virus on svt?

Admin

Jack of all trades
Administrator
Joined
Dec 31, 1969
Messages
1,275
Location
Server Room
Hi guys, we have obviously been monitoring this thread and looking for a cause.

The servers have been scanned numerous times and have come back with a clean bill of health.

I think it's highly likely that the virus could be coming from one of two sources.
  1. Banner Ads
  2. Image code injection

I'm looking into both, but it would be incredibly helpful if you could let me know what pages are triggering the virus alert. Additionally, if you could save that page as HTML and email it to [email protected]
 

nickstang545

New Member
Established Member
Joined
Feb 15, 2008
Messages
135
Location
Somerset, Ky
I JUST GOT THE VIRUS AGAIN!!!!!!!! I was looking around trying to see where the alert is thinking i was now protected. But i was wrong. Went to THE MARKET, clicked on SVT focus and contour for sale section and got the alert. Went back to THE MARKET and got the alert again. I am now staying off SVTperformance until this issue is fixed. i cant keep doing this. Send out a mass email when the problem is fixed or something but for now im gone and warn others of the same. I love this site, but its getting expensive. Thanks.
 

pony racer

New Member
Established Member
Joined
Sep 13, 2011
Messages
18
Location
Bridgeport, Ct
a friend of mine said "DNS cache poisoning most likely"

its kind of hard to screen shot when its happening, it imediatly closes your browser (at least it did for me..

i wil almost bet it is coming from one of the banner ads.. that keep scrolling through.. as i was on a page for a good few minutes reading the thread when it happend..
 

BLKFOX

Active Member
Established Member
Joined
Apr 28, 2011
Messages
1,366
Location
Indiana
It was all throughout my files on my computer...I got a pop up warning on a few threads that I looked at, I just didn't think anything about it and backed out.
 

jumperjack

Active Member
Established Member
Joined
Nov 11, 2007
Messages
1,787
Location
central pa
I have had this blocked for the third time. I have Norton 360 on Vista 64 and I have been very happy with the product. Always blocks and detects before infecting any of my home computers and I pay 99 bucks a year for all 3 PC's. This is a screen shot of the message from Norton when it happened.
1d839e66.jpg
 

BLKFOX

Active Member
Established Member
Joined
Apr 28, 2011
Messages
1,366
Location
Indiana
Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8365

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

12/13/2011 9:32:30 AM
mbam-log-2011-12-13 (09-32-30).txt

Scan type: Full scan (C:\|)
Objects scanned: 252702
Time elapsed: 26 minute(s), 33 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
c:\Users\Josh\AppData\Local\rcq.exe (Trojan.ExeShell.Gen) -> 3996 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\.exe\(default) (PUM.HijackExefiles) -> Bad: (nB) Good: (exefile) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Josh\AppData\Local\rcq.exe" -a "") Good: (firefox.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Josh\AppData\Local\rcq.exe" -a "") Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Josh\AppData\Local\rcq.exe" -a "") Good: (iexplore.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Josh\AppData\Local\rcq.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
 

jumperjack

Active Member
Established Member
Joined
Nov 11, 2007
Messages
1,787
Location
central pa
Again

I just signed on and went to premium members section and BAM again. Something really needs to be done about this.
a49ba384.jpg
 

Admin

Jack of all trades
Administrator
Joined
Dec 31, 1969
Messages
1,275
Location
Server Room
We've made a number of changes to seek out and isolate the virus warning messages.

please let me know if you experience any issues.

Thanks,
ADMIN
 

pony racer

New Member
Established Member
Joined
Sep 13, 2011
Messages
18
Location
Bridgeport, Ct
Trojan:Win64/Sirefef.J
Trojan:Win32/Alureon.TK
Trojan:Win64/Sirefef.B


Malwarebytes' Anti-Malware 1.51.2.1300
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 8377

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

12/21/2011 6:44:07 PM
mbam-log-2011-12-21 (18-44-07).txt

Scan type: Quick scan
Objects scanned: 173083
Time elapsed: 2 minute(s), 32 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
c:\Users\Rick\AppData\Local\hvo.exe (Trojan.ExeShell.Gen) -> 4748 -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Users\Rick\AppData\Local\hvo.exe" -a "iexplore.exe) Good: (iexplore.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Rick\AppData\Local\hvo.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Users\Rick\local settings\application data\hvo.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
c:\Users\Rick\local settings\application data\xql.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully.
 

olefafl

Member
Established Member
Joined
Jun 2, 2001
Messages
293
Location
Sector 14
I just got hit also.
Not sure if its the same thing but something keeps closing IE.
Website 178.17.163.189
I had the last page of the wife/GF pic thread open, but also had some others open.
 

DaleM

ATACMS changing the game!
Established Member
SVTP OG 4 Life
Joined
Dec 27, 2002
Messages
23,823
Location
FlahDah man.
Doing a full Symantic scan now. WIN 7 had to take me back to earlier points where my computer was working. All is fine by scanning for SVTP AIDS.
 

Users who are viewing this thread



Top