VaultNetwork.netVault Network Boards
Author Topic: Am picking up unwanted files from ACDC site. [Locked]
Midnite-FF
Posts: 11
Registered:
I'm sorry, yes, it is when I click on the forums, as Oreo says.
-Zalliun-  1 star
Posts: 89
Registered: 2002-1-30 14:07:47
looks like its the http://removethis----xbfsrepztq.biz/dl/adv489.php in the frame that contains it.


looks like its down now or at least unstable.


2006/12/19 23:09:15.380 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\new489[1].htm is JS/MS06-014!exploit trojan.

2006/12/19 23:09:49.137 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\new489[1].htm is JS/MS06-014!exploit trojan. Deleted

2006/12/19 23:10:22.481 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan. Deleted

2006/12/19 23:10:22.552 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan.

2006/12/19 23:10:22.604 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\new489[1].htm is JS/MS06-014!exploit trojan.

2006/12/19 23:10:22.897 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan. Deleted

2006/12/19 23:10:22.955 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan.

2006/12/19 23:10:23.021 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VCQFKKIM\slide489[1].htm is JS/CVE-2006-3730!exploit trojan.

2006/12/19 23:10:23.200 File infection: C:\Users\Flemming Riis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TB9I2U5U\xpladv489[1].wmf is Win32/Worfo trojan. Deleted


Diff AV than the ones above , if opened from firefox nothing is triggered

 

-----signature-----
Fake it till you make it
Drakier  4 stars
Posts: 1,486
Registered:
Oh I see now.


Thank you for the information. That helped me immediately locate the problem


I'm working on resolving it right now. seems somehow my forums got a small hack put in them. I'll clean the hack, then attempt to look for the hole and patch it.


Again, thank you for the notice, and finally the information needed to correct the problem.
Drakier  4 stars
Posts: 1,486
Registered:
I've removed the un-wanted link, but I still need to upgrade my board it seems.


I'll have to do this at another time as I currently don't have the time to upgrade it.


Thanks again. Sorry about the problems.
Midnite-FF
Posts: 11
Registered:
Thank you, Drakier. I knew you must not be aware of it, but I don't seem to have the technical knowledge to give you the precise info you need. I am thankful for the other two fellows who helped.

VaultNetwork.net is an independently operated community forum and is not affiliated with, endorsed by, or technically based on IGN, GameSpy, FilePlanet, GameStats, or the former IGN/GameSpy Vault Network.
References to VaultNetwork.net mean this site/domain. VNBoards-style presentation is a visual homage only. By using this site, you agree to the forum rules.