UltraBB Forums Home 
Home Search search Menu menu Not logged in - Login | Register

Welcome to the UltraBB public support forum! Did you know there is an inexpensive totally integrated gallery available for UltraBB? Read more here: Gallery Details

 Moderated by: Fake Mod Page:    1  2  Next Page Last Page  
New Topic Reply Printer Friendly
Tired  Rate Topic 
AuthorPost
 Posted: Thu Dec 24th, 2009 02:43 am
  PM Quote Reply
1st Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6640
Status: 
Online
Mana: 
User Gallery
I have been going through all the servers account by account.

I know a lot of you have been helpful and have been listening well.

A few of you have not changed password after the warning

If I find an infection on your site I will change your password without warning. It is the only way I can battle this.

There are a lot of customers now. I can't remember every single ones handle here per the account name. If you all of the sudden can't get in to FTP or cpanel PM me here and I'll give you the new password. Please don't change it and log in to your FTP without making sure your computer is clean. Please.

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 03:29 am
  PM Quote Reply
2nd Post
Devans
License Holder


Joined: Tue May 27th, 2008
Location: Iowa USA
Posts: 1397
Status: 
Offline
Mana: 
User Gallery
I was one of the bad boys...Actually I ever caught the thread until tonight, but mine is changed now :)

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 10:26 am
  PM Quote Reply
3rd Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1818
Status: 
Offline
Mana: 
User Gallery
Jim wrote: Please don't change it and log in to your FTP without making sure your computer is clean. Please.
Hi Jim,

"Making sure your computer is clean" is easier said than done. My expensive ESET NOD32 anti-virus says it's clean, but of course I have no way of knowing if it is checking for the right virus signature. Installing multiple AV products at the same time is a sure recipe for grief as each is likely to detect the other as a virus -- so no Avast for me.

I would prefer to check it myself. Can you provide some details of where and how this virus hides itself and which files it modifies?

I've been trying to find this information on the various online databases, but as every virus has several names and many variants, it's impossible to be sure you are referring to the right one.

As I understand it, the original infection was via a flaw in Adobe Reader and infected PDF files. Adobe say they will be releasing a fix on 12th January, but in the meantime it is advisable to disable Javascript in Adobe Reader -- how to do that and more details at:

 http://www.adobe.com/support/security/advisories/apsa09-07.html

regards,

Martin.

Last edited on Thu Dec 24th, 2009 10:28 am by martin_wynne

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 11:25 am
  PM Quote Reply
4th Post
Di
Administrator


Joined: Sat Apr 28th, 2007
Location: Columbus, Ohio USA
Posts: 2679
Status: 
Offline
Mana: 
User Gallery
Thanks for that bit of information, Martin

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 11:40 am
  PM Quote Reply
5th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6640
Status: 
Online
Mana: 
User Gallery
Thanks for the tip Martin, I have disabled javascript in mine now. Funny the date on that article corresponds within 3 days of our outbreak. How were we to know?

As for the exact affected files on the computer.... I couldn't tell you and be correct. Everything I read seem to point in different directions. I know specifically where it puts the code on the web files it alters and that is different from exactly what the internet says, making me guess this is a variant or mutation and not the original gumblar. The file names it affects are an identical list though.

If you need to know the exact location on the web files I can do that via screenshot, since attaching a sample of the code makes a topic unreadable if you have avast.

The code changes too, the base 64 encoded URL's are different per infected site but have been the same per particular site.

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 01:51 pm
  PM Quote Reply
6th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1818
Status: 
Offline
Mana: 
User Gallery
Jim wrote: Thanks for the tip Martin, I have disabled javascript in mine now.
You're welcome. :)

If you haven't tried it, an excellent alternative to Adobe Reader is the Foxit PDF Reader, free from:

 http://www.foxitsoftware.com/pdf/reader/

although for all we know that has its own flaws, of course.

regards,

Martin.

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 02:32 pm
  PM Quote Reply
7th Post
Mag
License Holder
 

Joined: Thu Jan 31st, 2008
Location: England, United Kingdom
Posts: 1405
Status: 
Offline
Mana: 
User Gallery
Thanks Martin I have disabled javascript in that as well.

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 03:01 pm
  PM Quote Reply
8th Post
TVDinner
Go UCONN!


Joined: Wed May 9th, 2007
Location: North Carolina USA
Posts: 1615
Status: 
Offline
Mana: 
User Gallery
Jim - can you please check my site that is hosted by you again. I know you said it was clean when you looked the other day, but I am running Mawaregytes today and it is finding some stuff (and removing it). But I wanted to make sure the forum files were ok.

Thank you sir.

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 03:10 pm
  PM Quote Reply
9th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6640
Status: 
Online
Mana: 
User Gallery
Good to go James, no trace.

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 03:21 pm
  PM Quote Reply
10th Post
TVDinner
Go UCONN!


Joined: Wed May 9th, 2007
Location: North Carolina USA
Posts: 1615
Status: 
Offline
Mana: 
User Gallery
thanks - weird. i wonder what Mawarebytes is finding because they have been finding some stuff.

