Announcement

Collapse
No announcement yet.

Forum Trojan

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Forum Trojan

    Just thought I'd warn you guys about a forum / wordpress Trojan which is doing the rounds and hit all my sites.
    It's basically an sql injection and a file overwrite Trojan. In most cases you will visit the forum or wordpress blog and have no clue that malicious code is coming down to you through your browser. In my case I had several high quality and respected antvirus, spyware and adware tools in place and not one of them warned me. The only software that reports it is Avast antivirus. Google site checks, AVG, Norton, Symantec, spybot, adaware, comodo..... none of them detect this.

    So how do you know?

    If the forum seems unusually slow and you get a lot of disc activity and what seems like a browser freeze for a few seconds then that is one warning (and what I got). Alternatively you can get the adobe acrobat plugin fail and an error message pop up.

    The worst thing about this trojan is that in most cases it is getting onto a server through the hosts security and then attacks every site on that server. In my case the hacker hadn't bothered to try to go through my security and had attacked the php server itself. IX webhosting have been hit hard by this and over 1/3rd of all their sites are affected (they are a very big hosting company).

    Lastly you can view the source of a page you suspect and if you see the text "Yahoo! Counter" and then a load of gobbledy gook following it then that site is infected.

    In my case the trojan was ineffectual and fortunately did no damage to any of my site visitors but I think that was just incompetence of the hacker and a bit of luck.

    If you get attacked successfully by this trojan it can install various hacks on your machine, one of which is a key logger. It can also place a bogus sysaudio file in your windows/system32 folder. Be careful out here as this one is extremely prolific right now.
    Last edited by Ashley Davis; 01-02-2009, 10:46 AM.
    Sponsored by CSM, Optifuel


    Your RC Heli World

  • #2
    Thanks for the heads up.
    Adrian
    sigpic
    http://www.passrightmotoringschool.co.uk

    Comment


    • #3
      Will avast AV free version deal with this problem ash?
      I feel a download coming on :(
      It's the key logger thing that worries me in this day & age of online banking paypal & ebay etc
      Martin
      Martin
      Aka RCSlopesurfer

      Comment


      • #4
        now youve scared me ash mine is extra slooooow today!!:(
        Ron

        hobby-hangar.co.uk
        SWRCH-GO big or Go home!
        http://www.ultimatebuildandfly.co.uk/

        Comment


        • #5
          Hi Ashley

          Did you try NOD32 by any chance - I've noticed this forum being quite slow on occasions recently...

          Many thanks

          Graham
          Blade 400 / DX6i / Phoenix / Blade CX2 / mCX / MSR
          Proud Owner of 2 Eddie Gold stars

          Comment


          • #6
            Cheers for the warning I'll be carefull if surfing and using a PC....

            Installs hacks... okay glad I use the Mac once again....
            Mark
            www.uavaerialservices.co.uk
            BNUCs - Operations certified
            CAA - Permit for Aerial Work

            Comment


            • #7
              I don't know what versions of avast detect it but it's probably worth a try in the short term.
              Sponsored by CSM, Optifuel


              Your RC Heli World

              Comment


              • #8
                oh, I should mention rcheliaddicts is fine, the trojan is not here.
                Sponsored by CSM, Optifuel


                Your RC Heli World

                Comment


                • #9
                  maybe thats why yesterday for a short period when i did a google search most of the sites that came up were blocked by google saying that this site was not a trusted server shortly afterwards every thing was ok maybe google fixed it.
                  Trex 550e dfc :-)
                  Sab Goblin 500 Sport/dx8 and 9
                  t-rex 450s x2 /Raptor 50
                  blade 130x 3off/mcpx x2 180cfx times 2
                  multiplex acromaster 3d (great fun) acrowot,sonic wing,Graupner junior 2mtr glider,beast biplane .
                  kyosho spree small plank
                  bogey combat plank x2 woop
                  http://www.cuffleymfc.co.uk



                  brian OB2 proud owner of 3X E.G.S+ 1boggy special star

                  Comment


                  • #10
                    Win32:Daonol is the trojons name I think. Apparently that web host has been plagued by it for a good few months now.
                    Regards,

                    Jason
                    Futaba 12FG/ Knight 3D / 450Pro / Beam E4 and a whole load of gliders!

                    Comment


                    • #11
                      [quote=brin;218246]maybe thats why yesterday for a short period when i did a google search most of the sites that came up were blocked by google saying that this site was not a trusted server shortly afterwards every thing was ok maybe google fixed it.[/quote]

                      Naa Google made an error or someone did and a lot of sites flagged unsafe when they were actually okay

                      See this:

                      [url]http://news.bbc.co.uk/1/hi/technology/7862840.stm[/url]
                      Last edited by Disc; 01-02-2009, 11:07 AM.
                      Mark
                      www.uavaerialservices.co.uk
                      BNUCs - Operations certified
                      CAA - Permit for Aerial Work

                      Comment


                      • #12
                        Cheers for the heads up Ash,most of it went straight over my head LOL but i will keep an eye out for anything unusual.

                        I also had the Google search showing the `this site is not trusted` yesterday but it cleared pretty quickly.:)

                        Comment


                        • #13
                          [quote=Ashley Davis;218232]
                          Lastly you can view the source of a page you suspect and if you see the text "Yahoo! Counter" and then a load of gobbledy gook following it then that site is infected.[/quote]

                          The only yahoo element in here is for the "Yahoo Messanger", which members input and uses a small script to pop on the posts if selected.

                          Will keep an eye out.
                          Cheers
                          Stuart

                          Comment


                          • #14
                            seems fairly simple to get rid of if you have it!
                            [url]http://www.spywaredb.com/remove-win32-aol-sbuddytrojan/[/url]

                            Manual Win32/AOL.SBuddy!Trojan removal:
                            Kill process aynax.exe
                            Delete file aynax.exe
                            Ron

                            hobby-hangar.co.uk
                            SWRCH-GO big or Go home!
                            http://www.ultimatebuildandfly.co.uk/

                            Comment


                            • #15
                              Ron

                              I have just looked at the processes running on my Lappy and that isnt one of them so i assume i am safe.

                              Will keep an eye out for it and check Clares computer later just in case as that was running a bit slooooow yesterday but there is nothing sensitive on that one.
                              Last edited by ChrisB; 01-02-2009, 11:32 AM.

                              Comment

                              Working...
                              X