Corvette Forum  


Go Back   Corvette Forum > Help & Feedback > Help Forum
Sign in using an external account
Register Forgot Password?
Register Vendors Buy a Vette Search Today's Posts Mark Forums Read FAQ PhotosGarage

Help Forum How To | General Corvetteforum Questions | Feedback

Corvette Store
 
 
C6 Parts & Accessories
C5 Parts & Accessories
Wheels & Tires
Sponsored Ads
 
 
Vendor Directory
 
Reply
 
 
 
 
Thread Tools Search this Thread
Old 11-18-2009, 07:35 PM   #1
Chevy Guy
CF Senior Member
 
Chevy Guy's Avatar
 
Member Since: Jan 2004
Send a message via AIM to Chevy Guy
Default Virius alerts [merged with 11/20 updates]

It seems the site is still under some kind of attack. I started my computer and came directly to this site, it was slow to load and I noticed on the lower left corner of my screen it was waiting on an odd URL with the F word in it, something like "www.f*ckthecrisis". As soon as the page loaded, my antivirus went nuts and caught 3 bloodhound exploit files.

The virus name is being reported as Bloodhound.Exploit.193 and it is a .swf file named inEt[1].swf.

It definitely came from a ad type of redirect from this site.

*edit*

Found it in my IE history, it is www.****thecrisis.biz, definitely a hack site stocked w/ viruses.



Domain Name: ****THECRISIS.BIZ
Domain ID: D32529972-BIZ
Sponsoring Registrar: REGTIME LTD.
Sponsoring Registrar IANA ID: 1362
Domain Status: ok
Registrant ID: CO513949-RT
Registrant Name: Anton Robin
Registrant Organization: Anton Soft
Registrant Address1: Kolitina 16-4
Registrant City: Moscow
Registrant State/Province: Moscow
Registrant Postal Code: 193009
Registrant Country: Russian Federation
Registrant Country Code: RU
Registrant Phone Number: +7.4956788435
Registrant Email: *************@pochta.ru
Administrative Contact ID: CA513949-RT
Administrative Contact Name: Anton Robin
Administrative Contact Organization: Anton Soft
Administrative Contact Address1: Kolitina 16-4
Administrative Contact City: Moscow
Administrative Contact State/Province: Moscow
Administrative Contact Postal Code: 193009
Administrative Contact Country: Russian Federation
Administrative Contact Country Code: RU
Administrative Contact Phone Number: +7.4956788435
Administrative Contact Email: *************@pochta.ru
Billing Contact ID: CB513949-RT
Billing Contact Name: Anton Robin
Billing Contact Organization: Anton Soft
Billing Contact Address1: Kolitina 16-4
Billing Contact City: Moscow
Billing Contact State/Province: Moscow
Billing Contact Postal Code: 193009
Billing Contact Country: Russian Federation
Billing Contact Country Code: RU
Billing Contact Phone Number: +7.4956788435
Billing Contact Email: *************@pochta.ru
Technical Contact ID: CT513949-RT
Technical Contact Name: Anton Robin
Technical Contact Organization: Anton Soft
Technical Contact Address1: Kolitina 16-4
Technical Contact City: Moscow
Technical Contact State/Province: Moscow
Technical Contact Postal Code: 193009
Technical Contact Country: Russian Federation
Technical Contact Country Code: RU
Technical Contact Phone Number: +7.4956788435
Technical Contact Email: *************@pochta.ru
Name Server: NS1.EVERYDNS.NET
Name Server: NS2.EVERYDNS.NET
Name Server: NS3.EVERYDNS.NET
Name Server: NS4.EVERYDNS.NET
Created by Registrar: REGTIME LTD.
Last Updated by Registrar: REGTIME LTD.
Domain Registration Date: Tue Jun 23 14:11:15 GMT 2009
Domain Expiration Date: Tue Jun 22 23:59:59 GMT 2010
Domain Last Updated Date: Fri Nov 13 12:11:24 GMT 2009

Last edited by Chevy Guy; 11-18-2009 at 07:44 PM.
Chevy Guy is offline   Reply With Quote
Old 11-18-2009, 08:04 PM   #2
ZPO
CF Senior Member
Support Corvetteforum!
 
