SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > Silent Hunter 3 - 4 - 5 > Silent Hunter 4: Wolves of the Pacific
Forget password? Reset here

Closed Thread
 
Thread Tools Display Modes
Old 09-28-10, 06:22 PM   #16
Gerald
SUBSIM Newsman
 
Gerald's Avatar
 
Join Date: May 2008
Location: Close to sea
Posts: 24,254
Downloads: 553
Uploads: 0


We can take and a few beers in Funchal for the reasons you have solved your PC prob.
__________________
Nothing in life is to be feard,it is only to be understood.

Marie Curie





Gerald is offline  
Old 09-28-10, 08:58 PM   #17
Reece
CINC Pacific Fleet
 
Reece's Avatar
 
Join Date: Sep 2003
Location: Down Under
Posts: 34,693
Downloads: 171
Uploads: 0
Default

I had almost the same thing with Java, it effected firefox, every time I fired it up it tried to update some application, had to exit quickly, this was a while ago, I tried uninstalling firefox and reinstalling, fired it up and the same thing starts, both avira and ad-aware didn't find anything so I just saved my Outlook Express, game saves etc then re-ghosted my machine, best thing in the long run I reckon!
__________________

Sub captains go down with their ship!
Reece is offline  
Old 09-29-10, 04:00 AM   #18
HunterICX
Rear Admiral
 
Join Date: May 2006
Location: Malaga, España
Posts: 10,750
Downloads: 8
Uploads: 0


Default

Same here, had a similiar malware that injected itself in some key system files mostly in the System32 folder so the virus just wouldn't die untill I did some heavy cleaning and restoring a bit frustrating and it really made me want to hurt people that create this kind of garbage.

HunterICX
__________________
HunterICX is offline  
Old 09-29-10, 04:08 AM   #19
Gerald
SUBSIM Newsman
 
Gerald's Avatar
 
Join Date: May 2008
Location: Close to sea
Posts: 24,254
Downloads: 553
Uploads: 0


And what they get paid, to develop PC infections
__________________
Nothing in life is to be feard,it is only to be understood.

Marie Curie





Gerald is offline  
Old 09-29-10, 04:37 AM   #20
Rhodes
Silent Hunter
 
Join Date: Aug 2005
Location: Figueira da Foz, Portugal
Posts: 4,515
Downloads: 110
Uploads: 0
Default

Ideed. But now, I opened this thread and got the same virus from the first time detected by nod32 and and java console pop up. But it's strange, subsim is not infected! I am not seeing any site apart from this.

PS: 29-09-2010 10:34:24 HTTP filter file http://drerlre.co.cc/1.zip a variant of Java/Mugademel.A trojan connection terminated - quarantined RHODES\Administrador Threat was detected upon access to web by the application: C:\Programas\Java\jre6\bin\java.exe.
Its was this that appear!
Rhodes is offline  
Old 09-29-10, 05:11 AM   #21
HunterICX
Rear Admiral
 
Join Date: May 2006
Location: Malaga, España
Posts: 10,750
Downloads: 8
Uploads: 0


Default

Odd, seems there's some traces left that is enough to restore the whole Virus.

I would do the following -

Disconnect the Internet
Do a full clean sweep with the scanners you have installed, use the tools you can find to get rid of the specific virus.
(perhaps Uninstall JAVA again and reinstall later when you have internet restored and there's no traces to be found of the virus)
perhaps you might want to tighten your security (enable Windows Firewall)
restore internet connection.

btw are you using Firefox yet? if not get it and use the No-Script plug in.
also CCleaner is a nice tool, I use it everytime before I close down my PC so it's fresh at start up.

also on the bottom of this page are 2 links to fix the vulnerability in Java: http://www.microsoft.com/security/po...tid=2147637327

HunterICX
__________________
HunterICX is offline  
Old 09-29-10, 05:34 AM   #22
Gerald
SUBSIM Newsman
 
Gerald's Avatar
 
Join Date: May 2008
Location: Close to sea
Posts: 24,254
Downloads: 553
Uploads: 0


No-Script is a good choice and firefox of course
__________________
Nothing in life is to be feard,it is only to be understood.

Marie Curie





Gerald is offline  
Old 09-29-10, 05:46 AM   #23
Rhodes
Silent Hunter
 
Join Date: Aug 2005
Location: Figueira da Foz, Portugal
Posts: 4,515
Downloads: 110
Uploads: 0
Default

Thanks. No, I still use IE8!

