Go Back  RCU Forums > RC Airplanes > Extreme Speed Prop Planes
 Virus/Trojan problem - read >

Virus/Trojan problem - read

Community
Search
Notices
Extreme Speed Prop Planes Discuss the need for speed with fast prop planes (Screamin Demon, Diamond Dust, Shrikes or any REAL sound breakin'''' plane)

Virus/Trojan problem - read

Thread Tools
 
Search this Thread
 
Old 06-06-2005 | 02:00 PM
  #1  
bob27s's Avatar
Thread Starter
My Feedback: (19)
 
Joined: Apr 2002
Posts: 5,576
Likes: 0
Received 0 Likes on 0 Posts
From: Cleveland, OH
Default Virus/Trojan problem - read

I thought I would post this here, as well in the Jett support forum....... since we have a great number of Jett engine owners that frequent this forum.


If in the past week you visited the Jettengineering.com web site, and in some way were affected by a trojan/virus/redirection type of VERY ANNOYING software..... I offer my apologies.

This predetory fecal matter was in no way intentional by myself (webmaster) or by Jett.

The web site server and host was hacked into last week, and we did not notice the problem until this past weekend when some 'hate email' started streaming in.

In most cases current virus protection and spyware protectors were able to stop it. In some cases, it made its way on through and messed up a few systems.

I spent most of the day today (June 6th, 2005) cleaning off the web site, and restoring the web site from a backup. It is currently clean, and the predatory crap is gone.

I have taken the precautions I can on my end to avoid a repeat problem.

Apparently a lot of sites have been hit lately. I guess it was just our turn.

I apprecaite your understanding.

Bob Brassell
Old 06-06-2005 | 02:18 PM
  #2  
Flyboy Dave's Avatar
My Feedback: (21)
 
Joined: Mar 2002
Posts: 13,864
Received 10 Likes on 10 Posts
From: Pinon Hills, CA
Default RE: Virus/Trojan problem - read

Bob....it wasn't the W32.Wallz virus, by chance ? I got hit with it. []

Dave.
Old 06-06-2005 | 02:34 PM
  #3  
bob27s's Avatar
Thread Starter
My Feedback: (19)
 
Joined: Apr 2002
Posts: 5,576
Likes: 0
Received 0 Likes on 0 Posts
From: Cleveland, OH
Default RE: Virus/Trojan problem - read

Im not 100% sure what it was. It came in as Generic.Dropper.b and Qhost.apd and some associate files. I had that and Alisa stuck on my machine here at work. AdAware got rid of some of it, took some registry edit to clear up some too.

It re-set my IE homepage to yoursearch.ws and also displayed the following "windows warning" message at the bottom of the screen (Which takes you to an anti-spyware sales site). Clearly, not windows generated.

Worst part, is even after it was cleaned, the registry entry kept re-loading it each time on start-up.

Anyone out there who can identity what this garbage was, Id be pleased to know and understand more about it.

Bob

Attached Thumbnails Click image for larger version

Name:	Mk27669.jpg
Views:	16
Size:	55.9 KB
ID:	281216   Click image for larger version

Name:	Om32949.jpg
Views:	18
Size:	35.3 KB
ID:	281217  
Old 06-06-2005 | 03:40 PM
  #4  
Flyboy Dave's Avatar
My Feedback: (21)
 
Joined: Mar 2002
Posts: 13,864
Received 10 Likes on 10 Posts
From: Pinon Hills, CA
Default RE: Virus/Trojan problem - read

No, Bob....it was a different bug. It keeps re-registering too. I found
out MSN has some "Blue Tooth" spyware in it, that you can't get rid of.

I wasn't implying that I got it from Jett....I didn't even go to Jett. I too
employed the Microsoft spyware this time.

See that "MSN Service....amsnmsgrs.exe" ? According to the man at
Microsoft, that ain't supposed to be there in my Microsoft Windows run
files. I can delete it, then Norton will say it blocked an intrusion attempt,
but go back to the run files....and there it is again. []

I tried to dump MSN, I don't know if it's really gone or not. MSN, like AOL
tries to take over your whole life. [X(]

Dave.
Attached Thumbnails Click image for larger version

Name:	Nl29008.jpg
Views:	13
Size:	39.1 KB
ID:	281245  
Old 06-06-2005 | 03:57 PM
  #5  
SSAN's Avatar
Senior Member
 
Joined: Jan 2002
Posts: 524
Likes: 0
Received 0 Likes on 0 Posts
From: Tempe, AZ
Default RE: Virus/Trojan problem - read

Hi Bob,

No problem at all! I knew there was some virus issues on Dub site as every time I go there, I get many of them in my system. Fortunately, my virus protection captured all of them and deleted it. I thought about sending an email to let you know, but I figure, since you are the web master, you probably already knew.

