C-Class (W203) 2001-2007, C160, C180, C200, C220, C230, C240, C270, C280, C300, C320, C230K, C350, Coupe

Free Body Kit Giveaway!

Thread Tools
 
Search this Thread
 
Rate Thread
 
Old 04-29-2008, 12:01 PM
  #1  
Former Vendor of MBWorld
Thread Starter
 
Extreme Dimensions's Avatar
 
Join Date: Jan 2008
Location: Fullerton, CA
Posts: 957
Received 10 Likes on 10 Posts
Too Many To List
Free Body Kit Giveaway!

Hi everyone, I just wanted to remind you that for 2008 we will be giving away 1 free body kit every month until the end of the year. Please visit http://www.extremedimensions.com/freebodykit/ in order to sign up to be eligible for the drawing for a free bodykit. Also be sure to visit our website: http://www.extremedimensions.com for all of your aftermarket aerodynamic needs. Good luck!!!
Old 04-29-2008, 12:20 PM
  #2  
Super Moderator

 
MJ50's Avatar
 
Join Date: Jul 2003
Location: MBworld
Posts: 21,149
Received 779 Likes on 758 Posts
bone stock E55 AMG
site's working now....
Old 04-29-2008, 02:04 PM
  #3  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
I just tried to go to this site.
When I go to the mercedes portion, it completely locked my system,
installed some backdoor software, apparently known as "Qbot" which caused
Norton Anti-Virus to tell me I had a virus,
Internet Explorer opened on it's own, and wanted to access the internet (I use firefox, told it to get bent)
rebooting didn't get rid of it.
Ending process of IE (running in the background I might ad, against my will)
just immediately opened another instance.

THIS SITE INSTALLED A VIRUS ON MY SYSTEM! I'm still trying to clean up the mess.
Old 04-29-2008, 02:15 PM
  #4  
Moderator Alumni
 
TruTaing's Avatar
 
Join Date: Apr 2006
Location: Seattle
Posts: 3,255
Likes: 0
Received 20 Likes on 7 Posts
w203 m112
Gotta use the noscript addon when surfing the web w/ firefox :x
Old 04-29-2008, 02:23 PM
  #5  
Super Moderator

 
MJ50's Avatar
 
Join Date: Jul 2003
Location: MBworld
Posts: 21,149
Received 779 Likes on 758 Posts
bone stock E55 AMG
my firefox froze on me too but didn't know it was a virus..
damn, gotta scan my computer now...
giveaway FTL...
Old 04-29-2008, 02:36 PM
  #6  
Member
 
karma23's Avatar
 
Join Date: Mar 2008
Posts: 108
Likes: 0
Received 0 Likes on 0 Posts
06 w219 & 00 w208
Same thing with mine. My work IT guy just came over and said that he's getting a report of a site trying to dump a virus on my machine.
Old 04-29-2008, 02:42 PM
  #7  
Super Moderator

 
MJ50's Avatar
 
Join Date: Jul 2003
Location: MBworld
Posts: 21,149
Received 779 Likes on 758 Posts
bone stock E55 AMG
and this thread is posted everywhere in this forum....
Old 04-29-2008, 02:52 PM
  #8  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Originally Posted by TruTaing
Gotta use the noscript addon when surfing the web w/ firefox :x
Can you elaborate please?
Where do we get this addon?
Old 04-29-2008, 02:58 PM
  #9  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
ROOTKIT

This site says it's a rootkit, which is VERY BAD!
http://www.wilderssecurity.com/showthread.php?t=156461
http://www.fileresearchcenter.com/Q/Q1.32585-9799.html
That being said, I think I got it before it could do too much damage.
I saw a process I didn't recognize (sorry, I didn't jot the name)
once I killed that I was able to stop IE.

I used a program called "ATF Cleaner" to clean out all my temp files.
Plus, I cleared my Firefox cache.
I deleted the folder and files mentioned in the link above, and
then ran ATF Cleaner again. (It's a small utility for clearing temp files, just search on it)
I went to c:\windows\prefetch
and deleted everything from today (sort by date)
and usually you can delete all this, but I just renamed the folder and then created a new empty one to be sure. There was a reference to the
offending file.
I scanned my system for qbot and deleted everything it found (you must enable hidden folders) And emptied my recycle bin.

