Project 1999

Go Back   Project 1999 > Blue Community > Blue Server Chat

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 12-12-2011, 05:44 PM
djdownward djdownward is offline
Aviak

djdownward's Avatar

Join Date: Oct 2011
Posts: 62
Default Forum and Java update malware?

I was browsing forums on my work computer and got an update prompt saying that java was in use on the page and if i wanted to update and use it.

Well I did the first time and apparently it loaded some pho windows security program said there were issues on the computer. It locked out the internet saying it was unsafe and insisted it let this program be installed.

I shut it down in safe mode and did a system restore, and have AVG and malwarebytes loaded on my work comp as well as my home comps.

Since I have done the restore I have had the same prompt from java saying java is in use on the forum pages and do I want to update and install.

I have been declining and canceling since then, and today I just saw it on my brand new home laptop, my scanners do not report anything malicious but I am still declining it all.

Anyone else had a problem like this on the forums? Didn't know where else to post. I guess I'll dup this onto blue forum too.
__________________
R99 - [Anonymous] Kudasai
  #2  
Old 12-12-2011, 05:47 PM
Uthgaard Uthgaard is offline
VIP / Contributor

Uthgaard's Avatar

Join Date: Aug 2010
Posts: 5,446
Default

Sounds like you got tricked into downloading a virus. You shouldn't need to update anything to view these forums.
  #3  
Old 12-12-2011, 05:52 PM
djdownward djdownward is offline
Aviak

djdownward's Avatar

Join Date: Oct 2011
Posts: 62
Default

Well I dont do anything on my work computer except browse forums and game sites. And I didnt have any real protection on it, but I dont understand how the same pop up would show up on my laptop at home and only prompt me while I'm browsing forums.

AVG still says I have no malicious stuff that it can detect.

Wierd, super paranoid now.
__________________
R99 - [Anonymous] Kudasai
  #4  
Old 12-12-2011, 08:31 PM
Handull Handull is offline
Planar Protector


Join Date: May 2011
Posts: 1,255
Default

I seem to get random attempts asking me to authorize java. I just always say no at this point unless its a site I absolutely know needs java to run. Malwarebytes is good, and so is TDSS Killer and Norton's Power Eraser (both free). TDSS only detects low level registry and root errors, etc. NPE is highly agressive and you need to be careful using it, as it can flag things like your .exe handling registry as malicious, but it does a good job at finding low and high level things that can be a problem. Then lastly i run malwarebytes to get the last of w/e was attacking me.
  #5  
Old 12-12-2011, 09:07 PM
Rogean Rogean is offline
¯\_(ツ)_/¯

Rogean's Avatar

Join Date: Oct 2009
Location: Massachusetts
Posts: 5,392
Default

I've also noticed a few pop ups that shouldn't be happening.. but it may have been related to other virus's I possibly obtained from a different website.

If you see javascript code in the source of the website anywhere that shouldn't be there, let me know asap.
__________________
Sean "Rogean" Norton
Project 1999 Co-Manager

Project 1999 Setup Guide
  #6  
Old 12-13-2011, 12:34 PM
getsome getsome is offline
Fire Giant

getsome's Avatar

Join Date: Apr 2010
Posts: 733
Default

i got hit by one from this website as well.

i was browsing here when i saw something attempted to turn off my firewall on my pc.

I was slaying dragons so i figured i would check it out in a few. about 1 hour later, all the normal bells and whistles from that xpantivirus 2012 malware started popping up. a back door rootkit came along for fun this time. ping.exe was a nasty variant of this infection. it will lag the fuck out of our pc, since it ramps your cpu processes up to 100%.

this happened saturday.
  #7  
Old 12-13-2011, 01:45 PM
Uthgaard Uthgaard is offline
VIP / Contributor

Uthgaard's Avatar

Join Date: Aug 2010
Posts: 5,446
Default

If you see anything like that, make a note of which ads were displayed at the time and which page it was on.

If it's recent enough, you should be able to go into offline mode and revisit the page as it appeared, firefox has a more detailed and accurate cache than ie though.
  #8  
Old 12-13-2011, 02:07 PM
Zallar Zallar is offline
Kobold

Zallar's Avatar

Join Date: Nov 2011
Location: Houston, Tx
Posts: 150
Default

Make sure your Java is patched to the latest version to prevent banner ads from injecting malware.
  #9  
Old 12-22-2011, 04:50 AM
disco disco is offline
Aviak


Join Date: Jul 2011
Posts: 89
Default

My virus scanner has been blocking something trying to enter my system everytime I browse the forums. The page will lock up and then after it contains it, it runs the page smoothly.
  #10  
Old 12-22-2011, 06:51 AM
arsenalpow arsenalpow is offline
Planar Protector

arsenalpow's Avatar

Join Date: Jan 2011
Posts: 2,225
Default

Quote:
Originally Posted by getsome [You must be logged in to view images. Log in or Register.]
i got hit by one from this website as well.

i was browsing here when i saw something attempted to turn off my firewall on my pc.

I was slaying dragons so i figured i would check it out in a few. about 1 hour later, all the normal bells and whistles from that xpantivirus 2012 malware started popping up. a back door rootkit came along for fun this time. ping.exe was a nasty variant of this infection. it will lag the fuck out of our pc, since it ramps your cpu processes up to 100%.

this happened saturday.
I had this exact same thing happen to me twice. I would be in EQ with these forums open in the background and the XP antivirus 2012 would pop up. Did a system rollback both times which fixed it. Also, I changed my browser to chrome and haven't had the issue since.
__________________
Monk of Bregan D'Aerth
Wielder of the Celestial Fists
Quote:
Originally Posted by Hollywood Hogan
The first thing you gotta' realize, brother, is this right here is the future of wrestling. You can call this the New World Order of Wrestling.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:07 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.