POSSIBLE SITE HACK

Avlis Headlines - www.avlis.org

Moderator: Event DM

Post Reply
User avatar
spool32
Team Member; Retired with Honors
Posts: 13280
Joined: Sun Dec 12, 2004 6:12 pm
Timezone: GMT -6
Location: Austin, TX

POSSIBLE SITE HACK

Post by spool32 » Sun Jun 07, 2009 11:50 pm

Folks, there's some chance our site has been hacked!
Details below:

You should be browsing with Firefox, with Adblock turned on... if you're not, you may end up with malicious code on your PC after logging in. We're working fast to find and remove the malicious code. Even if you are, you may still have been compromised.

If you think you've been infected, go here, download this, and run it:

http://www.malwarebytes.org/

Updates to follow...

-spool32
Success will be lovely, but you will have to go out and get it! Failure will invite itself in.


Your donation makes this sig possible!
Monthly donations help you Lose Weight Fast!
DM 101
Melakin Skywieder
Team Member; Retired with Honors
Posts: 6175
Joined: Mon Feb 10, 2003 8:25 pm
Location: Over the hill

Re: POSSIBLE SITE HACK

Post by Melakin Skywieder » Mon Jun 08, 2009 12:10 am

Seems more than likely

I got hit with some kind of Trojan when I logged in and Avlis was asking me to turn off pop up blockers which never has happened before. It appear that Mcphee caught and delete the offending program before it got in...least I hope so
If money it the root of all evil, I want to be a bad man!
User avatar
Li'll Divvil
Team Member; Retired with Honors
Posts: 6491
Joined: Tue Oct 05, 2004 6:57 pm
Timezone: GMT +1
DM Avatar: Tobin
Location: Dutchie in Germany
Contact:

Re: POSSIBLE SITE HACK

Post by Li'll Divvil » Mon Jun 08, 2009 12:17 am

Just ran the scan and found 2 trojans (or more likely same trojan 2x) and 3 adware thingies :shock:

Code: Select all

Files Infected:
C:\WINDOWS\system32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
Me is paranoid now
User avatar
Krator
Elder Sage
Posts: 4935
Joined: Thu Jun 10, 2004 6:44 pm
Timezone: GMT
Location: Amsterdam

Re: POSSIBLE SITE HACK

Post by Krator » Mon Jun 08, 2009 12:27 am

Chrome said it was it was "go00ogle.net" - so I added it to my hosts file.
Playing as: Sir Douglas Hope of Gorethar, old school paladin | Krator Blackfist, gold mage | Warren, half nymph barbarian
User avatar
S?retur
Apprentice Scholar
Posts: 960
Joined: Thu Jun 24, 2004 12:34 am
Timezone: GMT +1
Location: Norway; GMT +1/+2

Re: POSSIBLE SITE HACK

Post by S?retur » Mon Jun 08, 2009 1:20 am

Given the premise of a hacked site - how do we know that "Spool32" is in fact the one we naturally assume to be, giving some useful information, as opposed to the hacker giving a link to some program which appears to remove said offending object but which may very well be the very trojan we're supposed to avoid?

/paranoia

:wink:
Post Reply