<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: winxp-antivir-on-line-scan in Security</title>
<link>http://www.dslreports.com/forum/r21074091</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 06:04:02 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 06:04:02 EDT</lastBuildDate>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21092311</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : Happy digging kuk ;)<br><br>-Brian]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21092311</guid>
<pubDate>Thu, 11 Sep 2008 06:42:46 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21088590</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks for the reply & link at CastleCops.  Seems like this is the same discussion.  I'll see what I can dig up from the hosted website based on the Dave Taylor article linked above.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21088590</guid>
<pubDate>Wed, 10 Sep 2008 14:42:20 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21087067</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : I would have .. but don't have an account set up there and don't really want to set one up.  Too many things to keep track of.  :(  <br><br>I tried posting as a guest, but couldn't get past the squiggly letters.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21087067</guid>
<pubDate>Wed, 10 Sep 2008 10:05:13 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21087050</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : <div class="bquote"><small>said by  katarina <A HREF="/useremail/u/870884"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Here's what appears to be another of the same type thing at Castle Cops. <br><br>&raquo;<A HREF="http://www.castlecops.com/p1111767-Antispyware_XP_Pro_Malware_redirect_from_Google_Search.html" >www.castlecops.com/p1111767-Anti&middot;&middot;&middot;rch.html</A><br> </div>Gave them a nudge in the right direction ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21087050</guid>
<pubDate>Wed, 10 Sep 2008 10:02:10 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21087003</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : Here's what appears to be another of the same type thing at Castle Cops. <br><br>&raquo;<A HREF="http://www.castlecops.com/p1111767-Antispyware_XP_Pro_Malware_redirect_from_Google_Search.html" >www.castlecops.com/p1111767-Anti&middot;&middot;&middot;rch.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21087003</guid>
<pubDate>Wed, 10 Sep 2008 09:51:52 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21080443</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : <div class="bquote"><small>said by papafz :</small><br><br>hey there... i am getting this on one of my client's sites.  Going nuts trying to figure it out, but all of your observations about are exactly the same as mine (except i didnt get as far as u did in figuring out what caused it).<br><br>try searching for 'Kenny Meez'<br><br>If I go directly to KennyMeez.com i do not get the popup.. if i go from a Google result, i do but usually only the first time.<br><br>any help would be greatly appreciated.<br> </div>&raquo;<A HREF="http://www.google.com/search?hl=en&q=%2Fin.html%3Fs%3Dipw2&aq=f&oq=" >www.google.com/search?hl=en&q=%2&middot;&middot;&middot;aq=f&oq=</A><br><br>(thats a google link for the /in blahblah that the exploit uses) the first link is macafee site advisor, the second is this thread, the next are ways to fix it<br><br>happy hunting ;)<br><br>-Brian]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21080443</guid>
<pubDate>Tue, 09 Sep 2008 06:03:10 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21080074</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Thanks - while I knew from previous exploits that the problem is on the server, I didn't know specifically how these things work.<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21080074</guid>
