JS.Trojan.Seeker-based

Gamers can also use this forum to chat about any game related subject, news, rumours etc.

Moderator: maddog986

User avatar
Paul Vebber
Posts: 5342
Joined: Wed Mar 29, 2000 4:00 pm
Location: Portsmouth RI
Contact:

Post by Paul Vebber »

What was deleted by your anti-virus program...??

Trojans don't typically delete anything but in effect can give control of your PC to a remote operator, just like PC anywhere does.

I just DL'd the Wir 3.1 Win and scanned it for viruses and it had none.
Big Bill
Posts: 172
Joined: Sat Mar 24, 2001 10:00 am
Location: LI. NY. , USA

Post by Big Bill »

After I was infected with a trojin horse I downloaded Zone Alarm's free firewall, after a year I haven't had any problems with this type of attack. This Trogin horse problem is more prevelent with someone using a high speed connection. The hackers use a bot program to scan the internet for these connections and then place the Trojin, Zone Alarm makes your computer invisable to this kind of attack. It's free and it works.
nexus
Posts: 79
Joined: Thu Jun 28, 2001 8:00 am
Location: Siegen / Germany
Contact:

Post by nexus »

Originally posted by Big Bill:
After I was infected with a trojin horse I downloaded Zone Alarm's free firewall, after a year I haven't had any problems with this type of attack. This Trogin horse problem is more prevelent with someone using a high speed connection. The hackers use a bot program to scan the internet for these connections and then place the Trojin, Zone Alarm makes your computer invisable to this kind of attack. It's free and it works.

hello and thanx.

can you give me the website adress please??
Greetings

Frank
majama
Posts: 59
Joined: Wed Jul 25, 2001 8:00 am
Location: Poland

Post by majama »

I have comunicat by my AVP Monitor :
Virus : JS.Trojan.Seeker-based in C:\Windows\temporary internet...content.IE5\CP6VCT2Z\default(1).js

AVP cannot remove this virus :
dangerous situacion

i MUST LESS TRUST MATRIX SITES ?

majama
User avatar
Paul Vebber
Posts: 5342
Joined: Wed Mar 29, 2000 4:00 pm
Location: Portsmouth RI
Contact:

Post by Paul Vebber »

No, We have and continue to monitor the site for viruses, this appears to be a flase alarm caused by Macromedia SHockwave. Neither Norton nor mcAfee says there are any virus present.
majama
Posts: 59
Joined: Wed Jul 25, 2001 8:00 am
Location: Poland

Post by majama »

OK, thanks
Halgary
Posts: 40
Joined: Mon Jun 04, 2001 8:00 am
Location: Oulu, Finland

Post by Halgary »

Originally posted by Paul Vebber:
No, We have and continue to monitor the site for viruses, this appears to be a flase alarm caused by Macromedia SHockwave. Neither Norton nor mcAfee says there are any virus present.
Hope so. This troyan jumped on me when I went to see info about Combat Leader. Strangely enough, it didn't happen when I used Opera, but when I switched to IExplorer... WHAM!

I feel a bit nervous, since my anti-virus -program says it can't be removed.

I'm using F-Secure anti-virus software, if that helps.
User avatar
Paul Vebber
Posts: 5342
Joined: Wed Mar 29, 2000 4:00 pm
Location: Portsmouth RI
Contact:

Post by Paul Vebber »

Script based viruses are generally pretty obvious if you "view source" of the web page. If you "view source" and there is a block of code that calls registry edits, creating or renaming files etc, then you have to watch out.

Unfortunately in an attempt to get "protection" out there many products just block all scripts period. Once they get a bit more sohisticated, there will "false alarm" less often.

We take site security very seriously, but the script threat is one that a coule minutes of investigation of the source can clear up as a valid concern, or a false alarm.

We need the specific page link that caused teh problem, the virus checker and version, and a copy of any suspicious script you find for a report of web virus to be helpful.
Halgary
Posts: 40
Joined: Mon Jun 04, 2001 8:00 am
Location: Oulu, Finland

Post by Halgary »

Hmm. Every page on your server that has some kind of Flash-animation causes this.

I think I'll report this to F-secure. Propably a bug in the anti-virus -software.

