Don’t recall the name of the trojan atm but it was associated with a file called "orz.exe". orz.exe would reinitialize in my processes when I visited the forums this morning, and I don’t know if that had something to do with the weirdness we experienced this morning or not. Every time I visited the forums, something would boot up the orz.exe until I ended the process. it wouldn’t return until I checked the forums.
Anyway, got that cleaned up via TrendMicro’s Housecall (it had little info on the trojan itself, just some crap about being a backdoor program + other stuff ~_~ ). ALSO, I’m pretty sure it was putting an entry in my Services (control panel > administrative tools > services) called "Security 2@)#@#%*" or something (literally a bunch of random characters that definitely didn’t belong there). I disabled it (it masks itself as "stopped" even though when you check properties it is listed as "started") and it is no longer there so I think Housecall cleared that up.
After that, I came across something called "LoveFly.dll" and "smart.dll" (in Windows/system32) which are keyloggers to steal WoW account passwords only, apparently. Those were easy enough to remove, but I can only assume they came from FFS as well, since it’s the only gaming site I go to regularly and it’d make sense that a file that specific would target gaming sites.
ANYWAY. I know at least the Trojan was from FFS and the orz.exe file reinitializing is a concern because it came up on the forums. I don’t make a habit of visiting GH or the main site so I can avoid those, but if there’s something on the forums that would sorta suck. It suggests something in the code of the forums is working with the trojan. Unless something with the code errors this morning was to explain.
I couldn’t get a hold of you on IRC so I figured I’d post it here. Also just to notify anyone else who may have been at the site to check for those things (orz.exe, weird entry in Services, smart.dll/LoveFly.dll). The .dll files I think I picked up on Oct 25, according to the "Date Modified" dealy.
Update: Still have the weird entry in my Services. "Security Control" is what it’s called and it’s description is full of random/weird characters. Associated with the file "zordisa.dll" which is a trojan/backdoor. Not sure if this is from FFS but I really wouldn’t doubt it given the other crap I’ve picked up ;\ Back to fixing this, I guess.
As an additional update, I went through the registry and got rid of everything. Used a boot disk (I THINK THATS WHAT ITS CALLED) to manually delete the zordisa.dll and orz.exe (which apparently was still around). Also had to delete the Security Control service via command prompt. I think I’m mostly in the clearn now :<
everything should be removed now. if you get a specific warning or find suspicious code, let me know.
the google/firefox warning should be removed in a few days.
Opera has let me down as well ;(
everything should be removed now. if you get a specific warning or find suspicious code, let me know.
the google/firefox warning should be removed in a few days.
It’s gone for me now. Thanks.
maybe an update is in line
Hey Sarah. Question. If you guys seem to get all these injections…are the forums in anyway integrated with the site? If so, is it possible for you to upgrade the forums to the latest version (3.8.1)? Since there were some security exploits in vBulletin 3.6.9, IIRC. I can update the skin XML if needed.
=D
But Chrome makes some webpages look bad.