Here I am

Britney Spears virus links in posts

Attention: TDR Forum Junkies
To the point: Click this link and check out the Front Page News story(ies) where we are tracking the introduction of the 2025 Ram HD trucks.

Thanks, TDR Staff

site trouble ?

it would be cool if they made a TDR screen saver

Steve St.Laurent

Staff Alumni
FYI - at least 3 of our users have been infected by a new type of virus. As soon as I was made aware of it I researched it as best I could quickly and then shut the forums down to stop the spread. This virus watches for message post forms on your browser and if it sees you posting a message it inserts text and a link to the virus installer. If you click on that link and run the program then your PC is infected and all your posts from that point forward will have the text and link in it as well. I can't find where any of the anti-virus companies have found this virus so far. I have found 3 other vBulletin sites that have posts with this problem on it and several yahoo groups. It didn't appear until June 23rd it looks like. Keep in mind that thi virus is NOT here on our servers - it is on the individual users PC and simply puts a link on here. Thus far the text it inserts is:

Check it out ! Have you heard what has happened with Britney Spears last week? I was really shocked…

and then there is a link to a site with a . exe (without the space) file. The users that I know are infected on our site right now are EricBu12, Grizzly, and B. G. Smith. If you have clicked on that link then you are infected as well and that link will be added to all of your posts as well.

For now I have added a filter that will filter out . exe (without the space) which will stop this from spreading to other users. It will not however stop the text or the link from being added to your posts - it will just make the link not work. If you have been infected by this please after you make a post go back and edit your post and remove that text. I'm starting work on a filter that will find that text and the url and remove it if it's in posts but it probably won't be up and running until tomorrow.

Your help on keeping the posts clean until that's in place would be GREATLY appreciated. Keep in mind that if you are infected with this it will probably affect you on any forums or discussion areas you post to (I've found it on several yahoo groups as well as 3 other vB sites). Those sites probably don't have a filter in place to remove the exe extension so it will propagate further from your posts there. If you have been infected by this virus then you need to contact your anti-virus software supplier and get them working on the problem. Being that this is a very new virus they may not even be aware of it at this point in time.

UPDATE:

Ok folks. I have the filter in place now. Now if anyone has this virus the text will be removed and the link will be changed to say that executable files cannot be linked. I'll post right below this just what the virus would post so you can see it:



LINKS TO EXECUTABLE FILES NOT ALLOWED

So that's all you'll see on your posts if you have the virus. This will protect from it spreading further. I'm sure that other variants will come out so if you see wierd stuff at the beginning of posts please let me know and I can add that text to the filter. By stopped executable links that will stop any spread.

There is one issue however. If a website address has . exe in it that address is going to be killed as well. For example an address like www.executive.com would come out like this:

LINKS TO EXECUTABLE FILES NOT ALLOWEDcutive.com

I couldn't come up with a solution to that problem. But given the option of spreading a virus or this problem protecting our users is more important.

-Steve St. Laurent
Webmaster
 
Last edited:
It's surprising that Windows does not make it better known that in XP you have one "administrator" account by default, and that you can then create many other user accounts with "limited" status. That means, no new software programs may be installed on those accounts without the administrator's permission, including viruses. So those accounts are next to impossible to infect.



That's how I've been surfing, ever since I found that out.
 
It's surprising that Windows does not make it better known that in XP you have one "administrator" account by default, and that you can then create many other user accounts with "limited" status. That means, no new software programs may be installed on those accounts without the administrator's permission, including viruses. So those accounts are next to impossible to infect.



That's how I've been surfing, ever since I found that out.



That's easy to explain:



That's not always the case.



People are lazy.
 
I thought TDR had an auto-expulsion robot that would lock-out members caught visiting any Hollywood teeny-bopper gossip sites.



Where's a good thought-policeman when you need one? :)
 
I believe that OSX is based on Berkley UNIX. . or maybe BSD... I can't remember. . but either way, files with a ***** extension are Windows executables. I'd doubt that you'ld have to worry running OSX, Linux or any other Non-Windows O/S.
 