Since I didn't allow access to the internet with Zonealaem via IE, I think I was lucky.
God knows what this thing wanted to download to my system!
(or upload elsewhere)

Someone please contact the Mods and get this thing taken down, till the
site owner can get things properly sorted!

This really pisses me off!

Last edited by C230 Sport Coup; 04-29-2008 at 05:50 PM.
Old 04-29-2008, 03:23 PM
  #10  
Moderator Alumni
 
TruTaing's Avatar
 
Join Date: Apr 2006
Location: Seattle
Posts: 3,255
Likes: 0
Received 20 Likes on 7 Posts
w203 m112
Google "housecall" and use its features to remotely clean your computer. It is pretty dang good imo.

http://housecall.trendmicro.com/

You can just google "firefox noscript addon" too. Itll prevent little (java)scripts from running and thus preventing many potential harmful things from finding their way onto your computer. You can also directly choose what scripts to run and which ones NOT to run.

http://noscript.net/

GL

To admins/OP: Maybe these links should be temporarily disabled....

Last edited by TruTaing; 04-29-2008 at 03:26 PM.
Old 04-29-2008, 03:50 PM
  #11  
Senior Member
 
JLD2k3's Avatar
 
Join Date: May 2006
Location: VA
Posts: 268
Likes: 0
Received 1 Like on 1 Post
2002 C320
ED has a banner ad at the top of this page, but it's a virus planting spyware site...what's the deal? Moderator?
Old 04-29-2008, 03:56 PM
  #12  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Geez, I was going to try to warn people in other forums, but he's got this link posted in a zillion places.
I could spend all day trying to warn people.

I called them directly to let them know their site has been compromised.

Last edited by C230 Sport Coup; 04-29-2008 at 04:10 PM.
Old 04-29-2008, 04:42 PM
  #13  
MBworld Guru
 
FrankW's Avatar
 
Join Date: Apr 2002
Location: Diamond Bar, CA
Posts: 22,007
Likes: 0
Received 6 Likes on 6 Posts
white and whiter
i just went to their site, but it's fine for me.
Old 04-29-2008, 04:55 PM
  #14  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Define "fine.
Fine as you aren't noticing anything unusual?
But still no way for to you know if it installed.
Thats the point of a rootkit. Invisible to you,
while it sends your personal data off to some former eastern block country.

Once installed according to the stuff I read it hides itself completely.
I got lucky before it could completely install.
It did actually create the files they mention.
Since the only thing I'd used recently in IE was the
epc site, it did actually contain my username and login.
Since I blocked IE via Zonealarm firewall, it couldn't complete what it wanted to do. (Which likely is compile all your data, credit cards, logins etc and send off to whoever is on the receiving end)

I would recommend scanning your system with a rootkit scanner.
The IP address on the site seems to have changed, as I pinged it initially, it came up as one address, now it's showing as another, so perhaps they're on top of it.
In any case, I've blocked them in my hosts file so I can't accidentally go there.

Last edited by C230 Sport Coup; 04-29-2008 at 04:59 PM.
Old 04-29-2008, 05:03 PM
  #15  
MBworld Guru
 
FrankW's Avatar
 
Join Date: Apr 2002
Location: Diamond Bar, CA
Posts: 22,007
Likes: 0
Received 6 Likes on 6 Posts
white and whiter
i always have 3 AVP running. I would know if some thing's wrong with it.

if you have norton, I would suggest making the change. Kaspersky is much better.
Old 04-29-2008, 05:37 PM
  #16  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Hey that Noscript thing works really well.
Turns out the issue isn't on the exact pages he lists.
But if you dig deeper as I did, to look at W203 parts, thats where I got hit. adserv.cn is trying to load a script.

Thats when the trouble started for me. .cn is the domain suffix for China. I think they got hacked and someone put in some scripts to download to this site in china which is associated with Malware. http://malwaredomains.com/ So, not every page has the redirects to the download of this rootkit. Just checked and all if not most of the W203 parts the pages are infected.

