Jump to content
SAU Community

Recommended Posts

I thought it had gone, but alas, I just got another warning from my a/v (Avast pro).

Seems to identify it as WIN32 Trojano ...

My a/v catches it and terminates connection before there's any consequence.

This only happened for the first time on Friday I think.

Has never happened before, so I cant imagine, as previously mentioned by someone, that it's Invision, unless SAU has just changed their system over.

Also, had no old cache, i clean it almost daily, and IE is set to load new page everytime (no caching).

Anyways, not a big deal on my end, but perhaps might be helpful to track down the issue.

We use Avast on our server (Avast Server Edition) at work and yeah just about every trojan they find it labels it as a win32:trojano.

GET FIREFOX or OPERA instead of the IE browser.... ITS not the SAU board, its because the SAU board is Invision and Ie has a big hole in it ... the same will happen on any Invision Board using an Ie browser until Microsoft do something .

I have to stick with IE for compatability reasons and yes it appears to be SAU as other Invision Boards I've been to today, aren't affecting any of my virus scanners. The trojan doesn't appear as often as it was late last week, as I've only seen it twice in the 20 odd times I've either refreshed or been to the board today.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303704
Share on other sites

  • Replies 95
  • Created
  • Last Reply

Top Posters In This Topic

ok .. i have found a way to trigger it on cue to dload with IE

Its intermitant depending on how you navigate your Ie browser

I think this is better closed up again (forum) because Patching is not sufficent yet until its understood how it loads and got into the code. people that dont understand things will get all nasty again.

So better closing the hole again so they cant blame...

I am no mod or admin here so i can only reco what i would do gang.

later

back in a few hours ish!

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303914
Share on other sites

i am looking at all the manual ways now....

... For a try install norton in Safe mode ... Or systems restoring before hand and repeating...

Looking into this more now I see its a fairly old exploit reworked . So until more info unfolds its a bit hard.

F8 key hold down on reboot until you get Safe mode ... then run the the install. Its tricky because you have to some how get the Av to update in safe mode

My AV rips it straight out !!! Pm me if you would like to try it .

Munkyb0y Av only finds it once its been reported. the exploits can function and go on for months before this!

thanks mate, i will try this stuff tonight when i get home. i'm a bit noob with security, viruses etc. :nyaanyaa:

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303989
Share on other sites

Whoa ...Well Done Prank!!!... its gone :) i cant even get it to trigger now ...

For those that did get infected and AV crashed, try that link i splashed before. It did clean it surprisingly for free!

If your anti virus couldn't get rid of it and the trojan got round it, you need to either 1)update your virus scanner a damn lot more or 2)get a decent virus scanner. If some free net thing can get rid of it and a PC based one can't you've got security problems :blink:

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2304371
Share on other sites

hey guys mines still going through that 169vista site or whatever when i bring up sau homepage. and saying trojan infected yada yada

how exactly do i make sure ive deleted all the old internet files/cache and whatever else needs to be done to get rid of it for good?????

its giving me the shits at the moment

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306121
Share on other sites

Re occur! this is what i was worried about ...

Prank. i mentioned in your PM my bigger fears of how this may be happening.

Until you find whats loading it or re Writting, it will keep coming bac unfortunatly.

Dam i would luv to be a NEt admin at the moment ... i would Argue the Mozilla and be a hero in the work place by doing nothing !

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306194
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

triggered virus several times just then over the last few min's to see .

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124658&hl=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124503&hl=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...s&lastdate=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...194entry2306194[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...24535&st=40[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124803&hl=[2]

It re writes the code which is why i think what i think in Pranks PM. i am not going to Blurt it out here !

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306215
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

triggered virus several times just then over the last few min's to see .

Yup, I afraid its still in there guys. Got it just now as I clicked to read this thread...

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306262
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

Thats nice...

Still doesnt detract from the fact that it is fine for me, which... is what i initially said.

Doesnt mean its right for other people, i never said it was right for anyone else.

Im just giving more feedback on what ive already said

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306273
Share on other sites

Comes about 50% of the time. I can see IE trying to access something from http://196.regvista.com through the IFRAME and so I just hit stop and reload. Usually on the second or third attempt the page loads without the trojan.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306451
Share on other sites

Still had a major issue after you guys said it was removed, crashed my computer even after a complete cache refresh, spy wear check and removal as well as a full virus scan.

Virus would not allow to transfer documents, wouldn’t allow to run any programs in hope of finding the problem and removing it again.. Kept getting access denied, you do not have permission when trying to open Anti virus program, spy wear remover ect.

We ended up having to do a full system recover, which has seemed to fix it now. What ever happened, was worse the seconded time around.. An came from this site at some point.

Jus thought I would let you guys know.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306608
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



