Author Topic: Trojan detected  (Read 19095 times)

Offline EHM-2198 Didimo

  • Climbing
  • ****
  • Posts: 168
  • Karma: 0
    • http://www.virtual-aviation.net
Trojan detected
« on: April 12, 2008, 03:59:53 pm »
Just logged in to the main website and apparently there has been an update to the website that is causing some problems. I have not updated my browsers, still using the same browsers I have been using for quite a while: FireFox v2.0.0.9 and IE 7.0.5730.11.

Until about a week ago when I last logged in the site worked ok with both browsers with the exception of the PP section that only works in IE.

Today however after logged in, when I click on Divisions a new IE window pops up (as opposed to loading into the same frame) with only the menu (http://www.fly-euroharmony.com/site/menu_d.htm). Then clicking on any of these menu items (which is the only thing showing on the page) it does not load the target page.

I don't see any posting about a website update but likewise I have not changed my browsers either. Can somebody confirm that? The same happens on both FF and IE.

The buttons image map at the top has a target frame named I1 or something like that. I see some page error saying something that the frame does not exist or that it is null.

Offline EHM-1749 Hector

  • Geostationary orbit
  • ******
  • Posts: 436
  • Karma: 0
Trojan detected
« Reply #1 on: April 12, 2008, 07:13:44 pm »
I cannot get into ProPilot page. When I hit the PP and try to log in, I get a "new Page 3" window and nothing happens. April 12 at 1813Z

Good pilots keep their number of landings equal to their number of takeoffs. Takeoffs are optional but landings are Mandatory.

EHM-1670 William

  • Guest
Trojan detected
« Reply #2 on: April 12, 2008, 07:21:16 pm »
When the new page 3 opens go back to the original page you clicked from and it opens there. All very strange. :%

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #3 on: April 12, 2008, 09:47:08 pm »
Hmm... now that *IS* strange... not of my doing, I must hasten to add (and yes, it is I that is normally responsible for changes to the website...)

Since the menu that pops open looks "different" (can't explain, there's just something that feels different about it, other than it's opening in it's own window), I'd guess the graphics department have played. I'll have a wee looky at the script for the menus and see if I can't sort it.

BTW Didimo, 2.0.0.9 is *very* old (in Firefox terms...) Current version is 2.0.0.13, and I would very much recommend you upgrade as both .12 and .13 had major security updates in them.

UPDATE: Fixed, thanks all for reporting the error.
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

EHM-1944 Jaap

  • Guest
Trojan detected
« Reply #4 on: April 13, 2008, 09:01:29 am »
Thanks Murray,now we can go ahead again.

Offline EHM-2198 Didimo

  • Climbing
  • ****
  • Posts: 168
  • Karma: 0
    • http://www.virtual-aviation.net
Trojan detected
« Reply #5 on: April 13, 2008, 01:16:56 pm »
Site is fixed, thanks. Already installed my FF update as well.

May I ask what is it that the PP pages use that only works with IE?

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #6 on: April 13, 2008, 01:34:30 pm »
You'd need to ask Bruno, that's still his (other) baby...  :)
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

Offline EHM-0948 Bruno

  • Intergalactic!!
  • ********
  • Posts: 3,561
  • Karma: 0
Trojan detected
« Reply #7 on: April 13, 2008, 04:41:36 pm »
Hi Didimo,

On the time that I developed it, Firefox was still on the early stage so I didn't gave much attention to it.

My mistake of course :). We will try to adjust it as soon as we can.

Just to notice that you can download a FF extension that will permit you to use the IE API on Firefox.

Regards,

Offline EHM-1749 Hector

  • Geostationary orbit
  • ******
  • Posts: 436
  • Karma: 0
Trojan detected
« Reply #8 on: April 13, 2008, 05:16:43 pm »
Okay now in PP without the New Page 3 message. Everything looking good again.
Thanks Murray.

Good pilots keep their number of landings equal to their number of takeoffs. Takeoffs are optional but landings are Mandatory.

Offline EHM-1657 Jay

  • Super cruise
  • *****
  • Posts: 258
  • Karma: 0
    • http://www.ewr0688.com
Trojan detected
« Reply #9 on: April 14, 2008, 11:57:07 am »
Just to let you know the Page 3 message is still coming up in IE 7 :)
[img]

Offline EHM-1703 Philip

  • Intergalactic!!
  • ********
  • Posts: 2,312
  • Karma: 0
Trojan detected
« Reply #10 on: April 14, 2008, 12:25:41 pm »
Yes, looks nasty again. I will have Murray take a look when he can, we may have to take the site down for a bit so be prepared.
Phil Nutt EHM 1703
 