ZPO's Avatar
 
Member Since: Jan 2008
Location: Woodstock GA
Default Site problems?????

I'm getting the same thing as Chevy Guy.
ZPO is offline   Reply With Quote
Old 11-18-2009, 08:09 PM   #3
J T
Administrative Contributor
 
Member Since: Feb 2009
Default

Did this occur on the front/home page:
http://forums.corvetteforum.com/

Or while browsing a specific thread? If the later, it's possible, and has happened before, where a user can hide a "nasty" in their signature of their post. This means that it would get loaded by anyone viewing the thread where the post and signature was present. If this is the case, you'd need to inform where this thread is so the team can take necessary action, as it wouldn't be coming directly from Corvetteforum itself.

Of course it's possible that it's not the above and it's something else, such as through the ad network.
J T is offline   Reply With Quote
Old 11-18-2009, 08:14 PM   #4
Chevy Guy
CF Senior Member
 
Chevy Guy's Avatar
 
Member Since: Jan 2004
Send a message via AIM to Chevy Guy
Default

Quote:
Originally Posted by J T View Post
Did this occur on the front/home page:
http://forums.corvetteforum.com/

Or while browsing a specific thread? If the later, it's possible, and has happened before, where a user can hide a "nasty" in their signature of their post. This means that it would get loaded by anyone viewing the thread where the post and signature was present. If this is the case, you'd need to inform where this thread is so the team can take necessary action, as it wouldn't be coming directly from Corvetteforum itself.

Of course it's possible that it's not the above and it's something else, such as through the ad network.
Its defanitely the ad generator, its been owned. People are getting it all over the site.
Chevy Guy is offline   Reply With Quote
Old 11-18-2009, 08:31 PM   #5
JimTN
CF Senior Member
Support Corvetteforum!

 
JimTN's Avatar
 
Member Since: May 2004
Location: Tullahoma TN
Default

I'm using Firefox with AdBlockerPlus and I have all signatures turned off. McAfee has not given me any warning messages and I've been on the forum off and on all day.

I do not go through the front/home page, but use a desktop shortcut to go directly to the C6 General forum or the Off Topic forum.

Don't know if this information will help with any diagnosis or not. Just thought it might.
JimTN is online now   Reply With Quote
Old 11-18-2009, 08:44 PM   #6
vstol
CF Senior Member

 
Member Since: Mar 2002
Location: Stafford Va
Default

this just happened to me, lets fix it asap
vstol is offline   Reply With Quote
Old 11-18-2009, 08:45 PM   #7
newskatercat
CF Senior Member
St. Jude Donor '06-'07-'08-'09-'10-'11-'12

 
newskatercat's Avatar
 
Member Since: Dec 2005
Location: Cape Coral Fl
Default

AVG detected Javascript Obfuscation (type 714) www.f*ckthecrisis

as I just came on this site http://forums.corvetteforum.com/!
newskatercat is online now   Reply With Quote
Old 11-18-2009, 08:45 PM   #8
X-ZZ4
CF Senior Member
Cruise-In II Veteran
St. Jude Donor '03-'05-'06-'07
Support Corvetteforum!

 
X-ZZ4's Avatar
 
Member Since: Feb 2001
Location: Southern California & Portland, OR
Send a message via AIM to X-ZZ4
Default

Google Chrome is telling me this......

Warning: Visiting this site may harm your computer!
The website at forums.corvetteforum.com contains elements from the site *******.com, which appears to host malware – software that can hurt your computer or otherwise operate without your consent. Just visiting a site that contains malware can infect your computer.
For detailed information about the problems with these elements, visit the Google Safe Browsing diagnostic page for *******.com.
Learn more about how to protect yourself from harmful software online.


