Jump to content


This is a read only archive of the old forums
The new CBn forums are located at https://quarterdeck.commanderbond.net/

 
Photo

Forum hacked + upgraded


47 replies to this topic

#1 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 02:33 PM

Unfortunately, the CBn forums were hacked today because of an Invision Board security hole. The malicious user appears to have hacked into one of our templates so that people accessing the forums will be made vulnerable to a trojan virus.

We're not totally sure how the trojan would infect a PC, but if you were using any browser and accepted a file transfer on Windows at the time of the attack, it is highly recommended that you run an anti-virus scan and install any Microsoft Windows updates.

The forums have now been upgraded to the latest version of Invision Board. We're sorry for the delay in getting the site back online, but we thought it best to run a complete system backup earlier than scheduled.

#2 killkenny kid

killkenny kid

    Commander

  • Veterans
  • PipPipPipPip
  • 6607 posts
  • Location:Albany, New York

Posted 13 May 2006 - 02:59 PM

Thanks, will do. :tup:

#3 Simon

Simon

    Commander

  • Veterans
  • PipPipPipPip
  • 5884 posts
  • Location:England

Posted 13 May 2006 - 03:17 PM

Hi,

Thanks for this - I was indeed one of those to suffer, although Norton picked it up and deleted it.

I was sent an email saying I'd received a card from some Hotmail address. I had accepted it (it was my birthday recently!) but saw that the file extension had a strange ending and deleted it - but not before Norton clobbered it.

I can no longer see Today's Posts though - is this a side effect?

Best.

#4 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 03:20 PM

Hi,

Thanks for this - I was indeed one of those to suffer, although Norton picked it up and deleted it.

I was sent an email saying I'd received a card from some Hotmail address. I had accepted it (it was my birthday recently!) but saw that the file extension had a strange ending and deleted it - but not before Norton clobbered it.

I can no longer see Today's Posts though - is this a side effect?

Best.


Yes - an email was sent out as well earlier.

I just sent an email informing members of this.

Norton sounds as though it did it's job well.

Today's Posts just needs to be added again - it was lost when we did the upgrade.

#5 Bondian

Bondian

    Commander

  • Veterans
  • PipPipPipPip
  • 8019 posts
  • Location:Soufend-On-Sea, Mate. England. UK.

Posted 13 May 2006 - 03:29 PM

Hi Gang.

I was silly enough to open up the file and have been infected with a Trojan and spyware.

I'm in the process if removing them, but Norton cannot removed the files, so will try another anti-virus.

Thank you Dave for letting us know. :D

There's some real losers out there. :tup:

Cheers,


Ian

#6 Joyce Carrington

Joyce Carrington

    Commander CMG

  • Veterans
  • PipPipPipPip
  • 4631 posts
  • Location:Amsterdam, The Netherlands

Posted 13 May 2006 - 03:31 PM

Thanks for making sure the website is safe again, Dave. :tup:

Norton contained any damage. :D

#7 Bondian

Bondian

    Commander

  • Veterans
  • PipPipPipPip
  • 8019 posts
  • Location:Soufend-On-Sea, Mate. England. UK.

Posted 13 May 2006 - 03:44 PM

If anyone had any problems with their anti-virus not being able to remove the virus, please try AVG anti-virus.

Looks like this virus hijacks your browser (in IE) and installs some software called 'paytime.exe'.

#8 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 03:50 PM

Be sure to download and install Firefox :tup:

http://getfirefox.com

#9 Bondian

Bondian

    Commander

  • Veterans
  • PipPipPipPip
  • 8019 posts
  • Location:Soufend-On-Sea, Mate. England. UK.

Posted 13 May 2006 - 03:53 PM

Thanks, Dave. Good advice my friend. :tup:

Luckily I was working on Carol's machine when this happened. LOL

#10 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 03:54 PM

So long as it was, Carol's and not yours - that's fine :tup:

http://movies.apple....ses_480x376.mov

#11 Johnboy007

Johnboy007

    Commander CMG

  • Veterans
  • PipPipPipPip
  • 6990 posts
  • Location:Washington, D.C.

Posted 13 May 2006 - 04:04 PM

I had wondered why my AntiVirus was going nuts when I signed on this morning. There were about ten attempts to infect my computer, but fortunately my VirusScan is brand new and blocked all of them. Add another one whose Norton swatted it down.

Strange morning.

