PDA

View Full Version : Trojan horse?


Hrus
10-07-2009, 19:55
While browsing through forum, I got the warning from Avast antivirus:
Name of file: http://tag.gamersabc.com/ad/index.htm
Name: JS:Obfuscated-CE [Trj]
Type of malware: Trojan horse

anyone? some bad add?

Thyiad
10-07-2009, 20:22
The Moderators & Admins are aware of it. Rush is on it.

Most likely a false positive. I use Opera and Avira and I am not seeing anything. My guess is Mozilla or Avast is having a Norton moment.

Slythar
10-07-2009, 20:54
As Hrus said but I got the alert on the splash page about 20 minutes ago.

Are
10-07-2009, 23:55
I don't know if there's anything to it, but Norton reported 12 computer threats for this site when I logged on just now. It hasn't performed any actual blocking of said threats though, so most likely it's still safe to peruse these forums :)

TenYearsGone
11-07-2009, 00:34
I've been having problems here for a while.

At work: I've been getting the Trojan message all week. About 30% of the time that I try to enter the site, my IE shuts down. Not good.

ALSO: For well over a month, this site has been trying to download tag.admeld (or something like that) files onto my systems only to be blocked by the work and home firewall. What's really disappointing is I pm'd Elly so as not to make a stink about it and never heard a reply.

I get it that ad revenue helps run this site, but once this site is marked as malicious, the party is over. I do 98% of my surfing on DIII.net at work. If my work firewall marks this site, I'll rarely ever surf here again (at home I prefer to play games instead of read about them). It's only a matter of time before this place is banned from corporate web access.

A very disappointed TYG

butchie
11-07-2009, 00:58
I have no ads now as i'm pal, but i never had any warning before. I use firefox and avast antivirus.

Either i was very lucky at what ads were generated for me or maybe the problem is that your browser/firewall/antivirus security settings are too strict and it gives you "false" alarms.

adddm
11-07-2009, 01:14
Same Norton messages on my computer: here's the 12 threats:

Drive-By Downloads (what's this?)
Threats found: 12
Here is a sample:

Threat Name: Trojan Horse
File name: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\G1Q9SRO7\mpg2[1].gif
Signature (MD5): c26a70a02442035a7836c1f6d0a50bf0
Location: http://diablo.incgamers.com/forums/search.php?do=finduser&u=117079

Threat Name: Trojan Horse
File name: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GZKDIZWD\mpg2[1].gif
Signature (MD5): c26a70a02442035a7836c1f6d0a50bf0
Location: http://diablo.incgamers.com/forums/newreply.php?do=newreply&p=4792573

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/blog/comments/win-a-trip-to-blizzcon/

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/forums/search.php?do=finduser&u=20885

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/forums/newreply.php?do=newreply&p=4793515

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/forums/search.php?do=finduser&u=145288

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/forums/member.php?u=166460

Threat Name: 39818
File name: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GZKDIZWD\mpg2[1].gif
Signature (MD5): c26a70a02442035a7836c1f6d0a50bf0
Location: http://diablo.incgamers.com/forums/member.php?u=131620

Threat Name: Process Started
Process name: c:\windows\system32\scvhost.exe
Location: http://diablo.incgamers.com/forums/newreply.php?do=newreply&p=4792678

Threat Name: Direct link to Process Started
Location: http://diablo.incgamers.com/blog/diablo-iiis-first-arcane-spells/


Norton firewall also stopped three 'high level intrusions':

Attempt by DFMYTN91 on IEXPLORE.EXE
HTTP Malicious Toolkit Variant Activity
tag.gamersabc.com/ad/index.htm

Please let us know what's going on.

Rushster
11-07-2009, 02:07
Can everyone please tell me which country they are surfing from. This will help me try and find the agency delivering the banner. Thanks in advance!

adddm
11-07-2009, 02:31
Can everyone please tell me which country they are surfing from. This will help me try and find the agency delivering the banner. Thanks in advance!

USA - North Carolina if that matters.

Rushster
11-07-2009, 02:36
Yes it does. Thanks loads. Can others also please post their location also.

Tunk
11-07-2009, 03:32
Just got the same alert, location Finland.

It's the top banner that sometimes gets directed to tag.gamersabc.com/ad/index.htm

Rushster
11-07-2009, 04:43
OK thanks guys. If anyone sees it in a time frame after this post please llet me know. I think I have identified the ageny now and removed them from the ad pool. I will keep heking this thread.


Just got the same alert, location Finland.

It's the top banner that sometimes gets directed to tag.gamersabc.com/ad/index.htm

yugular
11-07-2009, 08:49
Can everyone please tell me which country they are surfing from. This will help me try and find the agency delivering the banner. Thanks in advance!

Finland.

I am Mac user and Safari and Firefox have notified me about threats for a week or so. I contacted SPF moderators about it and sent them the specs.

Thanks

yugular

edit. Just notified that someone else has had problems in Finland too.

I haven't got any alarms today btw.

DeadManWalking
11-07-2009, 13:29
Japan.
Got same alert today for the first time from Norton SafeWeb.

Here is the link:
http://safeweb.norton.com/report/show?url=diii.net

TenYearsGone
11-07-2009, 14:54
USA - New York

Gorny
11-07-2009, 16:02
No problems here in Chicago. I'm running Firefox and McAfee.

butchie
11-07-2009, 16:42
Got alert on http://diablo2.diablowiki.net/

from: http://tag.gamersabc.com/ad/index.htm

I'm browsing from Czech Republic

Crowd Control
11-07-2009, 20:11
I think the downloading part can only be scripted through IE, as other browsers don't allow scripts. Does this correspond with the alerts everyone is talking about?

TenYearsGone
12-07-2009, 02:13
I think the downloading part can only be scripted through IE, as other browsers don't allow scripts. Does this correspond with the alerts everyone is talking about?


Maybe - IE for me both at work and home.

Slythar
12-07-2009, 02:45
I haven't received an alert since my last post. My location is Surrey, BC, Canada

TenYearsGone
14-07-2009, 17:59
Yesterday (July 13) when I tried to enter the DIII.Net homepage, it shut down my IE. I haven't tried that page yet today so I could type this in here.

I also see in the D3 Community Forums a thread along these lines with Firefox reporting Incgamers as a hostile site.

Sorry this took so long to get here. RL has had me busy.

adddm
18-07-2009, 18:47
Received another minutes ago:

Norton firewall stopping another 'high level intrusion':

Attempt by DFMYTN91 on IEXPLORE.EXE
HTTP Malicious Toolkit Variant Activity
tag.gamersabc.com/ad/index.htm

My location is North Carolina, USA

I also have been experiencing internet access issues with my DSL since this started with frequent lost connection that Windows XP 'restores'. Full virus scans (Norton) have not turned up anything. Anyone know more about what the site above is trying to do or what to look for in case something has been downloaded onto our computers?

NASE
20-07-2009, 22:48
http://tag.gamersabc.com/ad/index.php

Just had two of those warnings. So it ain't over.

Belgium here if that's of any importance?

Prophecy
22-07-2009, 19:08
There seems to be a trojan in your ads :/

http://i31.tinypic.com/2dhfm95.jpg

Thyiad
22-07-2009, 23:05
No need to make another thread, Prohecy. Just read this one.

accelerator
29-07-2009, 19:57
Didnt notice the first episode but getting it via the strategy compendium on load last couple of days.

http://tag.gamersabc.com/ad/index.htm

Opera, Avast, UK

Firefox users usually have ad banning addons which is probably why you're not seeing it.