Argonath RPG Police Department

General => General Discussion => Topic started by: Ronnel on June 24, 2011, 22:06:03 pm

Title: JAVA popup : VIRUS
Post by: Ronnel on June 24, 2011, 22:06:03 pm
Please note that some users may get a JAVA popup screen when opening the site. This is due to a possible infection.
We are checking all files and will remove any problem.
Do not install anything.
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 24, 2011, 23:33:27 pm
Well I'm f**ked then
Title: Re: JAVA popup : VIRUS
Post by: Marcell on June 24, 2011, 23:37:28 pm
Aw shit, I believe i clicked yes once by mistake but my antivirus detected a trojan and deleted a file. Good to know, I thought it's a false-treat
Title: Re: JAVA popup : VIRUS
Post by: Morphine on June 24, 2011, 23:47:37 pm
I believe I accepted it and derp, no antivirus installed.
If you have also clicked it, immediately check your process list and terminate s.exe. It is one of the suspected threats of the keylogger dropped on the forum.
Run a full system scan too if you haven't already.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 24, 2011, 23:51:38 pm
ARFD forums don't seem to be infected, either do ADF or UA. I believe this is isolated to RON's FTP server.
Title: Re: JAVA popup : VIRUS
Post by: Morphine on June 25, 2011, 00:00:52 am
(http://i55.tinypic.com/r1fos3.png)
Here is what happens when you delete the virus from it's location.
The antivirus moves it to a chest since the virus fights back as much as it can.
Title: Re: JAVA popup : VIRUS
Post by: Bert on June 25, 2011, 00:01:31 am
ARFD forums don't seem to be infected, either do ADF or UA. I believe this is isolated to RON's FTP server.
The forum was infected
Title: Re: JAVA popup : VIRUS
Post by: James Bowling on June 25, 2011, 00:16:37 am
Please note that some users may get a JAVA popup screen when opening the site. This is due to a possible infection.
We are checking all files and will remove any problem.
Do not install anything.

I dnt install but I get the pop up.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 00:21:12 am
ARFD forums don't seem to be infected, either do ADF or UA. I believe this is isolated to RON's FTP server.
The forum was infected
No it wasn't. Something is being exploited. We are looking into it. I already decrypted the JavaScript code and we have a website URL already. This hacker just got out-hacked. More to come soon.

Oh ya, warn your friends!
Title: Re: JAVA popup : VIRUS
Post by: Pepper on June 25, 2011, 00:21:49 am
I get the pop ups on main site only but am start enough to know not to click anything popping up on the internet ;)
Title: Re: JAVA popup : VIRUS
Post by: Dolfa on June 25, 2011, 00:24:15 am
So..I just got avast anti-virus since its the best one, informed by friends and no threats were found. However I did run that pop up.
Title: Re: JAVA popup : VIRUS
Post by: JunkMan on June 25, 2011, 00:29:48 am
MSE rocks bud disinfected the virus and made him shut up even before poping up i love ya MSE!
Title: Re: JAVA popup : VIRUS
Post by: Salmonella on June 25, 2011, 00:36:08 am
ARFD forums don't seem to be infected, either do ADF or UA. I believe this is isolated to RON's FTP server.
True. usaa.argonathrpg also stayed up and clean. It runs on caion's VPN
Title: Re: JAVA popup : VIRUS
Post by: Julio. on June 25, 2011, 00:48:41 am
I just denied it access when I got it yesterday, as I never clicked anything ;)

Does it go under the name 'S.exe.?
Title: Re: JAVA popup : VIRUS
Post by: KhornateMonkey on June 25, 2011, 00:49:45 am
Thank f**k for McAfee. Detected it as a Trojan and deleted it for me  :sheriff:
Title: Re: JAVA popup : VIRUS
Post by: Ben on June 25, 2011, 00:53:06 am
AVG is shit. End of.