<pubDate>Tue, 09 Sep 2008 01:26:07 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21079732</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Another light bulb just went on ... <br><br>The exploit only working 1 time, & clearing the cache ...<br><br>The exploit only works 1 time so long as you HAVE visited the legitimate site after the initial attempt.  The reason is because the legit site is now in your cache & that is what loads on subsequent visits to the site.<br><br>The exploit will work multiple consecutive times if you HAVE NOT visited the legitimate site.<br><br>So if you go to Google, click their link to KennyMeez, you get malware.  Click the Google link again & again, & each time you still get malware.  After 1024 clicks on the Google link, if you then go directly to KennyMeez.com, the Google link will work correctly, because at that point you are actually loading the legit site from your browser /cache/.<br><br>As Kayrac's post pointed out the referrer it is looking for is of type *msn.*, but it looks to be even more general, *msn* (no dot needed).  So setting the referrer as h ttp://abc123msnabc123/ also triggers the malware site to load.<br><br>("Legit site".  I'm kind of saying it wrong.  The site is & has been "legit".  The Google link is "legit".  It is just that there exists an exploit on the sites' server, a server-side exploit, that causes the malware page to load when specific referrers are found.)<br><br>EDIT:  Oops, I misread the regular expression. <b>.*msn.*</b> will trigger on any (referrer) URL that has the chars <b>msn</b> in it.  (At first I disregarded the opening .* & then mistook the closing .* to mean literally msn(dot)* - I was thinking the Windows way :uhh:.<br><br>And I might also say I know nothing of Apache servers or server scripts or ... so what I'm saying while very likely not totally accurate, is accurate in principle.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21079732</guid>
<pubDate>Mon, 08 Sep 2008 23:50:46 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21079553</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : It looks like the same exploit. Clearing the cache usually lets you connect a second time.<br><br>Contact the server which hosts the site.<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21079553</guid>
<pubDate>Mon, 08 Sep 2008 23:22:31 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21079477</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : hey there... i am getting this on one of my client's sites.  Going nuts trying to figure it out, but all of your observations about are exactly the same as mine (except i didnt get as far as u did in figuring out what caused it).<br><br>try searching for 'Kenny Meez'<br><br>If I go directly to KennyMeez.com i do not get the popup.. if i go from a Google result, i do but usually only the first time.<br><br>any help would be greatly appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21079477</guid>
<pubDate>Mon, 08 Sep 2008 23:11:16 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21079117</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : So it is a server side exploit.<br><br>That makes a whole lot more sense to me compared the the 302.  Not to mention it was far easier to read ;-).<br><br>So Google is not hacked, the web page itself is not hacked, it is the server that has been hacked.<br><br>But the 302 is still relevant I suppose (not that I know what 200's or 302's are or mean).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21079117</guid>
<pubDate>Mon, 08 Sep 2008 22:06:34 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21079072</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : At first I was going to say "explain more, what?".<br><br>I guess I could have explained more.  I think I tried, but OFTEN the workings of this forum confuse me.<br><br>Anyhow, originally I was just going to describe the screenshots saying that they confirm what has been posted so far.<br><br>Further to that, & to explain a bit more ... I cleared my cache, & loaded davies directly - the 1st shot.<br><br>Note Data size: 9563, the size of the cached html file.  And the response, 200 OK.<br><br>Cleared my cache again, but this time loaded davies, & also spoofed the referrer as msn.com - the 2nd shot.<br><br>This time Data size: 0, & the response, 302 Found.  Not to mention the Location:.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21079072</guid>