I'm using FireFox now and it let's me through (although I'm scared to be here)......
X-ZZ4 is online now   Reply With Quote
Old 11-18-2009, 08:52 PM   #9
CHASLS2
CF Senior Member
 
CHASLS2's Avatar
 
Member Since: Aug 2006
Location: Port Richey FL
Default

I have no fire wall at all and i don't seem to be having any probs.
CHASLS2 is offline   Reply With Quote
Old 11-18-2009, 09:01 PM   #10
savewave
Administrator
CI 2-3-4-5-6-7-8-9-10-11-12
Wounded Warrior Escort '11
St. Jude Donor '03 thru '12
NCM Lifetime Member
 
savewave's Avatar
 
Member Since: Aug 1999
Location: Lakeland, TN; Miramar Beach, FL

Default

Not sure what's up with the messages some of you are getting, but I'll report the issue to the tech team at IB. I'm not getting any warning messages.
savewave is offline   Reply With Quote
Old 11-18-2009, 09:04 PM   #11
X-ZZ4
CF Senior Member
Cruise-In II Veteran
St. Jude Donor '03-'05-'06-'07
Support Corvetteforum!

 
X-ZZ4's Avatar
 
Member Since: Feb 2001
Location: Southern California & Portland, OR
Send a message via AIM to X-ZZ4
Default

Here's more from Google......

Quote:
Safe Browsing
Diagnostic page for *******.com

What is the current listing status for *******.com?
Site is listed as suspicious - visiting this web site may harm your computer.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.

What happened when Google visited this site?
Of the 2 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2009-11-18, and suspicious content was never found on this site within the past 90 days.
Malicious software includes 30 trojan(s).

This site was hosted on 1 network(s) including AS39150 (VLTELECOM).

Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, *******.com appeared to function as an intermediary for the infection of 5 site(s) including turkforum.net/, webhatti.com/, maktoob.com/.

Has this site hosted malware?
No, this site has not hosted malicious software over the past 90 days.

How did this happen?
In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

Next steps:
Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.
Updated 17 hours ago
©2008 Google - Google Home
http://safebrowsing.clients.google.c...hrome&hl=en-US
X-ZZ4 is online now   Reply With Quote
Old 11-18-2009, 09:41 PM   #12
Datawiz
CF Senior Member
Ft Myers Area Coordinator
CI-7-8-9-10 Veteran
Cruise-In IX AutoX Winner
St. Jude Donor '05-'06-'07-'08-'09-'10-'11
St. Jude/CI Name Tag Designer
Support Corvetteforum!
 
Datawiz's Avatar
 
Member Since: Feb 2005
Default

Forum has slowed down SIGNIFICANTLY in the last 10 minutes. I got the virus warning 2 hours ago. These clowns are hitting us again.
Datawiz is offline   Reply With Quote
Old 11-18-2009, 09:41 PM   #13
C2Driver
CF Senior Member
 
C2Driver's Avatar
 
Member Since: Feb 2008
Location: Toronto Ontario
Default

I came into OT with I.E.8 at 6:27PM and was immediately greeted by 4 notices of viruses by the Antivirus software provided by my ISP. 2 viruses were immediately deleted by my software. 1 was quarantined and 1 was deleted on reboot. I deleted the quarantined item after reboot. I have since scanned twice and appear to be virus free. Here's the log from my Antivirus software:

C:\Documents and Settings\Owner\Local Settings\Temp\jar_cache15463225937101245 36.tmp Trojan-Downloader.Java.Agent.ab Deleted 18/11/2009 6:27:04 PM
C:\Documents and Settings\Owner\Local Settings\Temp\jar_cache68610812648445384 .tmp Trojan-Downloader.Java.Agent.ab Deleted 18/11/2009 6:27:16 PM
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9R7CAC9X\index[1].htm Trojan-Downloader.JS.Agent.esm Delete at restart 18/11/2009 6:27:24 PM
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\KDG22NRC\manyWord[1].pdf Exploit.JS.Pdfka.anx Quarantined 18/11/2009 6:27:28 PM



