Trojan Detected When First Going to NCWW

Status
Not open for further replies.

LeftyTom

Tom
Corporate Member
moz-screenshot.png
This alert came up after I had run anti-virus and SpyBot:

File name: okelkas.co.cc/okellas5/ hcp.php\{gzip}
I insert space before hcp
Malware name: JS:Downloader-AEG
 
Last edited by a moderator:

sawduster

New User
Robert
I had this last nite as well ( late nite ) , but not this morning
Avast! blocked it
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 
Last edited:

Mr. Bill

New User
Bill Hinds
Same problem last night. Norton blocked the [EVIL]Trojan.[/EVIL]
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; GTB6.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET CLR 3.0.30618; InfoPath.2; Media Center PC 5.0; SLCC1; OfficeLiveConnector.1.5; OfficeLivePatch.1.3; Tablet PC 2.0; .NET4.0C; .NAP 1.1)
 

Bill Clemmons

Bill
Corporate Member
Guess we're all feeling pretty glad we've got anti-virus protection. AVG caught mine. :eusa_danc

Bill
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9 ( .NET CLR 3.5.30729; .NET4.0C)
 

froglips

New User
Jim Campbell
Thanks, we ran a site scan and didn't find anything "bad".

So leaning towards a Google Ad.

If anyone happens to notice which ad it might be, let us know.

Thanks for the updates!

Jim
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 

Bill Clemmons

Bill
Corporate Member
Jim, I don't know if the one I had (okelkas.co.cc/okellas5/ hcp.php\{gzip}) was related to an ad. It came up as soon as I entered my password and hit 'enter' when I was trying to log in. Once I cleared the pop-up warning, it went to a blank white screen. I had to close out that tab and reopen ncww to start over.

Bill
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9 ( .NET CLR 3.5.30729; .NET4.0C)
 

CaptnA

Andy
Corporate Member
Same here. I typed my password and as soon as I hit enter it hit.
Fortunately my protection caught it.
I don't know enough about such but am sure our resident 'geek squad' will handle it~
Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)
 

JimmyC

New User
Jimmy
Just got one, Avast killed it for me.:eusa_danc
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; eSobiSubscriber 2.0.4.16; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C)
 

froglips

New User
Jim Campbell
I have temporaraly disabled Google Ad's.

Please report back ASAP if the virus warnings are gone.

We are losing revenue as long as this is not enabled, but it'd really help us narrow down the issue.

Thanks,
Jim
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 

bitbight

New User
Ray
Just got hit with a virus also, Norton blocked it for me. Looks like a nasty one:

Risk Name: HTTP Malicious Toolkit Varient Activity 16
Severity: High
Attacking Comp: okelkas.co,cc (85.114.143.47,80)
Attack URL: okelkas.co,cc/okelkas5/trafflit.php

The virus popped up when I opened a shortcut I have in my browser for NCWW. I had not even logged in.

Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10 ( .NET CLR 3.5.30729; .NET4.0E)
 

sawduster

New User
Robert
for what it's worth, mine happened as soon as the site opened . It is my home page but I still have to log in if I want to post. I did not log in but I opened a thread and when I came back it popped up again :dontknow: after 2 times it didn't happen again for that session . It did the same thing later when I opened my browser . This was all after midnight last nite. Today I have had no probs at all and have opened my browser twice
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 

sawduster

New User
Robert
I just got it again . Had not logged in yet, only opened the page
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 

lottathought

New User
Michael
It just happened to me also.
Anti Virus caught it...but we really need to figure out what is causing it
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.7) Gecko/20100713 Firefox/3.6.7
 

fergy

New User
Fergy
Annoying. It got me. I had an incident this week, my AV software flagged it but it got past. Now I can't update the AV software, nor can I update Windows. And I'm getting captured and redirected.

Now I'll have to do a complete reinstall of everything.
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 1.1.4322; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; Zune 4.0)
 

froglips

New User
Jim Campbell
I've run another full scan of our server, to no avail.

I've also got Google Webtools scanning us for Malware, but nothing has been found.

If you encounter this error, please try to save off the source code of our webpage.

You can send me a copy via PM or to my external email froglips111302@yahoo.com

Thanks,
Jim
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
 
Status
Not open for further replies.

Premier Sponsor

Our Sponsors

LATEST FOR SALE LISTINGS

Top