<pubDate>Mon, 08 Sep 2008 21:59:38 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21076896</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Said by mysec:<br>"Another thing - why doesn't the last URL 66.232.126.192 appear in that code?"<br><br>This might help explain it...<br>&raquo;<A HREF="http://www.robtex.com/ip/66.232.126.192.html#a4" >www.robtex.com/ip/66.232.126.192.html#a4</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21076896</guid>
<pubDate>Mon, 08 Sep 2008 15:06:57 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21075577</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  Kayrac <A HREF="/useremail/u/485678"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Basically looks like they change a few things on their server(after breaking in) so it changes over to the malicious website when visiting from a search engine referrer, no malicious content is on davieshardware page</div><br>This is what turned up in the 2007 SloanTreeFarm Redirect exploit I posted earlier. Their page was clean, but the server which hosted them had been compromised.<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21075577</guid>
<pubDate>Mon, 08 Sep 2008 10:53:51 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074789</link>
<description><![CDATA[<A HREF="/useremail/u/485678"><b>Kayrac</b></A> : I posted this over on another forum, MDL<br><br>within 5 minutes i had my answer :)<br><br>&raquo;<A HREF="http://www.askdavetaylor.com/how_people_hack_apache_web_server_rewrite_rules.html" >www.askdavetaylor.com/how_people&middot;&middot;&middot;les.html</A><br><br>credits to sowhat-x and sysadmini ;)<br><br>-Brian<br><br>Basically looks like they change a few things on their server(after breaking in) so it changes over to the malicious website when visiting from a search engine referrer, no malicious content is on davieshardware page<br><br>I couldn't figure it out myself, had to call in the professionals :P]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074789</guid>
<pubDate>Mon, 08 Sep 2008 07:32:23 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074636</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : Thank you all for checking this out.  It's fascinating to watch the discussion, but much of it is way over my head.<br><br>All I know is that when I run into this stuff I do not click on anything and use task manager to end any running applications.<br><br>It is nice to have confirmed that it is not downloading without those "clicks."]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074636</guid>
<pubDate>Mon, 08 Sep 2008 05:10:02 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074384</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : The second and fourth jpg's show the 'GET' command, and I'd hazard that's where the breach happened. One and three hit the actual page.<br><br>FYI - It looks like jpg 2 shows a different response-head that may well point to the actual target in jpg 4.<br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074384</guid>
<pubDate>Mon, 08 Sep 2008 01:28:45 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074375</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Can you explain more?<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074375</guid>
<pubDate>Mon, 08 Sep 2008 01:24:48 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074364</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Two shots, one direct, one spoofed.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21074364?c=1347599&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="5597 bytes" BORDER=0 WIDTH=494 HEIGHT=389 SRC="/r0/download/1347599~6cb13911d13a066aca7dc85c9914ec21/davies1.png"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21074364?c=1347600&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="5315 bytes" BORDER=0 WIDTH=505 HEIGHT=326 SRC="/r0/download/1347600~ee86b6dfd447c2b5b69e9b35594200a3/davies2.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074364</guid>
<pubDate>Mon, 08 Sep 2008 01:21:09 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074361</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> Another thing - why doesn't the last URL 66.232.126.192 appear in that code? </div>Maybe why? It looks like it self-refers to the doc (page) in question...maybe?<br><br><A HREF="images/pre_load.cssrel=stylesheettype=text/css">   <br> <b> if(self.parent.frames.length!=0){self.parent.location=document.location}<br><br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074361</guid>