File generated by Rogers Online Protection Anti-Virus
C2Driver is online now   Reply With Quote
Old 11-18-2009, 09:56 PM   #14
mbowers13
CF Senior Member

 
mbowers13's Avatar
 
Member Since: Jul 2009
Location: Online
Default

I don't know if it helps but I use the HOSTS file here and I have no warnings from Chrome. I also use FF w/AdBlock Plus.
mbowers13 is offline   Reply With Quote
Old 11-18-2009, 10:02 PM   #15
leghumper
CF Senior Member
 
leghumper's Avatar
 
Member Since: Aug 2006
Location: This post copyright, TLH Inc. All rights reserved.
Default



[IMG][/IMG]
leghumper is offline   Reply With Quote
Old 11-18-2009, 10:03 PM   #16
daddy'svette
CF Senior Member
 
daddy'svette's Avatar
 
Member Since: Jul 2009
Location: Surprise AZ
Send a message via Yahoo to daddy'svette
Default

Got the bug here too.

What antivirus program will get rid of it? I use McAfee, ran a full scan and found nothing. Can't get rid of what you can't find!
daddy'svette is offline   Reply With Quote
Old 11-18-2009, 10:06 PM   #17
Scoob
CF Senior Member
 
Scoob's Avatar
 
Member Since: Mar 1999
Location: Life's tough, wear a helmet. NJ
Default

Quote:
Originally Posted by Chevy Guy View Post

The virus name is being reported as Bloodhound.Exploit.193 and it is a .swf file named inEt[1].swf.
Yep. My Symantec quarrantined it right away.
Scoob is online now   Reply With Quote
Old 11-18-2009, 10:18 PM   #18
OnyxC6
CF Senior Member
 
OnyxC6's Avatar
 
Member Since: Aug 2005
Default

I had to use Malware bytes

see my post on the main C6%2

Last edited by OnyxC6; 11-18-2009 at 10:39 PM.
OnyxC6 is offline   Reply With Quote
Old 11-18-2009, 10:39 PM   #19
GS Ragtop
CF Senior Member
St. Jude Donor '08-'09-'11
 
GS Ragtop's Avatar
 
Member Since: Nov 1999
Location: Next to LeBron's empty house
Default

Here's a screen capture of the event - AVG v9, Windows 7, IE8.

GS Ragtop is offline   Reply With Quote
Old 11-18-2009, 10:44 PM   #20
ddecart
Moderator
SPARTAN and
HOCKEYTOWN MODERATOR
CI 3-4-5-6-8-9-10 Vet
CI-9 AutoX Winner
CI-3 Go Kart Champ
St. Jude '03-'04-'05-'06-'07-'08-'09-'10-'11
 
ddecart's Avatar
 
Member Since: Aug 1999
Location: Time Flies When You're Lovin' Life!
Default

Why am I NOT getting anything like this? I'm browsing the forum with google chrome, firefox, and IE7 right now. None of them are getting anything.

I'm also browsing through a proxy server/firewall. Maybe that has something to do with it??
ddecart is offline   Reply With Quote
Old 11-18-2009, 10:44 PM
 
Go Back   Corvette Forum > Help & Feedback > Help Forum
Reload this Page Virius alerts [merged with 11/20 updates]
 
 
 
Reply

Tags
714, bloodhoundexploit193, centiyo, centiyocom, exploit, firefox, javascript, norton, obfuscation, profiles, trojandownloaderjavaagentab, type, vbseo, vbulletin, wwwcentiyocom


Thread Tools Search this Thread
Search this Thread:

Click for Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -4. The time now is 11:12 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.5.1 PL1
Emails & Password Backup