UltraBB Forums Home 
Home Search search Menu menu Not logged in - Login | Register
UltraBB Forums > UltraBB > Troubleshooting > FLASH CHAT WARNING

Welcome to the UltraBB public support forum! Did you know there is an inexpensive totally integrated gallery available for UltraBB? Read more here: Gallery Details

 Moderated by: Fake Mod Page:    1  2  Next Page Last Page  
New Topic Reply Printer Friendly
FLASH CHAT WARNING  Rate Topic 
AuthorPost
 Posted: Mon Dec 28th, 2009 10:08 am
  PM Quote Reply
1st Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
The virus we have all had to deal with could have originated from flash chat. Flash chat it's self (the folders on your site) are not infected, however a web reference in one of the preload flash routines point at an infected page spreading the virus.

IF YOU HAVE FLASH CHAT GET RID OF IT. DELETE THE FOLDER OR RENAME THE FOLDER AND CONTACT ME. IF YOU VISIT ANOTHER SITE WITH FLASH CHAT WARN THEM.

This way it can't be spread. As ming ming duck would say... "This is sewious"

Jim

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 11:06 am
  PM Quote Reply
2nd Post
wingnutter
Forever Learning


Joined: Wed May 14th, 2008
Location: Ireland
Posts: 1368
Status: 
Offline
Mana: 
Can we just change the web reference Jim?

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 11:37 am
  PM Quote Reply
3rd Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
They might have the link saved.That's why changing the folder name is safest.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 02:08 pm
  PM Quote Reply
4th Post
EricC
Worm Can Opener
 

Joined: Wed Jun 11th, 2008
Location: Altamont, New York USA
Posts: 294
Status: 
Offline
Mana: 
Jim wrote: This way it can't be spread. As ming ming duck would say... "This is sewious"

Jim


You can tell who has young children.....;)

 

....So seeing as I do not have Flash Chat is why I did not get infected?

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 02:12 pm
  PM Quote Reply
5th Post
Mag
License Holder


Joined: Thu Jan 31st, 2008
Location: England, United Kingdom
Posts: 1031
Status: 
Offline
Mana: 
Seems like that to me Eric, our site was ok as well and we don't use any chat programs.

Aha Jim, so the boys watch Wonder Pets LOL

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 02:15 pm
  PM Quote Reply
6th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
LOL Flash chat might be what was unsuspectingly spreading it big time. A google search on the actual injected virus JS:Illredir-A shows TONS of sites on tons of hosts hit since right before Christmas. It was wide spread but since a lot of ex wow users have flash chat AND the infection isn't in the actual files it would be impossible to detect and quick to spread.

Avast only added that particular strain on the 21st of this month. Now variant B is sweeping....

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 02:43 pm
  PM Quote Reply
7th Post
Di
Administrator


Joined: Sat Apr 28th, 2007
Location: Columbus, Ohio USA
Posts: 1971
Status: 
Offline
Mana: 
Mag wrote:
Aha Jim, so the boys watch Wonder Pets LOL

LOL! what do you think?

Attachment: ming_ming.jpg (Downloaded 45 times)

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 03:25 pm
  PM Quote Reply
8th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1002
Status: 
Offline
Mana: 
Jim wrote: Avast only added that particular strain on the 21st of this month. Now variant B is sweeping....
It's variant B that's affecting my forum. One of my members is a major retail supplier of kit to the hobby and every time I go to a page where he has posted I get this warning :

yourmodelrailway.net/images/avatars/contains sample of JS:Illdirect B (Trj)

If I delete his post then there's no problem with the rest of the topic.
This member doesn't have an avatar and has never had one. I have contacted him and he says because of the importance to his business his machines are continuously scanned for viruses etc and they are clean.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 03:40 pm
  PM Quote Reply
9th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1115
Status: 
Offline
Mana: 
EDIT: deleted

See next.

Last edited on Mon Dec 28th, 2009 03:52 pm by martin_wynne

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 03:50 pm
  PM Quote Reply
10th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1115
Status: 
Offline
Mana: 
Hi Bob,

Forget everything I just said. :whatever:

The index.php file in your /avatars/ folder (which should be empty) is infected, and my ESET NOD32 AV has now found it.

More to the point, the virus is actually called: JS/TrojanDownloader.Agent.NRL

which means that at long last I can search for some meaningful information about it. So thanks for that at least. See attached.

regards,

Martin.

Attachment: ymr_virus.png (Downloaded 41 times)

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 04:07 pm
  PM Quote Reply
11th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
There's not supposed to be an index.php in avatar folders......

