Virus (on user side) that modify user posts

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785

Virus (on user side) that modify user posts

Postby DjDoxy » Mon Feb 26, 2007 2:19 pm

Warning: This post contains links to virus... be careful and do not clic them unless you know what you are doing

One of my user have a strange problem:

When he posts on the forum, his messages are altered by a "virus" and finaly look like this:

have you seen this?
[link removed (some one is bound to try the link) - karlsemple]

... real message here...

Dont forget to see [link removed (some one is bound to try the link) - karlsemple]


or like that:

... real message here...
just look [link removed (some one is bound to try the link) - karlsemple]


Note: I left the URL as is, except that I added a space to avoid any of you to clic by error on the link... as it is linked to a virus :evil: !

I asked the concerned user to check his machine with a antivirus, but no virus were found. :?

I checked, this "show.exe" contains a virus (a Trojan named "Peacomm") 8O.

I tried to use the word censoring, but if it correctly mask the display of the link, the URL is still valid and it is still possible to clic on the link and go to the malicious page.

So I have 2 questions:

- Does anybody ever heard of such a virus (or malware or whatever its name is) and know a way to clean up the user's machine
- Is it normal that the censoring only affect the URL display and not the actual link ?
DjDoxy
Registered User
 
Posts: 13
Joined: Wed Dec 14, 2005 2:30 pm

Postby espicom » Mon Feb 26, 2007 6:40 pm

Anyone who downloads an EXE file and ignores the warnings of their browser and/or antivirus software is, well, let's avoid using derogatory names right now.

Cleaning it out involves letting the antivirus software do its job. If the attack has been out for more than 24 hours and the user's antivirus software has not been updated to detect it yet, they should submit the information to the AV company to have them fix that.
Jeff
Fixing 1016/1030/1034 Errors | (obsolete link) | MySQL 4.1/5.x Client Error | phpBBv2 Logo in ACP
Support requests via PM are ignored!
"To be fully alive is to feel that everything is possible." - Eric Hoffer
User avatar
espicom
Registered User
 
Posts: 17906
Joined: Wed Dec 22, 2004 1:14 am
Location: Woodstock, IL

Postby DjDoxy » Tue Feb 27, 2007 8:08 am

espicom wrote:Anyone who downloads an EXE file and ignores the warnings of their browser and/or antivirus software is, well, let's avoid using derogatory names right now.

I agree, but remember that not all users are as experienced as we are.
Some people does not even now what "an EXE file" is.

By the way, there is a new URL in this user messages:
[link removed (some one is bound to try the link) - karlsemple]
DjDoxy
Registered User
 
Posts: 13
Joined: Wed Dec 14, 2005 2:30 pm

Postby DjDoxy » Tue Feb 27, 2007 8:24 am

DjDoxy wrote:[link removed (some one is bound to try the link) - karlsemple]

Oops :oops:
Sorry, I did not see that the URL was concealed in my original message.
DjDoxy
Registered User
 
Posts: 13
Joined: Wed Dec 14, 2005 2:30 pm

Postby ChrisRLG » Tue Feb 27, 2007 9:31 am

DjDoxy

here we would not be able to assist you or the member to get clean.

Not sure if the provision of this link here would be counted as spam either - if so - I am sorry Mods - done only to provide assistance.

This is NOT a link to my own forum - but a link to a 'federation' of forums that assist victims of malware - any forums on that list would be able to assist you both, in making sure you are both clean from malware.

http://asap.maddoktor2.com/
phpBB: The All Important Rules - Bertie Bear 3.0 - No support via PM system - use the forums please.
phpBB v2: Retirement (1/1/2009) : phpBB v3: Read Me Topic - Custom BBCodes - Support Template
I am also on the Moderator Team of phpBB.com
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
My Links: MS MVP (Consumer Security) - Malware Removal:University - Own Forum:Custom BBCode testing
User avatar
ChrisRLG
Business Manager
Business Manager
 
Posts: 3459
Joined: Wed Nov 24, 2004 3:18 pm
Location: Essex, UK


Return to 2.0.x Support Forum

Who is online

Users browsing this forum: Yahoo [Bot] and 11 guests