Jump to content
SAU Community

Recommended Posts

I thought it had gone, but alas, I just got another warning from my a/v (Avast pro).

Seems to identify it as WIN32 Trojano ...

My a/v catches it and terminates connection before there's any consequence.

This only happened for the first time on Friday I think.

Has never happened before, so I cant imagine, as previously mentioned by someone, that it's Invision, unless SAU has just changed their system over.

Also, had no old cache, i clean it almost daily, and IE is set to load new page everytime (no caching).

Anyways, not a big deal on my end, but perhaps might be helpful to track down the issue.

We use Avast on our server (Avast Server Edition) at work and yeah just about every trojan they find it labels it as a win32:trojano.

GET FIREFOX or OPERA instead of the IE browser.... ITS not the SAU board, its because the SAU board is Invision and Ie has a big hole in it ... the same will happen on any Invision Board using an Ie browser until Microsoft do something .

I have to stick with IE for compatability reasons and yes it appears to be SAU as other Invision Boards I've been to today, aren't affecting any of my virus scanners. The trojan doesn't appear as often as it was late last week, as I've only seen it twice in the 20 odd times I've either refreshed or been to the board today.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303704
Share on other sites

  • Replies 95
  • Created
  • Last Reply

Top Posters In This Topic

ok .. i have found a way to trigger it on cue to dload with IE

Its intermitant depending on how you navigate your Ie browser

I think this is better closed up again (forum) because Patching is not sufficent yet until its understood how it loads and got into the code. people that dont understand things will get all nasty again.

So better closing the hole again so they cant blame...

I am no mod or admin here so i can only reco what i would do gang.

later

back in a few hours ish!

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303914
Share on other sites

i am looking at all the manual ways now....

... For a try install norton in Safe mode ... Or systems restoring before hand and repeating...

Looking into this more now I see its a fairly old exploit reworked . So until more info unfolds its a bit hard.

F8 key hold down on reboot until you get Safe mode ... then run the the install. Its tricky because you have to some how get the Av to update in safe mode

My AV rips it straight out !!! Pm me if you would like to try it .

Munkyb0y Av only finds it once its been reported. the exploits can function and go on for months before this!

thanks mate, i will try this stuff tonight when i get home. i'm a bit noob with security, viruses etc. :nyaanyaa:

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2303989
Share on other sites

Whoa ...Well Done Prank!!!... its gone :) i cant even get it to trigger now ...

For those that did get infected and AV crashed, try that link i splashed before. It did clean it surprisingly for free!

If your anti virus couldn't get rid of it and the trojan got round it, you need to either 1)update your virus scanner a damn lot more or 2)get a decent virus scanner. If some free net thing can get rid of it and a PC based one can't you've got security problems :blink:

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2304371
Share on other sites

hey guys mines still going through that 169vista site or whatever when i bring up sau homepage. and saying trojan infected yada yada

how exactly do i make sure ive deleted all the old internet files/cache and whatever else needs to be done to get rid of it for good?????

its giving me the shits at the moment

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306121
Share on other sites

Re occur! this is what i was worried about ...

Prank. i mentioned in your PM my bigger fears of how this may be happening.

Until you find whats loading it or re Writting, it will keep coming bac unfortunatly.

Dam i would luv to be a NEt admin at the moment ... i would Argue the Mozilla and be a hero in the work place by doing nothing !

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306194
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

triggered virus several times just then over the last few min's to see .

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124658&hl=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124503&hl=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...s&lastdate=[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...194entry2306194[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...24535&st=40[2]

detected: Trojan program Trojan-Downloader.HTML.Agent.ao Script: http://www.skylinesaustralia.com/forums/in...=124803&hl=[2]

It re writes the code which is why i think what i think in Pranks PM. i am not going to Blurt it out here !

Edited by ishh
Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306215
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

triggered virus several times just then over the last few min's to see .

Yup, I afraid its still in there guys. Got it just now as I clicked to read this thread...

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306262
Share on other sites

no it's not R31Nismoid.... I am sitting here triggering it again like I showed Prank ...

Thats nice...

Still doesnt detract from the fact that it is fine for me, which... is what i initially said.

Doesnt mean its right for other people, i never said it was right for anyone else.

Im just giving more feedback on what ive already said

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306273
Share on other sites

Comes about 50% of the time. I can see IE trying to access something from http://196.regvista.com through the IFRAME and so I just hit stop and reload. Usually on the second or third attempt the page loads without the trojan.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306451
Share on other sites

Still had a major issue after you guys said it was removed, crashed my computer even after a complete cache refresh, spy wear check and removal as well as a full virus scan.