I'm glad it's all cleaned up now.
Old 06-06-2005 | 04:16 PM
  #6  
bob27s's Avatar
Thread Starter
My Feedback: (19)
 
Joined: Apr 2002
Posts: 5,576
Likes: 0
Received 0 Likes on 0 Posts
From: Cleveland, OH
Default RE: Virus/Trojan problem - read

The site has not had any know problems in the past. My server has run pretty clean. The firewall has done a good job keeping folks out. This event started on May 28th from what I can tell. A handful of files were altered on the site, most notibly the home page.

My research today seems to indicate it may have been due to a HUGE security hole in a PHP bulletin board program I had loaded ages ago in 2001. Has not been utilized, and was loaded just for a test. But apparently there was a big problem, recently discovered, which allowed folks access through the BBS into some very critical host/server files and functions.

http://www.phpbb.com/phpBB/viewtopic...1dd1ec6ce6b919
Old 06-06-2005 | 07:41 PM
  #7  
RC-Captain's Avatar
Senior Member
 
Joined: Nov 2002
Posts: 2,981
Likes: 0
Received 0 Likes on 0 Posts
From: RCHill, NJ
Default RE: Virus/Trojan problem - read

May I offer some helping advice. To begin I have had to reload my windows ME 3 times and lost my wonderful windows XP due to these annoying viruses.

But after going through such a tedious ordeal I learned an incredible amount of information on how to fix these things.

Looking at what you guys have shown , this type of virus is an automatic web search service . the only way it gets on your computer is from a screen that tells you to push yes to continue. Well DON'T push yes hit ESC key instead or F4 I believe to close the window.

The best way to fix or get rid of these files is to start your computer in SAFE MODE. If you don't know how ask. Then go to your registry (startup) and un-check all of the files you see with IE. SYSTEM32 in the file name. Also look for anything that has the word search, help, or spool in it and un-check it under the system config /start up tab.

Then restart your computer in normal mode and see if you have the same problems if yes go back and look for more stuff in the start up that shouldn't be there. Safe mode only loads the files needed to run the computer so your screen may look weird but your computer will run as usual.

I know this works because I use to have to close hundreds of MSN windows when surfing and now NONE of these windows open by themselves when I am surfing or idling while on-line using AOL.

Good Luck
Old 06-06-2005 | 10:19 PM
  #8  
Sukhoi_Madness's Avatar
 
Joined: Oct 2004
Posts: 579
Likes: 0
Received 0 Likes on 0 Posts
From: Birmingham, UNITED KINGDOM
Default RE: Virus/Trojan problem - read

I have just visited the Jett site and the issue appears to still be there...

On at least this page... www.jettengineering.com/ engines/bse30.html

The Trojans still exist... Norton got them all...

I did not go further into the site and I entered originally vie a Google picture search...

Read this straight after by coincidence.

Matt
Old 06-07-2005 | 07:21 AM
  #9  
bob27s's Avatar
Thread Starter
My Feedback: (19)
 
Joined: Apr 2002
Posts: 5,576
Likes: 0
Received 0 Likes on 0 Posts
From: Cleveland, OH
Default RE: Virus/Trojan problem - read

ORIGINAL: Sukhoi_Madness

I have just visited the Jett site and the issue appears to still be there...

On at least this page... www.jettengineering.com/ engines/bse30.html

The Trojans still exist... Norton got them all...

I did not go further into the site and I entered originally vie a Google picture search...

Read this straight after by coincidence.

Matt

Thanks...... good catch......

What a friggin mess......

Every single html and php file was corrupted. All have now been restored. Annoying!
Old 06-07-2005 | 08:37 AM
  #10  
Blade47's Avatar
Senior Member
 
Joined: Jun 2003
Posts: 1,216
Likes: 0
Received 0 Likes on 0 Posts
From: Whitehorse, YT, CANADA
Default RE: Virus/Trojan problem - read

If you have a virus or Trojans that are replicating after your system seems to have been cleaned ( on Win XP ) ..go to properties of your computer and turn OFF system restore ... run your anti virus program ...reboot and run one more time and leave the restore off.

the little buggers hide in there and will restore after each boot... By turning off the restore windows will delete ALL restore points ...at a later date when you turn on it will rebuild a clean point ....hope this helps

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.