Get this folks...

Discussion in 'malware problems & news' started by JeremyWW, Aug 24, 2007.

Thread Status:
Not open for further replies.
  1. JeremyWW

    JeremyWW Registered Member

    Joined:
    Apr 13, 2005
    Posts:
    237
    Glad to oblige... :D
     
  2. The_Duality

    The_Duality Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    276
    Location:
    Liverpool, UK
    Lol ;) it is much appreciated :p

    Im quite interested to see if there is any more news on it. Call it morbid, but I want to know what effect this malware has had.
     
  3. JeremyWW

    JeremyWW Registered Member

    Joined:
    Apr 13, 2005
    Posts:
    237
    I would guess that most of the 'effect' was to knock Alwil's credibility. It had the desired effect on me anyway - brought me back here! And I'm happy with what I find...NOD32 AV Beta is running sweetly so far...
     
  4. The_Duality

    The_Duality Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    276
    Location:
    Liverpool, UK
    I find that you just cannot beat NOD... for me anyway. It is always a matter of opinion. I would love to install the beta, but im waiting for the internal error problem to be sorted.

    Sorry for the off topic mods!

    Anyway, back on topic, its doing the job for me, because it is still there! Surely it should be fixed by now! Just take the forums offline for a bit!
     
  5. flyrfan111

    flyrfan111 Registered Member

    Joined:
    Jun 1, 2004
    Posts:
    1,229
    It is still infected.
     
  6. Tarq57

    Tarq57 Registered Member

    Joined:
    Oct 7, 2006
    Posts:
    966
    Location:
    Wellington NZ
    Now getting a "404 Not Found" error when attempting to visit. Firefox and IE7.
     
  7. marc57

    marc57 Registered Member

    Joined:
    Aug 15, 2006
    Posts:
    83
    Location:
    St Marys,WV. U.S.A.
    Norton is also showing it as infected.
     
  8. Tarq57

    Tarq57 Registered Member

    Joined:
    Oct 7, 2006
    Posts:
    966
    Location:
    Wellington NZ
    And now (linking from the Avast home page) "Down for Maintenance."
     
  9. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Interesting, but I don't see it as hurting their credibility. Maybe their pride, but Avast did detect it right? Even banks and Government sites get hacked. Anyways, it's good to see it reported and it's getting fixed.
     
  10. JeremyWW

    JeremyWW Registered Member

    Joined:
    Apr 13, 2005
    Posts:
    237
    True...and yes, it did...
     
  11. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Thanks JeremyWW, It's good to see Avast caught it. I wish I saw this post earlier so I could try my setup in shadow mode. It's not often one gets to see malware without looking for it. Good find :)
     
  12. The_Duality

    The_Duality Registered Member

    Joined:
    Apr 3, 2007
    Posts:
    276
    Location:
    Liverpool, UK
    Yep, cheers Jeremy :thumb:

    As has been said, at least now it is being fixed. And maybe they will consider measures to prevent it happening again.
     
  13. nadirah

    nadirah Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    3,647
    Here's a screen capture of mediacount.net:
     

    Attached Files:

  14. JeremyWW

    JeremyWW Registered Member

    Joined:
    Apr 13, 2005
    Posts:
    237
    I just had an e-mail from Alwil. It's anonymous - obviously - but states what's happening:

    "We found that software used to run forum on our pages is vulnerable and have to be changed/updated (but there is probably no update available for this code inhections exploit). We have to find the best solution to this problem. The forum will be off until the solution will be found."
     
  15. mauserme

    mauserme Registered Member

    Joined:
    Aug 25, 2007
    Posts:
    2
    JeremyWW - I am a fairly regular poster on the avast! forum and have not received that email. Given that it was sent anonymously I would question its source.
     
  16. JeremyWW

    JeremyWW Registered Member

    Joined:
    Apr 13, 2005
    Posts:
    237
    Sorry, my post was confusing - I meant I was quoting it here anonymously. I know precisely who it's from. I was the first one to notify them directly by e-mail last night which is why I've had the dialogue with them. I suggest you e-mail them at 'virus at avast dot com', and ask for an explanation, as I did.
     
  17. ThunderZ

    ThunderZ Registered Member

    Joined:
    May 1, 2006
    Posts:
    2,459
    Location:
    North central Ohio, U.S.A.
    It is down for maintenance now. :rolleyes:
     
  18. mauserme

    mauserme Registered Member

    Joined:
    Aug 25, 2007
    Posts:
    2
    My mistake ... :)

    I emailed one of the developers last evening (without asking for a response) so at least you and I are trying to accomplish the same thing. Its interesting that this attack started at the beginning of the weekend when staff would be low. But I'm sure they'll get it sorted.
     
  19. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Visited te link with IE7, Opera and FF.

    hxxp://mediacount. net /strong/ 020sdsfg/

    I get it with all.
     

    Attached Files:

  20. GmG

    GmG Registered Member

    Joined:
    Oct 13, 2006
    Posts:
    48
    Location:
    Italy
    mediacount is Storm Worm (WORM/Zhelatin / Nuwar) site.
     
  21. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    aigle,
    Have you tried visiting the site with IE GeSWall'ed (to track the flow of events)?
     
  22. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Nothing was executed on my system.
    I stopped on this message. GW log is attached.
     

    Attached Files:

  23. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    That page is trying to install/run a MDAC component? Interesting.
     
  24. LUSHER

    LUSHER Registered Member

    Joined:
    Feb 28, 2007
    Posts:
    440
    This is really scary.... I hope I wasn't infected.
     
  25. DavidR

    DavidR Registered Member

    Joined:
    Sep 28, 2005
    Posts:
    6
    Location:
    United Kingdom
    Whilst it might be an embarrassment to have the forum software hacked through a vulnerability, at no time were avast users vulnerable to the attack. As has been said avast detected the infection.

    Whilst Firefox and Opera weren't vulnerable to the attach, those with IE or an IE clone, would have had the Web Shield block the attempt to infect.

    I too got an email from one of the Alwil team as l too reported it to avast, so it would apear that only those who contacted avast like JeremyWW got an email.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.