Virus

FYI - at least 3 of our users have been infected by a new type of virus. As soon as I was made aware of it I researched it as best I could quickly and then shut the forums down to stop the spread. This virus watches for message post forms on your browser and if it sees you posting a message it inserts text and a link to the virus installer. If you click on that link and run the program then your PC is infected and all your posts from that point forward will have the text and link in it as well. I can't find where any of the anti-virus companies have found this virus so far. I have found 3 other vBulletin sites that have posts with this problem on it and several yahoo groups. It didn't appear until June 23rd it looks like. Keep in mind that thi virus is NOT here on our servers - it is on the individual users PC and simply puts a link on here. Thus far the text it inserts is:







and then there is a link to a site with a . exe (without the space) file. The users that I know are infected on our site right now are EricBu12, Grizzly, and B. G. Smith. If you have clicked on that link then you are infected as well and that link will be added to all of your posts as well.



For now I have added a filter that will filter out . exe (without the space) which will stop this from spreading to other users. It will not however stop the text or the link from being added to your posts - it will just make the link not work. If you have been infected by this please after you make a post go back and edit your post and remove that text. I'm starting work on a filter that will find that text and the url and remove it if it's in posts but it probably won't be up and running until tomorrow.



Your help on keeping the posts clean until that's in place would be GREATLY appreciated. Keep in mind that if you are infected with this it will probably affect you on any forums or discussion areas you post to (I've found it on several yahoo groups as well as 3 other vB sites). Those sites probably don't have a filter in place to remove the exe extension so it will propagate further from your posts there. If you have been infected by this virus then you need to contact your anti-virus software supplier and get them working on the problem. Being that this is a very new virus they may not even be aware of it at this point in time.



-Steve St. Laurent

Webmaster



Steve I clicked on the Britney link and opened it. My Norton 2003 detected and disabled it immediately , I hope. I will test with this post.



Bill Davis
 
Check it out! Have you heard what has happened with Britney Spears last week? I was really shocked…



I dont care if I get a virus. I want to find out what happened w/ Brittney last week.
 
Check it out! Have you heard what has happened with Britney Spears last week? I was really shocked…



I dont care if I get a virus. I want to find out what happened w/ Brittney last week.



And here I thought this was a Dodge Cummins site.



Dave
 
Steve,



Do you know if this virus will get by the checks in Vista? It's supposed to pop up a little window everytime something is installed so the user has to ok the installation.
 
My computer appears to be okay now. I ran my Norton Full System Scan, which took hours. It did find a virus. It said that it was potentiality dangerous and it removed it. This will be my third post, virus free, knock on wood. EricBu12 has not been able to remove his. He said he will try the Norton software I have. We have been sending PM's back and forth.
 
Steve,



Do you know if this virus will get by the checks in Vista? It's supposed to pop up a little window everytime something is installed so the user has to ok the installation.

If you shut down the User Accounts,it will attach itself just like former OS. also do NOT shut down the guest account, you may need it some Day...
 
FWIW, the site hosting the virus, reznicak. eu, seems to have removed it. Actually, the whole website seems to be off-line. That domain is registered to someone in the Czech Republic, and there's no indication whether the site owner knew about the virus/worm, or didn't know, or when he knew if he did, in fact, know.

Grizzly, could you post the identifying info about the virus? THe info should still be in your scan logs. This would be a good thing to send to other AV producers. Even better would be a copy of the virus. I run Linux and am much less susceptible to Windows virii. Come to think of it, I also run WinXP, and have never had a virus with it. It does help to be selective about where I stick my, errrr, I mean where I click my mouse.

N
 
Check it out! Have you heard what has happened with Britney Spears last week? I was really shocked…



I dont care if I get a virus. I want to find out what happened w/ Brittney last week.



I think people that want to open stuff like this up are wanting to see some action:-laf
 
Back
Top