PSid a full scan with out my internet connection enable and notting. Scann with the program that erase the malware, noting also.

Came here and had the anti-irus pop up window about the same zip file trying to get in. I do not get it. For one view, this site has a java virus that etc,etc,etc. On the other hand, this never happend here and this forum is one of the safetest that I know.
Well, if it's detected and it do not enters my pc and infects, it's fine!
Damn those who invented such things...

Last edited by Rhodes; 09-29-10 at 09:17 AM.
Rhodes is offline  
Old 09-29-10, 10:05 AM   #24
SeaWolf U-57
Ace of the Deep
 
Join Date: May 2008
Posts: 1,231
Downloads: 92
Uploads: 0
Default Problem when logging in

Today when I log into SubSim I was told I needed to install Java ok never had that before.
And then the next time I went to log in My nod 32 antivirus software went crazy and warned me that this site was trying to send Trojans to my computer
What gives
SeaWolf U-57 is offline  
Old 09-29-10, 11:15 AM   #25
HunterICX
Rear Admiral
 
Join Date: May 2006
Location: Malaga, España
Posts: 10,750
Downloads: 8
Uploads: 0


Default

my scanners have kept quiet and so did Java.
@Work : AVG
@Home : Avast

I think you ran into a malware that exploits the vulnerability of Java and infests it.
They just hit you at random, mostly through banners, ads and scripted advertising.

has NOD32 been able to identify the malware? and what web browser are you using?

EDIT: someone else on this forum caught the same problem when visiting a different website:
http://www.subsim.com/radioroom/showthread.php?t=175495

HunterICX
__________________
HunterICX is offline  
Old 09-29-10, 12:50 PM   #26
SeaWolf U-57
Ace of the Deep
 
Join Date: May 2008
Posts: 1,231
Downloads: 92
Uploads: 0
Default

I Found this in my quarantine folder of Nod32it was never allowed to install


29/09/2010 …. drerlre.co.cc/client.zip… java/TrojanDownloader.agent.NBU trojan
29/09/2010 … drerlre .co.cc/1.zip ….. A variant of java/Mugade


(I removed the http:// to stop them being active links)


I connected using my Firefox browser

Edit ...... why did subsim ask for java to be installed in the first place ???
SeaWolf U-57 is offline  
Old 09-29-10, 01:17 PM   #27
Jimbuna
Chief of the Boat
 
Jimbuna's Avatar
 
Join Date: Feb 2006
Location: 250 metres below the surface
Posts: 190,473
Downloads: 63
Uploads: 13


Default

Nothing to do with SS but I upgraded a Java applet about a month ago and ended up having to reformat a machine
__________________
Wise men speak because they have something to say; Fools because they have to say something.
Oh my God, not again!!

Jimbuna is offline  
Old 09-29-10, 02:04 PM   #28
SeaWolf U-57
Ace of the Deep
 
Join Date: May 2008
Posts: 1,231
Downloads: 92
Uploads: 0
Default

Quote:
Originally Posted by jimbuna View Post
Nothing to do with SS but I upgraded a Java applet about a month ago and ended up having to reformat a machine


Hhmmm Ok but I just un-installed Firefox and ran some hitman software that found nothing but would not un-install again.
So Restored my machine to before today’s java up data check all was ok then started up IE 64bit version check around the sites I used no problems so far.
But opened the SubSim forum and you guessed it these pages use a version of java to view them NFW am I doing that again the pages load ok without it
SeaWolf U-57 is offline  
Old 09-29-10, 02:20 PM   #29
SeaWolf U-57
Ace of the Deep
 
Join Date: May 2008
Posts: 1,231
Downloads: 92
Uploads: 0
Default

I hit the red cross on the up-date and left the forum and just returned but the message did not re-appear
SeaWolf U-57 is offline  
Old 09-30-10, 04:20 AM   #30
JScones
Navy Seal
 
Join Date: Apr 2005
Posts: 5,501
Downloads: 19
Uploads: 0
Default

I started getting this message this afternoon. Now it pops up everytime I touch this site, and ONLY this site.

JScones is offline  
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 12:42 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright © 1995- 2025 Subsim®
"Subsim" is a registered trademark, all rights reserved.