Divinity Banner
Topic Options
#455149 - 05/10/12 01:38 PM Virus on forum ?
melianos Offline
Orc


Registered: 12/03/09
Posts: 444
I use AVG Free edition, and since yesterday, everytime I open a window, I get a pop-up as he blocked a threat.

http://img856.imageshack.us/img856/3894/larian.jpg

Got a security problem ? smile

Top
#455150 - 05/10/12 03:07 PM Re: Virus on forum ? [Re: melianos]
Raze Online   content
Angel


Registered: 03/10/03
Posts: 17326
Loc: Canada

Just this forum?

Top
#455151 - 05/10/12 03:48 PM Re: Virus on forum ? [Re: Raze]
Arokh Online   content
Whelp


Registered: 04/22/11
Posts: 344
Loc: Bradford, United Kingdom
Looks like you have a spyware infection which are typically not detected by antivirus programs as they are legitimate programs but are just a nuicance. They are typically installed when installing 'free' software from websites and most just track your surfing habits so they can display tailored adverts.

I recommend malwarebytes (malwarebytes.org) to get rid of rouge spyware and adware. Finds a lot of stuff antivirus programs miss and it's free. The paid version has realtime protection but the free one works great for one time removals. I used to use it when I worked in a PC repair shop & it removed a program that drove me nuts - random internet explorer windows would open diaplaying all sorts of crap even when I wasn't using the PC. All other programs failed to find it.

A word of caution though; back up your system first as malwarebytes removes even the most stubborn malware and if windows system files have been modified by malware it can delete the files somtimes rendering your system unbootable.


Edited by Arokh (05/10/12 03:55 PM)
_________________________
By fire and by blood I join with thee in the Order of the Flame!

Arokh's Lair - Drakan & Severance: Blade of Darkness forums - http://www.arokhslair.net


Top
#455152 - 05/11/12 02:54 AM Re: Virus on forum ? [Re: Arokh]
Xanlosch Offline
Prophet


Registered: 03/11/03
Posts: 3845
Loc: Germany, Saxony, Dresden
If you looked into HTML source code of someone forum page then you will find in the first line a javascript request to an external site (like in the screenshot). NoScript (Firefox addon) tells me, that some elements of this forum are blocked and the blocked elements refers to this external site. Looks like someone hacked the forum or inspected the code in some way.
_________________________
Xanlosch's Home - Fortombla hortomosch !
Kein Support via Foren-PM - postet mehr im Forum.

Top
#455153 - 05/11/12 03:21 AM Re: Virus on forum ? [Re: Xanlosch]
Raze Online   content
Angel


Registered: 03/10/03
Posts: 17326
Loc: Canada

I noticed that URL coming up in the status bar after I posted (the next time I checked for new posts).

Top
#455154 - 05/11/12 04:05 AM Re: Virus on forum ? [Re: Raze]
ForkTong Offline

Jack of all trades
Larian Studios




Loc: Krynn
Someone managed to insert one line in a config file of this forum. But that's all they could do, they couldn't read the file, or the database, just insert text into one file.

Thanks for the heads up, fixed it and I'm looking into ubbthreads security updates.
_________________________
Tweeting @forktong

Top
#455157 - 05/11/12 12:35 PM Re: Virus on forum ? [Re: ForkTong]
Arokh Online   content
Whelp


Registered: 04/22/11
Posts: 344
Loc: Bradford, United Kingdom
Ah right, never thought about looking at the HTML. Just that I see so many computers with similar problems I suspected spyware. Also I wasn't getting the problem on my system.

My forum got hacked a few years ago, the only problem I have is with spambots.
_________________________
By fire and by blood I join with thee in the Order of the Flame!

Arokh's Lair - Drakan & Severance: Blade of Darkness forums - http://www.arokhslair.net


Top
#455158 - 05/11/12 04:44 PM Re: Virus on forum ? [Re: Arokh]
melianos Offline
Orc


Registered: 12/03/09
Posts: 444
Was just this forum ^^

The popup doesn't show anymore.

Top
#455160 - 05/12/12 04:50 PM Re: Virus on forum ? [Re: melianos]
AlrikFassbauer Offline
Elder Druid


Registered: 03/10/03
Posts: 19505
Loc: Rogue Squadron
@Xanlosch : A tiny article in the current issue of the magazine "c't" hints towards a certain kind of forum hacking for using it to earn money through advertisements in a way ... I don't recall everything correctly anymore, especially since I'm very, very tired right now.
_________________________
When you find a big kettle of crazy, it's best not to stir it.
--Dilbert cartoon

"Interplay….some zombiefied unlife thing going on there" - skavenhorde at RPGWatch

Top


Moderator:  Lar_q, Lynn, Macbeth, Raze