#12 Bondian

Bondian

    Commander

  • Veterans
  • PipPipPipPip
  • 8019 posts
  • Location:Soufend-On-Sea, Mate. England. UK.

Posted 13 May 2006 - 04:36 PM

So long as it was, Carol's and not yours - that's fine :tup:

http://movies.apple....ses_480x376.mov

LOL. I just got a "bitch slap" for that. LOL

Okay. Norton couldn't remove the files, but AVG did. However, there's three files that have to be removed manually and in 'safe mode'.

If anyone is having a problem, please try the following. In fact even if your anti-virus has removed the virus, this would still be worthwhile doing.

You will also need to restore your homepage.

Open up your browser, and do the following.

Tools -> Internet Options ->. In the 'Homepage' section, please type in your regular homepage, and click on 'ok'.

1). Removal of 'secure32' browser hijack.

Start -> Search -> For Files and Folder. Click on 'all files and folders', and type in 'secure32'. Once the search had found this file please delete it.

2). Removal of 0mcamcap.exe. (please note it's a zero not an oh).

Start -> Search -> For Files and Folder. Click on 'all files and folders', and type in '0mcamcap.exe'. Once the search had found this file please delete it.

3). Removal of paytime.exe.

Start -> Search -> For Files and Folder. Click on 'all files and folders', and type in 'patyime.exe'. Once the search had found this file please delete it.

That should be all you need to do.

Cheers,


Ian

#13 jl151080

jl151080

    Midshipman

  • Crew
  • 27 posts

Posted 13 May 2006 - 04:45 PM

I'm another who was affected.

I'm a little worried, as when I clicked on the link a message from Norton said there was a trojan and something about a file being unrepairable.

I immediatly switched the power to my computer off, which I know your not supposed to do, but I wanted to prevent any more damage being done.

I then restarted the computer and ran a full Norton anti virus scan. I bought norton literally a couple of days ago, but nothing was picked up from the scan :tup:

I've also done a scan at symantec online, but nothing was picked up there either :D

Edited by jl151080, 13 May 2006 - 04:46 PM.


#14 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 04:47 PM

AVG is free, and seems to have done a better job for Bondian.

http://free.grisoft....2/lng/us/tpl/v5

#15 marktmurphy

marktmurphy

    Commander

  • Veterans
  • PipPipPipPip
  • 9055 posts
  • Location:London

Posted 13 May 2006 - 05:00 PM

Hmm- use Firefox and was a bit confused as to why it was crashing out everytime I came to CBN this morning. My Norton says there no problem but perhaps I'll try this AVG too.

#16 Bryce (003)

Bryce (003)

    Commander RNVR

  • Commanding Officers
  • PipPipPipPip
  • 10110 posts
  • Location:West Los Angeles, California USA

Posted 13 May 2006 - 05:50 PM

Well done Admiral - Oddly, I had just changed my password in the last 24 hours and my Norton system does a full auto scan on Mondays and Fridays. I've suffered no ill effects, but my sympathy to any here at CBn who have.

One of these days, one of these "super hackers" is going to be executed on live TV worldwide. It'll send a message.

Hopefully, I'll get to be one of the trigger men. Anyone care to join me? I'll pay for your ammo and the pints afterwards.

Again, well done Admiral.

#17 marktmurphy

marktmurphy

    Commander

  • Veterans
  • PipPipPipPip
  • 9055 posts
  • Location:London

Posted 13 May 2006 - 06:11 PM

One of these days, one of these "super hackers" is going to be executed on live TV worldwide. It'll send a message.


*edges quietly away*

#18 Athena007

Athena007

    Commander RNVR

  • Commanding Officers
  • PipPipPipPip
  • 12936 posts
  • Location:H O L L Y W O O D

Posted 13 May 2006 - 06:15 PM

This is horrible. My computer is safe, but still... EVIL!

As for virus protection. I used to use Norton (had major problems w/ it), and then AVG (wasn't catching everything).

But now I used AVAST, which I would highly recommend: http://www.avast.com --- they have a free home edition.

#19 Thom Paine

Thom Paine

    Midshipman

  • Crew
  • 34 posts
  • Location:Strathroy, Ontario, Canada

Posted 13 May 2006 - 07:43 PM

I run Linux 99% of the time and never worry about stuff like this.

Thanks for the notice though.