I also just turned off the java in adobe as recommended (thanks for that)

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 03:35 pm
  PM Quote Reply
11th Post
TVDinner
Go UCONN!


Joined: Wed May 9th, 2007
Location: North Carolina USA
Posts: 1615
Status: 
Offline
Mana: 
User Gallery
Jim - just sent you a PM - believe my other site TBB is infected. I PM's you what I did so far. thanks!

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 04:45 pm
  PM Quote Reply
12th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6640
Status: 
Online
Mana: 
User Gallery
James, ***poke poke*** If those sites were hosted with me I would have cleaned them already :)

Hope we can get it worked out.

Back To Top PM Quote Reply

 Posted: Thu Dec 24th, 2009 08:38 pm
  PM Quote Reply
13th Post
§issie
License Holder /Paul's blonde


Joined: Sun Jun 15th, 2008
Location: DeLand, Florida USA
Posts: 618
Status: 
Offline
Mana: 
User Gallery
Jim i know y'all have been so busy..

BUT ...Can i just say ' Thank You ' for all you and Di do for ALL of us

Try and relax over Christmas and New Years.. You and Di deserve it...

Hug and kiss your boys and enjoy them

Back To Top PM Quote Reply  

 Posted: Thu Dec 24th, 2009 10:15 pm
  PM Quote Reply
14th Post
bhyder
License holder


Joined: Wed Aug 19th, 2009
Location: South Carolina USA
Posts: 143
Status: 
Offline
Mana: 
User Gallery
§issie wrote:
Jim i know y'all have been so busy..

BUT ...Can i just say ' Thank You ' for all you and Di do for ALL of us

Try and relax over Christmas and New Years.. You and Di deserve it...

Hug and kiss your boys and enjoy them

yes i agree 100% family 1st. life is short and kids grow up so fast, enjoy them while ya can.

i wanted to add thanks for the tip MARTIN i did as suggested and disabled javascript ran avast and found 5 infected files.
question why would avast not find the infected files until javascript was disabled ?

thanks again to everyone for all ur help the last few days well over the last soon to be year with ultrabb, id been lost without you guys leading the way for me.
i owe you all so much, if in anyway i can ever help anyone just holler at me.

johnny/jj

Back To Top PM Quote Reply

 Posted: Fri Dec 25th, 2009 09:56 pm
  PM Quote Reply
15th Post
wingnutter
Forever Learning


Joined: Wed May 14th, 2008
Location: Ireland
Posts: 1839
Status: 
Offline
Mana: 
User Gallery
Can you check mine as well Jim please, as I just don't know what I am looking for there. My PC is showing no infections with Avast but I'd like to be sure about the site before I change password again. I already change it about once a month and don't save it in the FTP program.

Back To Top PM Quote Reply  

 Posted: Sat Dec 26th, 2009 02:00 am
  PM Quote Reply
16th Post
Jim
I work here


Joined: Wed Apr 11th, 2007
Location:  
Posts: 6640
Status: 
Online
Mana: 
User Gallery
I had already checked yours Steve, there are no signs of infection at all. Yes I just re checked :)

Back To Top PM Quote Reply

 Posted: Sat Dec 26th, 2009 11:00 am
  PM Quote Reply
17th Post
wingnutter
Forever Learning


Joined: Wed May 14th, 2008
Location: Ireland
Posts: 1839
Status: 
Offline
Mana: 
User Gallery
Thanks very much Jim.

Back To Top PM Quote Reply  

 Posted: Sat Dec 26th, 2009 02:01 pm
  PM Quote Reply
18th Post
TVDinner
Go UCONN!


Joined: Wed May 9th, 2007
Location: North Carolina USA
Posts: 1615
Status: 
Offline
Mana: 
User Gallery
Thank you again Jim

Back To Top PM Quote Reply

 Posted: Sat Dec 26th, 2009 04:10 pm
  PM Quote Reply
19th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1318
Status: 
Offline
Mana: 
User Gallery
What can I say. My forum is trouble free for all members and it's all thanks to Jim's tireless efforts.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 01:19 am
  PM Quote Reply
20th Post
snooze
License Holder
 

Joined: Sun Mar 16th, 2008
Location:  
Posts: 147
Status: 
Offline
Mana: 
User Gallery
Well now that its the 27th, is Christmas over? ;)

People have been complaining about virus activity on my site again. The Chatbox people are saying it ain't them, which makes sense to me because the viruses I've been seeing elsewhere just seem to attach themselves to any active program, script or whatever, it's not like the application comes with a virus. But I really don't know tech stuff like this. <sigh>

There is java code on my Recent Posts side menu, but that's all I'm seeing.

Back To Top PM Quote Reply

Current time is 08:43 pm Page:    1  2  Next Page Last Page    
UltraBB Forums > UltraBB > Troubleshooting > Tired Top



Hosting

UltraBB 1.17 Copyright © 2007-2011 Data 1 Systems, INC.
Page processed in 0.3214 seconds (12% database + 88% PHP). 28 queries executed.