Help Forum How To | General Corvetteforum Questions | Feedback

Malware alert???

Thread Tools
 
Search this Thread
 
Old Jan 31, 2012 | 08:47 AM
  #1  
Quick Silver Z's Avatar
Quick Silver Z
Thread Starter
Team Owner
15 Year Member
Veteran: Navy
St. Jude 15 Year Donor
 
Joined: Mar 2007
Posts: 35,183
Likes: 2,125
From: Right Corner Pocket of Illinois
No-IL Events Coordinator
2026 Corvette of the Year Finalist - Unmodified
2025 C6 of the Year Winner - Unmodified
2020 C6 of the Year Finalist - Unmodified
2020 Corvette of the Year Finalist (appearance mods)
2019 C6 of Year Winner (appearance mods)
2018 C6 of Year Finalist
St. Jude Donor '12 thru '26
Default Malware alert???

Anyone else getting an antivirus alert every time they open a post here???

"URL: http://simbeppc.com/jscript/pixel.js"

Base of suspicious web addresses:
Old Jan 31, 2012 | 09:19 AM
  #2  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

We're looking into it. Thanks for the report.
Old Jan 31, 2012 | 11:14 AM
  #3  
RC45's Avatar
RC45
Race Director
 
Joined: Jun 2003
Posts: 14,051
Likes: 9
From: Houston TX
Default

Heads up to thise that do not have proper AV software, I browsed the forum last night at about 2am from my 2nd laptop - a new build and had not yet installed AV software. The Malware has a pretty nasty payload.

Injects a System Check utility that looks like a legit Windows program that scans your PC and finds issues with your drive, memory and system and then shows you disk "crashing" - looks like all your files are gone, but what it does is set the +H (hidden attrib) to your drive as it is running its "check".

Took a couple hours to isolate and remove, including pre and post cleanup scans.

Are these rogue malware infections coming via unpoliced banner ads on CF?

ESET Nod32 caught the malware on my main laptop.

Last edited by RC45; Jan 31, 2012 at 11:16 AM.
Old Jan 31, 2012 | 11:17 AM
  #4  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

It's still being investigated, but it's not believed to be through advertisements.
Old Jan 31, 2012 | 12:00 PM
  #5  
Quick Silver Z's Avatar
Quick Silver Z
Thread Starter
Team Owner
15 Year Member
Veteran: Navy
St. Jude 15 Year Donor
 
Joined: Mar 2007
Posts: 35,183
Likes: 2,125
From: Right Corner Pocket of Illinois
No-IL Events Coordinator
2026 Corvette of the Year Finalist - Unmodified
2025 C6 of the Year Winner - Unmodified
2020 C6 of the Year Finalist - Unmodified
2020 Corvette of the Year Finalist (appearance mods)
2019 C6 of Year Winner (appearance mods)
2018 C6 of Year Finalist
St. Jude Donor '12 thru '26
Default

FYI: I am no longer getting the Kaspersky AV alert...
Old Jan 31, 2012 | 12:03 PM
  #6  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

To clarify, the link was removed shortly after your posting. Investigating how and to prevent it in the future is what's currently being done.

Thanks!
Old Jan 31, 2012 | 12:09 PM
  #7  
1%r's Avatar
1%r
Team Owner
Supporting Lifetime Gold
15 Year Member
St. Jude 15 Year Donor
 
Joined: Mar 2003
Posts: 96,496
Likes: 82
St. Jude Donor '03 through '17
Default

My Malware has only alerted me to tracking cookies, nothing else?
Old Jan 31, 2012 | 12:12 PM
  #8  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

You won't be alerted unless the issue is live, which it was earlier this morning. It was removed shortly after Quick Silver Z's, so there currently is no threat.

Originally Posted by jersey jay
My Malware has only alerted me to tracking cookies, nothing else?
Corvette Stories

The Best of Corvette for Corvette Enthusiasts

story-0

10 Ugly Corvettes That We Still Kinda Love

 Joe Kucinski
story-1

Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

 Brett Foote
story-2

10 Things Every Corvette Owner Needs (2026 Edition)

 Michael S. Palmer
story-3

8 Most "Only Corvette Owners Understand" Quirks and Problems

 Pouria Savadkouei
story-4

10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

 Joe Kucinski
story-5

How Much Horsepower Every Corvette Engine "LOST" in 1972

 Joe Kucinski
story-6

Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

 Michael S. Palmer
story-7

Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

 Joe Kucinski
story-8

150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

 Joe Kucinski
story-9

8 Coolest Corvette Pace Cars (and Replicas) of All Time

 Verdad Gallardo
Old Jan 31, 2012 | 12:24 PM
  #9  
hcvone's Avatar
hcvone
Team Owner
Supporting Lifetime Gold
25 Year Member
Active Streak: 30 Days
Top Answer: 3
Top Answer: 5
 
Joined: Aug 1999
Posts: 20,318
Likes: 1,905
From: Huntingdon Valley Pa/ Town of Webb NY
Default

Got it a minite ago 12:24 ET
Old Jan 31, 2012 | 12:27 PM
  #10  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

Can you provide the exact details as to what the alert was regarding and what page you was on that generated the error?