<pubDate>Mon, 08 Sep 2008 01:19:08 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074341</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : Thanks -- very clever in covering tracks, don't you think?<br><br>Another thing - why doesn't the last URL 66.232.126.192 appear in that code?<br><br><br>---]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074341</guid>
<pubDate>Mon, 08 Sep 2008 01:09:40 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074316</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> Now, can someone explain how these images are loaded onto my browser screen and there is no html file cached? </div> It may be here in the code: <br>HTTP/1.x 200 OK<br>Date: Mon, 08 Sep 2008 03:46:27 GMT<br>Server: Apache/1.3.41 (Unix) PHP/5.2.6<br>X-Powered-By: PHP/5.2.6<br>Expires: Thu, 19 Nov 1981 08:52:00 GMT<br><b>Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 </b><br>Pragma: no-cache<br>Connection: close<br>Transfer-Encoding: chunked<br>Content-Type: text/html<br>----------------------------------------------------------<br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074316</guid>
<pubDate>Mon, 08 Sep 2008 01:01:34 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074295</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Maybe someone can make sense of this.<br>And as I thought, you are going to davies, but then sent to malware site. </div><br> Yes, just like the old Google exploit. Here are the firewall alerts:<br><br>First, to google search:<br><br>[att=1]<br><br>Then clicking on the link to davieshardware.com:<br><br><textarea name="code" class="text" cols=50 rows=10>C:\&gt;nslookup davieshardware.com&#012;Name:    davieshardware&#012;Address:  66.96.132.39&#012;</textarea><!--end code block--><br>[att=2]<br><br>Then a page 302 error redirects to the site that calls out for the WinAntiVir files. From <b>therube's</b> code:<br><br>hxxp://87.248.180.90/in.html?s=ipw2<br><br>[att=3]<br><br>WhoIS:<br><br><textarea name="code" class="text" cols=50 rows=10>inetnum: 87.248.176.0 - 87.248.191.255&#012;netname: STARNETMD&#012;descr: SC STARNET SRL&#012;descr: Chisinau, Moldova&#012;country: MD&#012;admin-c: SA4929-RIPE&#012;tech-c: SA4929-RIPE&#012;status: ASSIGNED PA&#012;remarks: INFRA-AW&#012;remarks: Leased for Users&#012;mnt-by: MNT-STARNETMD&#012;source: RIPE # Filtered&#012; &#012;role: StarNet Administrator&#012;remarks:&#012;address: SC "STARNET" SRL&#012;address: 55, Maria Cibotari str.&#012;address: MD2012 Chisinau&#012;address: Moldova, Republic of&#012;</textarea><!--end code block--><br><div class="bquote"><small>said by  Its a Secret <A HREF="/useremail/u/1531837"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>It looks to me like the referrer link has been encrypted/ scrambled so you can't see where it's pointed to. I may be wrong, but I don't think so.</div>Probably - I don't see a URL in <b>therube's</b> code but the firewall shows:<br><br>[att=4] <br><br>WhoIS:<br><br><textarea name="code" class="text" cols=50 rows=10>NetRange: 66.232.96.0 - 66.232.127.255&#012;CIDR: 66.232.96.0/19&#012;NetName: NOC4HOSTS1&#012;NetHandle: NET-66-232-96-0-1&#012;Parent: NET-66-0-0-0-0&#012;NetType: Direct Allocation&#012;NameServer: NS.NOC4HOSTS.COM&#012;NameServer: NS2.NOC4HOSTS.COM&#012;Comment:&#012;RegDate: 2005-10-21&#012;Updated: 2006-06-27&#012; &#012;RAbuseHandle: NAA7-ARIN&#012;RAbuseName: Noc4Hosts Abuse Admin&#012;RAbusePhone: +1-877-801-1443&#012;RAbuseEmail: abuse@noc4hosts.com&#012;</textarea><!--end code block--><br>Not much info - can someone else search for this?<br><br>Now we are at the cleverest part of the exploit because no html page is cached in IE. (I cannot get the exploit to run in Opera).<br><br>Only the .gif files and the .js files are cached which do the work:<br><br>[att=5]<br><br>If you look at the screen after everything is loaded, it is a series of .gif files but no html file and no source code.