EuroHarmony Community Forums

Archive => EuroHarmony VA => Old Forum => Technical discussions => Topic started by: EHM-2198 Didimo on April 12, 2008, 03:59:53 pm

Title: Trojan detected
Post by: EHM-2198 Didimo on April 12, 2008, 03:59:53 pm
Just logged in to the main website and apparently there has been an update to the website that is causing some problems. I have not updated my browsers, still using the same browsers I have been using for quite a while: FireFox v2.0.0.9 and IE 7.0.5730.11.

Until about a week ago when I last logged in the site worked ok with both browsers with the exception of the PP section that only works in IE.

Today however after logged in, when I click on Divisions a new IE window pops up (as opposed to loading into the same frame) with only the menu (http://www.fly-euroharmony.com/site/menu_d.htm). Then clicking on any of these menu items (which is the only thing showing on the page) it does not load the target page.

I don't see any posting about a website update but likewise I have not changed my browsers either. Can somebody confirm that? The same happens on both FF and IE.

The buttons image map at the top has a target frame named I1 or something like that. I see some page error saying something that the frame does not exist or that it is null.
Title: Trojan detected
Post by: EHM-1749 Hector on April 12, 2008, 07:13:44 pm
I cannot get into ProPilot page. When I hit the PP and try to log in, I get a "new Page 3" window and nothing happens. April 12 at 1813Z
Title: Trojan detected
Post by: EHM-1670 William on April 12, 2008, 07:21:16 pm
When the new page 3 opens go back to the original page you clicked from and it opens there. All very strange. :%
Title: Trojan detected
Post by: EHM-0654 Murray on April 12, 2008, 09:47:08 pm
Hmm... now that *IS* strange... not of my doing, I must hasten to add (and yes, it is I that is normally responsible for changes to the website...)

Since the menu that pops open looks "different" (can't explain, there's just something that feels different about it, other than it's opening in it's own window), I'd guess the graphics department have played. I'll have a wee looky at the script for the menus and see if I can't sort it.

BTW Didimo, 2.0.0.9 is *very* old (in Firefox terms...) Current version is 2.0.0.13, and I would very much recommend you upgrade as both .12 and .13 had major security updates in them.

UPDATE: Fixed, thanks all for reporting the error.
Title: Trojan detected
Post by: EHM-1944 Jaap on April 13, 2008, 09:01:29 am
Thanks Murray,now we can go ahead again.
Title: Trojan detected
Post by: EHM-2198 Didimo on April 13, 2008, 01:16:56 pm
Site is fixed, thanks. Already installed my FF update as well.

May I ask what is it that the PP pages use that only works with IE?
Title: Trojan detected
Post by: EHM-0654 Murray on April 13, 2008, 01:34:30 pm
You'd need to ask Bruno, that's still his (other) baby...  :)
Title: Trojan detected
Post by: EHM-0948 Bruno on April 13, 2008, 04:41:36 pm
Hi Didimo,

On the time that I developed it, Firefox was still on the early stage so I didn't gave much attention to it.

My mistake of course :). We will try to adjust it as soon as we can.

Just to notice that you can download a FF extension that will permit you to use the IE API on Firefox.

Regards,
Title: Trojan detected
Post by: EHM-1749 Hector on April 13, 2008, 05:16:43 pm
Okay now in PP without the New Page 3 message. Everything looking good again.
Thanks Murray.
Title: Trojan detected
Post by: EHM-1657 Jay on April 14, 2008, 11:57:07 am
Just to let you know the Page 3 message is still coming up in IE 7 :)
Title: Trojan detected
Post by: EHM-1703 Philip on April 14, 2008, 12:25:41 pm
Yes, looks nasty again. I will have Murray take a look when he can, we may have to take the site down for a bit so be prepared.
Title: Trojan detected
Post by: EHM-1657 Jay on April 14, 2008, 12:29:06 pm
I might have an idea as to why this is happening, let me go verify something quickly, will be back shortly :)
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 12:34:54 pm
On it. It's the same thing as last time (that's mostly for the MTs benefit) and since I'm at work it's going to take me a little longer to fix it...
Title: Trojan detected
Post by: EHM-1657 Jay on April 14, 2008, 12:36:28 pm
Oh ok, cool, will check back tomorrow :) :)
Title: Trojan detected
Post by: EHM-1944 Jaap on April 14, 2008, 12:59:32 pm
Just tried to enter the PP division.We have now a "new page 3".
I cannot enter the division :$
As I am at Rodos with a B763 on the moment I will take a short holiday.;)
Title: Trojan detected
Post by: EHM-1570 Bruce on April 14, 2008, 01:00:00 pm
My Anti virus software is flagging up a Trojan on the Home web page.
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 01:13:54 pm
Should be fixed again. Apologies for the annoyance...
Title: Trojan detected
Post by: EHM-1592 Niels on April 14, 2008, 01:17:13 pm
Mine as well (ZoneAlarm).
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 01:21:10 pm
Thanks gents. Which one in particular? It might help us stop this happening in the future?
Title: Trojan detected
Post by: EHM-1570 Bruce on April 14, 2008, 01:29:23 pm
Hi Murray my anti virus is detecting the following virus: Trojan-Clicker.JS.AGENT.H  hope this helps.
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 01:41:35 pm
*Many* thanks for that Bruce.