Offline EHM-1657 Jay

  • Super cruise
  • *****
  • Posts: 258
  • Karma: 0
    • http://www.ewr0688.com
Trojan detected
« Reply #11 on: April 14, 2008, 12:29:06 pm »
I might have an idea as to why this is happening, let me go verify something quickly, will be back shortly :)
[img]

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #12 on: April 14, 2008, 12:34:54 pm »
On it. It's the same thing as last time (that's mostly for the MTs benefit) and since I'm at work it's going to take me a little longer to fix it...
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

Offline EHM-1657 Jay

  • Super cruise
  • *****
  • Posts: 258
  • Karma: 0
    • http://www.ewr0688.com
Trojan detected
« Reply #13 on: April 14, 2008, 12:36:28 pm »
Oh ok, cool, will check back tomorrow :) :)
[img]

EHM-1944 Jaap

  • Guest
Trojan detected
« Reply #14 on: April 14, 2008, 12:59:32 pm »
Just tried to enter the PP division.We have now a "new page 3".
I cannot enter the division :$
As I am at Rodos with a B763 on the moment I will take a short holiday.;)

Offline EHM-1570 Bruce

  • Geostationary orbit
  • ******
  • Posts: 409
  • Karma: 1
Trojan detected
« Reply #15 on: April 14, 2008, 01:00:00 pm »
My Anti virus software is flagging up a Trojan on the Home web page.
Bruce Woodbridge
EHM 1570

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #16 on: April 14, 2008, 01:13:54 pm »
Should be fixed again. Apologies for the annoyance...
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

Offline EHM-1592 Niels

  • Climbing
  • ****
  • Posts: 160
  • Karma: 1
Trojan detected
« Reply #17 on: April 14, 2008, 01:17:13 pm »
Mine as well (ZoneAlarm).
"...and this is the very first Fokker airplane built. The Dutch call it the mother Fokker."

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #18 on: April 14, 2008, 01:21:10 pm »
Thanks gents. Which one in particular? It might help us stop this happening in the future?
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

Offline EHM-1570 Bruce

  • Geostationary orbit
  • ******
  • Posts: 409
  • Karma: 1
Trojan detected
« Reply #19 on: April 14, 2008, 01:29:23 pm »
Hi Murray my anti virus is detecting the following virus: Trojan-Clicker.JS.AGENT.H  hope this helps.
Bruce Woodbridge
EHM 1570

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #20 on: April 14, 2008, 01:41:35 pm »
*Many* thanks for that Bruce.

@Everyone: I have now discovered (and with luck blocked) the vector that was being used to apply this malware to the site (MT should look in our private forum for full information).

It shouldn't happen again in the sort of timeframe it did yesterday/today, but just in case I have taken further precautions; a backup of the files that are being replaced each time, so one quick unpack operation will put them back as was...
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

EHM-1944 Jaap

  • Guest
Trojan detected
« Reply #21 on: April 14, 2008, 01:47:14 pm »
Thanks again Murray.
I can enter PP again,however funny is that a Mcafee scan did not find any virus.

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #22 on: April 14, 2008, 01:56:25 pm »
Look up the name Bruce reported on McAfee's forum ;)

We're not the first people hit by this malware, and you're not the first McAfee user wondering why it doesn't get detected...
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

Offline EHM-2198 Didimo

  • Climbing
  • ****
  • Posts: 168
  • Karma: 0
    • http://www.virtual-aviation.net
Trojan detected
« Reply #23 on: April 14, 2008, 07:53:42 pm »
IVAO got hit some days ago if I remember correctly :( I hope my PC did not get infected. I just ran AdAware and did not detect anything extraordinary (tracking cookies only).

Currently running Norton AV with the updates but I hope it finds nothing. Then again... for what it seems NAV fails miserably at detecting some things. Can anybody recommend a better antivirus?

Offline EHM-0654 Murray

  • Administrator
  • Intergalactic!!
  • ***
  • Posts: 4,531
  • Karma: 5
  • VA Management
    • The Ponderings of PMUK
Trojan detected
« Reply #24 on: April 14, 2008, 08:37:09 pm »
Personally, I only use NOD32 on my on equipment (thirty day demo available from their website). If you check out AV Comparatives, you discover that Eset NOD32 has won "best of year" two years running. Plus, it's dead light on computer resources, and it's also blindingly fast. Furthermore, it's not tremendously expensive for home use (£27 per year)

And before anyone finds out "by accident" and thinks there's sommat dodgy going on, yes, the company my mate David and I run is a NOD32 reseller, but that's mostly because we were both using it before we started the company and thought reselling would be a nice way of getting it cheaply (and it is ;D)
Murray Crane // EHM-0654 // Twitter
VA Management

KEEP CALM AND CARRY ON

 

anything