I just scanned and don't see any issue.
Originally Posted by hcvone
Got it a minite ago 12:24 ET
Old Jan 31, 2012 | 01:28 PM
  #11  
RC45's Avatar
RC45
Race Director
 
Joined: Jun 2003
Posts: 14,051
Likes: 9
From: Houston TX
Default

This is from the 8:20am log - the last incident I had.

http : //forums.corvetteforum.com/c5-parts-for-sale-wanted-53 HTML/ScrInject.B.Gen virus connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files (x86)\Internet Explorer\iexplore.exe.
http : //forums.corvetteforum.com/c5-parts-for-sale-wanted-53 » GZ » file.htm HTML/ScrInject.B.Gen virus
And this was the activity at 8:05am - the injection and the infection. Both caught by ESET.

1/31/2012 8:05:14 AM HTTP filter archive http : //forums.corvetteforum.com/politics-religion-and-controversy-88 HTML/ScrInject.B.Gen virus connection terminated - quarantined HPLAPTOP1\Administrator Threat was detected upon access to web by the application: C:\Program Files (x86)\Internet Explorer\iexplore.exe.
1/31/2012 8:05:34 AM Real-time file system protection file C:\Users\Administrator\AppData\Local\Mic rosoft\Windows\Temporary Internet Files\Content.IE5\J8FVHUZT\politics-religion-and-controversy-88[1].htm HTML/ScrInject.B.Gen virus deleted HPLAPTOP1\Administrator Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\Internet Explorer\iexplore.exe.

Last edited by RC45; Jan 31, 2012 at 01:35 PM.
Old Jan 31, 2012 | 05:06 PM
  #12  
DebRedZR1's Avatar
DebRedZR1
Moderator
Supporting Lifetime
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jul 2005
Posts: 29,346
Likes: 3,886
From: West MI
CF Banner Relay Captain
West MI & JAX/NE Florida
Events Coordinator
St. Jude Donor '11-'17, '21
Default

Originally Posted by RC45
Heads up to thise that do not have proper AV software, I browsed the forum last night at about 2am from my 2nd laptop - a new build and had not yet installed AV software. The Malware has a pretty nasty payload.

Injects a System Check utility that looks like a legit Windows program that scans your PC and finds issues with your drive, memory and system and then shows you disk "crashing" - looks like all your files are gone, but what it does is set the +H (hidden attrib) to your drive as it is running its "check".

Took a couple hours to isolate and remove, including pre and post cleanup scans.

Are these rogue malware infections coming via unpoliced banner ads on CF?

ESET Nod32 caught the malware on my main laptop.
This is exactly what crashed my laptop beyond repair 2 weeks ago. I run AVG and keep it updated but no warnings, the system check popped up and could not get rid of it. The Repair place said this has been popping up a lot lately
Old Jan 31, 2012 | 07:26 PM
  #13  
leadfoot4's Avatar
leadfoot4
Team Owner
25 Year Member
Active Streak: 60 Days
Active Streak: 90 Days
Community Builder
 
Joined: May 2001
Posts: 87,367
Likes: 1,593
From: Western NY
Default

Originally Posted by DebRedZR1GSVert
This is exactly what crashed my laptop beyond repair 2 weeks ago. I run AVG and keep it updated but no warnings, the system check popped up and could not get rid of it. The Repair place said this has been popping up a lot lately
For the sake of everybody else's peace of mind, did your "repair place" suggest any means of preventing further attacks?


Old Feb 1, 2012 | 01:01 AM
  #14  
RC45's Avatar
RC45
Race Director
 
Joined: Jun 2003
Posts: 14,051
Likes: 9
From: Houston TX
Default

Originally Posted by leadfoot4
For the sake of everybody else's peace of mind, did your "repair place" suggest any means of preventing further attacks?


The key is to not panic when these utils fake data loss.

It is unlikely they can delete the system files whil ethe machine is running, that is why I suspected they where running the attrib -h util to fake me into buying their software.

Good AV software - ESET Nod32 is very good. Keep Process Explorer ready to launch to see these malicious bits of code executing.

And above all else, keep all your precious data in a single folder int he root called data with all your folders under there and back it up regularly to a USB stick (they are availabl ein 128GB sizes now) and to external hard drives.

