UltraBB Forums Home 
Home Search search Menu menu Not logged in - Login | Register
UltraBB Forums > UltraBB > Troubleshooting > Problems, please read.

Welcome to the UltraBB public support forum! Did you know there is an inexpensive totally integrated gallery available for UltraBB? Read more here: Gallery Details

 Moderated by: Fake Mod Page:  First Page Previous Page  1  2  3  4  5  Next Page Last Page  
New Topic Reply Printer Friendly
Problems, please read.  Rate Topic 
AuthorPost
 Posted: Tue Dec 22nd, 2009 01:29 am
  PM Quote Reply
21st Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Hi Jim,

Could you clarify how this virus works?

All my saved ftp passwords are encrypted in the ini files, so I'm a bit puzzled how the virus would manage to decrypt them -- or if it can, what's the point of having them saved in encrypted form?

If I don't save them, and have to enter them manually, that surely makes them vulnerable to keylogger viruses? I suppose I could copy and paste them into the ftp login from somewhere else.

Whatever, I'm extremely reluctant to change them. NOD32 reports my system clean and I can't detect any problems on any of my sites. It will be a big headache to change them all -- I have half a dozen different ftp accounts, and some are used in other software such as Help&Manual and Camtasia to automate uploads. One of them is hard-encoded (with obfuscation) in one of my own programs distributed to users. If I change it I shall have to issue an upgrade version to everyone using it.

I'm also puzzled that all the links you gave are 6 months old. I can't find any news reports that this has suddenly become a panic in the last few days.

:?

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 01:58 am
  PM Quote Reply
22nd Post
snooze
License Holder
 

Joined: Sun Mar 16th, 2008
Location:  
Posts: 147
Status: 
Offline
Mana: 
User Gallery
I wasn't having a problem other than a notice that an explorer file was closing, even I never had the ie browser open (i'm using chrome), but i just installed avast (my mcafee just ran out) and now I'm getting the notice about this one:

JS:Illredir-A [Trj]

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 02:01 am
  PM Quote Reply
23rd Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
Yes that is unusual.(the old threads)

I did an internet search using part of the malicious code and got some real recent threads. That's how I determined what the bug was. It isn't that particular one but a variant.

Anyhow your site was not affected at all.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 02:33 am
  PM Quote Reply
24th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
ALSO we have just proved that a cleaned site will get re infected if you do not change the password to your FTP.

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 02:43 am
  PM Quote Reply
25th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Jim wrote: ALSO we have just proved that a cleaned site will get re infected if you do not change the password to your FTP.
Hi Jim,

I'm willing to change them if I must, but the other part of your request was not to save them. I'm very reluctant to do that -- surely the greater risk is keylogger viruses if they have to be entered every time? It's a pain fiddling about with copy and paste and entering bits of password in the wrong order to defeat keyloggers.

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 02:47 am
  PM Quote Reply
26th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
What is this world coming to? You store them and a virus hacks them and sends them to china. You don't store them and a virus logs the entry as you go in.

Like I said, if your site was going to be affected it would have and on the 19th sometime after 1:07 PM EST. If not by now it probably never will. You are doing something right Martin :)

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 07:33 am
  PM Quote Reply
27th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
I was locked out of my pop3 account this morning and then it suddenly opened up and it was flooded with 80+ returned e-mail notifications from all over Spain from people and places I have never heard of. Sounds bad. Not a good start to the computing day.

Last edited on Tue Dec 22nd, 2009 08:18 am by Robert

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 07:39 am
  PM Quote Reply
28th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
I now have e-mails pouring with reports of Avast coming up with this trojan from a lot of the avatars on the forum : JS:lllredir-A [TRJ]

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 08:55 am
  PM Quote Reply
29th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
I have been deleting those posts with the avatar warnings and that seems to have cleared the problem, for now at least.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 10:15 am
  PM Quote Reply
30th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
OK this is strange. From the avatars?

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 10:20 am
  PM Quote Reply
31st Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
Yes Jim but so far only two people have been affected. Avast stopped the download of the avatar in question and I have deleted the posts because even with the avatars removed the same warning kept coming from Avast. The topics where the posts were are now clear.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 10:28 am
  PM Quote Reply
32nd Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
OK Bob that is sort of impossible. Since the software does not allow remote avatars this would be difficult.

Do you allow signatures? An image drawn from a site that is infected could do this but signature is the only way or a copy and paste from an infected page.

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 10:54 am
  PM Quote Reply
33rd Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1819
Status: 
Offline
Mana: 
User Gallery
Robert wrote: because even with the avatars removed the same warning kept coming from Avast
Hi Bob, Jim,

Sorry to state the obvious, but this of course means that the problem is not with the avatars.

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 11:00 am
  PM Quote Reply
34th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
The warning that comes up Jim is the same as the one when the avatar was there, identical wording and stating the same url for the missing avatar. It only stops doing that when the whole post is deleted. I'll wait to see if it happens again and take a snapshot.
Is it possible that the whole post was contaminated?

Last edited on Tue Dec 22nd, 2009 11:02 am by Robert

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 11:30 am
  PM Quote Reply
35th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6649
Status: 
Offline
Mana: 
User Gallery
It's possible that there was no contamination. Avast evidently added at least one of the text strings that triggers the virus to their definitions. I know this because I posted the string as text on a forum and that page shows a false positive.

Also a file I was working with to match the string and delete it from files is tagged today by avast as a virus and I know it is not dangerous. So I would still like to investigate if it happens today again but I don't think there is any real threat.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 11:55 am
  PM Quote Reply
36th Post
EricC
Worm Can Opener


Joined: Wed Jun 11th, 2008
Location: Altamont, New York USA
Posts: 325
Status: 
Offline
Mana: 
User Gallery
After reading this I am not sure what or if I need to do anything. It doesn't appear my sites are experiencing any problems, but I want to be sure.

 

:?

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 12:24 pm
  PM Quote Reply
37th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
Thanks Jim. I'm starting to relax a little now. Nothing has happened during the last couple of hours.

Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 12:27 pm
  PM Quote Reply
38th Post
John Floyd
License Holder


Joined: Sun Jan 27th, 2008
Location: The Great Dismal Swamp Of, North Carolina USA
Posts: 471
Status: 
Offline
Mana: 
User Gallery
My Site has hung in there for a little over 7 hours now, still doing good

John 

Back To Top PM Quote Reply

 Posted: Tue Dec 22nd, 2009 01:17 pm
  PM Quote Reply
39th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1320
Status: 
Offline
Mana: 
User Gallery
One of my members has just had this come up on entering our Recent Topics page, before clicking on anything :


Back To Top PM Quote Reply  

 Posted: Tue Dec 22nd, 2009 02:43 pm
  PM Quote Reply
40th Post
Mag
License Holder
 

Joined: Thu Jan 31st, 2008
Location: England, United Kingdom
Posts: 1407
Status: 
Online
Mana: 
User Gallery
Blimey Robert, give Jim a chance to draw breath, he is running around after so many customers at the moment ROFL:):)

Back To Top PM Quote Reply

Current time is 10:41 am Page:  First Page Previous Page  1  2  3  4  5  Next Page Last Page    
UltraBB Forums > UltraBB > Troubleshooting > Problems, please read. Top



Hosting

UltraBB 1.17 Copyright © 2007-2011 Data 1 Systems, INC.
Page processed in 0.4311 seconds (9% database + 91% PHP). 27 queries executed.