Shoutbox

Messenger Plus! Fourm Trojan? - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: General (/forumdisplay.php?fid=11)
+---- Forum: Forum & Website (/forumdisplay.php?fid=13)
+----- Thread: Messenger Plus! Fourm Trojan? (/showthread.php?tid=21156)

Messenger Plus! Fourm Trojan? by ~*Jparto*~ on 02-05-2004 at 05:19 PM

Ok, I just got this trojan warning from VirusScan On-Access (from Microsoft). Guess what I got it from? The Mess. Plus! Forums! It even says: showthread[4] and showthread[6]. I know this is from plus! because whenever i load a thread, it says that in the adress-bar. One problem is that I can't make a screen-shot. The size would be too big.


What do you think??*-)


RE: Messenger Plus! Fourm Trojan? by Johnny_Mac on 02-05-2004 at 05:24 PM

Save the screenshot as a gif or something, then its a perfect size to upload.

And those VirusScan On-Access pick up anything, even if someones avatar is from a site they have "blacklisted". :rolleyes:


RE: Messenger Plus! Fourm Trojan? by dom. on 02-05-2004 at 05:53 PM

could it be a cookie?


RE: Messenger Plus! Fourm Trojan? by wj on 02-05-2004 at 06:15 PM

At least post a link


RE: Messenger Plus! Fourm Trojan? by DXtremz on 02-05-2004 at 06:22 PM

*cough* Shaun's sig *cough*

Norton pops up every time i view shauns sig :p just the lil "format c" thing in his sig...nothing to worry about did in irc too

see look


[13:21:01] <@Shaun> echo j | format c:

Scan type:  Realtime Protection Scan
Event:  Virus Found!
Virus name: Bat.QuickFormat.Trojan
File:  D:\Program Files\mIRC\logs\#kboy.log
Location:  Quarantine
Computer:  DXTREMZ
User:  Billy & Lauren
Action taken:  Quarantine succeeded : Access denied
Date found: Thursday, February 05, 2004  1:21:01 PM

Thats pretty lame, because text isnt gonna hurt anything :p


RE: Messenger Plus! Fourm Trojan? by wj on 02-05-2004 at 06:34 PM

Nice!

So. I just have to point out, You cant throw that much power in there using a modem and windows xp home.... SHAME!


RE: Messenger Plus! Fourm Trojan? by wj on 02-05-2004 at 06:36 PM

Hehehehehe

It only pops up for me when doing a reply and your sig shows in the thread history.

quote:
Scan type:  Realtime Protection Scan
Event:  Virus Found!
Virus name: Bat.QuickFormat.Trojan
File:  C:\Documents and Settings\williamm.TIMBERCON\Local Settings\Temporary Internet Files\Content.IE5\CPQ345IV\newreply[2].php
Location:  Quarantine
Computer:  GYRO
User:  williamm
Action taken:  Quarantine succeeded : Access denied
Date found: Thursday, February 05, 2004  10:37:28 A


RE: Messenger Plus! Fourm Trojan? by Johnny_Mac on 02-05-2004 at 07:13 PM

Making those things too damn sensitive is what make people go "ohhh... msgplus has blah blah in it cause my norton said so!!!" :rolleyes:


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-05-2004 at 07:35 PM

i don't understand how format c: could be at all harmful, even if it was in a context of attempting to run :-/  because 99% of users run everything off c: so wouldnt be able to format it if they tried (this disk is in use)


RE: Messenger Plus! Fourm Trojan? by DXtremz on 02-05-2004 at 07:51 PM

Because if someone puts it in a batch file and you are running dos or something it would format it ...Dunno, kinda dumb :-/


RE: Messenger Plus! Fourm Trojan? by ~*Jparto*~ on 02-05-2004 at 07:58 PM

quote:
Originally posted by Johnny_Mac
Save the screenshot as a gif or something, then its a perfect size to upload.


...and i would do that how?
quote:
Originally posted by wj
At least post a link

Nope, no link in the message...


Hey! found something!

The trojan is called: Exploit-URLSpoof.gen

It sort of sounds like THIS THREAD

btw: I've saved the screen shot in paint. does that make anything better or worse?

I'll make the screenshot when someone tells me how to make the screenshot a gif "or something".


...and yes...i'm waiting....