That way if something does fry your laptop/PC, no sweat, you only lose a day or 2 of data.
Old Feb 9, 2012 | 01:58 PM
  #15  
DebRedZR1's Avatar
DebRedZR1
Moderator
Supporting Lifetime
20 Year Member
Liked
Loved
Community Favorite
 
Joined: Jul 2005
Posts: 29,346
Likes: 3,886
From: West MI
CF Banner Relay Captain
West MI & JAX/NE Florida
Events Coordinator
St. Jude Donor '11-'17, '21
Default

Originally Posted by leadfoot4
For the sake of everybody else's peace of mind, did your "repair place" suggest any means of preventing further attacks?

Not really, the advice below is much better!

Originally Posted by RC45
The key is to not panic when these utils fake data loss.

It is unlikely they can delete the system files whil ethe machine is running, that is why I suspected they where running the attrib -h util to fake me into buying their software.

Good AV software - ESET Nod32 is very good. Keep Process Explorer ready to launch to see these malicious bits of code executing.

And above all else, keep all your precious data in a single folder int he root called data with all your folders under there and back it up regularly to a USB stick (they are availabl ein 128GB sizes now) and to external hard drives.

That way if something does fry your laptop/PC, no sweat, you only lose a day or 2 of data.
Now that I know what it was I was having issues prior when I logged in to windows so the system check didn't seem odd at the time. I couldn't get rid of it and then all the files were hidden
Best to keep things backed up! There are plenty of online services that will do it automatically too for those of us who don't always hook up the external hard drive.
Old Feb 14, 2012 | 01:21 PM
  #16  
Kerrmudgeon's Avatar
Kerrmudgeon
Race Director
10 Year Member
 
Joined: Mar 2009
Posts: 19,777
Likes: 4,592
From: Canada's capital
2020 Corvette of the Year Finalist (appearance mods)
C1 of Year Finalist (appearance mods) 2019
Default

Windows security didn't catch any of the TWELVE viruses i picked up, and I mostly only go on here. Machine was s l o w i n g down a lot. I had to load avg to pick them up, and still had to go back 3 days to get rid of them. I hope this isn't going to be a reoccurring problem, I don't need the grief!
Old Feb 14, 2012 | 01:25 PM
  #17  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

I'm not aware of any recent events on CF since the last confirmation approximately 2 weeks ago.
Originally Posted by Kerrmudgeon
Windows security didn't catch any of the TWELVE viruses i picked up, and I mostly only go on here. Machine was s l o w i n g down a lot. I had to load avg to pick them up, and still had to go back 3 days to get rid of them. I hope this isn't going to be a reoccurring problem, I don't need the grief!

Get notified of new replies

To Malware alert???





All times are GMT -4. The time now is 11:27 PM.

story-0
10 Ugly Corvettes That We Still Kinda Love

Slideshow: 10 ugly Corvettes that we still kinda love.

By Joe Kucinski | 2026-06-03 10:34:17


VIEW MORE
story-1
Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

A lot of money has changed hands at the online auction house over the years.

By Brett Foote | 2026-06-03 10:21:50


VIEW MORE
story-2
10 Things Every Corvette Owner Needs (2026 Edition)

Slideshow: 10 great gifts Corvette enthusiasts actually want for Father's Day!

By Michael S. Palmer | 2026-06-03 15:43:40


VIEW MORE
story-3
8 Most "Only Corvette Owners Understand" Quirks and Problems

Slideshow: These are the quirks, annoyances, and oddly lovable problems that every Corvette owner eventually learns to live with.

By Pouria Savadkouei | 2026-05-28 09:31:39


VIEW MORE
story-4
10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

Slideshow: 10 reasons why the C6 Z06 is still a performance benchmark after 20 years.

By Joe Kucinski | 2026-05-27 17:20:09


VIEW MORE
story-5
How Much Horsepower Every Corvette Engine "LOST" in 1972

Slideshow: How much horsepower every Corvette engine lost in 1972.

By Joe Kucinski | 2026-05-27 16:54:53


VIEW MORE
story-6
Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

Slideshow: How to Protect A Convertible Top: 10 DOs & DON'Ts

By Michael S. Palmer | 2026-04-03 00:00:00


VIEW MORE
story-7
Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

Slideshow: The 10 most explosive Corvettes ever built based on power-to-weight ratio.

By Joe Kucinski | 2026-05-20 07:23:03


VIEW MORE
story-8
150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

Slideshow: From C1 to C8 we compare every Corvette generation by the numbers.

By Joe Kucinski | 2026-05-12 16:54:12


VIEW MORE
story-9
8 Coolest Corvette Pace Cars (and Replicas) of All Time

Slideshow: Some Corvette pace cars became collectible legends, while others perfectly captured the look and attitude of their era.

By Verdad Gallardo | 2026-05-11 09:50:51


VIEW MORE