Nice stuff they have though, now that I can safely check it out. AMG bumpers and such for $299 ! But alas nothing for the coupe.

Last edited by C230 Sport Coup; 04-29-2008 at 05:43 PM.
Old 04-29-2008, 05:52 PM
  #17  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Originally Posted by FrankW
i always have 3 AVP running. I would know if some thing's wrong with it.

if you have norton, I would suggest making the change. Kaspersky is much better.
I dare you to go to the W203 section and see if it catches it.
Well, no don't. But the noscript add on blocks it.
Just curious if Kaspersky see's it.
Old 04-29-2008, 06:45 PM
  #18  
MBWorld Fanatic!
 
Mu9enx's Avatar
 
Join Date: Aug 2007
Location: Sacramento/San Gabriel/Riverside
Posts: 3,560
Likes: 0
Received 2 Likes on 2 Posts
01' C32o
i've been on that site plenty of times, but it seems fine also. i also logged in with 2 different computers, and i know i'm protected. seems fine to me

but thanks for the heads up though, i'mma have to hella scan it now
Old 04-29-2008, 07:12 PM
  #19  
Super Member
 
UK-C200's Avatar
 
Join Date: Nov 2007
Location: London, GB
Posts: 529
Likes: 0
Received 0 Likes on 0 Posts
RHD C200 Sport Coupe, RHD SLK-55, LHD SLK-350
Originally Posted by Mu9enx
i've been on that site plenty of times, but it seems fine also. i also logged in with 2 different computers, and i know i'm protected. seems fine to me

but thanks for the heads up though, i'mma have to hella scan it now
Highly reccommend Spybot Search and Destroy - available here http://www.safer-networking.org/en/index.html
Old 04-29-2008, 07:42 PM
  #20  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Originally Posted by UK-C200
Highly reccommend Spybot Search and Destroy - available here http://www.safer-networking.org/en/index.html
Yes, good program.
But it didn't catch it.

Anyone who's already infected needs a rootkit scanner.
Old 04-30-2008, 11:26 AM
  #21  
Former Vendor of MBWorld
Thread Starter
 
Extreme Dimensions's Avatar
 
Join Date: Jan 2008
Location: Fullerton, CA
Posts: 957
Received 10 Likes on 10 Posts
Too Many To List
I want to apologize for everything that has happened with our site yesterday. Lucikly C230 Sport Coup gave me a call and alerted me as to what was going on with our site. My management has told me that someone has hacked our site, but everything should be fine now. If anyone finds anything else wrong at all, please let me know right away so that I can have it properly fixed. Thanks!
Old 04-30-2008, 12:11 PM
  #22  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
I updated S&D today, and noticed it had a 3 rootkit updates that loaded.
Well, too bad I wasn't up to date.I went from 1.5 to 1.52.
Rootkits are like the new thing to the security industry, but they've actually been around a long time. (back orifice for instance)
Also, immunized my system, which may very well block the connection to the offending server that was running the toxic scripts. But I added them to my hosts file so either way I can't be connected.

Well it was a learning experience for me, which I can likely apply in my job to the real world.
Just hate when it happens to me!

Thomas, just went to your site, and I do see at least in the W203 section, it no longer it trying to run scripts from the offending server (which I won't list here, as someone may inadvertently click on it).
Hopefully they got all the scripting removed from all the pages it was affecting, and your people took the time to check every page.

BTW, nice stuff. Too bad there's nothing for the coupe!

Last edited by C230 Sport Coup; 04-30-2008 at 12:18 PM.
Old 04-30-2008, 01:12 PM
  #23  
Moderator Alumni
 
TruTaing's Avatar
 
Join Date: Apr 2006
Location: Seattle
Posts: 3,255
Likes: 0
Received 20 Likes on 7 Posts
w203 m112
Originally Posted by UK-C200
Highly reccommend Spybot Search and Destroy - available here http://www.safer-networking.org/en/index.html
Spybot is best for its smaller application called "tea timer." It monitors registry changes and you can chose to allow them or not, but for whatever reason the last versions of spybot came w/ tea timer defaulted to being off and not even being installed.