  • Latest Posts

    • My experience with Rising Sun Exports Before agreeing to the sale I tried to do as much research as I could (obviously), his Facebook reviews are 98% and he goes Live at least once or twice a week. I contacted 2 people in the UK who had used him for their imports, both had positive feedback. His explanation and talk through of the import process was thorough, answering any query no matter how stupid it was. It felt as soon as the money was sent, communication dropped off. I asked for shipping updates every 2 weeks or so, not wanting to pester him, he never had any updates. I wasn't informed the car had been dropped off at the port, I only found out by his Facebook story. I asked for the photos taken at the port, knowing he would need some for insurance purposes. I received a few 5 second clips and that's it. When asked again, he said his staff had them. Weeks later I asked again, he tells me he doesn't have any, but does have 50 photos from the original advert. I never received them. I eventually got the documents sent via WhatsApp after I mentioned the port was requesting them. I purchased a CarVX report, to find out the vehicle is a Grade R with recorded accident damage, first recorded in 2017 when it was first auctioned. He never told me the grade, then again I didn't ask. His response was "Grade R means nothing, it wasn't chassis damage". Still, I would have liked to have been informed about it. Jon prides himself on being open and honest when it comes to inspecting cars, it's his main job doing so at the auctions for customers. When the vehicle arrived in the UK I noticed a few little cosmetic issues. It's a 21 year old car so it wasn't going to be mint condition. The side skirts are cracked on each corner and the sealant is failing. The front grill on the bonnet/hood isn't secured very well, mounting studs are missing. Both minor things, but again, it would have been nice to be told. During a Facebook Live walk around video of the vehicle, he mentioned it has a front Whiteline anti roll bar/sway bar. While on the inspection ramp, I noticed the stock item has been installed. When first questioned, his response was "the ARB? Switched? Since when, it never had them". Since sending video and photo evidence I've not received a response. I'm probably being over critical of the overall condition of an old car, but all I wanted was honesty (which he claims to have). I'm aware I wasn't his only customer, he's busy doing XYZ but other reviews praise him for great communication with regular updates and photos, I felt I didn't receive the same treatment. 
    • I was able to get some underside photos while the car was on the ramp The suspension is all Altezza/IS200/IS300 so getting part's will hopefully be less of a headache
    • Welcome to my 2004 Toyota Mark ii IR-V Fortuna (series 2) With a 1JZ-GTE powerplant under the bonnet (hood) it'll give me plenty of scope for power upgrades. For those who aren't familiar with imports, the 1JZ-GTE is a 2.5L 6 cylinder VVTi engine with a single turbocharger. This has the factory R154 5 speed gearbox, along with a aftermarket 2 way LSD differential (brand unknown). Under the arches are a set of CST Zero 1 alloys, 18x9 +30 225/40 up front and 18x9.5 +15 265/35 on the rear. The car was quite low in Japan and there's evidence of the wheels catching the rolled arches/fenders. The tyre's aren't great so I'm in two minds whether to replace both or just the tyres and put up with the wider wheels on the rear. The car still uses stock brakes with the addition of some braided hoses. The exterior is stock with the exception of a BN Sports front bumper and a replacement Fortuna grill  Moving to the interior, the steering wheel has been replaced with a dished MOMO steering wheel (which will get swapped for my Momo Tuner for the time being) Defi Link Gauges are mounted above the climate controls and on the A pillar, the Oil Temp,Oil Pressure,Water Temp and Boost gauges should help with spirited and track driving  The stock seats have been replaced with some retrimmed Recaro bucket seats. Being a larger build these are a little snug, unfortunately the orange isn't for me so I'll look into replacing these down the line. Other modifications include a twin plate clutch, Blitz intercooler, Evolve alloy radiator, a stainless exhaust with decat, HKS EVC-S boost controller and coil overs
    • Apologies for the long read My R34 GTT was up for sale at the beginning of spring due to a few repairs creeping up. The strut tops needed replacing, roof and bonnet (hood) painting (yay for 3 stage pearl) and the underside stripped and treated. I sold the car which allowed me to be in a much better place financially. Leading up to the sale I was already thinking about the replacement. In an ideal world it needed to be a good all-rounder. Something I can mess around with, modify, do track days, do the school run, go on long drives etc.  Options included but not limited to... Laurel C35, Evo 8/9, Civic FD2, Impreza Hawkeye, Aristo and even an Audi S4 Avant (I've already got the Mazda 6 wagon). But there was always one car at the top of the list The Toyota Mark ii JZX110 I found an advert on a Facebook group for an example in Japan, from a seller called Jon at Rising Sun Exports. A few messages back and forth and Jon calls me from Yokohama one morning (or afternoon in his case). He briefly explained the import process, the costs involved and a repeat of the advert. After much deliberation, the price was agreed and the sale was locked in. I've never imported a vehicle so I jumped into the unknown head first. The money transfer was completed through wise.com (fees apply), very easy to use and the money was with him within a day or two.  The car suspension was raised for the vessel and the car dropped off at the port. It was 7 weeks later when the bill of lading was received and the freight invoice sent to me, followed by the export certificate a couple of days after (both digital copies) In the mean time the port had been in contact. I needed an agent to deal with the NOVA (notification of vehicle arrival) along with the tax/duty invoice, this was £75.00. The port also had a fee of £100, I'm guessing to cover the cost of the 10 day 'free storage' and for moving the car off the boat etc. They need a copy of the vehicle invoice, freight invoice and export certificate to allow the vehicle to pass through customs. The vessel arrived on Tuesday 5th August, the tax/duty invoice was generated and sent over. This is generally tax 20% and duty 10% of the vehicle value. Although the invoice came in at a higher amount than I had calculated. Once HMRC had received the payment the vehicle could be released from customs. I thought once the tax/duty was paid you could collect at any point, that's not the case. Your agent will need to book a collection slot, I requested Thursday 7th which was accepted, with a 9:00am slot allocated. It was a 5:00am start from Norfolk heading to Southampton. We eventually found the compound, upon presenting the bill of lading and some ID they released the car (they drove it out of the compound to the front ready for us to load up). The email from the port stated each slot had a 10 minute window, which seemed abit farfetched but the staff said it's not a strict rule. We were there for approx. 30-40 mins in total. A week prior to collecting I contacted my garage and explained the situation, I was able to get an inspection slot that afternoon. For the registration, DVLA require the car to be insured, for this I used a company called Adrian Flux who can insure the vehicle using the VIN number. 
    • Hey guys, looking for these side skirts if anyone can help me out. 
×
×
  • Create New...