Author Topic: Am picking up unwanted files from ACDC site.
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
I tried it a second time and got them again. McAfee called them trojans. I am unable to send a private message on these boards, so I am forced to make it public. Sorry, Drakier.

 

-----signature-----
Link to this post
Crelic_MT 
Title: Poppy's Plaything
Posts: 8,820
Registered: May 4, '03
Extended Info (if available)
Real Post Cnt: 8,666
User ID: 798,284
Subject: Am picking up unwanted files from ACDC site.
Not to change the subject as I'm sure he'll see this...
but why can't you PM? You have over 20 posts...

-C

 

-----signature-----
Don't blink, Don't even blink
Blink and you're dead
They are fast, faster than you can believe
Don't turn your back, don't look away
and don't blink.
Link to this post
Drakier 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
could you be more specific?

 

-----signature-----
Link to this post
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
The Vault won't do a private tell for me. It, instead, keeps giving me ads that want me to pay for a special service.

When ACDC starts loading, McAfee gives me a message. It does it four times in a row. It finds four files that it calls trojan and deletes them. I ran a full scan to make sure my system was clean. Then I loaded Decal and AC and everything was fine. So I clicked on the ACDC site again (using the url in ACDC) and the trojan conversation happened again. The reason I was trying to get to the ACDC site is cause Decal seems to be loading more slowly than before and when ACDC loads Decal and then AC, Decal doesn't get loaded first and the toon doesn't have a Decal toolbar. I just wanted to let you know about that when this trojan thing happened.

I don't know how to deal with this sort of thing, so I just let McAfee handle it. Is there something I should have done?

 

-----signature-----
Link to this post
Drakier 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
Again.. could you be more specific.

I need exact error messages and exact filenames.

I can't try to fix something that I don't know is broken. (Although I have a hard time believing it detects 4 files as ACDualClient itself doesn't really contain 4 files...it does.. barely)

Please be specific.

 

-----signature-----
Link to this post
Maddy_ACEDL 
Posts: 12,311
Registered: Feb 23, '00
Extended Info (if available)
Real Post Cnt: 11,836
User ID: 12,026
Subject: Am picking up unwanted files from ACDC site.
<< I don't know how to deal with this sort of thing, so I just let McAfee handle it. Is there something I should have done? >>

Besides not using McAfee (or Symantec) products?

 

-----signature-----
Link to this post
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
Sorry it is taking me so long to reply. It takes quite a while to rescan my puter and clean it up.

I was mistaken about it being 4 files. It is 3 files.

xpladv489[1].wmf - McAfee claims this is Exploit WMF
new489[1].htm - McAfee claims this is VBS/Psyme
slide489[1].htm - McAfee claims this is JS/Exploit - BO Gen

I tried it again this morning. Did not get those error messages when I browsed Warcry, The Vault, Turbine, Dell, NBC news, ACHeaven and several other sites.

They appeared when I browsed to ACDC using my saved url in favorites.

 

-----signature-----
Link to this post
Drakier 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
Umm.. those aren't my files.

and they aren't on my site as far as I can tell.

What page do you go to when they appear?

 

-----signature-----
Link to this post
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
I go to acdualclient.drakier.com.

I had thought that they were appearing when I browsed. That's why I browsed all over the place after cleaning my hard drive of the files. I didnt get them til I went to your site. I have used ACDC for years and I have never had any problem with your site. That is why I am asking you about it. What sort of mechanism is at work here?

I will simply avoid your site for now. But I sure would like to know what is happening.

 

-----signature-----
Link to this post
OREOSTARS 
Posts: 2,720
Registered: Mar 3, '05
Extended Info (if available)
Real Post Cnt: 2,404
User ID: 1,032,895
Subject: Am picking up unwanted files from ACDC site.
They are only when you access the forums Drakier. I had this problem, NOD32 Picked up all up and I was safe, but I think it is something you should get fixed happy

 

-----signature-----
(none)
Link to this post
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
I'm sorry, yes, it is when I click on the forums, as Oreo says.

 

-----signature-----
Link to this post
-Zalliun- 
Posts: 13,296
Registered: Jan 30, '02
Extended Info (if available)
Real Post Cnt: 13,116
User ID: 638,564
Subject: Am picking up unwanted files from ACDC site.
looks like its the http://removethis----xbfsrepztq.biz/dl/adv489.php in the frame that contains it.

looks like its down now or at least unstable.

2006/12/19 23:09:15.380 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\new489[1].htm is JS/MS06-014!exploit trojan.
2006/12/19 23:09:49.137 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\new489[1].htm is JS/MS06-014!exploit trojan. Deleted
2006/12/19 23:10:22.481 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan. Deleted
2006/12/19 23:10:22.552 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan.
2006/12/19 23:10:22.604 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan.
2006/12/19 23:10:22.897 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan. Deleted
2006/12/19 23:10:22.955 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan.
2006/12/19 23:10:23.021 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan.
2006/12/19 23:10:23.200 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\xpladv489[1].wmf is Win32/Worfo trojan. Deleted


Diff AV than the ones above , if opened from firefox nothing is triggered

 

-----signature-----
Fake it till you make it
Link to this post
Drakier 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
Oh I see now.

Thank you for the information. That helped me immediately locate the problem

I'm working on resolving it right now. seems somehow my forums got a small hack put in them. I'll clean the hack, then attempt to look for the hole and patch it.

Again, thank you for the notice, and finally the information needed to correct the problem.

 

-----signature-----
Link to this post
Drakier 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
I've removed the un-wanted link, but I still need to upgrade my board it seems.

I'll have to do this at another time as I currently don't have the time to upgrade it.

Thanks again. Sorry about the problems.

 

-----signature-----
Link to this post
Midnite-FF 
Posts: ????
Registered: ????
Extended Info (if available)
Real Post Cnt: 0
User ID: 0
Subject: Am picking up unwanted files from ACDC site.
Thank you, Drakier. I knew you must not be aware of it, but I don't seem to have the technical knowledge to give you the precise info you need. I am thankful for the other two fellows who helped.

 

-----signature-----
Link to this post

Valid XHTML 1.0 Transitional Powered by PHP