Home Menu

Site Navigation


User Tag List

Reply
 
Thread Tools Rate Thread Display Modes
Old 08-20-2012, 03:06 PM #46
nevada's Avatar
nevada nevada is offline
Senior Member
 
Join Date: Jun 2012
Location: washington
Posts: 4,990
nevada has a spectacular aura about nevada has a spectacular aura about nevada has a spectacular aura about
nevada nevada is offline
Senior Member
nevada's Avatar
 
Join Date: Jun 2012
Location: washington
Posts: 4,990
nevada has a spectacular aura about nevada has a spectacular aura about nevada has a spectacular aura about
The Virus problem on this site is getting out of control

maybe these can be merged?
theres atleast one other recent theread out there aswell.
nevada is offline   Reply With QuoteReply With Quote
Old 08-21-2012, 04:04 PM #47
jrm's Avatar
jrm jrm is offline
Senior Member
 
Join Date: May 2010
Location: Nor Cal
Posts: 1,636
jrm will become famous soon enough
jrm jrm is offline
Senior Member
jrm's Avatar
 
Join Date: May 2010
Location: Nor Cal
Posts: 1,636
jrm will become famous soon enough
"disguises self as a adobe/java update"

Quote:
Originally Posted by BMeister View Post
the virus is called Sirefef. to this day I have yet to find an anti-virus that will block it. agv, essentials, norton have been unsuccessful in preventing this virus. it disguises itself as an adobe or java update. one you get it, its very hard to get rid of. even software like malwarebytes removes only portions of it. then it eventually comes back. check the Eset antivirus site for the tools you need to remove.
once you go to install the fake update, will the anti virus catch it or is it too late.
jrm is offline   Reply With QuoteReply With Quote
Old 08-21-2012, 04:59 PM #48
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
Quote:
Originally Posted by jrm View Post
once you go to install the fake update, will the anti virus catch it or is it too late.
When you see the prompt for the fake update you're already infected. What happens is a bug in Java or Flash is used to siliently install the rootkit. Once the rootkit is up and running, it launches its first payload, which is the fake update thing. It will keep launching that, redirecting your browser, stealing your usernames and passwords, and other fantastic stuff until the rootkit is removed. When I caught it, the antivirus software was catching and preventing the payload launches... but did not recognize the rootkit or see that it was installed and running. Neither did McAfee's rootkit removal util, neither did Kapersky's TDSSKiller. Combofix did find and remove it.

-E
eli_lilly is offline   Reply With QuoteReply With Quote
Old 08-21-2012, 05:13 PM #49
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
Quote:
Originally Posted by BMeister View Post
the virus is called Sirefef. to this day I have yet to find an anti-virus that will block it. agv, essentials, norton have been unsuccessful in preventing this virus. it disguises itself as an adobe or java update. one you get it, its very hard to get rid of. even software like malwarebytes removes only portions of it. then it eventually comes back. check the Eset antivirus site for the tools you need to remove.
Mine is trying to run the adobe update. How do I get rid of it?
Sungod is offline   Reply With QuoteReply With Quote
Old 08-21-2012, 06:14 PM #50
run4estrunner's Avatar
run4estrunner run4estrunner is offline
Member
 
Join Date: Apr 2012
Location: San Luis Obispo, CA
Posts: 148
run4estrunner is an unknown quantity at this point
run4estrunner run4estrunner is offline
Member
run4estrunner's Avatar
 
Join Date: Apr 2012
Location: San Luis Obispo, CA
Posts: 148
run4estrunner is an unknown quantity at this point
Quote:
Originally Posted by Sungod View Post
Mine is trying to run the adobe update. How do I get rid of it?
You can start by laying off the gay porn sungod
run4estrunner is offline   Reply With QuoteReply With Quote
Old 08-21-2012, 09:08 PM #51
scottm's Avatar
scottm scottm is offline
Member
 
Join Date: Jul 2009
Location: Holland, MI
Posts: 598
scottm is on a distinguished road
scottm scottm is offline
Member
scottm's Avatar
 
Join Date: Jul 2009
Location: Holland, MI
Posts: 598
scottm is on a distinguished road
Quote:
Originally Posted by Sungod View Post
Mine is trying to run the adobe update. How do I get rid of it?
If your Restore function isn't already disabled try that. Mine was already disabled by the time I tried it. Like I said, this is a nasty bug.
__________________
'03 4R SR5 4x4 V6 bone stock; '03 Land Cruiser; B-767 (company vehicle)
scottm is offline   Reply With QuoteReply With Quote
Old 08-22-2012, 08:56 AM #52
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
Quote:
Originally Posted by Sungod View Post
Mine is trying to run the adobe update. How do I get rid of it?
Download and run combofix.

-E
eli_lilly is offline   Reply With QuoteReply With Quote
Old 08-22-2012, 11:37 AM #53
CXS CXS is offline
Senior Member
 
Join Date: Oct 2010
Location: Naples, Florida
Age: 73
Posts: 2,854
Real Name: Chris
CXS will become famous soon enough
CXS CXS is offline
Senior Member
 
Join Date: Oct 2010
Location: Naples, Florida
Age: 73
Posts: 2,854
Real Name: Chris
CXS will become famous soon enough
If the Admin let's it ride with all these reported problems its simply a matter of time before it's totally infected or malware is injected and it becomes inaccessible. I know that as a fact because I spent yesterday fixing my vBulletin site that was infected.

