trojan/malware warning (merged threads)

Discussion in 'Website discussion' started by 92se-r, Jun 20, 2010.

  1. moka

    moka Moka Was Here!

    Joined:
    Dec 3, 2009
    Messages:
    901
    Likes Received:
    1
    Trophy Points:
    18
    Location:
    Los Angeles
    hi guys, please be patient with me here. I have been working on this for the past two or so days as much as i can, i have finally found the code that was injected into the website, it was tough and not easy at all to the point were i almost gave up on it, i had to sleep on it for a night and figured it out and i am in the process of removing the code and clearing everything up as i type this. the hackers were smart enough to have had some of the code actually "hidden" in the database so it would be tough to find in the first place.

    Thanks...
     
  2. mouse jockey

    mouse jockey i can't type the letter s

    Joined:
    Nov 22, 2007
    Messages:
    388
    Likes Received:
    0
    Trophy Points:
    0
    Occupation:
    molecular researcher
    Location:
    Just outside of La Jolla
    You guys that ride with Moka, buy him a few beers and pizza. I'll contribute to the fund. Thanks MOKA!

    tom
     
  3. b3rnard

    b3rnard Member

    Joined:
    Feb 9, 2009
    Messages:
    794
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Northridge (SFV)
    Sounds like the DB security is compromised. Glad you found it :beer:
     
  4. ManInAShed

    ManInAShed New Member

    Joined:
    Feb 14, 2009
    Messages:
    1,631
    Likes Received:
    0
    Trophy Points:
    0
    Occupation:
    Destroyer of worlds.
    Location:
    Yellowknife / Windansea
    Moka, thank you. Brewskis! :beer:

    I hope STR is payin ya in great heaps o schwag.
     
  5. fatguy1

    fatguy1 Active Member

    Joined:
    Jan 5, 2010
    Messages:
    1,077
    Likes Received:
    0
    Trophy Points:
    36
    Occupation:
    owner of auto detail co.
    Location:
    anaheim ca.
    Moka is the shizzzle........I'm gonna detail his bike for him
     
  6. Jeepdude

    Jeepdude Member

    Joined:
    Jun 14, 2008
    Messages:
    151
    Likes Received:
    0
    Trophy Points:
    16
    I am on my blackberry, hard to look through all the posts so sorry if I am asking something thst has already been answered.

    I picked up the bug on my computer...it is redirecting IE search results and Norton 360 is going nuts saying it is blocking intrusion attempts. I tried restoring to an earlier date, and that fixed the issue for a bit, but everything started acting up again shortly after.

    Does anyone know specifically what bug this is? What is the best way to eliminate completely?

    Thanks for the help!
     
  7. bluefirepictures

    bluefirepictures Almost Local Rider/Photog

    Joined:
    Feb 11, 2007
    Messages:
    948
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Poway ---> Long Beach
    Home Page:
    is this what you have?

    http://www.socaltrailriders.org/forum/pub/47000-dam-computer-virus-4.html#post692196

    it's 5 pages long but worth reading the linked page and the first page for screen shots of the issue.

    If it looks like this is what you have pm me your email. I'm only using str on my itouch. If I need to I can start up a "virus proof" set up on my pc and pm that way also
     
  8. gooseaholic

    gooseaholic Active Member

    Joined:
    Oct 21, 2007
    Messages:
    8,901
    Likes Received:
    14
    Trophy Points:
    38
    Occupation:
    Auto inspection
    Location:
    Orange,ca Via Seattle, WA
    Hum guess I can come on. I used explorer to open the page instead of firefox. My anti virius did pick up a trojan though. Looks like it cleared it however.
     
  9. Dino Brown

    Dino Brown Sir Smack-Alot

    Joined:
    Apr 27, 2007
    Messages:
    6,184
    Likes Received:
    11
    Trophy Points:
    38
    Update...

    -Moka deserves a HUGE round of applause!
    -Moka should consider a career in forensics
    -The website has been resubmitted (to Google) 8-[
    -Been waiting ALL DAY for Google to remove the warning :protest:
    -All we can do is wait!!!

    *If the warnings continue, please share that info with our members
    *If you no longer see a warning- share that info as well
     
  10. thomaswildchild

    thomaswildchild Active Member

    Joined:
    Feb 13, 2010
    Messages:
    2,389
    Likes Received:
    5
    Trophy Points:
    38
    Occupation:
    I am a Machinist
    Location:
    Fullerton CA
    Home Page:
    Thanks Moka! Ill buy you some grub next time we ride man.
     
