PDA

View Full Version : Trojan?



Mike Switzer
08-24-2014, 06:04 PM
When I opened this forum just now my antivirus said it detected, blocked, and treated a trojan named vbulletin_read_marker

I have never had this happen before. I closed the window & re opened it & this time it opened normally.

Edit - Check that. This time the popup window was behind the browser. I get the message every time I open the forum.

Bill
08-24-2014, 07:36 PM
Which browser are you using? I don't see anything like that using Firefox.

Mike Switzer
08-24-2014, 09:30 PM
I am using firefox. It just started doing it today.

Matt Gonitzke
08-25-2014, 04:36 AM
It did it to me this morning, too.

dewi8095
08-25-2014, 04:40 AM
I get a "virus/malware blocked" notice regularly from this site.

Don

FlyingRon
08-25-2014, 05:12 AM
vbulletin_read_marker is not a "trojan." It's a small piece of JavaScript the forum software uses to support the "mark as read" feature. Your malware alerter is a little too sensitive.

Hal Bryan
08-25-2014, 06:40 AM
Thanks for chiming in, Ron. I've never seen this script get flagged as malware before - as you said, it definitely isn't. I just ran vBulletin's diagnostics to be sure, and all the files check out.

Mike Switzer
08-25-2014, 07:59 AM
vbulletin_read_marker is not a "trojan." It's a small piece of JavaScript the forum software uses to support the "mark as read" feature. Your malware alerter is a little too sensitive.

If so, then why did it just start yesterday, and why does it not do it on any other vbulletin site I go to?

FlyingRon
08-25-2014, 08:03 AM
Why it just started happening, I have no idea. Perhaps your software changed it's signatures it is looking for.

Unfortunately, there are gazillions of versions of vBulletin outthere and hundreds of add-on packages to the extent that no two vBulletin sites are the same. This one (as my site is as well) is running a fairly recent (not the latest 4.2 release which is 4.2.4 and there are some serious security bugs unrelated to the subject of this tread that Hal may wish to check to see if it is worth updating). They're actually up to verion 5 now, but a lot of people are a bit reticent to switch to that because it's not trivial and there has been some problems with it.

At least this board is a whole lot better off than POA or AOPA who are still running 3.x versions.

Mike Switzer
08-29-2014, 03:06 PM
Well, as of this morning it isn't doing it anymore, and I have not changed any settings on my antivirus.

dewi8095
08-30-2014, 05:10 AM
Well, as of this morning it isn't doing it anymore, and I have not changed any settings on my antivirus.

Same for me. It stopped after it was reported by Mike. I haven't seen it since 8/25.

Don

Kyle Boatright
08-31-2014, 02:48 PM
Got this a minute ago:

Norton Blocked a attack by:
Web Attack: Sweet Orange Exploit Kit Website.

I'm using Internet Explorer.

Hal Bryan
09-02-2014, 07:59 AM
Thanks for the heads-up, Kyle - I'm not seeing anything malicious on this end. Kaspersky isn't reporting anything, the vBulletin diagnostics don't show any suspect files, and our hosting company just ran a full malware scan that came back clean.

Kyle Boatright
09-02-2014, 07:19 PM
Thanks for the heads-up, Kyle - I'm not seeing anything malicious on this end. Kaspersky isn't reporting anything, the vBulletin diagnostics don't show any suspect files, and our hosting company just ran a full malware scan that came back clean.

It happened when I opened the forum, but could have come from an advertisement on another page I had open simultaneously. Who knows.

Thanks for the follow-up.

Mike Switzer
09-13-2014, 10:29 AM
As of this AM it is back. I have not changed any settings.

Hal Bryan
09-15-2014, 10:22 AM
This should be fixed now - thanks for the heads-up, Mike.

Mike Switzer
09-15-2014, 01:26 PM
It looks like it - It did it this AM when I logged on but not this time.

Mike Switzer
09-23-2014, 11:15 AM
This AM I am getting the virus warning again

Hal Bryan
09-24-2014, 07:25 AM
This was resolved yesterday, but I'm seeing indications that the file in question may have been compromised yet again - we're investigating.

Mike Switzer
09-24-2014, 07:47 AM
This morning is OK - I wonder if something in the software is updating itself causing it to keep coming back?

Mike Switzer
10-07-2014, 02:36 PM
It is back. Wasn't there this AM when I checked in but just now it is back.

Hal Bryan
10-07-2014, 03:09 PM
Ugh - thanks for the heads-up, Mike. I've let the hosting company know.

Hal Bryan
10-07-2014, 03:58 PM
Fixed...again. I'm trying to get to the bottom of why this keeps happening...