View Full Version : Trojan in another ad


bond90
12th December 2007, 01:39
Hi to all personnel of the site, I wanted to report a problem; in one of the ad which appear after the loading of a page, my antivirus found a trojan:a file was trying to download itself to the computer, it was called "c.wmf"; in addiction, the trojan was found in some elements of the page
here is the log of the antivirus

11/12/2007 23.05.20 AMON file C:\DOCUME~1\xxxx\IMPOST~1\Temp\0vvuuwpv.wmf modified variant of Win32/Exploit.WMF trojan horse
11/12/2007 23.05.06 IMON file http://afcmoney.org/c.wmf modified variant of Win32/Exploit.WMF
11/12/2007 23.05.05 IMON file http://afcmoney.org/out/pCvxfipBR.html HTML/Exploit.IESlice. trojan horse
11/12/2007 23.05.01 IMON file http://afcmoney.org/jw/index.htm JS/Redirector.A
11/12/2007 23.05.00 IMON file http://afcmoney.org/ns/spl.htm JS/TrojanDownloader.Small.CN

Hope this will help you, thanks for your priceless service

m4sta
12th December 2007, 01:46
Yeah like this what i postet not so long ago
30 minutes ago
http://www.ipmart-forum.com/showthread.php?t=209980

bond90
12th December 2007, 01:49
Yeah like this what i postet not so long ago
30 minutes ago
http://www.ipmart-forum.com/showthread.php?t=209980

In fact I said "another ad" ;) :)

m4sta
12th December 2007, 02:03
But the trojan is located on the same site afcmoney.org. Hope they delete the site from ads becouse this is quite anoying

bond90
15th December 2007, 17:06
Seems the staff doesn't mind about us...I know advertising is needed to keep this great service alive, but this shouldn't affect the usage of the site...I think it should be removed, for the reputation of the forum itself...Hope they will consider it...

~: SuYoG :~
15th December 2007, 17:18
@ bond90 we already working on it wait 2 admin or master mods reply !

bond90
16th December 2007, 12:34
@ bond90 we already working on it wait 2 admin or master mods reply !

Thanks SuyoG for your reply, mine was only a provocation, waiting for a reply...

-=[tp12]=-
16th December 2007, 12:36
Thanks SuyoG for your reply, mine was only a provocation, waiting for a reply...

Your prob must have been solved now...
As some of the ads have been removed...
You still facing the prob...:?:

bond90
16th December 2007, 12:45
Your prob must have been solved now...
As some of the ads have been removed...
You still facing the prob...:?:

Yesterday I was still facing the problem; today I don't know; I've seen an ad from the same group, but the antivirus didn't warn me; however, I'm on another computer with avg instead of nod32...I'll try with my pc asap; thanks for your help again, I'll let you know there

-=[tp12]=-
16th December 2007, 12:47
Yesterday I was still facing the problem; today I don't know; I've seen an ad from the same group, but the antivirus didn't warn me; however, I'm on another computer with avg instead of nod32...I'll try with my pc asap; thanks for your help again, I'll let you know there

Sure mate...
Awaiting for your reply...

valuz
17th December 2007, 10:52
I am still facing the problemm.In 2 minutes now it tried 3 times starting the download of this file.A bit confusing.

Cliddo
17th December 2007, 11:18
I also have the trojan problem in the ads. :(

bond90
17th December 2007, 17:24
I'm very sorry tp12...
here's new report

17/12/2007 15.14.21 AMON file C:\DOCUME~1\xxx\IMPOST~1\Temp\4o8f4qan.wmf modified variant of Win32/Exploit.WMF trojan horse quarantined. deleted Event occurred on a file modified by application: C:\PROGRA~1\Mozilla Firefox\firefox.exe. File has been quarantined.you may close this window.
17/12/2007 15.14.13 IMON file http://afcmoney.org/c.wmf modified variant of Win32/Exploit.WMF trojan horse
17/12/2007 15.14.12 IMON file http://afcmoney.org/out/pCvxfipBR.html HTML/Exploit.IESlice.I trojan horse connection aborted
17/12/2007 15.14.10 IMON file http://afcmoney.org/jw/index.htm JS/Redirector.A trojan horse connection aborted
17/12/2007 15.14.09 IMON file http://afcmoney.org/ns/spl.htm JS/TrojanDownloader.Small.CN trojan horse connection aborted

the address is the same as before, all of them belong to afcmoney.org....hope
a solution will be found...

F2504x4
3rd March 2008, 01:47
They say a picture is worth a thousand words


http://pic19.picturetrail.com/VOL1028/7341432/18853979/306798320.jpg

http://pic19.picturetrail.com/VOL1028/7341432/18853979/306798848.jpg

3com
3rd March 2008, 04:19
nah never found that.....clean ur temp folder...looks on ur screenshot...there is no such trojan on forum