  11. jerell

    jerell New Member

    Joined:
    Jul 10, 2009
    Messages:
    19
    Likes Received:
    0
    Trophy Points:
    0
    Occupation:
    Yes. I have one.
    Location:
    SoCal
    Moka = my hero.
     
  12. Jeepdude

    Jeepdude Member

    Joined:
    Jun 14, 2008
    Messages:
    151
    Likes Received:
    0
    Trophy Points:
    16
    :beer:
    OK...it looks like I was able to fix the problem. I didn't have any of the major issues described in what you had quoted, but I found an app that fixed the issue. As it turns out I had the TDSS rootkit installed on my computer causing all the issues. The website I found that hd the link to the fix had all kinds of reports of this issue. I am glad to be done with it.


    I will look for the Google warning to get cleared. STR is not nearly as nice when browsing on the blackberry.

    Thanks to everyone who helped clean the site up!
     
  13. Waldo

    Waldo Lebowski Urban Achiever

    Joined:
    Mar 26, 2007
    Messages:
    3,777
    Likes Received:
    0
    Trophy Points:
    36
    Location:
    Foothill Ranch... but my credit card lives at The
    Well, this is the first time I've been on the site in a few days, since first my home computer and then my work comp started blocking it. Ironically, my home laptop died at the same time, which I feared was an STR-induced virus. Nope - dead motherboard! Now I'm n my 10+ year old Mac G4, and let me tell you IE 5.2 in the modern world of web is not fun!

    So to quote from Marathon Man..."Is it safe?"
     
  14. jeffj

    jeffj Bloated Mountain B'hiker

    Joined:
    Jul 15, 2007
    Messages:
    2,617
    Likes Received:
    0
    Trophy Points:
    36
    Occupation:
    Bloated Mountain Biker
    Location:
    Castaic, CA
    All is not fixed. . . . .

    First of all, MOKA rules :bang:
    =================================
    Just an FYI: The social groups section is still FUBAR even worse than it was earlier. Earlier, it was just formatted strangely and would go to the first page from the beginning of the group by default, but it was possible to to go to the 'last page' to get to the most recent posts.

    Now, it's just blank :-k
     
  15. moka

    moka Moka Was Here!

    Joined:
    Dec 3, 2009
    Messages:
    901
    Likes Received:
    1
    Trophy Points:
    18
    Location:
    Los Angeles
    Hi guys, i would just like to point out that there will be some slight glitches here and there since the software has been updated. I have already contacted george about all these details and he will be responsible for fixing/updating whatever is broken.

    As of now all injected code has been removed and cleaned [-o-], database has been repaired and optimized. Forum has been updated, template needs some work to utilize the update completely. Google has been contacted twice already regarding the removal of the warning with no response yet, hoping i will be getting a response from them about this with in a day or two at most.

    my work here is done (I Hope) :lol: . Good Day! :beer:
     
  16. mfoga

    mfoga Intense Whore

    Joined:
    Apr 7, 2008
    Messages:
    8,147
    Likes Received:
    0
    Trophy Points:
    36
    Location:
    Moreno Valley
    I know you dont want to hear this but mmm its not gone.#-o

    I just came on and Kaspersky just denied
    6/29/2010 5:59:21 AM Denied: Exploit.JS.Agent.bav higesi.in/x/?src=world&id=crow&o=o//higesi Internet Explorer

    FYI I modified the link to people dont click it on accident.
     
  17. dstepper

    dstepper (R.I.P.) Over the hill

    Joined:
    Feb 2, 2005
    Messages:
    12,683
    Likes Received:
    34
    Trophy Points:
    48
    Occupation:
    www.themostprogram.com owner
    Location:
    Laguna Beach
    Home Page:
    NOD 32 also found something it did not like early this AM.

    Dean
     

    Attached Files:

  18. rustin

    rustin _

    Joined:
    Oct 21, 2009
    Messages:
    89
    Likes Received:
    0
    Trophy Points:
    0
    I had a problem too this morning:

     
  19. Cilantro13

    Cilantro13 ...

    Joined:
    Oct 30, 2008
    Messages:
    359
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Parkland, Florida
    STR is still sending scripts to my local machine as of right now... I would like nothing more than to wring the necks of the jerks who write these things.
     
  20. stinky180

    stinky180 Will make it Reign....

    Joined:
    Aug 6, 2008
    Messages:
    1,638
    Likes Received:
    2
    Trophy Points:
    36
    Location:
    Irvine
    bored at work today and decided to check out str with internet explorer rather than firefox.

    this looks like a new 'virus' on str. doesn't look the same as the previous stuff

    [​IMG]
     

Share This Page

Help keep STR alive, please click the donation button below