I could have done with this topic before allowing it once...downloaded MalwareBytes, so it stopped it spreading further, chucking it into quarantine!
s.exe may be the one to look out for in Task Manager.  If it is running, find out where the file location is, remember it, and make sure your anti-virus gets rid of the spreading. Reboot your computer, and if it is no longer in Task Manager, delete s.exe manually by going into the specified location. Do not open it.

I did that...no more virus ;)
Title: Re: JAVA popup : VIRUS
Post by: Allison on June 25, 2011, 00:54:29 am
Oddly enough I never got a popup or anything.  :lol:
Title: Re: JAVA popup : VIRUS
Post by: Bert on June 25, 2011, 00:57:53 am
I just denied it access when I got it yesterday, as I never clicked anything ;)

Does it go under the name 'S.exe.?
yes , that's what i got
Title: Re: JAVA popup : VIRUS
Post by: Ben on June 25, 2011, 01:00:52 am
I just denied it access when I got it yesterday, as I never clicked anything ;)

Does it go under the name 'S.exe.?
yes , that's what i got
High five to the other innocent fool, who thought it was actually Java  :lol:
Title: Re: JAVA popup : VIRUS
Post by: [Rstar]Vince on June 25, 2011, 01:07:11 am
Java plugin needs my permission to run.. good thing I seen this first. Doubt I would've installed it anyway as I was wary why it was popping up in the first place. :conf:
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 01:28:36 am
Yes, to confirm, s.exe is the malicious file. The website has been reported to the authorities and shall cease operations soon. Various Argo sites and servers are also continuing to be DDoS'ed. Just hang in there guys. We'll catch the bastard. I already got his website, shouldn't be hard now.
Title: Re: JAVA popup : VIRUS
Post by: Goodandy on June 25, 2011, 01:50:42 am
I clicked a few times on it. :hit:  :help:

Anyone know where I can find it? I did a scan, found nothing. I am still unsure if it is there.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 01:57:00 am
I clicked a few times on it. :hit:  :help:

Anyone know where I can find it? I did a scan, found nothing. I am still unsure if it is there.
Scan with both Anti-Virus and Anti-Spyware.
Title: Re: JAVA popup : VIRUS
Post by: Goodandy on June 25, 2011, 01:58:26 am
I clicked a few times on it. :hit:  :help:

Anyone know where I can find it? I did a scan, found nothing. I am still unsure if it is there.
Scan with both Anti-Virus and Anti-Spyware.

But where can I find the virus inside my PC? Should I search for it?
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 02:00:35 am
I clicked a few times on it. :hit:  :help:

Anyone know where I can find it? I did a scan, found nothing. I am still unsure if it is there.
Scan with both Anti-Virus and Anti-Spyware.

But where can I find the virus inside my PC? Should I search for it?
No. Scan. You're not looking for one specific file with a predictable name. It could be running in your computer's memory too.
Title: Re: JAVA popup : VIRUS
Post by: Goodandy on June 25, 2011, 02:01:48 am
I clicked a few times on it. :hit:  :help:

Anyone know where I can find it? I did a scan, found nothing. I am still unsure if it is there.
Scan with both Anti-Virus and Anti-Spyware.

But where can I find the virus inside my PC? Should I search for it?
No. Scan. You're not looking for one specific file with a predictable name. It could be running in your computer's memory too.

Alright, hopefully I don't have anything...  :neutral:
Title: Re: JAVA popup : VIRUS
Post by: Jack White on June 25, 2011, 02:03:32 am
My anti-virus program, aka derek finished the job.

