RRS Trojan??? A little help please.

tastybrain
atheist
tastybrain's picture
Posts: 9
Joined: 2009-10-20
User is offlineOffline
RRS Trojan??? A little help please.

Every time I log on to RRS, my Kaspersky gives me an alert that it detects a Trojan. Every thing I click on a link, it gives me the same message. I'm not super tech savvy but I'm not greenhorn either.

Here's the detailed report. What's going on here?

12/21/2009 9:36:24 PM    Infected    Trojan program Exploit.JS.Pdfka.auq    http://www.rationalresponders.com/sites/www.rationalresponders.com/cms.js//cms    High   
 

 

thanks! this is a recent development so I'm not sure what's happening. I haven't made any significant software changes recently.


Deadly Fingergun
atheist
Deadly Fingergun's picture
Posts: 237
Joined: 2009-11-19
User is offlineOffline
Exploit.JS.Pdfka.* is a

Exploit.JS.Pdfka.* is a JavaScript exploit often associated with PDF files. I don't see any javascript of the sort associated with this exploit being loaded with this site.

There are several possibilities that come to mind for me:

  • False positive. This site does load quite a few scripts remotely.
  • Something in your browser's cache is infected. Clean out your cache.
  • You have an infection that is interplaying with some of the scripts on this site. Run a complete scan of your local system.
  • One of the advertisers buying space on the site is being less than reputable. Consider ad blocking software or script blocking software.

 

Big E wrote:
Clown
Why, yes, I am!


tastybrain
atheist
tastybrain's picture
Posts: 9
Joined: 2009-10-20
User is offlineOffline
cleaned the cache

well I cleared the cache but only for one day. I wasn't sure if I should clear the whole history or not. these are things I rarely concern myself with so I don't know that much about it.

I'm guessing it's a false positive since the application listed in the notification is Mozilla.exe (i.e. firefox itself) or am I wrong? I performed a full scan this weekend so I don't think I'm infected.


tastybrain
atheist
tastybrain's picture
Posts: 9
Joined: 2009-10-20
User is offlineOffline
so, should i clear the whole

so, should i clear the whole cache history? will that just increase initial loading times on some webpages or will it affect anything else?


Deadly Fingergun
atheist
Deadly Fingergun's picture
Posts: 237
Joined: 2009-11-19
User is offlineOffline
Nuke the whole cache (which

Nuke the whole cache (which is not your history, that's just a list of URLs you've loaded before, not the contents). It will slow loading on some web pages until the cache is filled again.

Do another scan. I know they're a pain, but under Windows your really can't be too cautious.

http://noscript.net/

http://adblockplus.org/en/

Big E wrote:
Clown
Why, yes, I am!


ClockCat
ClockCat's picture
Posts: 2265
Joined: 2009-03-26
User is offlineOffline
:o

 No, this is a problem with the RRS site.

 

I have the same problem with Avast warning me. It only happens here. Nowhere else. It also only happens occasionally.

 

This didn't happen before. When I abort the connection the page still loads, so it leads me to thinking that it is due to one of the advertising banners put up.

 

 

Theism is why we can't have nice things.


Cpt_pineapple
atheist
Posts: 5492
Joined: 2007-04-12
User is offlineOffline
My firefox keeps crashing

My firefox keeps crashing here due to "data execution prevention"

 

 

 


Sapient
High Level DonorRRS CO-FOUNDERRRS Core MemberWebsite Admin
Posts: 7589
Joined: 2006-04-18
User is offlineOffline
 I got the warning today

 I got the warning today from avast using IE.  

I sent it off to the guy who would be looking into it.

 

I also got this later from some dickface...

 

Sent: Tuesday, December 22, 2009 7:26 AM
Subject: Re: [Rational Responders newsletter] ChristMyAss day broadcast at Rational Response Squad LIVE!
 

Hey, Thanks for sending me the Trojan!  Luckily Kaspersky blocked it for me.  Your email is now blocked and I'll be sure to let everyone know that your emails might contain malicious software. Peace.

 

Vote for Democrats to save us all from the anti-American Republican party!

Please become a Patron of Brian Sapient


Sapient
High Level DonorRRS CO-FOUNDERRRS Core MemberWebsite Admin
Posts: 7589
Joined: 2006-04-18
User is offlineOffline
Ok the problem was looked

Ok the problem was looked into.  It was related to a tracking code that one of my developers installed to track a few of my stalkers.  I had him remove it for now, my antivirus didn't pick anything up this time.  I assure you it was nothing but a tracking device that caused no harm to any computer.

 

 Let me know if it has gone away for you.

 

Vote for Democrats to save us all from the anti-American Republican party!

Please become a Patron of Brian Sapient


Deadly Fingergun
atheist
Deadly Fingergun's picture
Posts: 237
Joined: 2009-11-19
User is offlineOffline
Sapient wrote:Ok the problem

Sapient wrote:

Ok the problem was looked into.  It was related to a tracking code that one of my developers installed to track a few of my stalkers.  I had him remove it for now, my antivirus didn't pick anything up this time.  I assure you it was nothing but a tracking device that caused no harm to any computer.

 

 Let me know if it has gone away for you.

 

So it was a false positive.

Shawking!

 

 

Big E wrote:
Clown
Why, yes, I am!