Site is bugged with Trojans!

Sort:
kohai

 Bloodhound.Exploit.196 is a heuristic detection for files attempting to exploit the Adobe Acrobat. 

What exactly does Norton have to say when you click where it says "view details" on that detection notice pop up ?

Skaar
kohai wrote:

 Bloodhound.Exploit.196 is a heuristic detection for files attempting to exploit the Adobe Acrobat. 

What exactly does Norton have to say when you click where it says "view details" on that detection notice pop up ?


It says it has been blocked, and gives the location of a file in temp files. The location for all the attacks are located in temp internet files.

askon

Says the person who is probably using win XP SP 2 and internet explorer... It's not the site it's your computer. Reformat get firefox.

kohai

http://www.avira.com/en/security_news/pdf_exploit.html

 

There have been an increasing number of websites containing manipulated PDF files. If these files are opened, they infiltrate systems with a Trojan via the Acrobat PDF Reader. The result of this infection is the disabling of anti-virus programs, falsification of search results and manipulation of advertising banners.

[which is what your norton is recognising as Bloodhound.Exploit.196 and seeing as how, as far as i am aware, this site doesn't run on pdf files, the virus you talk of, didn't come from this site]

Skaar
askon wrote:

Says the person who is probably using win XP SP 2 and internet explorer... It's not the site it's your computer. Reformat get firefox.


Vista.

Skaar
kohai wrote:

http://www.avira.com/en/security_news/pdf_exploit.html

 

There have been an increasing number of websites containing manipulated PDF files. If these files are opened, they infiltrate systems with a Trojan via the Acrobat PDF Reader. The result of this infection is the disabling of anti-virus programs, falsification of search results and manipulation of advertising banners.

[which is what your norton is recognising as Bloodhound.Exploit.196 and seeing as how, as far as i am aware, this site doesn't run on pdf files, the virus you talk of, didn't come from this site]


I have the updated version of Adobe.

Skaar
Skaar wrote:
kohai wrote:

http://www.avira.com/en/security_news/pdf_exploit.html

 

There have been an increasing number of websites containing manipulated PDF files. If these files are opened, they infiltrate systems with a Trojan via the Acrobat PDF Reader. The result of this infection is the disabling of anti-virus programs, falsification of search results and manipulation of advertising banners.

[which is what your norton is recognising as Bloodhound.Exploit.196 and seeing as how, as far as i am aware, this site doesn't run on pdf files, the virus you talk of, didn't come from this site]


I have the updated version of Adobe.

 

Like I said earlier, it doesn't happen every time. When I click to go to a page, there is a certain ad causing this because it shows in the status bar "waiting for website, etc. then it shows a web address link in the status bar downloading something that Norton and AntiVir block.


kohai

I wasn't saying you didn't have.

What that article was saying, was that the virus your computer has contracted [so norton says]

There have been a number of websites containing manipulated [bugged] PDF files. If these files are opened, they infiltrate systems with a Trojan via the Acrobat PDF Reader.

This in turn will cause the disabling of anti-virus programs,  and manipulation of advertising banners.

Has your vista done all its regular patches updates ?

have you downloaded anything at all recently ?  [honestly ? ]

did you remember to scan each and every download before opening it ?[honestly? ]

As a suggestion, check to see if you have system restore turned on, and if there is a check point set up on it.. if there is, try rolling back your computer.

Also, i would strongly suggest that you do some more research on both Downloader Agents and Bloodhound in conjuction with Norton ... then cross reference the results with Sophos and see what you get..

Skaar
kohai wrote:

I wasn't saying you didn't have.

What that article was saying, was that the virus your computer has contracted [so norton says]

There have been a number of websites containing manipulated [bugged] PDF files. If these files are opened, they infiltrate systems with a Trojan via the Acrobat PDF Reader.

This in turn will cause the disabling of anti-virus programs,  and manipulation of advertising banners.

Has your vista done all its regular patches updates ?

have you downloaded anything at all recently ?  [honestly ? ]

did you remember to scan each and every download before opening it ?[honestly? ]

As a suggestion, check to see if you have system restore turned on, and if there is a check point set up on it.. if there is, try rolling back your computer.

Also, i would strongly suggest that you do some more research on both Downloader Agents and Bloodhound in conjuction with Norton ... then cross reference the results with Sophos and see what you get..


The only thing I've downloaded recently has been the Amazon mp3 downloader. I hardly download anything at all. Whenever I have downloaded programs, I always use Cnet.com. My Vista has all updates. The only website that I have trouble on is here. I've never had this to happen anywhere else.

chessext

That's funny. My computer is as clean as it gets (I'm a software developer) and since some days I get this nice popup when clicking on a game (and sometimes in this forum). Has definitely nothing to do with anything virus/trojan related.

 

chess.com popup

erik

i started a post about this stuff on Symantec's website. we'll see what people say!?

http://community.norton.com/norton/board/message?board.id=nis_feedback&thread.id=12501

:)

erik

interesting replies. maybe out of date AV? maybe using two AV programs at the same time? maybe other software outdated? anyway, it's confirmed: Chess.com does NOT have problems.

http://community.norton.com/norton/board/message?board.id=nis_feedback&thread.id=12501

anyone experiencing malware issues on Chess.com should get computer help immediately!

De-Lar

Erik, I think only two people actually believed chess.com has a virus.  The bad thing is, those two people can cause a lot of damage by spreading false claims.  Speaking before thinking.  Frown

Skaar

http://tinypic.com/view.php?pic=14ceh05&s=4

In this pic I managed to hit print screen to see the web address that is loading in the status bar. You can see 'exploits' in the address.

I updated to all of the new Adobe programs. This time Adobe popped up asking to allow or deny access, which it wasn't doing before. AntiVir, and Norton are still blocking whatever it is.

erik

skaar:

i recommend you go to the Norton forums - i think the people there can help you figure out what is wrong with your computer. see my links above.

chessfanforlife

Erik...just let them solve the problem on their own...they're big boys.

Chillapov

Erik, i have a strong feeling something is wrong. A friend of mine called me today and stated that he logged on to the site today and in doing so twice, he aquired a virus. He states that his computer froze for a while each time.  I was thinking that nothing was wrong, probably system errors. But upon seeing this post, I must say.... something is wrong.

erik
Grand_Chill wrote:

Erik, i have a strong feeling something is wrong. A friend of mine called me today and stated that he logged on to the site today and in doing so twice, he aquired a virus. He states that his computer froze for a while each time.  I was thinking that nothing was wrong, probably system errors. But upon seeing this post, I must say.... something is wrong.


i agree. what is wrong is that people allow spyware onto their computers, run outdated virus protection or conflicting programs, etc. the state of internet security is wrong. as for our site, nothing is wrong.

RedSoxpawn

Never felt anything wrong with the site, and I know my spyware and other security is outdated, working on updating it though

chessfanforlife

ERIK, read my post above.