American History X - Derek shows who's the boss (http://www.youtube.com/watch?v=dgn7SUzGZpw#ws)
Title: Re: JAVA popup : VIRUS
Post by: Heather on June 25, 2011, 02:25:35 am
WOW I still remember the password of my ARPD forum acc.Last post was in 2009 :D Passed the word on to Hidduh and some other people in MSN.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 02:29:03 am
WOW I still remember the password of my ARPD forum acc.Last post was in 2009 :D Passed the word on to Hidduh and some other people in MSN.
/me facepalms hard
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 02:32:19 am
f**k. I killed 's.exe' using task manager, but my anti virus didn't pick anything up.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 02:34:55 am
f**k. I killed 's.exe' using task manager, but my anti virus didn't pick anything up.
I'm not sure if the actual name of the file being downloaded is the same as the one that executes the malicious download, but that's highly suspicious regardless. Update everything and boot into Safe Mode and have your A/V and A/S BOTH fully scan your computer.
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 02:42:23 am
I have Webroot, and it's meant to be an anti virus with a spy scanner ._. That's all I've got.
Title: Re: JAVA popup : VIRUS
Post by: [Rstar]Vince on June 25, 2011, 02:46:46 am
I have Webroot, and it's meant to be an anti virus with a spy scanner ._. That's all I've got.

Silly asian software your parents have. :sheriff:
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 02:50:26 am
I have Webroot, and it's meant to be an anti virus with a spy scanner ._. That's all I've got.

Just a suggestion, never trust an Anti-Virus software that claims to also remove Spyware, because it's a BS marketing gimmick. They are SOMETIMES able to detect it, but they can next to never remove it, and they almost never detect it anyway, so you're left wide open. If you have Windows XP or higher, get or turn on Windows Defender in addition to your Anti-Virus software.

Edit: Oops, fixed a weird typo.
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 03:07:13 am
How do you perform a full scan with Windows Defender? When I press 'Scan', it only performs a quick scan.
Title: Re: JAVA popup : VIRUS
Post by: Allison on June 25, 2011, 03:08:49 am
There is a down arrow by the 'scan' button on top. Click it and go down to full scan.
Title: Re: JAVA popup : VIRUS
Post by: [Rstar]Paul on June 25, 2011, 03:13:13 am
More information can be found here Argonath Club (http://club.argonathrpg.com/)
Title: Re: JAVA popup : VIRUS
Post by: XSniper on June 25, 2011, 03:20:31 am
Um is this suppose to happen?....
(http://i55.tinypic.com/6ofn7m.png)
It's been on for the whole day, restarted my laptop and still, wth?
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 03:21:32 am
There is a down arrow by the 'scan' button on top. Click it and go down to full scan.

Oh. Duh.
Title: Re: JAVA popup : VIRUS
Post by: Allison on June 25, 2011, 03:24:01 am
There is a down arrow by the 'scan' button on top. Click it and go down to full scan.

Oh. Duh.
Fail.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 03:24:45 am
Um is this suppose to happen?....
(http://i55.tinypic.com/6ofn7m.png)
It's been on for the whole day, restarted my laptop and still, wth?
It's an attack on Argo. Ignore the popup and do NOT run it.

Edit: Oh! The image loaded for me after I posted. Clear your browser cache and then come back to the page and hit Ctrl+F5 to do a hard refresh.

Double Edit: Seems IE is running the JavaScript automatically, even in IE9. Scan your computer and avoid using the website in that browser for the time being.
Title: Re: JAVA popup : VIRUS
Post by: XSniper on June 25, 2011, 03:30:12 am
My PC got f***ed earlier with s**tloads of viruses. But I managed to remove them all!  :war:

Warning

**To windows users if Windows Defender suddenly pops up while on the forums saying 1 threat to computer and it asks for a scan DO NOT scan it! It's a fake program that uses the same java from "Windows Defender" and when you scan it downloads the virus into your pc.

Java is not the virus! (in this situation) because, Windows Defender tricks you mkaing it look like it is the virus when the fake Windows Defender itself is the virus.***

To MAC osx or other users Java could be your virus, if you accidentially did click yes close "s.exe" And any other "java.exe" BUT!! with a suspicious number EX: java23.exe <- VIRUS!

