Jump to content
SAU Community

Recommended Posts

its the reverse placebo effect.

there used to be the problem on the board, hence this topic, but its since been fixed. however some people dont realise its been fixed, and hence are thinking its somehow still happening :(

God I hope so... I've had enough of working on SAU to last me another 6 months, and I'm still not finished. :D

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302766
Share on other sites

  • Replies 95
  • Created
  • Last Reply

Top Posters In This Topic

Fingers xed... I saw the boards down today at work, logged on later in the day no problems.

Just logged on at home (11.28pm, 3/7) and I had the exploit blocked (I'm hoping from a locally cached version of the page, but I haven't logged on from here for a week?)

Anyway, I know you'll still be monitoring it - just thought I'd let you know.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302820
Share on other sites

it will be a patching problem not entirley on the IVB side. Wait for dicrosoft to patch it properly Ie wise and Ivb to run out the kink's i bet over a few weeks . IVB the will be still very worried about it and a few features will no doubt be not functioning for saftey ! .

Microsoft let out a Doossie with one of there upgrades that found pirate copies of Xp . since then alot of people are unpatched and there are lots of conflicts.

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302830
Share on other sites

No, haven't received it before... Was only reading about the Billion boards being affected by it this morning, didn't even blink as to why the SAU boards were down (stocktake was a b!tch.)

Silly me didn't check the timestamp in the temp file before it was removed... I've reloaded the page & IE many a time anyway - hasn't reappeared.

Who knows, peculiarity of Apache or one of the various proxies I'm running through I guess...

(Edit: Ugh... bloody thing is still running, back soon.)

Edited by cooks44
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302902
Share on other sites

Got it today at work after the site had been down... and just got it now at home. Each time my McAfee seems to have caught it, although there is a HEAP of HDD activity for quite some time and the computer slows down... (and no, I wasn't running a virus scan)

So something still creepy in there guys,

M

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302952
Share on other sites

The reason this security alert comes up is because of an exploit used on IE.

This utility released by Norton (antivirus software developers) can be used to disable windows scripting... if at any time you find that you need windows scripting enabled (if one of your apps won't work) you can use the same utility to re-enable it.

http://www.symantec.com/avcenter/noscript.exe

Its recommended that you turn off scripting so that no malicious websites or people can force your browser to download and run trojans/worms.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2302981
Share on other sites

this is more an exploit being found By your Av than Trojans loading off the SAU Page slowing down your systems hard disk.

It doesn’t mean that a Trojan is loading ... It means it has vulnerable scripting and it is possible.. < this is the message to get out !

I highly doubt that anyone got infected as it was just a generic warning from the AV reading the scripting.

Prank i would try to word a statement that states it is the vulnerability that has been found, Detected by AV not a virus or Trojan.

I am Guessing a bit there because i don’t know if anyone got infected but that’s my guess in the confusion !

For someone to achieve this they would need access to private FTp to embedded the server or an identical mirror linked with the embedded server.

Most members would have this Short cutted so the mirror would not work either.

If by the slightest chance it was mirrored then its going to jag non members surfing from an engine.

Tell the whingers that it is there old Av update that is detecting the Script.

and to please be patient.

if you can Categorically state that nothing dloaded from the page and infected anyone then this will help out a lot with the complaints you may get....

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303336
Share on other sites

GET FIREFOX or OPERA instead of the IE browser.... ITS not the SAU board, its because the SAU board is Invision and Ie has a big hole in it ... the same will happen on any Invision Board using an Ie browser until Microsoft do something .

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303398
Share on other sites

Hi guys,

Just in case it helps, the offending file that McAfee pointed at was called 0day.htm

This file goes to http://196.regvista.com/0day.htm

Maybe this would help to sniff it out?

Immediately after McAfee finds it and cleans it, McAfee is disabled! And there is a c$#@load of hard drive activity for several minutes..

Cheers,

Matt.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303417
Share on other sites

yeah i got the trojan downloaded to my home machine over the weekend. i removed all the crud using adaware but my pc is now a bit fuxored unfortunately. AVG is broken so i've tried uninstalling it and installing norton but cant get through the install without it dying. :D

anyone got any advice? :P

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303473
Share on other sites

I thought it had gone, but alas, I just got another warning from my a/v (Avast pro).

Seems to identify it as WIN32 Trojano ...

My a/v catches it and terminates connection before there's any consequence.

This only happened for the first time on Friday I think.

Has never happened before, so I cant imagine, as previously mentioned by someone, that it's Invision, unless SAU has just changed their system over.

Also, had no old cache, i clean it almost daily, and IE is set to load new page everytime (no caching).

Anyways, not a big deal on my end, but perhaps might be helpful to track down the issue.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303490
Share on other sites

i am looking at all the manual ways now....

... For a try install norton in Safe mode ... Or systems restoring before hand and repeating...

Looking into this more now I see its a fairly old exploit reworked . So until more info unfolds its a bit hard.

F8 key hold down on reboot until you get Safe mode ... then run the the install. Its tricky because you have to some how get the Av to update in safe mode

My AV rips it straight out !!! Pm me if you would like to try it .

