Hello Guest November 25, 2024, 06:14:58 *
Welcome, Guest. Please login or register.

Login with username, password and session length
 
Pages: 1 2 [3]   Go Down

Author Topic: Trojan Horse reported by Avast antivirus today  (Read 20947 times)

TerryRussell

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #50 on: December 28, 2009, 03:50:09 »

I have other things to do in my life.... Such as some research on the nasty that was involved.

FYI: (1) The site was not infected. One page only was affected, that being the main page at www.shipsim.com, which I told people repeatedly to not visit.

(2) The page had embedded code in it, as I stated earlier. It tried to get the "Fragus downloader" trojan installed. But if you had either updatedWindows in the past 6 weeks or else got any of the Antivirus programs installed (Norton, MacAfee, Kapersky, Panda, etc etc etc) they would have caught this straight away, provided it had been updated in the past 8 weeks or so.

It might have tried to install an ActiveX control instead (see below).

If you for some strange reason don't have antivirus installed, the Tojan would then download any of hundreds of nasties.

The first one would probably have been an ActiveX that permits someone else to remotely control your PC. But your A/V should have stopped that. In fact, so far as I can see, the default settings in Internet Explorer would have prevented that or at lleast asked your permission to proceed with the installation of the ActiveX control.
Logged

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #51 on: December 28, 2009, 03:55:34 »

Thanks Doc.

Any ideas at current, how it got there?
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

Jayshum

  • Forum member
  • Posts: 310
Re: Trojan Horse reported by Avast antivirus today
« Reply #52 on: December 28, 2009, 10:29:05 »

Stuart, if you've gone without a PC for any length of time, one that you you work on for atleast 5 hours everyday, as well as talk and stay in touch with friends on (due to having very little money), you'd know that your sense of humour would right now seem a little anger-inducing. As you're probably a child, I'll pass on that and move on!

Terry, sorry if I came across in any other manner than inquisitive. As I said, 2 weeks without my computer is driving me nuts, and affecting my work. To be honest, this post offered me a slight glimmer of hope. So with this, I go back to 'no shipsim, occasional visit to boring forum' mode.
Logged

Kapn Jonah

  • Forum member
  • Posts: 1663
Re: Trojan Horse reported by Avast antivirus today
« Reply #53 on: December 28, 2009, 18:33:27 »

Stuart?! A Child!? Your nuts Jayshum!  :o :o :doh: :doh:
Logged
Regards,
Jonah

TerryRussell

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #54 on: December 28, 2009, 18:49:52 »

Terry, sorry if I came across in any other manner than inquisitive. As I said, 2 weeks without my computer is driving me nuts, and affecting my work. To be honest, this post offered me a slight glimmer of hope. So with this, I go back to 'no shipsim, occasional visit to boring forum' mode.

No, you didn't do that. Not sure why you thought you did. I was grumping at Stu, who assumes that merely because I post here 24/7 I must have no other life...  :evil:

But, have you checked that all the fans are working in your PC? It really does sound like a blocked airway or fan failure. If you start the PC and go to the BIOS settings (usually either DEL or F1 will get you there just after it starts), you should see a PC Health screen (or some such title). Take a look at the temparatures and see if any of them is rising by much.
« Last Edit: December 28, 2009, 18:52:52 by TerryRussell »
Logged

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #55 on: December 28, 2009, 23:33:39 »

Stuart, if you've gone without a PC for any length of time, one that you you work on for atleast 5 hours everyday, as well as talk and stay in touch with friends on (due to having very little money), you'd know that your sense of humour would right now seem a little anger-inducing. As you're probably a child, I'll pass on that and move on!
Damn. I've been found out.

Stuart?! A Child!? Your nuts Jayshum!  :o :o :doh: :doh:
Thank you Capt. J.


No, you didn't do that. Not sure why you thought you did. I was grumping at Stu, who assumes that merely because I post here 24/7 I must have no other life...  :evil:
Oh I AM sorry, Dr. T. I thought you had thicker skin than that... I thought the ability to recognise comments for their humorous intent was something you inherited from your great grandfather, eh M'Lord.
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

Wave Music

  • Forum member
  • Posts: 4767
Re: Trojan Horse reported by Avast antivirus today
« Reply #56 on: December 28, 2009, 23:51:06 »

Damn. I've been found out.

I wonder then how old I am?  :o
Logged
keep it gnarly

Firestar

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #57 on: December 29, 2009, 00:33:48 »

Wave Music doesn't follow ages in the same numeric way everyone else does. He uses a different system on his planet, based more on location than time. ;D

It's a mess to understand, don't even ask Wave Music, I doubt he can explain it in a way for you guys to understand without your brains imploding immediately. Also, don't ask Wave Music for a picture of himself or his planet. It's a disaster... :o
« Last Edit: December 29, 2009, 00:36:14 by Firestar »
Logged

TerryRussell

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #58 on: December 31, 2009, 10:19:19 »

Oh I AM sorry, Dr. T. I thought you had thicker skin than that... I thought the ability to recognise comments for their humorous intent was something you inherited from your great grandfather, eh M'Lord.

Indeed I do, serf. That's why my comment had the usual wicked grin icon by it. Still, I forgive you. You may arise from your prostrate position.

