't like as it may well crash just while it is searching for it... or it might be that this is a phantom used by norton for self testing... no one at norton will bother telling anyone- and this issue was first raised 2 years ago! it is equally possible that norton is being tricked into stopping checking your drive when it reaches this phantom- and simply tells you all is well.

I've even tried to fake a virus to see if it will spot it, but doesn't- zonelabs did (warning that some aspects of it were dodgy, but recognised it as probably clean)
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: RMS Canada on January 08, 2010, 02:52:54
Is it safe to go back on the Ship Sim '08 website now?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: J3nsen on January 08, 2010, 03:17:03
Yes, its safe. The problem is solved and fixed  :blush:
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on January 08, 2010, 13:03:58
Yes, its safe. The problem is solved and fixed  :blush:

It is a bit of a shame that no one ever explained what it was. I don't normally openly criticise Vstep but on this occasion I will.

By not providing all the information they had on it, it made it harder for anyone to confirm whether or not they were infected and find info on eradication. Not impressed on that one and I shall be staying clear of their main website- including the online shop- until Vstep issues a formal notice on it.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: TerryRussell on January 08, 2010, 14:35:58
And yet I thought I had explained it quite clearly at the top of this very page.

http://80.95.161.114/shipsim/forum/index.php/topic,17042.msg228827.html#msg228827
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on January 08, 2010, 14:44:46
Sorry Terry. No offence, but I actually meant VSTEP. As good with computers as you undoubtedly are, something that poses a threat to customers should not be responded to by a volunteer.

Also, I would like to know what steps have been taken to ensure that the site is now safe to use- especially when the online shop is concerned... debit cards, personal details etc.

The silence from VSTEP has been deafening.

I don't think it is acceptable for any online company to just say "if your a/v is working then you are ok..."
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: RMS Canada on January 08, 2010, 23:01:29
Yes, its safe. The problem is solved and fixed  :blush:

Okay then, just checking, thanks!
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on January 09, 2010, 00:22:08
NB Just to clarify, my above post was not intending to criticise any of the goderation team.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Firestar on January 30, 2010, 20:30:02
nice that shipyard link alerts my kaspersky with an trojan XD
Does this mean there's another problem?
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Stuart2007 on January 30, 2010, 21:04:33
Maybe yes. Maybe no.


I hope that helps clarify things.
Title: Re: Trojan Horse reported by Avast antivirus today
Post by: Captain Best on January 30, 2010, 21:05:45
There's only one thing to find it out.

Install Norton 2003 and see what's happends  ;D