<br><br>But if I load directly into the browser:<br><br>hxxp://87.248.180.90/in.html?s=ipw2<br><br>I get the the html file and can watch the code loading everything (thanks <b> therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></b> for getting that URL):<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;&lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" &#012;&lt;html&gt;&#012;&lt;head&gt;&#012;&lt;meta http-equiv="Content-Type" content="text/html; charset=iso-8859-2"&gt;&lt;title&gt;Windows Antivirus&lt;/title&gt;&#012;&lt;script&gt;var mw_texts = new Array();&lt;/script&gt;&#012;&lt;script&gt;var install_link = 'http://soft-upgrade-network.com/antivirus.v.1.0.20586.exe';&lt;/script&gt;&#012;&lt;script language="javascript" src="images/brand_co.js"&gt;&lt;/script&gt;&#012;&lt;script language="javascript" src="images/mouse_te.js"&gt;&lt;/script&gt;&#012;&lt;link href="images/pre_load.css" rel="stylesheet" type="text/css"&gt;&#012; &lt;script language=javascript&gt;if(self.parent.frames.length!=0){self.parent.location=document.location}&lt;/script&gt;&lt;script language=javascript&gt;window.moveTo(0, 0); window.resizeTo(screen.availWidth, screen.availHeight);&lt;/script&gt; &lt;link href="images/window00.css" rel="stylesheet" type="text/css"&gt;&#012;&lt;link href="images/this_lan.css" rel="stylesheet" type="text/css"&gt;&#012;&lt;link href="images/translat.css" rel="stylesheet" type="text/css"&gt;&#012;&lt;/head&gt;&#012;&lt;body&gt;&#012; &#012;&lt;div id="preloader"&gt;&lt;/div&gt;&#012;&lt;script language="javascript" src="images/mouse_bl.js"&gt;&lt;/script&gt;&#012;&lt;div class="mw_final_win" id="mw_results_window"&gt;&#012;&lt;a class="mw_final_res" href="javascript:install_begun();"&gt;&lt;/a&gt;&#012;&lt;/div&gt;&#012; &#012;&lt;div class="mw_window" id="mw_main_win"&gt;&#012;&lt;div class="mw_win_body"&gt;&#012;&lt;!--plaz--&gt;&#012;&lt;div class="mw_window_plaz"&gt;&#012; &#012;&lt;div class="mw_search_left_panel"&gt;&#012;&lt;a href="javascript:install_begun();" class="mw_security_panel"&gt;&lt;/a&gt;&#012;&lt;/div&gt;&#012;&lt;!-- dfsdfsdfsdfsdfsdfsdf dsf sdf sdf sdf sdfd --&gt;&#012; &#012;&lt;div class="mw_window_body"&gt;&#012; &#012;&lt;div id="mw_disk_c" class="mw_wi_disk mw_hd_disk"&gt;&lt;span class="mw_name"&gt;&lt;span class="local_c"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="mw_err_1" class="mw_error"&gt;&lt;span class="hardw_error"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;div id="mw_disk_d" class="mw_wi_disk mw_hd_disk"&gt;&lt;span class="mw_name"&gt;&lt;span class="local_d"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="mw_err_2" class="mw_error"&gt;&lt;span class="hardw_error"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;div id="mw_disk_dvd" class="mw_wi_disk mw_dvd_disk"&gt;&lt;span class="mw_name"&gt;&lt;span class="local_dvd"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;div id="mw_disk_fldr" class="mw_wi_disk mw_folder_disk"&gt;&lt;span class="mw_name"&gt;&lt;span class="shared"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="mw_err_3" class="mw_error"&gt;&lt;span class="sec_thr"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&#012; &#012;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;hr color="#CCCCCC" size="1"&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;hr color="#CCCCCC" size="1"&gt;&#012; &#012;&lt;div class="mw_disclaimer"&gt;&lt;span class="secr_thr_fndd"&gt;&lt;/span&gt;&lt;/div&gt;&#012; &#012;&lt;div class="mw_progress_bar"&gt;&#012;&lt;span class="mw_status" id="mw_status"&gt;&lt;/span&gt;&#012;&lt;div class="pb_decor"&gt;&lt;div class="decor_lp"&gt;&lt;/div&gt;&lt;div class="decor_rp"&gt;&lt;/div&gt;&lt;div id="mw_progress_bar"&gt;&lt;/div&gt;&lt;/div&gt;&#012;&lt;A id="mw_cncl_but" class="mw_cancel" href="javascript:install_begun();"&gt;&lt;/A&gt;&#012;                                &lt;div id="simulation_1"&gt;&lt;span class="simulation_qts"&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;/div&gt;&lt;!-- dfsdfsdfsdfsdfsdfsdf dsf sdf sdf sdf sdfd --&gt;&#012;&lt;div class="mw_display_filename"&gt;&#012;&lt;span class="mw_status"&gt;&lt;span class="object"&gt;&lt;/span&gt;&lt;/span&gt;&#012;&lt;span class="mw_filename" id="mw_file_name"&gt;&lt;/span&gt;&#012;&lt;/div&gt;&#012; &#012;&lt;div class="mw_test_results" id="mw_inwin_results"&gt;&lt;div class="mw_test_rez_decor"&gt;&lt;div class="mw_res_rtc"&gt;&lt;/div&gt;&#012;&lt;div class="mw_header_f_res"&gt;&lt;span class="hrdw_n_sec"&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;a class="mw_remove_button" href="http://soft-upgrade-network.com/antivirus.v.1.0.20586.exe"&gt;&lt;/a&gt;&#012;&lt;div class="mw_res_pads"&gt;&#012;&lt;span class="mw_res_hdr"&gt;&lt;span class="hrdw_errors"&gt;&lt;/span&gt;&lt;/span&gt;&#012;&lt;div class="mw_res_text"&gt;&lt;span class="perfomance_usw"&gt;&lt;/span&gt;&lt;/div&gt;&#012;&lt;/div&gt;&lt;/div&gt;&#012; &#012;  &lt;/div&gt;&#012;&lt;/div&gt;&#012;&lt;!