I'll get back to you tomorrow. bedtime;)


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-05-2004 at 08:01 PM

When you're saving the picture from paint, there's a dropdown menu "File Type" - change that to GIF

:| your av sure does suck if it picks things like that up


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-05-2004 at 08:03 PM

quote:
Originally posted by DXtremz
Because if someone puts it in a batch file and you are running dos or something it would format it ...Dunno, kinda dumb :-/
By loading that batch file you're blocking access to c: so it can't be formatted :P
RE: Messenger Plus! Fourm Trojan? by ~*Jparto*~ on 02-05-2004 at 08:06 PM

I did that. Ummm....the colours seemed to change....uhhh....a lot!

Here it is anyway.


RE: Messenger Plus! Fourm Trojan? by Johnny_Mac on 02-05-2004 at 08:08 PM

just got the same thing... on newreply.php (i usually use quick reply, was gonna add attachment this time so now i noticed it :P)

this is it:

[Image: attachment.php?tid=21156&pid=198265]


RE: Messenger Plus! Fourm Trojan? by theguy on 02-05-2004 at 08:33 PM

:dodgy: newreply virus.


RE: Messenger Plus! Fourm Trojan? by Chrono on 02-05-2004 at 08:37 PM

this is all so damn dodgy :dodgy:

:lol:


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-05-2004 at 08:39 PM

:-/ norton has never done that for me

"QuickFormat"? :lol: you mean to say the mycode inserter was mistaken for a disk formatter or something because of its name?


RE: Messenger Plus! Fourm Trojan? by WDZ on 02-05-2004 at 09:24 PM

:lol: Stupid anti-virus program... I wonder if it would do the same on a page that tells you how to format your hard drive... ^o)

Obviously, this isn't a problem with the forums. :banana:


RE: Messenger Plus! Fourm Trojan? by Johnny_Mac on 02-06-2004 at 10:38 AM

I dunno what to do really.. just click dont tell me again I suppose. :undecided:


RE: Messenger Plus! Fourm Trojan? by reisyboy on 02-06-2004 at 04:43 PM

Well put it like this do u trust WDZ :P lol :) And you have you ansawer of what todo. Personally id trust him :)


RE: Messenger Plus! Fourm Trojan? by CookieRevised on 02-06-2004 at 08:18 PM

What is the world coming to, if this kind of *beep* is detected as a virus????? OMG... this is very very very very dodgy indeed... What's next, flashing a bright red screen with MOST DANGEROUS VIRUS FOUND if someone types "Bull Shit" ????....

On the other hand, maybe if you scanned "executables" (exe, com, bat, vbs, pif, scr) instead of "All Files", you won't have this *beep*... :dodgy: Learn to setup your programs right :dodgy:



quote:
Originally posted by Johnny_Mac
Making those things too damn sensitive is what make people go "ohhh... msgplus has blah blah in it cause my norton said so!!!" :rolleyes:
Indeed.... people are too paranoid these days and they believe everything they'll see...

quote:
Originally posted by fluffy_lobster
By loading that batch file you're blocking access to c: so it can't be formatted
Yes it can!!! The line is read in memory, so even if the batch is deleted, the line will be executed. You will only get an error like "batch not found" after the line is executed, cause it tries to look for a next line. But I think that's the least of your problems then....
RE: Messenger Plus! Fourm Trojan? by Guido on 02-07-2004 at 08:14 PM

Shit .... I have norton antivirus, and it never popped up for me :P

That's bad, right? :gfdrin:


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-07-2004 at 08:26 PM

No, you might just have lower security settings, or different options for what to do when it finds them set.  Your version might not scan internet pages.

At least you know that norton won't spontaneously delete your IRC logs when you close mIRC because somebody said the magic word :dodgy:  I only just figured how to fix this.


RE: Messenger Plus! Fourm Trojan? by Huuf on 02-07-2004 at 10:21 PM

Blah, stupid ppl configured it to high, I have no problems with it. I got no firewall on this pc :p, it is run on the server :p


RE: Messenger Plus! Fourm Trojan? by fluffy_lobster on 02-07-2004 at 11:02 PM

quote:
Originally posted by Huuf
Blah, stupid ppl configured it to high, I have no problems with it. I got no firewall on this pc :p, it is run on the server :p
Actually I just installed it a week ago and didn't change any of the default settings :-/

Nothing to do with firewalls either... :P

RE: Messenger Plus! Fourm Trojan? by Guido on 02-08-2004 at 12:20 AM

I mean, it's a millionaire company, can't they implement a method to distinguish "format c:" when it's in a text or html file from when it's inside a .bat??? :banana: