Go Back   Download Forums > Website Support > Website / File Downtimes

Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-30-2008, 01:46 AM
kapusky kapusky is offline
Pawn
 
Join Date: Jul 2008
Posts: 3
Question Trojan found on khinsider.com

Now before you chew me out and say noob, lol. I'll should show some proof. This might have already been fixed as I emailed one of the admins earlier today, but got no reply.

I'm using McAfee Site Advisor a toolbar that checks pages for spyware and "bad stuff", and it told me that khinsider website was red for having downloads on the site that some people consider adware, spyware or other potentially unwanted programs. bla bla bla...

So, I checked out the info page for khinsider.com found here.
http://www.siteadvisor.com/sites/khinsider.com

Apparently, http://www.khinsider.com/(placeing a space here, so no one clicks it and regets it)downloads/index.shtml has JS/Psyme trojan.

more info on Index.shtml found on the site is found here.
http://www.siteadvisor.com/sites/khinsider.com/downloads/14556623/

and here is some info i got from McAfee's Threat Library found on
http://vil.nai.com/vil/content/v_136045.htm

Characteristics -

JS/Psyme trojan is a javascript detection for malicious IFrames embedded on various legitimate websites. The javascript itself generally uses the String.fromCharCode method to generate the iframe HTML source from decimal Unicode values. document.write is then used to make the web browser render the iframe element within the victims web browser.

The inserted iframe usually contains the following elements

name=3e
src='http://77.221.{removed}/.if/go.html?3822747c2f'
width=279
height=243
style='display: none'

Finally, since khinsider.com has a trojan, most sites that are linked to khinsider.com including this site is also marked red

Don't get me wrong, I think the site rocks and helped me get my scratched cds back. I just think that should be fixed before I recommend this site to my friends since I’m known for being a techie.
  #2 (permalink)  
Old 07-30-2008, 04:48 AM
Dragonlady's Avatar
Dragonlady Dragonlady is offline
Administrator and Guardian Dragon
 
Join Date: Jan 2008
Location: in my own little world
Posts: 2,254
Send a message via Yahoo to Dragonlady
Default

I think you should have posted this over at khinsider.com's forum since that is where it's coming from.
  #3 (permalink)  
Old 07-30-2008, 05:01 AM
kapusky kapusky is offline
Pawn
 
Join Date: Jul 2008
Posts: 3
Default

ummm... I thought this was their form, lol. Can you provide a link or helpfull tips on finding their other form?
  #4 (permalink)  
Old 07-30-2008, 06:09 AM
Dragonlady's Avatar
Dragonlady Dragonlady is offline
Administrator and Guardian Dragon
 
Join Date: Jan 2008
Location: in my own little world
Posts: 2,254
Send a message via Yahoo to Dragonlady
Default

No. We do not have anything to do with khinsider.com's forum. We are ffdownloads.com forum. The link to their forum is KHInsider.com Forums
  #5 (permalink)  
Old 07-30-2008, 10:38 PM
KainTepes's Avatar
KainTepes KainTepes is offline
Pawn
 
Join Date: Jul 2008
Posts: 1
Default

a trojan? ouch... didnt think that there was anything that bad on the site. other than a few cruddy songs, that is..(just a joke)
__________________
who, what, when, where, why? KHAN!!!
  #6 (permalink)  
Old 07-30-2008, 11:08 PM
Dragonlady's Avatar
Dragonlady Dragonlady is offline
Administrator and Guardian Dragon
 
Join Date: Jan 2008
Location: in my own little world
Posts: 2,254
Send a message via Yahoo to Dragonlady
Default

There isn't anything bad on this site, The Hylia or downloads.khinsider.com. There's no telling what khinsider.com has going.
  #7 (permalink)  
Old 08-01-2008, 06:21 PM
kapusky kapusky is offline
Pawn
 
Join Date: Jul 2008
Posts: 3
Cool Eureka! No trojan (hopefully)

Eureka! I figured it out. I don’t think it is a trojan, just a great idea that happens to mimic the JS/Psyme trojan.

Have you ever noticed on the khinsider site that certain parts of the site never disappear, such as the left part of the screen that has links to this form and popular searches, and the "bluepart.htm" that has links to the home page and an couple of ads. The site took advantage of this and used php to basically "paste" the stuff that are reused on the page.

Smart huh.

Well unfortunately, the way they had "bluepart.htm" display the ads was by using an Iframe, which is used to display "ad-a.php" page (their random ad generator page) on "bluepart.htm", Which is finally pasted on Index.shtml.

So McAfee thinks that the JS/Psyme trojan is on that page when it's actually not.

Simply figure out a different way to display the ads, most likely without an iframe, and I think the problem should be solved.

It might be a while before McAfee double checks your site for changes though.

Hmm, now how should I word this on their form. LOL
  #8 (permalink)  
Old 08-01-2008, 08:08 PM
Darkling's Avatar
Darkling Darkling is offline
Master
 
Join Date: Jul 2007
Posts: 174
Default

wait, so there's no trojan here right?
coz the last time I got trojan, it is comboed by the brontok, making my computer unable to be cleaned...
and I end up getting no choice but to reinstall the whole thing... T_T

not a very fun thing to do, so to make sure, it's safe in here rite??
  #9 (permalink)  
Old 08-02-2008, 02:38 AM
williamscheefjr williamscheefjr is offline
Master
 
Join Date: Jul 2008
Posts: 181
Default

I scan everything I download from any site and this site has yet to make AVAST go off, or spyware terminator. Thank god for custom scans. So yes I would say this site is safe. Mcaffee Siteadvisor does mark this site as red, but I dont really believe it should be red I think it should be green.

Last edited by williamscheefjr : 08-02-2008 at 02:50 AM.
  #10 (permalink)  
Old 08-02-2008, 02:22 PM
Dragonlady's Avatar
Dragonlady Dragonlady is offline
Administrator and Guardian Dragon
 
Join Date: Jan 2008
Location: in my own little world
Posts: 2,254
Send a message via Yahoo to Dragonlady
Default

McAfee as well as Norton are not very good anti-virus programs like they tend to think that they are. They basically just want your money. Avast is free and does ten times better than most of the ones you have to pay for. It's never gone off on any of these sites before on me. And it even lets me know if a site is know for phishing before the page loads. So I say this site is totally safe except for the bot's links. Never click on them. Of course I try to catch them before anyone can click on them and banish them to the seventh level of hell. So I wouldn't put too much stock into anything that McAfee says.
Closed Thread


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 05:05 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0
foot
The Hylia Copyright