View Full Version : So um I got hit by a torjan.
Sithdarth
06-16-2011, 01:30 PM
The only thing on my entire laptop that was loading anything was a Firefox tab open to the playing games forum (or one of the other sub forums I forget now). Suddenly I got a pop up about needing an older version of Java to run whatever which I knew right away was a bad sign and should never happen on this site. I canceled that then about 10 seconds later Firefox shut down and Vista Security Home 2012 shows up saying I have a trojan. Long story short I've dealt with this enough in terms of my Dad's computer to know exactly how to get rid of it, which I did. Now I'm not absolutely positive where it came from or how it got on my computer but I do know a couple of things:
1) I never clicked a download link anywhere
2) The only page that was loading was for NPF
Just throwing this out there as a heads up that someone might be doing something hinky with the ad banner or something.
Meister
06-16-2011, 01:40 PM
Thanks for the warning. Everyone, please watch out for this, and if you get a trojan warning or anything like it, take a second to note down what page you were loading and any other relevant details, most importantly what ad banner was up at the time since that's the most likely culprit.
Bells
06-16-2011, 02:15 PM
Wierd, but probably coincidental. I just had a java update today while i was on NPF. But it was a official update, not a downgrade, notified via the taskbar and java icon, not any page... I had that "hoem secuirty 2012" thing too, it was a pain. I considered formating the pc before i learned how to deal with it.
Maybe you should do a deeper cleaning too, maybe you have another trojan around that allowed this one to come through.
shiney
06-16-2011, 03:02 PM
We appreciate your report, next time however I would ask that you take note of the specific time and what ad is displayed at the top of the screen, otherwise I'm unable to determine if it came through an ad or was because of other unsavory activities you may have done previously.
Sithdarth
06-16-2011, 03:53 PM
Yeah sorry about that. It was a sort of an all of a sudden thing. By time I realized what was going on it had closed Firefox and wasn't letting me open it again. I can tell you that I'm pretty sure it was around 1:46 pm give or take a few minutes and that I'm pretty sure it was the Playing Games subforum that was loading. It happened so fast and unexpectedly I'm not 100% sure though.
Maybe you should do a deeper cleaning too, maybe you have another trojan around that allowed this one to come through.
Probably not I was just stupidly vulnerable because I had been attempting to set up a VPN and had turned off both my firewall and antivirus software and forgot to turn them back on.
mauve
06-17-2011, 03:32 AM
I got a weird java update thing on the playing games tab too, although I'm hoping it's not the same thing you dealt with.
Time: 1:30 AM Pacific time. Banner ad: something about an airline? (Sorry, I loaded a new page before thinking about screencapping the ad.)
I'm running my virusscan as we speak, and Vista hasn't said it's stopped/found anything, so hopefully it's nothing.
Osterbaum
06-17-2011, 05:01 AM
So it seems I'm having a similar problem. I'm using Firefox and so far have been able to load only three separate pages, one of them being NPF. Somehow I doubt that 80% of the sites I frequent are down at the same time. I'm sorry to say I can't really help you with what caused this though. It first occurred just now; this morning when I opened up my computer and NPF was the first site I went to.
Now any help anyone might provide would be apreciated. My first instinct was to just run a scan of my computer, but seems like Comodo is acting up and just simply refuses to do that.
e: Seems this was a false alarm. My roommate had the same problem and now the problem just sort of fixed itself on both our computers. This would suggest the problem we had was due to our service provider, since we both use the same connection provided by the same company.
mauve
06-17-2011, 03:44 PM
Update: My virusscan program decided it hates life, so I took it into Best Buy and they did indeed find a trojan. Aforementioned antivirus softwarew apparently finally got around to finding and blocking it TODAY, after finding nothing in three subsquent scans last night. Yaaaaaay antivirus program.
Anyway, I was on Steam after getting said fake java popup, so hopefully nothing happened there.
Sifright
06-18-2011, 01:02 PM
Welp literally 30 seconds ago on the main page of the forum I just had an advert attempt to make me download something, was 15kb in size.
Edit: To clarify There was no banner at the top of the page and I hadn't clicked anything on the page yet.