Munkyb0y Av only finds it once its been reported. the exploits can function and go on for months before this!

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303497
Share on other sites

GET FIREFOX or OPERA instead of the IE browser.... ITS not the SAU board, its because the SAU board is Invision and Ie has a big hole in it ... the same will happen on any Invision Board using an Ie browser until Microsoft do something .

This is not an option for me

cheers.

Hi guys,

Just in case it helps, the offending file that McAfee pointed at was called 0day.htm

This file goes to http://196.regvista.com/0day.htm

Maybe this would help to sniff it out?

I just got the identical thing.

I've been browsing SAU for 4 hours now (from the uber protected work PC). And the Norton box just fired up @ 10:44 with the same above ^^^

I've flushed ALL the temp files etc etc etc.

And ive just done it again.

Will report back if it get it again

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303506
Share on other sites

Hello again.. this is a test

I am using ie 6 NO AV and nothing is connecting , Downloading or Executing .

As i mentioned before to Munky these exploits are oftern not reported for months so everyone is oblivious until there is an Alert.. Then poo fly fanward forth!

this ie exploit can be used so braodly so i still think the Sau board is fine now upgraded and more the users buggy infected Pc's ,its just that this situation Alerted alot of people that they had a problem....

For all the people with Disabled AV Try this link to actualy see what state your PC is in. Not sure if the demo will clean it! My guess is it will :D

http://www.trendmicro.com/hc_intro/default.asp

Ie is Every uni students wet dream to practice code on .... Its also the most cloaked process giving people the impression that its fine because its always running . DANGEROUS

I am still working on the manual removal... It would be good to look at the old unpatched pages ???

Bac soon ish!

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/2/#findComment-2303636
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



  • Latest Posts

    • I was using the wiring diagram I have So 12.74V is coming into the rear Fuel Pump relay as I measured.  When I turn the key to ON im getting 0.6V to the Fuel Pump plug; which i assume is backfeed voltage and doesnt include the 12V from ignition power.  The rear relay is working and being triggered.  From the diagram I clearly see the rear relay 80 = Rear Relay going into the Body/H loom (R-27) 27 = Fuel Pump plug going into the Body/H loom (T-20) 40 = Short Connector (R-27) I'm reading 12.74V on the blue/black wire which is the power for the Fuel Pump   From this diagram I can see the Ignition relay goes into the front and up to the ignition  2 = Fuel Pump Relay <1M> (R-27) 37 = ING Relay <1M> I started from the pump using this reference Which the way I read it (referencing Nissan wiring color codes) is: Pin Wire Color Function 1 B/P (Black/Pink) Ground 2 L/W (Blue/White)        ECU Trigger 3 SB (Sky Blue) Fuel Pump 5 L/B (Blue/Black) 12V Constant Tested SB to SB on Fuel Pump for continuity - confirmed Tested negative on Fuel Pump to 12V battery and L/B - confirmed 12V Pulled the relay putting 12V between Pin 1 & 2 and testing continuity on Pin 3 & 4 - confirmed relay   So that has me looking at this part of the circuit to understand whats happening here...and im still confused. From best I can tell; the disconnect is back to my previous diagram; between Ignition Relay and Fuel Pump Relay...which yet again; afaik is where the immobiliser should.    Thats what I was trying to explain to GTSboy; im not trying to fix it myself; yet I seem to have to get a Masters in Electrical Engineering (while im busy doing my actual job of DevOps & Cloud Engineering) somehow.  I just wanted more expert opinions; or more so that what I tested is correct and proves it to something around that area; to go back to the alarm tech (for a 3rd time) that he needs to fix it. He keeps telling me its not the alarm. He lives on the complete other side of the city so i understand not wanting to make a trip but as I said before if its the alarm it should be up to him to fix it. But he's adament its not; even though I pointed out the FP was immobilised through the original alarm. To my mind; it seems that the ECU is sending the signal; but the ignition is not getting 12V down the line.       
    • Maybe also really stiffly sprung track cars. Get the inside wheel up in a corner and all the fun stops. Also me sometimes (rarely) when I have to stand on the brake to convince the diff to drive the wheel that is still on the ground when I'm trying to diagonally get over severe driveway entrance, etc.
    • I feel like I'm missing something. You had an authorised installer come out and install a new alarm. Post install the car doesn't start, and you aren't getting the installer back to fix what they did wrong?
    • So either way it is gearbox out and look what is wrong?  I know about the input shaft bearing. Even before swap/new clutch the it sounded exactly like this: So is that inout shaft bearing or the other was installed backwards?  And can some please tell me the part number for that input shaft bearing? The gearbox is small box from R34 N/A and number is FS5W71C. Thank you  
    • I am yet to see anyone ever regret a quaife or helical. ...other than drifting/skidpan duties. I kind of want to upgrade my factory helical with a Quaife (but really it's not ultimately that different, and is a MASSIVE UNDERTAKING), that's how good the hype is about them, that I want to try them 'just to see'  
×
×
  • Create New...