--//plaz--&gt;&#012;&lt;/div&gt;&#012; &#012;&lt;/div&gt;&#012;&lt;/body&gt;&#012;&lt;script language="javascript" src="images/unic_scr.js"&gt;&lt;/script&gt;&#012;&lt;script language="javascript" src="images/text_con.js"&gt;&lt;/script&gt;&#012;&lt;script language="javascript" src="images/file_nam.js"&gt;&lt;/script&gt;&#012;&lt;script language="javascript" src="images/domFunct.js"&gt;&lt;/script&gt;&#012;&lt;script language="javascript" src="images/startaft.js"&gt;&lt;/script&gt;&#012;&lt;/html&gt;&#012;</textarea><!--end code block--><br>Now, can someone explain how these images are loaded onto my browser screen and there is no html file cached?<br><br>---<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/21074295?c=1347590&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="10741 bytes" BORDER=0 WIDTH=384 HEIGHT=376 SRC="/r0/download/1347590~f23aaabfd93976c3c18305aee27ea52d/kerio-google.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/21074295?c=1347591&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="11204 bytes" BORDER=0 WIDTH=384 HEIGHT=376 SRC="/r0/download/1347591~4161ea5d7f91fafcd498abd6361f7188/kerio-daview.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/21074295?c=1347592&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="11148 bytes" BORDER=0 WIDTH=384 HEIGHT=376 SRC="/r0/download/1347592~b78674e1275d717de4ba103df4050965/kerio-87.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/21074295?c=1347593&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="10774 bytes" BORDER=0 WIDTH=384 HEIGHT=376 SRC="/r0/download/1347593~edc0f74909a482cb4037f29815fcd8a0/kerio-winantivir.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/21074295?c=1347594&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="12147 bytes" BORDER=0 WIDTH=225 HEIGHT=660 SRC="/r0/download/1347594~0da3038950298d1a7231efc460e93573/google-cache.gif"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width=1%>&nbsp;</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074295</guid>
<pubDate>Mon, 08 Sep 2008 00:54:46 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074258</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : &raquo;<A HREF="http://www.msn.com/" >www.msn.com/</A> works to.<br><br>So by using a spoofer, simply by setting the URL & the Referrer, I can get the malware site to load.<br><br><textarea name="code" class="text" cols=50 rows=10>http://www.davieshardware.com/sales.html&#012; &#012;GET /sales.html HTTP/1.1&#012;Host: www.davieshardware.com&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://www.msn.com/&#012; &#012;HTTP/1.x 302 Found&#012;Date: Mon, 08 Sep 2008 04:33:17 GMT&#012;Content-Type: text/html; charset=iso-8859-1&#012;Transfer-Encoding: chunked&#012;Connection: keep-alive&#012;Server: Apache&#012;Location: http://87.248.180.90/in.html?s=ipw2&#012;----------------------------------------------------------&#012;http://87.248.180.90/in.html?s=ipw2&#012; &#012;GET /in.html?s=ipw2 HTTP/1.1&#012;Host: 87.248.180.90&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://www.msn.com/&#012;Cookie: visited=16&#012; &#012;HTTP/1.x 302 Found&#012;Date: Mon, 08 Sep 2008 04:36:29 GMT&#012;Server: Apache/1.3.39 (Unix) PHP/5.2.5 with Suhosin-Patch&#012;X-Powered-By: PHP/5.2.5&#012;Set-Cookie: visited=17&#012;Location: http://winxp-antivir-on-line-scan.com/1/?id=20586&#012;Connection: close&#012;Transfer-Encoding: chunked&#012;Content-Type: text/html&#012;----------------------------------------------------------&#012;http://winxp-antivir-on-line-scan.com/1/?id=20586&#012; &#012;GET /1/?id=20586 HTTP/1.1&#012;Host: winxp-antivir-on-line-scan.com&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://www.msn.com/&#012;Cookie: PHPSESSID=9c61627a737dfb6c3e220bbf40bab6fd&#012; &#012;HTTP/1.x 200 OK&#012;Date: Mon, 08 Sep 2008 04:33:18 GMT&#012;Server: Apache/1.3.41 (Unix) PHP/5.2.6&#012;X-Powered-By: PHP/5.2.6&#012;Expires: Thu, 19 Nov 1981 08:52:00 GMT&#012;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&#012;Pragma: no-cache&#012;Connection: close&#012;Transfer-Encoding: chunked&#012;Content-Type: text/html&#012;----------------------------------------------------------&#012;</textarea><!