As a Mac user I was unaware but starting yesterday morning my users started sending me PM's, e-mails and phone calls telling me we had been hacked. It sounded pretty much like the messages above but by noon it was inaccessible. I hope it doesn't happen here.
__________________
Chris - '07 SR5
‘05 Limited - sold
CXS is offline   Reply With QuoteReply With Quote
Old 08-22-2012, 01:01 PM #54
jimithing jimithing is offline
Member
 
Join Date: Apr 2010
Location: Plano, TX
Posts: 790
jimithing is on a distinguished road
jimithing jimithing is offline
Member
 
Join Date: Apr 2010
Location: Plano, TX
Posts: 790
jimithing is on a distinguished road
Quote:
Originally Posted by CXS View Post
If the Admin let's it ride with all these reported problems its simply a matter of time before it's totally infected or malware is injected and it becomes inaccessible. I know that as a fact because I spent yesterday fixing my vBulletin site that was infected.

As a Mac user I was unaware but starting yesterday morning my users started sending me PM's, e-mails and phone calls telling me we had been hacked. It sounded pretty much like the messages above but by noon it was inaccessible. I hope it doesn't happen here.
Would be nice if they would at least comment and say what's going on. I PM'ed the Admin and one of the moderators a link to this thread a couple days ago and haven't gotten a response. And they obviously haven't posted in here either. Kinda sucks.
__________________
2007 Shadow Mica Sport Edition V6 4x4
jimithing is offline   Reply With QuoteReply With Quote
Old 08-22-2012, 05:06 PM #55
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
Quote:
Originally Posted by eli_lilly View Post
Download and run combofix.

-E
I looked at combofix. It looks pretty aggressive. How scary is it to use?
Sungod is offline   Reply With QuoteReply With Quote
Old 08-23-2012, 08:18 AM #56
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
admin admin is offline
Administrator
admin's Avatar
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
Just catching up on this thread. Looking into it. I don't run into any issues, and I visit the site from variety of computers/OSes.

Investigating ...

Update 1:

I haven't found anything suspicious. I also scanned the site using a 3rd party tool, which found no issues either. Here are the results of the scan:
Sucuri SiteCheck - Free Website Malware Scanner

Update 2:
Another service reported the site as safe. See attached screensnap.

Update 3:
AVG reported this site as safe as well.

Update 4:
Norton is also reporting the site as safe:


I'll keep digging.
Attached Images
The Virus problem on this site is getting out of control-capture-png  The Virus problem on this site is getting out of control-avg-png  The Virus problem on this site is getting out of control-norton-png 
admin is offline   Reply With QuoteReply With Quote
Old 08-23-2012, 09:31 AM #57
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
Sungod Sungod is offline
Senior Member
 
Join Date: Jan 2003
Location: DC
Posts: 1,223
Sungod is on a distinguished road
As soon as I opened this site today I got a pop up message regarding another block from malwarebytes. I'll be happy to send you my logs from malware and mcafee.
Sungod is offline   Reply With QuoteReply With Quote
Old 08-23-2012, 09:54 AM #58
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
admin admin is offline
Administrator
admin's Avatar
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
Yes, definitely interested in the logs, as it may be related to a particular thread or post. You can email it to me directly to infotoyota-4runner.org

Also, what OS and browser+version are you using?

Thanks,
admin.
admin is offline   Reply With QuoteReply With Quote
Old 08-23-2012, 10:04 AM #59
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
eli_lilly eli_lilly is offline
Member
 
Join Date: Jun 2012
Location: South Florida
Posts: 98
eli_lilly is on a distinguished road
Quote:
Originally Posted by Sungod View Post
I looked at combofix. It looks pretty aggressive. How scary is it to use?
I thought the same thing, but it's just run it and let it go. Takes maybe 30 mins. After I saw them use it on my PC here at work, I downloaded it and ran it on two desktops at home and two laptops. It found and removed something on my main desktop, even though I run MS Security Essentials.

-E
eli_lilly is offline   Reply With QuoteReply With Quote
Old 08-23-2012, 12:21 PM #60
admin's Avatar
admin admin is offline
Administrator
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
admin admin is offline
Administrator
admin's Avatar
 
Join Date: Nov 2005
Location: Canada
Posts: 541
admin will become famous soon enough
Gents, for those that are getting virus alerts, do they happen across the site or on a specific thread? If specific thread, can you post the thread url here?

Thanks,
admin.
admin is offline   Reply With QuoteReply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Temperature Control Problem pinchshopper 3rd gen T4Rs 0 07-31-2011 07:10 AM
light control problem heffley_boy Classic T4Rs 1 08-06-2007 07:01 AM
VSC and Traction Control Problem JM4Runner7 Problems & Warranty Issues 2 11-11-2005 11:40 AM
I'm having a problem with this site now Iman74 Software Related Questions & Answers 9 11-25-2003 01:04 AM

Powered by vBadvanced CMPS v3.2.2

All times are GMT -4. The time now is 08:35 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Feedback Buttons provided by Advanced Post Thanks / Like (Lite) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging (Lite) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
***This site is an unofficial Toyota site, and is not officially endorsed, supported, authorized by or affiliated with Toyota. All company, product, or service names references in this web site are used for identification purposes only and may be trademarks of their respective owners. The Toyota name, marks, designs and logos, as well as Toyota model names, are registered trademarks of Toyota Motor Corporation***Ad Management plugin by RedTyger
 
Copyright © 2020