Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Possible virus on homepage?

AreelAreel Member Posts: 285

Everytime I go to the MMORPG.com homepage, my anti-virus software stops a file from being loaded onto my computer.  It insists that I need to reboot to remove it.  The name of the "infection" is:

Win32/MSA-935423!exploit

If it's not a virus, I'm sorry for wasting your time.

Seriously.
It's Are'el. This forum doesn't allow apostrophes in usernames.

«1

Comments

  • MaddieeMaddiee Member Posts: 43
    Yes every time im logging on as well, im getting a vrius alert.. Virus softaware is saying that a trojan horse or somethins being sent from this ip adress.
  • AdminAdmin Administrator RarePosts: 5,623
    I think we smashed this.  Thank you for the report!

    - MMORPG.COM Staff -

    The dead know only one thing: it is better to be alive.

  • shane910shane910 Member Posts: 359

      What do ya mean by "smashed it"?    Cause it is still happening I just had it happen twice.

      Is it a virus or just something of yours acting up?

     Thanks

  • drbaltazardrbaltazar Member UncommonPosts: 7,856

    ya i got microsoft live onecare on and its called a trjan downloader i think it might be a good idee to scann the site or wtv you do in those case it might be a funy guy that when he post it call us anyway now i raised my security and nomore so watch your site plz scan it when you get the chance cause i love this site ty .

    might be another name cause im translating its in french for me but its a trojan   (downloader or a word like that)

     

  • shane910shane910 Member Posts: 359

     Yeah I have onecare as well.  It says it is  Trojandownloader:Win3...

      Any help is appriciated, cause this is my fav site!

      Thanks

  • AdminAdmin Administrator RarePosts: 5,623

    Apparently there is a trojan outbreak that exploits a venerability in MS Windows related to the way ANI cursor files are handled (info here http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=141860).  We identified the infection almost immediately and deleted the script that was being fired from our web servers.

    What we need to know from this point forward:

    1) Are you still seeing this warning?  If so, are you still seeing it after forcing a cache refresh (Ctrl-F5 will do this)

    2) What page(s) are you seeing this on.  We only found it on our home page and removed the injected code ASAP.

    We are currently searching all of our servers for more instances.  Microsoft is working on a patch for this exploit, until then we are left with having to manually find and remove the trojan.

    - MMORPG.COM Staff -

    The dead know only one thing: it is better to be alive.

  • shane910shane910 Member Posts: 359

    I got it about 2 mins before my first post.  It was just on the home page from what I could tell, came up like an activex pop up.

       Onecare said it was quarantined, so I removed it now I am scaning will check to see if it happens again once it is complete.

  • drbaltazardrbaltazar Member UncommonPosts: 7,856
    cool you took care of it outch that was fast doesnt do it anymore ty mmorpg
  • shane910shane910 Member Posts: 359

      Yeah GJ guys didn't happen this time.

       I deleted the quarantined file then scanned and it was still there removed it again and now it is gone, so users may want to run an extra scan just to be safe.

  • ChicagoCubChicagoCub Member UncommonPosts: 381
    It's back again...on every page this time.
  • SWGLoverSWGLover Member, Newbie CommonPosts: 539

    I keep get a message from my firewall that it's blocked an intrusion attempt. The IP goes to Korea.

    Happens with every page.

  • vingvegavingvega Member Posts: 577
    Originally posted by SWGLover


    I keep get a message from my firewall that it's blocked an intrusion attempt. The IP goes to Korea.
    Happens with every page.



    Yeah..go figure.   I can see them now....

    Korean: "They no buy from our in game SUPA-MALL.  They just uninstall game when play 2 hour.  Send MMORPG the exploit! Then they buy from our SUPA-MALL in game store!"

     

     

  • tkobotkobo Member Posts: 465

    Oddly, i thought all that (the trojan warning, and intrusion warning)and the "microsoft data access- remote data services,download me"  message was just a poor taste april fools joke.

    When i went to see what the "trojan" was thru the info at "viruslist.com" it said "can't find virus record".So i just figured it was a bad april fools joke, and that the virus didnt actually exist.

    i could be wrong, but id swear its coming from the advertising banner at the top of the page.

     

  • ZorvanZorvan Member CommonPosts: 8,912

    "Microsoft Data Access - Remote Data Services Dat.... " from Microsoft Corporation". If you trust the website and the add-on and want to allow it to run, click here.....

    That's what I'm getting on every page.

  • AdminAdmin Administrator RarePosts: 5,623

    The worm hit us again, this time getting 2 templates (one in the header and one on the home page).  The good news is we are fast at locating now.  The bad news is that there is *nothing* we can do to stop the worm from re-infecting us until Microsoft releases a hotfix for our web servers

    We will do our best to stay on top of this and remove it as it comes in.  Being a large portal I think we are going to get it a lot - since it likely feeds off the browing history of those it infects...

    - MMORPG.COM Staff -

    The dead know only one thing: it is better to be alive.

  • FloppyFloppy Member Posts: 19

    just happened to me, its on more than just homepage though its every page.

    Win32/MSA-935423!exploit    my AV says the filename is 7517p[1].jpg

  • KazzerKazzer Member Posts: 648

    I was about to post about this, everytime i enter this site or forums, my firewall removes a trojan, sucks

  • ZorvanZorvan Member CommonPosts: 8,912
    Originally posted by Admin


    The worm hit us again, this time getting 2 templates (one in the header and one on the home page).  The good news is we are fast at locating now.  The bad news is that there is *nothing* we can do to stop the worm from re-infecting us until Microsoft releases a hotfix for our web servers
    We will do our best to stay on top of this and remove it as it comes in.  Being a large portal I think we are going to get it a lot - since it likely feeds off the browing history of those it infects...
    Well, it's not much of a problem for those of us who are comp savvy, but alot of the youngsters and some adults who aren't so quick to notice stuff will probably add it thinking it's another ActiveX download from MS or something. Maybe a large front page disclaimer until MS gets on the ball? Thanks for the info, Admin.
  • AlienovrlordAlienovrlord Member Posts: 1,525

    I'm seeing on the homepage and on the Post Message editing page (got it when first went to write this)

    I did cntl-F5 and that didn't get rid of it.

    Nice to know you folks are working on it though.

    Edit - also got it when was redirected to the thread after I submitted.  Seems to be coming up more often now.

  • PwndStarPwndStar Member Posts: 111

    I'm getting the warning every page I visit and also on the forum. NOD32 popups everytime on everypage.

    Even after clearing cache and doing force reloads.

    ----------
    currentlyplaying:
    age of conan

  • BahzBahz Member UncommonPosts: 182
    Same, even after try the cache refresh thingy
  • skywisenightskywisenight Member UncommonPosts: 348
    May I take this moment to mention my browser of choice, Firefox, which seems to not have this problem, along with many of those pesky activex issues.



    You know, just want to spread the love.
  • pompey606pompey606 Member UncommonPosts: 439
    my antivirus has started going crazy on the site now, it was fine yesterday

    image

  • scrow76scrow76 Member UncommonPosts: 2

    Same -on this file

    7517p[1].jpg  - Exploit-ANIFile.c - trojan

     http://vil.nai.com/vil/content/v_141860.htm

    Cas

  • AreelAreel Member Posts: 285
    Well, on the plus side, it doesn't seem to be a very good trojan, as most of our anti-virus software is catching it immediately.  It's more annoying than damaging.

    Seriously.
    It's Are'el. This forum doesn't allow apostrophes in usernames.

Sign In or Register to comment.