Virus would not allow to transfer documents, wouldn’t allow to run any programs in hope of finding the problem and removing it again.. Kept getting access denied, you do not have permission when trying to open Anti virus program, spy wear remover ect.

We ended up having to do a full system recover, which has seemed to fix it now. What ever happened, was worse the seconded time around.. An came from this site at some point.

Jus thought I would let you guys know.

Link to comment
https://www.sau.com.au/forums/topic/124535-trojans/page/3/#findComment-2306608
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



  • Latest Posts

    • Ok glad you clarified on the frenchy’s options , I was worried about if my oem hoses would fit the new compressor or not if I just bought the bracket/compressor kit ,  didn’t realize they also sold a larger full conversion kit. Hmm may just go oem in that case then to make it easy only because I plan to sell this car to upgrade to a 32 GTR or 34 GTT.
    • Right, here's a video of the basic operation at least.  This is what you can expect day to day when you turn the car on and it boots from standby.  The only thing from a media point of view I haven't gotten working is for it to autoplay plexamp when it turns on from standby (it works from cold boot) but that's more of a plexamp problem as it will autoplay other music players.  Also attached is my one stray cable.  It's part of the screen's wiring adapters but there's just nowhere for it to go in my car.  I've just now done a bit of research and found a matching port on a 2010-2014 head unit with BOSE.  Mine has no BOSE so that's that case pretty much closed I think.  Plugging in the Infiniti AC panel basically did nothing for me, so that's a dead end as well.  Next port of call is to mess with this CANBUS module and see what I can find from it.  I found this resource containing the DBC files for a 2010+ G37 : https://github.com/icecube45/Dash_InfinitiG37/blob/master/InfinitiG37.dbc I'll now have something to go from when I try to extract my CANBUS data so I can see if the HVAC Mode, Fan Speed, Temperature, etc. match and also the gear shifter position.  It's a pretty big assumption that it's just mismatched CAN signals but considering all the devices in the CAN network are talking to each other (AC can be fully adjusted just with no info on screen) it might be a safe one.  I will report back WhatsApp Video 2025-02-26 at 12.49.10.mp4
    • Thanks for that Paul.  Do you think if I posted a picture you'd be able to remember where it went? 
    • Sorry Duncan, I didn't get a notification for the replies.  Thanks for responding!  It's a full Android device, but does allow you to use CarPlay/AA as well.  This is the one I bought from NaviRS on AliExpress: https://www.aliexpress.com/item/1005006368602668.html?spm=a2g0o.order_list.order_list_main.111.59aa1802JDzQ0E - the 2K 8G-256G CAM variant but it seems to have gone up by £170 since I bought it!  My purchase was £307.14.   It's not the fastest thing in the world but performs perfectly adequately.  It stays on standby unless I disconnect the battery and let it power down, then it's just a fairly standard Android bootup time from cold.  The DSP Equaliser is very nice and made the standard stereo system sound pretty decent compared to the stock screen.  Perhaps I can take a video of it when I get a sec. It *allegedly* supports the reverse camera, but I'm yet to get that working.  It has options for reverse cam (a camera unit can be bought separately) or 360 cameras (also bought separately).  To be fair it doesn't seem to detect that the shifter was put into reverse but I'm working on a theory about this as well.  At the moment I'm going without which is a bit annoying considering the car is an absolute canal barge but so far I haven't caused any damage I'll grab a picture of the wire I'm missing later today when I can get outside.  My theory, by the by, is that not only is the head unit different, but the CANBUS network has different signals for the different years.  I think this because I have a spare AC panel from a newer Infiniti G37 (as opposed to my Nissan panel) which wouldn't control anything except the volume when I had it wired up with the stock system.  I'm going to throw it back in and see if the screen will respond to it.  I've just ordered an arduino CANBUS module so I can have a look at the signals going around the car and see if I can spot anything.  I'm thinking if I can work out what it's expecting vs what it's getting I might be able to translate and relay the signal back but so far just a theory anyway. I also found this on my travels, so far the only one that specifically matches my car: https://www.aliexpress.com/item/1005002822934280.html?spm=a2g0s.imconversation.0.0.33433e5fgttovi If you look at the picture of the before, it has the card reader slot, and the picture of the head unit is exactly the same as the one pictured in my original post.  I asked if they sell the cables separately but sadly they won't.  I didn't want to just buy this one because it's a super old Android version and only dual core - likely slow as hell. 
    • As above, you did refill the coolant and burp the system before running it again didn't you?
×
×
  • Create New...