This was confirmed by Windows because I had contacted them earlier when I had sh**tloads of viruses on my pc.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 03:33:04 am
My PC got f***ed earlier with s**tloads of viruses. But I managed to remove them all!  :war:

Warning

**To windows users if Windows Defender suddenly pops up while on the forums saying 1 threat to computer and it asks for a scan DO NOT scan it! It's a fake program that uses the same java from "Windows Defender" and when you scan it downloads the virus into your pc.

Java is not the virus! (in this situation) because, Windows Defender tricks you mkaing it look like it is the virus when the fake Windows Defender itself is the virus.***

To MAC osx or other users Java could be your virus, if you accidentially did click yes close "s.exe" And any other "java.exe" BUT!! with a suspicious number EX: java23.exe <- VIRUS!

This was confirmed by Windows because I had contacted them earlier when I had sh**tloads of viruses on my pc.

Windows Defender is not a virus. Read my second edit in the post above your's. You infected your own computer by mistake and it attacked your Windows Defender. What really happened is IE9's default JavaScript settings fail, so they automatically ran the JavaScript attack which loaded Java, which ran the malicious executable on the other site containing the virus on your computer. This then detected you had Windows Defender installed, and "hacked" it so that it would be useless and possibly output invalid information, as well as possibly installing fake anti-malware on your computer. Immediately redownload Windows Defender from the MS website and boot into safe mode, remove your viruses, install Windows Defender, scan with that, and then update your computer and don't use IE on ARPD forums until the attack has been blocked.
Title: Re: JAVA popup : VIRUS
Post by: Leonardo on June 25, 2011, 03:36:38 am
Forums are loading a bit slower after that. Normally i'd load 3 pages at the same time and they would naturally load then all after 10 seconds, now, after 30 seconds, they are still loading and i gotta refresh then to load... bah
Title: Re: JAVA popup : VIRUS
Post by: XSniper on June 25, 2011, 03:37:08 am
(http://i55.tinypic.com/246w55f.png)


It almost struck me on Chrome
Title: Re: JAVA popup : VIRUS
Post by: Allison on June 25, 2011, 03:40:17 am
No issues, and I use FireFox 5.0. Hm...Must only target certain browsers.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 03:40:36 am
Forums are loading a bit slower after that. Normally i'd load 3 pages at the same time and they would naturally load then all after 10 seconds, now, after 30 seconds, they are still loading and i gotta refresh then to load... bah
Ya, a DDoS attack is happening at the same time.

(http://i55.tinypic.com/246w55f.png)


It almost struck me on Chrome
Ya, thankfully Chrome will stop it with default settings. :cop:

No issues, and I use FireFox 5.0. Hm...Must only target certain browsers.
No, all browsers are affected. It's just down to your JavaScript settings on whether it runs or not. IE9, unfortunately, has default settings to auto-run them so it's easier on users, but less secure, which is why users are getting infected with it.
Title: Re: JAVA popup : VIRUS
Post by: Goodandy on June 25, 2011, 04:47:39 am
Um is this suppose to happen?....
(http://i55.tinypic.com/6ofn7m.png)

I have the same problem, any way to change it... If not just wait?  :help:
Title: Re: JAVA popup : VIRUS
Post by: Allison on June 25, 2011, 04:48:36 am
I'd say you have to wait until whatever is happening is done with.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 05:44:53 am
Edit: Oh! The image loaded for me after I posted. Clear your browser cache and then come back to the page and hit Ctrl+F5 to do a hard refresh.

Double Edit: Seems IE is running the JavaScript automatically, even in IE9. Scan your computer and avoid using the website in that browser for the time being.
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 07:38:45 am
Windows Defender did not pick anything up. Is this a good thing, or a bad thing?
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 07:41:44 am
Windows Defender did not pick anything up. Is this a good thing, or a bad thing?
Good.
Title: Re: JAVA popup : VIRUS
Post by: Exterminator on June 25, 2011, 09:40:00 am
What should i do if i opened the popup several times..

