Page 1 of 3

avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sat Jan 12, 2013 12:33 am
by studiodaz
What is going on? I keep getting blank pages or

Infection Details
URL: http://www.d8bforum.com/
Process: C:\Program Files (x86)\Google\Chrome\App...
Infection: JS:Iframe-XJ [Trj]

Infection Details
URL: http://www.sonido-7.com/
Process: C:\Program Files (x86)\Google\Chrome\App...
Infection: JS:Iframe-XJ [Trj]

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sat Jan 12, 2013 4:00 am
by Petersueco
I'm seeing this one on my side too. But I'm on Firefox and my AVG anti-virus is stopping me from getting through.

I just reported AVG about the problem. Looking into it.

Thanks for the heads up!

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 5:29 pm
by Petersueco
Well, I believe we are back.

But all the sites in my server has been infected. Please have your anti-virus updated.

You may get warnings trying to access the database site. For some reason I don't understand the forum has not been affected... yet.

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 6:04 pm
by anyhorizon
Well done, Peter! I was always able to access the database but the forum just went AWOL.

Peter

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 6:06 pm
by studiodaz
it good to see the site back up again.

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 7:14 pm
by Petersueco
Thanks guys. It have been a hell of a weekend !!

Please update your anti-virus software and run full system scans on your computers, just to be safe. Many html files have been infected and I'm uploading the backup files right now. I'm using AVG and it is catching the buggers.

Sorry for the inconvenience.

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 7:15 pm
by studiodaz
Clicking on the board index at the top of the page index.php
I get a bank page with an "OK" in it. it send me here http://stradedelleparole.archivibasso.it/rel.php

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 7:17 pm
by Petersueco
I can't reproduce this in my system.

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sun Jan 13, 2013 7:25 pm
by studiodaz
Petersueco wrote:I can't reproduce this in my system.



I just cleared my browser cashe and its working now :-)

Re: avast says Infection: JS:Iframe-XJ [Trj] for this forum.

PostPosted: Sat Jan 19, 2013 8:44 am
by Dan Worley
1/18/2013. Google is reporting this site as an attack site.

Just letting you know, Peter.

Regards,

Dan

Image

Here's the info you get when clicking on that link.

Safe Browsing
Diagnostic page for http://www.d8bforum.com

What is the current listing status for http://www.d8bforum.com?
This site is not currently listed as suspicious.

Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.

What happened when Google visited this site?
Of the 24 pages we tested on the site over the past 90 days, 22 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-01-18, and the last time suspicious content was found on this site was on 2013-01-18.
Malicious software includes 1 trojan(s), 1 exploit(s). Successful infection resulted in an average of 9 new process(es) on the target machine.

Malicious software is hosted on 2 domain(s), including archivibasso.it/, retyukilo.dyndns.org/.

1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including archivibasso.it/.

This site was hosted on 1 network(s) including AS46606 (BLUEHOST).

Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, http://www.d8bforum.com did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?
No, this site has not hosted malicious software over the past 90 days.

Next steps:
Return to the previous page.
If you are the owner of this web site, you can request a review of your site using Google Webmaster Tools. More information about the review process is available in Google's Webmaster Help Center.