@Everyone: I have now discovered (and with luck blocked) the vector that was being used to apply this malware to the site (MT should look in our private forum for full information).

It shouldn't happen again in the sort of timeframe it did yesterday/today, but just in case I have taken further precautions; a backup of the files that are being replaced each time, so one quick unpack operation will put them back as was...
Title: Trojan detected
Post by: EHM-1944 Jaap on April 14, 2008, 01:47:14 pm
Thanks again Murray.
I can enter PP again,however funny is that a Mcafee scan did not find any virus.
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 01:56:25 pm
Look up the name Bruce reported on McAfee's forum ;)

We're not the first people hit by this malware, and you're not the first McAfee user wondering why it doesn't get detected...
Title: Trojan detected
Post by: EHM-2198 Didimo on April 14, 2008, 07:53:42 pm
IVAO got hit some days ago if I remember correctly :( I hope my PC did not get infected. I just ran AdAware and did not detect anything extraordinary (tracking cookies only).

Currently running Norton AV with the updates but I hope it finds nothing. Then again... for what it seems NAV fails miserably at detecting some things. Can anybody recommend a better antivirus?
Title: Trojan detected
Post by: EHM-0654 Murray on April 14, 2008, 08:37:09 pm
Personally, I only use NOD32 (http://www.eset.com) on my on equipment (thirty day demo available from their website). If you check out AV Comparatives (http://www.av-comparatives.org/), you discover that Eset NOD32 has won "best of year" two years running. Plus, it's dead light on computer resources, and it's also blindingly fast. Furthermore, it's not tremendously expensive for home use (£27 per year)

And before anyone finds out "by accident" and thinks there's sommat dodgy going on, yes, the company my mate David and I run is a NOD32 reseller, but that's mostly because we were both using it before we started the company and thought reselling would be a nice way of getting it cheaply (and it is ;D)
Title: Trojan detected
Post by: EHM-2155 Mariano on April 15, 2008, 12:28:17 am
Kaspersky is supposed to be good, fast and cheap too.
By the way, for those worried with possible infections in IE (undoubtly, the most vulnerable browser available out there) and that PP is supposed to work only in IE, I should recommend you using Opera. PP works fine and its a nice browser. Ive been using it for as long as I can remember. And its fairly immune to web based attacks programmed for IE, as far as I remember, ive never been infected that way.
Title: Trojan detected
Post by: EHM-0654 Murray on April 15, 2008, 08:23:46 am
Kaspersky is very strong, but I always found it extremely slow when I was running it. Of course, that was a couple of versions ago, at things may have improved greatly since then.

I'm intrigued to hear that PP works in Opera. Perhaps the PP code isn't all that far away from being cross-browser - it's on my list of things to look at, but said list is *very* long at present, and maggots deliberately trying to break the current site for everyone else only makes it longer... Fingers crossed, won't happen again today and we can all get back to what we want to be doing, rather than what we need to be doing... ;)
Title: Trojan detected
Post by: EHM-1570 Bruce on April 15, 2008, 09:05:22 am
I use Kaspersky and it is very good, one thing I have found is that I have problems logging into the FLogger if Kaspersky is running, I turn off Kaspersky , then logon to the FLogger then restart Kaspersky, other than that I have no problems with it.
Title: Trojan detected
Post by: EHM-0654 Murray on April 15, 2008, 10:34:52 am
Well, touch wood, etc, etc, we're past when the trojan was re-applied yesterday without incident today. We will of course keep monitoring things throughout the day to be safe, but I think we can finally begin to draw the line under this one...
Title: Trojan detected
Post by: EHM-2155 Mariano on April 15, 2008, 11:25:23 am
I made a little video showing me locking a flight with Opera. Quality is the result of fitting a desktop to the size of YouTube window, but I think it can be seen that im locking the flight and then unlocking it
http://www.youtube.com/watch?v=TBUxJGSB9K8
Title: Trojan detected
Post by: EHM-1883 Matt on April 15, 2008, 05:04:24 pm
I might be slightly responsible for the attack guys...

Please tell me whether the guy who hacked or attacked had a name like Felaco and/or was Turkish.

I say this because on another website which I'm a moderator on, a guy named Felaco attacked it and he was definitely Turkish as the messages were in Turkish and he hacked it with messages and malware with some really disgusting stuff about how he thought Greeks were vile.

Me and an Admin managed to get it all off, but please tell me whether it was the same sort of thing considering I wasn't here when the attack happened

I am so sorry if it is related to this horrid person :[
Title: Trojan detected
Post by: EHM-0654 Murray on April 15, 2008, 06:30:37 pm
Matt,

Only thing we have that identifies the perp is the IP address that did the uploads, and that reverse traced to Russia. I don't think this was "your fault" per say, and I don't really want to say very much more about it. ;)
Title: Trojan detected
Post by: EHM-1883 Matt on April 15, 2008, 08:13:32 pm
ah, ok. Not a word more from me;D
Title: Trojan detected
Post by: EHM-1944 Jaap on April 16, 2008, 01:38:34 pm
Ok Mariano,I downloaded Opera and it's perfect with PP.
Thanks, I will use it from now on.