Also the main argo webiste doesnt open for me many times, refreshing restarting e.t.c doesnt help but it automatically fixes in a few hours
Title: Re: JAVA popup : VIRUS
Post by: Exterminator on June 25, 2011, 09:41:45 am
Forums are loading a bit slower after that. Normally i'd load 3 pages at the same time and they would naturally load then all after 10 seconds, now, after 30 seconds, they are still loading and i gotta refresh then to load... bah
Ya, a DDoS attack is happening at the same time.

(http://i55.tinypic.com/246w55f.png)


It almost struck me on Chrome
Ya, thankfully Chrome will stop it with default settings. :cop:

No issues, and I use FireFox 5.0. Hm...Must only target certain browsers.
No, all browsers are affected. It's just down to your JavaScript settings on whether it runs or not. IE9, unfortunately, has default settings to auto-run them so it's easier on users, but less secure, which is why users are getting infected with it.

I chose always run on this site, what to do D:
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 09:44:20 am
1. Stop double posting and follow the rules.
2. Read the whole topic. :P

Scan your whole computer with Anti-Virus and Anti-Spyware, and modify your browser's settings and remove the exception for this site.
Title: Re: JAVA popup : VIRUS
Post by: Steven J on June 25, 2011, 09:45:06 am
Oddly enough I never got a popup or anything.  :lol:

Same
Title: Re: JAVA: virus
Post by: Ben on June 25, 2011, 09:55:40 am
Okay. Local disk, prngram files, users, <you>, appdata, local, temp...s.exe! Thats where i found it i think.
Get malwarebytes, its free and effective. Do a full scan, and quarantine/remove anything you get.
Title: Re: JAVA: virus
Post by: Chief J. Schappell on June 25, 2011, 09:57:11 am
Okay. Local disk, prngram files, users, <you>, appdata, local, temp...s.exe! Thats where i found it i think.
Get malwarebytes, its free and effective. Do a full scan, and quarantine/remove anything you get.
Yes, "s.exe" is the malicious file responsible.
Title: Re: JAVA popup : VIRUS
Post by: Janar on June 25, 2011, 14:50:07 pm
CHROME PIC


It almost struck me on Chrome

Yup, got the same thing...

But I chose "Always run on this site", how can I remove it now?
Title: Re: JAVA popup : VIRUS
Post by: [Rstar]Paul on June 25, 2011, 14:54:26 pm
Try uninstalling Java and re-installing it.
Title: Re: JAVA popup : VIRUS
Post by: Chief J. Schappell on June 25, 2011, 15:08:23 pm
In Google Chrome: Wrench Icon > Options > Under The Hood > Content Settings > JavaScript > Manage Exceptions.
Title: Re: JAVA popup : VIRUS
Post by: Rare on June 25, 2011, 15:27:29 pm
Tutorials on disabling Java for Web Browsers....

Firefox

Step #1: Go to firefox Settings (from top left corner ) > Options. At Contents tab, unmark Java Scriptthen OK.

Just reverse this setting to enable java script on your browser.

Google Chrome

Step #1: Click on settings icon at the top right corner then Options. Now Under the Hood > Content Settings.
Step #2: Look for the Java Script thing under Content Settings. You may block and allow different sites, or turn it off.

Just reverse this setting to enable java script on your browser

Internet Explorer

Step #1: Click on Tools > Internet Options > Security Tab. Now click on Internet Icon then Custom Lavel.
Step #2: Change the Scripting to Disable or Prompt (Default is always: Enable)

Just reverse this setting to enable java script on your browser
Title: Re: JAVA popup : VIRUS
Post by: Cester on June 25, 2011, 18:58:09 pm
f**k the time right now argonath forum got hack with this screen

(http://desmond.yfrog.com/Himg818/scaled.php?tn=0&server=818&filename=viruse.png&xsize=640&ysize=640)
Title: Re: JAVA popup : VIRUS
Post by: [R*]EliteTerm on June 25, 2011, 20:42:31 pm
Someone mentioned that there was a keylogger downloaded by the Trojan.

