Notice: Some raiding positions are available, check here for more info.
Page 1 of 4 1234>
Topic Options
#227726 - 12/12/11 03:15 PM Malicious Java Download
Agonize Offline
F'N Pufnstuf


Registered: 05/14/07
Posts: 1072
Loc: Valley City, North Dakota
My norton keeps popping something up when i come here about a Malicious Java Download and it says the source is theleverageguild.com or some [censored], so Slam or Luna able to take care of this or?
Top
#227727 - 12/12/11 03:20 PM Re: Malicious Java Download [Re: Agonize]
Edelan Offline
Bear Bum


Registered: 02/25/08
Posts: 3027
Loc: Colorado
Site is clean for me and 3 different AV programs \:\(

Clear yo ca$h? \:\)
_________________________


V.P. of the DK Fan Club

Top
#227734 - 12/13/11 09:34 AM Re: Malicious Java Download [Re: Edelan]
MmBacon Offline
and Eggs


Registered: 02/01/11
Posts: 724
Loc: Boston, MA
When(if) its pops up again get the exact name and detail from Norton - I am interested in this.

I have been seeing some strange things occuring with Symantec products and Windows 7 Systems based on if they running 32/64.

But before all that - download "Malware Bytes" (Or Malware Antibytes - cant remember) but it is by far the absolute best anti malware program I have ever used. (Far superior to its expensive, resource hogging, counter part from Norton.)
_________________________
--


"Carpe Bacon, Bitch!."

Bacon's Retribution Videos Link

Top
#227742 - 12/13/11 01:17 PM Re: Malicious Java Download [Re: MmBacon]
Agonize Offline
F'N Pufnstuf


Registered: 05/14/07
Posts: 1072
Loc: Valley City, North Dakota
I have MB already. But here is what Norton says



Top
#227752 - 12/14/11 06:23 AM Re: Malicious Java Download [Re: Agonize]
MmBacon Offline
and Eggs


Registered: 02/01/11
Posts: 724
Loc: Boston, MA
Hmmmmm - When I got home Ill check a few of the 'sites' that can probably give me some good answers where is is coming from and what it really is.

I have a gut feeling its some worm attemping to mask itself as a java update to get by being a .exe - but was missing the dig sig of a real java update so norton caught it. But ill let you once I can get some decent data.
_________________________
--


"Carpe Bacon, Bitch!."

Bacon's Retribution Videos Link

Top
#227767 - 12/15/11 12:21 PM Re: Malicious Java Download [Re: MmBacon]
Evilwood Moderator Offline
Scarecrow


Registered: 05/10/05
Posts: 5436
I am getting a pop-up and message from Trend when coming here also...
Top
#227772 - 12/16/11 05:37 AM Re: Malicious Java Download [Re: Evilwood]
MmBacon Offline
and Eggs


Registered: 02/01/11
Posts: 724
Loc: Boston, MA
From what I managed to read about this file - and after looking over a little bit of the source code - it looks like it is a JAR file containing malware and other malicious goodies which can compromise your passwords/usernames. Since the file is technically (more or less) an .exe - it is disguising itself by probably imitating the interesting code of a java download (which are common and your computer usually does on a weekly basis without most of you really even knowing).

A crappy virus program (not saying norton is top of the line) would have let this program slide - but norton and many other larger programs will verify digitial signatures (which you can kinda think about as doing what an authenticator does for wow, but for a program). Not fool proof - but there a TONs of people without protection on their comps and this would easily have gotten by.

P.S. It is not the site itself they are coming from - it is the web banner adds. Most of these sites allow the user to upload their own flash files - which is a horrible idea.
_________________________
--


"Carpe Bacon, Bitch!."

Bacon's Retribution Videos Link

Top
#227781 - 12/16/11 01:11 PM Re: Malicious Java Download [Re: MmBacon]
Edelan Offline
Bear Bum


Registered: 02/25/08
Posts: 3027
Loc: Colorado
I'm now getting something from forum.issseem.org or something, someone needs to put a call into Wuk \:\(
_________________________


V.P. of the DK Fan Club

Top
#227794 - 12/19/11 11:02 AM Re: Malicious Java Download [Re: Edelan]
Edelan Offline
Bear Bum


Registered: 02/25/08
Posts: 3027
Loc: Colorado
I sent Wood a facebook message, I'm still getting "counter" and weird [censored] when accessing the main forum page.
_________________________


V.P. of the DK Fan Club

Top
#227795 - 12/19/11 12:28 PM Re: Malicious Java Download [Re: Edelan]
Dirtykarl Moderator Offline
Mastah HiJackah


Registered: 06/29/05
Posts: 16422
Loc: Connecticut
I sent Slam, Wuk and Lu a note but I have no clue what happens in the back ground.
_________________________
I am a very responsible person, every time something goes wrong....I am responsible.

DK fan club member count = 4 and rising!

Top
Page 1 of 4 1234>


Moderator:  Gorthad, Misfit, Evilwood, Dirtykarl, Bareass 
Hop to:

Generated in 0.017 seconds in which 0.002 seconds were spent on a total of 14 queries. Zlib compression enabled.