Ps Edit:<html>
<head/>
<body>
<iframe src="http://ad.doubleclick.net/adi/N4022.161249.ADNETIK/B5054104.4;sz=728x90;click0=http://g-ie1.wtp101.com/click?bc=CgZnb29nbGUSIDRkZmNlN2I3MDAwY2NjZDcwYTdjM jUwOGJjODY1YzlmIZqZmZmZmck.KMj07YMHMOcBONeAn4QHQKL cVEoGNzI4eDkwWiZodHRwOi8vd3d3Lm51a2xlYXJmb3J1bXMuY 29tL2luZGV4LnBocGIRbnVrbGVhcmZvcnVtcy5jb22KAQ5BQk9 WRV9USEVfRk9MRKABAaoBPzkyOF8wLjQ0MDQ5NDQxODE0NDIzf DE5MV8wLjQxNDE0MjQwMDAyNjMyfDQ0N18wLjE0NTM2MzE2Njk yODI5fLABoAe6AQc5MjhfMC40wgEYOTI4XzAuNHwxOTFfMC40f DQ0N18wLjF82gMMODQuOS4xNDQuMTk54gMCR0LqAwJNNPADAPo DC1NvdXRoYW1wdG9uggQAigQCZW6SBAJlbpoESE9wZXJhLzkuO DAgKFdpbmRvd3MgTlQgNi4xOyBVOyBlbikgUHJlc3RvLzIuNi4 zMCBWZXJzaW9uLzEwLjYxLGd6aXAoZ2ZlKaIEBU9wZXJhqgQCN jCyBAtESHJQQmljQUFKQboEJDNlZTQ0Y2M5LTQ3ZDUtNDIzMS1 hNzE1LWNkMDM5ODA4ZjU1ZuAEAOkEAAAAAAAAAADxBFBn3jbyj ZI.-AQAgAUB&google_click_url=http%3A%2F%2Fadclick.g.doubleclic k.net%2Faclk%3Fsa%3Dl%26ai%3DB05UTt-f8TdeZM4jK8AOfuZnkC86KieUB5rac2xPC69zADgAQARgBIAA4 AVCAx-HEBGC73q-D0AqCARdjYS1wdWItNjIwMjg5MDc1NzgyNTUxN6AB3vGD7gOyA RV3d3cubnVrbGVhcmZvcnVtcy5jb226AQk3Mjh4OTBfYXPIAQn aASZodHRwOi8vd3d3Lm51a2xlYXJmb3J1bXMuY29tL2luZGV4L nBocJgCoAHAAgTIAqbexBSoAwHoA6AH6AO_AegDvwP1AwABAMi ABuC0x9_7xfurxAE%26num%3D1%26sig%3DAGiWqtwmcQAph7k rTu45zK6UIIfzC5amnw%26client%3Dca-pub-6202890757825517%26adurl%3D&redir=;ord=1602596685?" width="728" height="90" marginwidth="0" marginheight="0" hspace="0" vspace="0" frameborder="0" scrolling="no" bordercolor="#000000">
<!--
Evidon tag
Campaign: UK_Standard_Top Right
Ad Size: 728x90
-->
<script type="text/javascript" src="http://c.betrad.com/surly.js?;ad_w=728;ad_h=90;coid=366;nid=1443;ecaid =231">
<script>
<script id="ba.js" type="text/javascript" src="http://c.betrad.com/geo/ba.js">
<script>
<script type="text/javascript" src="http://c.betrad.com/a/n/366/1443.js?r=0.28209441613862585">
<script>
<img width="1" height="1" src="http://www.wtp101.com/f?c=231&e=1"/>
<img width="1" height="1" src="http://www.wtp101.com/push_sync"/>
<style id="bass-COMMON" type="text/css">
<div id="BAP-holder">
<img src="http://l2.betrad.com/ct/0_0_0_231_0_1443/gb/0/1/0/0/0/0/15/242/366/0/pixel.gif?v=359&ttid=2&d=g-ie1.wtp101.com&m=5&r=0.8681231682138497" height="1" width="1"/>
<style id="bass-6" type="text/css">
</body>
</html>
vBulletin® v3.8.5, Copyright ©2000-2024, Jelsoft Enterprises Ltd.