Originally Posted by C230 Sport Coup
But it didn't catch it.
Sport Coup: if you had tea timer on, you would have probably been able to tell if the program was installing itself and not give it permission to make changes to your registry and to fully install itself.

edit: id also be a bit weary of DLing/installing programs that are suppose to get rid of malicious programs too... Often its just a ploy to get you to install more malicious software.

Last edited by TruTaing; 04-30-2008 at 01:17 PM.
Old 04-30-2008, 01:48 PM
  #24  
MBWorld Fanatic!
 
C230 Sport Coup's Avatar
 
Join Date: Jun 2002
Location: So. Oregon Coast
Posts: 6,912
Received 122 Likes on 112 Posts
C230 Sport Coup + 2006 W164 ML350 + 99 Ford Escort (What the heck, it gets 38 mpg!)
Yes, actually it was Tea Timer that tipped me off.
It was asking if some Usrpromt thing could be changed.
Turned out, it was NAV trying to tell me I had a virus.
I disallowed it, yanked my network card, and then went into the
SD to see what I'd disallowed.
It showed that NAV was trying to alert me to files in a folder
called c:\doc_settings\all users\ _qbothome

A quick search on the name of the directory was what alerted me I'd been hosed.
I run Zone Alarm free, and it also popped up and IE wanted access to the internet. But I wasn't using IE. (I have it set to ASK for IE, just in situations like this) I use Firefox, and for good reason.
Saved my butt yesterday.

I noticed a process running I didn't recognize (since I pretty much know whats supposed to be running on my system), it was one related to one of the files in the _qbothome. (Which I determined using process explorer)

I killed that, then was able to delete the _qbothome folder.
I did a search on anything with Qbot in it, and found some stuff in the prefetch folder, and deleted that too.
Once that process was shut down, I was able to kill IE, which previously would not end, or would just restart instantly.

One of the links mentioned some registry keys, but I wasn't effected since it never fully installed, since I didn't allow it access to the internet.
Still , I'm amazed the way it deftly downloaded the files and folder to my system and ran the program all in about 5 seconds.
According to what I read,
If it had installed it would have made itself invisible, and attached itself to the windows UI (part of making itself invisible), and you'd have to use a windows CD to boot to a command prompt to delete the files.
NASTY STUFF!!!!! I wonder how many people now have a backdoor into their system transmitting credit cards, SS #'s, and whatever else off to some internet crook because of this.

Originally Posted by TruTaing
Spybot is best for its smaller application called "tea timer." It monitors registry changes and you can chose to allow them or not, but for whatever reason the last versions of spybot came w/ tea timer defaulted to being off and not even being installed.

I took the advise and installed the noscript which then allowed me to see which script was the offending site.

I then did a search to find a reasonably up to date list of known malicious sites in the form of a hosts file.

I added all those sites to my hosts file, + the one that had the bad script
adserv dot cn.

I updated Spybot, which also added a large list of blacklisted sites via the
internet security settings, but the hosts file is the sure way to block, as I'm not sure if in using Firefox if it looks at the Internet security settings.

I'll go back and make sure tea timer is turned on!

And yes, often so called "programs that are suppose to get rid of malicious programs " can often be spyware.

Best to do a search before downloading, and read the EULA and privacy agreements well on something new and unknown.
When it says something about you agreeing to allow info to be sent back for the purposes of providing ad content, or "custom" content, just say no!

Sport Coup: if you had tea timer on, you would have probably been able to tell if the program was installing itself and not give it permission to make changes to your registry and to fully install itself.

edit: id also be a bit weary of DLing/installing programs that are suppose to get rid of malicious programs too... Often its just a ploy to get you to install more malicious software.

Last edited by C230 Sport Coup; 04-30-2008 at 01:57 PM.

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 


You have already rated this thread Rating: Thread Rating: 1 votes, 1.00 average.

Quick Reply: Free Body Kit Giveaway!



All times are GMT -4. The time now is 07:43 AM.