Find and delete the Trojan and anything that it downloaded, THEN CHANGE YOUR PASSWORDS. It won't do you any good if the keylogger's still in the computer.
Title: Re: JAVA popup : VIRUS
Post by: Mikal on June 25, 2011, 20:56:05 pm
Someone mentioned that there was a keylogger downloaded by the Trojan.

Find and delete the Trojan and anything that it downloaded, THEN CHANGE YOUR PASSWORDS. It won't do you any good if the keylogger's still in the computer.
've just ran AVG, Advanced SystemCare and defragmented my PC, nothing found yet... :o
I think I canceled the pop up yesterday..
Title: Re: JAVA popup : VIRUS
Post by: Cane on June 25, 2011, 21:03:07 pm
Someone mentioned that there was a keylogger downloaded by the Trojan.

Find and delete the Trojan and anything that it downloaded, THEN CHANGE YOUR PASSWORDS. It won't do you any good if the keylogger's still in the computer.

Meep. Do you know what the name of the file is? Also, my Windows Defender didn't find anything, so...
Title: Re: JAVA popup : VIRUS
Post by: Bert on June 25, 2011, 21:04:02 pm
Someone mentioned that there was a keylogger downloaded by the Trojan.

Find and delete the Trojan and anything that it downloaded, THEN CHANGE YOUR PASSWORDS. It won't do you any good if the keylogger's still in the computer.

Meep. Do you know what the name of the file is? Also, my Windows Defender didn't find anything, so...
It was called s.exe for me
Title: Re: JAVA popup : VIRUS
Post by: Mikal on June 25, 2011, 21:07:02 pm
Where can I find s.exe if I have it?
Title: Re: JAVA popup : VIRUS
Post by: Boozman on June 25, 2011, 21:10:21 pm
Where can I find s.exe if I have it?
You can check if it's running in the Task Manager under the Processes tab.
Title: Re: JAVA popup : VIRUS
Post by: Mikal on June 25, 2011, 21:13:52 pm
Ok thanks, well I can't see any s.exe. :)
Title: Re: JAVA popup : VIRUS
Post by: Boozman on June 25, 2011, 21:23:47 pm
Ok thanks, well I can't see any s.exe. :)
That's a good sign.
Title: Re: JAVA popup : VIRUS
Post by: Morphine on June 25, 2011, 21:33:01 pm
I just denied it access when I got it yesterday, as I never clicked anything ;)

Does it go under the name 'S.exe.?
Yes it runs under the name s.exe with a random description.
Title: Re: JAVA popup : VIRUS
Post by: Julio. on June 30, 2011, 12:22:24 pm
If you have this, chances are that AVG, Windows Defender will not find it, SOOO:

Download Malwarebytes Antimalware

If anything will do it, that will.



That guy thinks he's awesome, chances are he's either 11, or an unloved 50 year old Virgin with no life. It has not yet struck him that even when you use a proxy etc, your details can be retrieved from the proxy itself.
Title: Re: JAVA popup : VIRUS
Post by: [Rstar]Norrage on June 30, 2011, 15:03:47 pm
This is still going on so this won't be locked.
Title: Re: JAVA popup : VIRUS
Post by: Julio. on June 30, 2011, 19:05:57 pm
f**k the time right now argonath forum got hack with this screen

(http://desmond.yfrog.com/Himg818/scaled.php?tn=0&server=818&filename=viruse.png&xsize=640&ysize=640)

He used 'you're' instead of 'your' and he spelt apparently wrong.

So Regarding the 'f**k with the Best' bit, he ain't the best as the best can spell <: D
Title: Re: JAVA popup : VIRUS
Post by: Exterminator on June 30, 2011, 19:07:29 pm
This is still going on so this won't be locked.

Why would you lock a topic like this anyway, even if this ends we still need to discuss it..
SimplePortal 2.3.7 © 2008-2025, SimplePortal