Hey, everyone! Grab the boards. The serf's up. YAY!
Logged

Wave Music

  • Forum member
  • Posts: 4767
Re: Trojan Horse reported by Avast antivirus today
« Reply #59 on: December 31, 2009, 11:40:28 »

Wave Music doesn't follow ages in the same numeric way everyone else does. He uses a different system on his planet, based more on location than time. ;D

It's a mess to understand, don't even ask Wave Music, I doubt he can explain it in a way for you guys to understand without your brains imploding immediately. Also, don't ask Wave Music for a picture of himself or his planet. It's a disaster... :o

I thought that joke exhausted some months ago.  Oh well...
Logged
keep it gnarly

Firestar

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #60 on: December 31, 2009, 16:31:44 »

Hard to joke about something like that. O_-
Logged

Wave Music

  • Forum member
  • Posts: 4767
Re: Trojan Horse reported by Avast antivirus today
« Reply #61 on: December 31, 2009, 16:55:46 »

Actually, yes.  :-X
Logged
keep it gnarly

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #62 on: January 01, 2010, 14:48:39 »

Has ANYONE heard any more on this? >:(


EDIT: Having just purchased a new version of Norton (I know, I know... there are better products- like 'nothing')

The wikipedia entry for Norton is a little worrying in terms of its service, (I spent considerable time today trawling through its help forum looking for help- lots of complaints there about service).

Most worrying is the section on how they 'ignore' certain spytools from the FBI... Does that also meen MI6, MOSSAD, DGSE, FSB etc as well? How about the man in the moon?

Having just spent £50 on this programme that even its own website firewall test has reported as flawed, I'm not best pleased. I have written- in my usual, subtle way- to their customer services. I await their response with baited breath (if a hacker hasn't got into their pop server and deleted it  ::))

I know avs have been discussed before, but I'd be interested to know anyone elses opinion on this...


EDIT: Oh and theres the c: [stroke] fauxviris [stroke] carny ride [dot] exe   issue which it appears Norton2007 doesn't like as it may well crash just while it is searching for it... or it might be that this is a phantom used by norton for self testing... no one at norton will bother telling anyone- and this issue was first raised 2 years ago! it is equally possible that norton is being tricked into stopping checking your drive when it reaches this phantom- and simply tells you all is well.

I've even tried to fake a virus to see if it will spot it, but doesn't- zonelabs did (warning that some aspects of it were dodgy, but recognised it as probably clean)
« Last Edit: January 01, 2010, 23:14:47 by Stuart2007 »
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

RMS Canada

  • Forum member
  • Posts: 897
Re: Trojan Horse reported by Avast antivirus today
« Reply #63 on: January 08, 2010, 02:52:54 »

Is it safe to go back on the Ship Sim '08 website now?
Logged
All ahead full!

J3nsen

  • Forum member
  • Posts: 1751
Re: Trojan Horse reported by Avast antivirus today
« Reply #64 on: January 08, 2010, 03:17:03 »

Yes, its safe. The problem is solved and fixed  :blush:
Logged
http://80.95.161.114/shipsim/forum/index.php/topic,10335.250.html

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #65 on: January 08, 2010, 13:03:58 »

Yes, its safe. The problem is solved and fixed  :blush:

It is a bit of a shame that no one ever explained what it was. I don't normally openly criticise Vstep but on this occasion I will.

By not providing all the information they had on it, it made it harder for anyone to confirm whether or not they were infected and find info on eradication. Not impressed on that one and I shall be staying clear of their main website- including the online shop- until Vstep issues a formal notice on it.
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

TerryRussell

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #66 on: January 08, 2010, 14:35:58 »

And yet I thought I had explained it quite clearly at the top of this very page.

http://80.95.161.114/shipsim/forum/index.php/topic,17042.msg228827.html#msg228827
Logged

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #67 on: January 08, 2010, 14:44:46 »

Sorry Terry. No offence, but I actually meant VSTEP. As good with computers as you undoubtedly are, something that poses a threat to customers should not be responded to by a volunteer.

Also, I would like to know what steps have been taken to ensure that the site is now safe to use- especially when the online shop is concerned... debit cards, personal details etc.

The silence from VSTEP has been deafening.

I don't think it is acceptable for any online company to just say "if your a/v is working then you are ok..."
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

RMS Canada

  • Forum member
  • Posts: 897
Re: Trojan Horse reported by Avast antivirus today
« Reply #68 on: January 08, 2010, 23:01:29 »

Yes, its safe. The problem is solved and fixed  :blush:

Okay then, just checking, thanks!
Logged
All ahead full!

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #69 on: January 09, 2010, 00:22:08 »

NB Just to clarify, my above post was not intending to criticise any of the goderation team.
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

Firestar

  • Guest
Re: Trojan Horse reported by Avast antivirus today
« Reply #70 on: January 30, 2010, 20:30:02 »

nice that shipyard link alerts my kaspersky with an trojan XD
Does this mean there's another problem?
Logged

Stuart2007

  • Forum member
  • Posts: 6201
Re: Trojan Horse reported by Avast antivirus today
« Reply #71 on: January 30, 2010, 21:04:33 »

Maybe yes. Maybe no.


I hope that helps clarify things.
Logged
Join the campaign for 'Pride of Bilbao' and SSE (on one disc).... Model by TFM ship builders.

Captain Best

  • Forum member
  • Posts: 3237
Re: Trojan Horse reported by Avast antivirus today
« Reply #72 on: January 30, 2010, 21:05:45 »

There's only one thing to find it out.

Install Norton 2003 and see what's happends  ;D
Logged
Pages: 1 2 [3]   Go Up
 
 


SMF 2.0.14 | SMF © 2017, Simple Machines