PDA

View Full Version : viruses comnig from my site?


teamgwho
4-19-05, 11:18 AM
I run www.lostinjersey.com

I got an email about two weeks ago from a fellow who said he went to visit this page

http://www.itsnewjersey.com/lostinjersey/ship/seaking.html

and he got an error on the page, and his antivirus says it caught a virus from that page, link to screen shot below

http://www.itsnewjersey.com/lostinjersey/graphics2005/outlook.bmp

I just loaded new content to my site today. I created the file this morning, laoded the file this morning. Email my fan club about the new content. got an email within 20 minutes stating this page had the same problem as the previous person described.

http://itsnewjersey.com/lostinjersey/abandon/swimclub.html

I visit these pages, they show up and I get no problems. ran virus checker on the files, no viruses detected. I dont think there's anything on my home computer. I am having trouble with an asshat making a nussance of himself, you can read the details in a thread in my forums

http://itsnewjersey.proboards30.com/index.cgi?board=genwnj&action=display&num=1112752802

I wouldn't put it past the guy to hack me or cause trouble but I admit I have no real evidence to support this other then that he's a complete ******* who has it in for me. He ran his own website but I don't know if he's skilled enough to try and **** with my site. I see threads from other users with similar issues the past few weeks and I'm wondering if there's something going on with the servers, or if I've been hacked. or what. please help.

toastmaster
4-19-05, 12:37 PM
I run www.lostinjersey.com

I got an email about two weeks ago from a fellow who said he went to visit this page

http://www.itsnewjersey.com/lostinjersey/ship/seaking.html

and he got an error on the page, and his antivirus says it caught a virus from that page, link to screen shot below

http://www.itsnewjersey.com/lostinjersey/graphics2005/outlook.bmpDude, how the HELL did you manage to make the image so big?!? It's 100x bigger than it should be! See converted version here: http://www.digitaltoast.co.uk/outlook.png - 33k compared to 3072k! Anyway, did you look at the antivirus page for that virus?
http://vil.nai.com/vil/content/v_101033.htm
It may also be related to this thread:
http://forum.powweb.com/showthread.php?t=50094

scrappy
4-19-05, 12:45 PM
If you havent been hacked. I am looking over your extremely large .bmp file and notice this guy has two tool bars has a "Java" program running in his taskbar. I bet he may have been hit with some sort of Spyware attack from another site and should run some anti-spyware programs (lavasoft ad-aware S.E.) and see if that helps. He should also run a full Virus scan using Mcafee and the latest definitions. Some spyware will automatically connect to their own place and send them files they do not want.
Also he has three different times that he recieved this trogan. Were these three times the exact times that he visited that particular page on your website?
Chances are if it's not effecting all the users who visit that page, it probably is not something wrong with that page and there is a LOT of spyware crap out there to mess around like this.

IanS
4-19-05, 01:19 PM
If you havent been hacked. I am looking over your extremely large .bmp file and notice this guy has two tool bars has a "Java" program running in his taskbar. I bet he may have been hit with some sort of Spyware attack from another site and should run some anti-spyware programs (lavasoft ad-aware S.E.) and see if that helps. He should also run a full Virus scan using Mcafee and the latest definitions. Some spyware will automatically connect to their own place and send them files they do not want.
Also he has three different times that he recieved this trogan. Were these three times the exact times that he visited that particular page on your website?
Chances are if it's not effecting all the users who visit that page, it probably is not something wrong with that page and there is a LOT of spyware crap out there to mess around like this.I agree - I visited the links provided and stayed around a while and nothing happened. The most likely is a spyware program of some kind - multiple copies of it.

The site is clean if you've checked it via downloading and running an AV check - I fully agree it is likely to be coincidence that more than one person should report a problem. Maybe they should do some house-cleaning before accusing others :D

teamgwho
4-20-05, 08:53 AM
I didnt take the image, the dude did, and being I have broadband I didnt pay attention to the file size. and as for the smaller version, you cant read the name of the virus.

as for your links, thanks, that answers a lot.

teamgwho
4-20-05, 08:56 AM
thanks for the help, I'm passing this on to the two fellows who made the reports.

toastmaster
4-20-05, 10:25 AM
I didnt take the image, the dude did, and being I have broadband I didnt pay attention to the file size. and as for the smaller version, you cant read the name of the virusHuh? The smaller version is only smaller in filesize, all the info is there...wait, I just thought - your browser may be scaling it - click on the image to see it "full size", I think I see what you mean now. For future reference for anyone wanting to post screengrabs, here's a couple of good hints:
Download Irfanview (free)
http://www.irfanview.com/
Press "print screen" on keyboard (or alt-prtinscreen to just grab a window - good tip, that!)
Press CTRL-V to past it into Irfanview
IMAGE>DECREASE COLOUR DEPTH (256 colours)
File > SAVE AS - choose filetype of png, binary compression, level 9.

You'll end up with a semi-lossless version of the original image, but at 100th the size of the original usually. Might take an extra minute to do, but many others will thank you for it!
Remember, screen grabs and web graphics: png
Photos: jpg