I'm using F-Secure Anti-Virus 5.30 build 7262

[ October 07, 2001: Message edited by: Halgary ]</p>
Galahad
Posts: 7
Joined: Sat Oct 06, 2001 8:00 am

Post by Galahad »

I encountered the virus alert as well. Hopefully, this information will help.

It seems to be most prevelant on the link to the new napoleon game page. I use Norton Anti Virus, and just updated the virus definitons two or three days before finding the alert here.

The alert is a was a registry edit script.

Norton gave me the option of ending the script, which I did. That shut down all open windows of Internet Explorer.

I tried again on a different and expendable platform. I ran a virus check, and it was virus free. I went to the Nap game page, and allowed the script to run. No apparaent effects, BUT

A virus scan then showed an infection with the WScript.KakWorm virus.

Hope this helps.

Galahad
(Formerly Repo Man, with all of 6 posts)
User avatar
Marc von Martial
Posts: 5292
Joined: Thu Jan 04, 2001 4:00 pm
Location: Bonn, Germany
Contact:

Post by Marc von Martial »

Hi,

the Worm you´re reffering too is an explicit Outlook Express / Outlook / IE Newsreader Worm. It has nothing to do with JS or Webistes:

http://www.symantec.com/avcenter/venc/data/wscript.kakworm.html


Marc

[ October 09, 2001: Message edited by: Marc Schwanebeck [GS_Marcks] ]</p>
User avatar
Marc von Martial
Posts: 5292
Joined: Thu Jan 04, 2001 4:00 pm
Location: Bonn, Germany
Contact:

Post by Marc von Martial »

Despite from the "problem" we´re facing here:
A suggestion from an IT professional:
Can you guys move the whole web to an Apache-based webserver?

Apache (which runs on WindowsNT, Linux, FreeBSD, AIX, Solaris...) is known for its solidity and securiy. Qwest carries Apache as well.

MS-IIS + Windows2000 , unfortunately are not very secure nor reliable.

How difficult it would be to do move the whole site? Apache supports .asp and things usualy considered "Microsoft only".

You would get better reliability (uptime), if managed in a usual way, no security issues, is less expensive (if you have to pay for the software, like Qwest. So I do not know if this actualy translates to the "end users", like MatrixGames), better handling of heavy traffic loads, less resource-intensive (so the same machine can do more work)... and no users complaining about a worm gotten from your site.
I agree 100% <img src="wink.gif" border="0">
Galahad
Posts: 7
Joined: Sat Oct 06, 2001 8:00 am

Post by Galahad »

Im aware that the worm is related to OE, but I did go from virus free (according to Norton) to being infected after letting the script run (according to Norton).

I still get the alert of a script.

As my grandmother used to say, something isn't kosher in denmark.

Galahad
JTGEN
Posts: 136
Joined: Tue Nov 21, 2000 10:00 am
Location: Finland

Post by JTGEN »

I get a warning ocasionally from McAfee too. It just says that I should delete a certain file manually, because it can not do it automatically or something like that. But that file is nowhere to be found on the computer.
User avatar
Charles2222
Posts: 3687
Joined: Mon Mar 12, 2001 10:00 am

Post by Charles2222 »

If I recall correctly, it doesn't say it cannot delete it, it says it cannot 'repair' it. There's also an option to quarantine it. It don't seem to have a problem deleted it, as your not being able to find it shows.

(Updated after I got on at home and dared get on this website with the trojan irritatingly still hammering away)- Actually I was incorrect, it doesn't say it cannot 'repair' the trojan, it says it cannot 'clean' it. Those dirty trojans!

[ October 19, 2001: Message edited by: Charles_22 ]</p>
User avatar
Charles2222
Posts: 3687
Joined: Mon Mar 12, 2001 10:00 am

Post by Charles2222 »

Yay! The Trojans wannabes have beat a hasty retreat. Thanks guys!
User avatar
Marc von Martial
Posts: 5292
Joined: Thu Jan 04, 2001 4:00 pm
Location: Bonn, Germany
Contact:

Post by Marc von Martial »

We just took the script offline untill we find time to implement a new one to spy on you folks <img src="biggrin.gif" border="0"> , just kidding of course.
Post Reply

Return to “General Discussion”