#20 TortillaFactory

TortillaFactory

    Lt. Commander

  • Veterans
  • PipPipPip
  • 1964 posts
  • Location:Deep 13

Posted 13 May 2006 - 08:18 PM

Firefox caught it, as did Norton - can't recommend the former enough. Norton, however, is largely useless. Luckily it worked for this. Thanks for the notfication.

Is the little gun icon coming back, or are we stuck with a generic blue V in our Firefox tabs?

#21 B. Brown

B. Brown

    Sub-Lieutenant

  • Crew
  • Pip
  • 477 posts
  • Location:New York

Posted 13 May 2006 - 09:14 PM

Luckily, I didn't receive this virus.

Thanks a lot for sending the email to me, letting me know.

Without the email, I would have never realized the virus was sent, and if I got it, I'd be in a pile of **** right now.

Thanks again.

Hopefully those sons of b****es rot in hell.

#22 Double-0-Seven

Double-0-Seven

    Lt. Commander

  • Veterans
  • PipPipPip
  • 2710 posts
  • Location:Ontario, Canada

Posted 13 May 2006 - 09:21 PM

I didn't receive the e-mail nor have I been on the forum all day so I shouldn't be affected by it right? I might run a virus check after just to be on the safe side. :tup:

#23 Qwerty

Qwerty

    Commander RNVR

  • Commanding Officers
  • PipPipPipPip
  • 85605 posts
  • Location:New York / Pennsylvania

Posted 13 May 2006 - 09:23 PM

What [censored]s. Useless, pathetic internet trolls.

Glad to see everything is pretty much back to normal.

#24 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 09:25 PM

Only around half of our members received the email.

#25 Carver

Carver

    Lt. Commander

  • Veterans
  • PipPipPip
  • 1470 posts
  • Location:Birmingham, UK

Posted 13 May 2006 - 09:50 PM

I only got the email tonight telling me the site had been hacked. I didn't get the card email, but I'm running an AVG scan just in case. Pathetic bastards, do they not have anything better to do with their lives? I gotta say though, hats off to Dave for informing us all about it so to avoid any of us getting viruses, and I'm glad things are getting back to normal.

#26 darkpath

darkpath

    Lt. Commander

  • Veterans
  • PipPipPip
  • 2688 posts
  • Location:Stamford, CT

Posted 13 May 2006 - 09:55 PM

I've also done a scan at symantec online, but nothing was picked up there either :tup:


By default, Symantec Antivirus does not look for so-called expanded threats. There is an option that can be selected when preparing to run a scan of the hard drive. Also, by default, Symantec Antivirus only flags such expanded threats; but, the default behavior can be changed to delete such threats.

On note of caution: if the threat is running as a service or has somehow managed to acquire sufficiently high permissions, then the threat may not be deleted. For this reason, it's best to run such a scan for expanded threats in safe mode.

If I may be of service to anyone having trouble sorting out my description, please let me know and I will do my best to unmuddle my description.

Cheers!

#27 Lady Templar

Lady Templar

    Lt. Commander

  • Veterans
  • PipPipPip
  • 1277 posts
  • Location:Brussels, Belgium

Posted 13 May 2006 - 10:08 PM

Aw, my computer was infected by a Trojan worm as soon as I looged on CBn. But it has been - let's hope it was ! - removed by the Norton anti-virus. I firstly thought there was something wrong with CBn.

#28 The Admiral

The Admiral

    Admiral

  • The Admiralty
  • PipPipPipPip
  • 7777 posts
  • Location:United Kingdom

Posted 13 May 2006 - 10:14 PM

Aw, my computer was infected by a Trojan worm as soon as I looged on CBn. But it has been - let's hope it was ! - removed by the Norton anti-virus. I firstly thought there was something wrong with CBn.


Try running a scan with AVG just to be safe.

#29 TGO

TGO

    Lieutenant

  • Crew
  • PipPip
  • 783 posts
  • Location:Brooklyn, NYC, NY

Posted 13 May 2006 - 10:49 PM

I did suspect the e-mail had a virus. But, having a Mac...my computer laughs at such nonsense...like Windows viruses, for example. :tup:

#30 Lady Templar

Lady Templar

    Lt. Commander

  • Veterans
  • PipPipPip
  • 1277 posts
  • Location:Brussels, Belgium

Posted 13 May 2006 - 11:16 PM

The e-mail reached me unfortunatelly too late. But thanks Dave and all the CBn team for your help and explanations about what happened.

Just a question: I'm using Norton. Can I download AVG without problem ?