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 04:11 pm
  PM Quote Reply
12th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
It's gone now :)

It was index.html. It's supposed to be blank. The virus has not previously written to blank index files.

It looked like someone uploaded an alternate index file then it got hacked. Good catch Martin.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 04:14 pm
  PM Quote Reply
13th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
OK I just checked about 6 previously infected sites, all had a zero K file size for index.html in the avatar folder. Seems like a Bob exclusive.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 04:16 pm
  PM Quote Reply
14th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
martin_wynne wrote: Hi Bob,

Forget everything I just said. :whatever:

The index.php file in your /avatars/ folder (which should be empty) is infected, and my ESET NOD32 AV has now found it.

More to the point, the virus is actually called: JS/TrojanDownloader.Agent.NRL

which means that at long last I can search for some meaningful information about it. So thanks for that at least. See attached.

regards,

Martin.

Martin:

The different virus protection companies name the viruses themselves and they can be different names. I examined the virus string, except for the base 64 encoded URL it was identical.

Thanks for finding this Martin, Bob can rest a little better now.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 04:38 pm
  PM Quote Reply
15th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1115
Status: 
Offline
Mana: 
Jim wrote:The different virus protection companies name the viruses themselves and they can be different names.
Yes I know, and it makes it next to impossible to search for information about a specific virus, or to be sure that any information found is relevant.

ESET NOD32 last updated the virus signature for this one on 25th December, and first detected it on 16th December.



Bob can rest a little better now.
Maybe, but I think he would rest even better if he knew how it became infected in the first place, and how to prevent it happening again. Previous measures to protect the FTP password seem to have failed? :?

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 04:48 pm
  PM Quote Reply
16th Post
Jim
Father


Joined: Wed Apr 11th, 2007
Location:  
Posts: 4684
Status: 
Online
Mana: 
That's why I figured he was infected, all but one other site I changed the password on didn't get re infected. The other (after the reinfection) I changed the password and didn't tell them what it was for a few days, no reinfections after that.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 05:01 pm
  PM Quote Reply
17th Post
martin_wynne
Licence Holder


Joined: Sun May 25th, 2008
Location: West Of The Severn, United Kingdom
Posts: 1115
Status: 
Offline
Mana: 
Jim wrote: That's why I figured he was infected, all but one other site I changed the password on didn't get re infected. The other (after the reinfection) I changed the password and didn't tell them what it was for a few days, no reinfections after that.
Hi Jim,

On the Control Panel for my UK hosting provider (it's not cPanel), I can turn off all FTP access. I have now taken to doing that -- I turn it on only for a few minutes when I need to do an FTP transfer, and then turn it off again.

But I can't seem to do that in cPanel, unless I'm missing something?

Even more worrying is that the the main account FTP password seems to be the same as the cPanel password -- so if it's stolen, the cPanel could also be hacked?

On my UK hosting, the passwords are different, and the Control Panel has a captcha in the login.

regards,

Martin.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 05:18 pm
  PM Quote Reply
18th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1002
Status: 
Offline
Mana: 
An exclusive for me. How flattering but I could have done without it. Must hurry back to the forum now and check for myself.

Back To Top PM Quote Reply

 Posted: Mon Dec 28th, 2009 05:52 pm
  PM Quote Reply
19th Post
Robert
Member


Joined: Fri Jul 18th, 2008
Location: Benidorm, Spain
Posts: 1002
Status: 
Offline
Mana: 
Update on the above. No trace of the virus found so it looks like we are clear once more. Thankfully there doesn't appear to be any damage caused but the nuisance value has been very high indeed. As a matter of interest I downloaded my database this morning and ran Avast, Ad-Aware and Superantispyware over it to no effect, as far as they were concerned it was clean.

Back To Top PM Quote Reply  

 Posted: Mon Dec 28th, 2009 08:13 pm
  PM Quote Reply
20th Post
Devans
License Holder


Joined: Tue May 27th, 2008
Location: Iowa USA
Posts: 976
Status: 
Offline
Mana: 
Hey Jim,

As you know, I used to use Flash Chat, on our forum. I have since upgraded to the new chat program, that you have here. I do, however, still have the Flashchat, although I have removed all links to it, in the forum. Should the Flash Chat folder(s) be deleted from cpanel?

I have no intentions on using it again, I just was unsure of which files and folders to remove.

Back To Top PM Quote Reply

Current time is 02:46 am Page:    1  2  Next Page Last Page    
UltraBB Forums > UltraBB > Troubleshooting > FLASH CHAT WARNING Top



Hosting

UltraBB 1.17 Copyright © 2007-2008 Data 1 Systems
Page processed in 0.2635 seconds (7% database + 93% PHP). 31 queries executed.