--end code block--><br>I've tried a number of other "likely" search engines as the referrer (including www.live.com & ask.com) but only Google, Yahoo, & MSN seem to make it click.<br><br>Now, mysec's link mentions 302's & so do my captures, HTTP/1.x 302 Found.<br><br>Note that /cache/ or cookies may have an affect on what you see or don't see.  Like if a page is in /cache/ & I resend the spoof, I can't capture it again, until I clear /cache/.<br><br>(I see a "koma3504" to the left of this post.  Does anyone else?  What does it mean?)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074258</guid>
<pubDate>Mon, 08 Sep 2008 00:36:46 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074227</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Ok, looks like it is going to be related to the search engine?<br><br>I manually open up davies.<br>I click the Product Line link, the & product.html page opens.<br><br>I manually open up davies.<br>I manually change the URL line to read davies/product.html (but do not press return).<br>I spoof the referrer to, &raquo;<A HREF="http://search.yahoo.com/" >search.yahoo.com/</A>.<br>The malware page opens.<br><br>Note that many times, after first doing this, it is not repeatable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074227</guid>
<pubDate>Mon, 08 Sep 2008 00:26:55 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074164</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : I'm not finished reading it yet, but it appears that we should see discrepancy in the listed search engine (green) URL & the actual website URL?  But in this case, they are the same?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074164</guid>
<pubDate>Mon, 08 Sep 2008 00:08:29 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074138</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : It looks to me like the referrer link has been encrypted/ scrambled so you can't see where it's pointed to. I may be wrong, but I don't think so.<br><br>Opinions on this?<br><br>PS - I used to use code like this to protect my private js from being nicked.<br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074138</guid>
<pubDate>Sun, 07 Sep 2008 23:59:44 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074091</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Maybe someone can make sense of this.<br>And as I thought, you are going to davies, but then sent to malware site.<br><br><textarea name="code" class="text" cols=50 rows=10>http://rds.yahoo.com/_ylt=A0geu5T2n8RIhxEAKJpXNyoA;_ylu=X3oDMTEzajlma2luBHNlYwNzcgRwb3MDMQRjb2xvA2FjMgR2dGlkA0RGRDVfMTMx/SIG=11om9p0p8/EXP=1220931958/**http%3a//davieshardware.com/index.html&#012; &#012;GET /_ylt=A0geu5T2n8RIhxEAKJpXNyoA;_ylu=X3oDMTEzajlma2luBHNlYwNzcgRwb3MDMQRjb2xvA2FjMgR2dGlkA0RGRDVfMTMx/SIG=11om9p0p8/EXP=1220931958/**http%3a//davieshardware.com/index.html HTTP/1.1&#012;Host: rds.yahoo.com&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://search.yahoo.com/search;_ylt=A0geu71amcRIz.wAaKil87UF?p=davies+hardware&amp;ei=UTF-8&amp;iscqry=&amp;fr=sfp&#012;Cookie: YLS=v=1&amp;p=0&amp;n=0; PH=fn=CH7mzqunQWRt56e.Nok-&amp;l=en-US; F=a=FQCDrdkMvTBrQGXXM0sXdCxdtTo2GS1zxHOAgQ0iVrQdfd1lU8uLnIEVdHLqHVnXab27zp2dwYpdNC N0sAqdd3OfnA--&amp;b=SI_P; ystat_cn_bc=11752904991107379741; B=2ssp5cl42c4lq&amp;b=4&amp;d=4NxfvXtpYEIaqeg3pV90SL6ZhDEAMbmDu1skFFwlukNx&amp;s=uo; PL=V=1.1&amp;d=2Y7.G3_fGIM5CYSjL3dBf6R6Q3UtzuBBfSm2xL1IWjAGIbCD8puzvXyB1mPOdJdTrpiSpJM8wHh5ByFrsQ--; Y=v=1&amp;n=f17cvluv5g8j3&amp;l=i914diao/o&amp;p=m1s0kkdb53020600&amp;r=7d&amp;lg=en-US&amp;intl=us&amp;np=1; T=z=QvywIBQDa1IBrLo0BQURj1IMTUzBk42Nk8yNDE2MA--&amp;a=QAE&amp;sk=DAAwvKfseiuizp&amp;ks=EAAiPJHKS_djkTfz9k5BzjNZA--~A&amp;d=c2wBTmpJMEFUa3hNVGcxTXpZeE53LS0BYQFRQUUBZwFOTTZPN0lLQ0JPU0NJRlZaRTVMS0g2V0sySQF0 aXABaWxla01DAXp6AVF2eXdJQkE3RQ--&#012; &#012;HTTP/1.x 302 Found&#012;Date: Mon, 08 Sep 2008 03:46:24 GMT&#012;Cache-Control: private, max-age=0, no-cache&#012;P3P: policyref="http://p3p.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE GOV"&#012;Location: http://davieshardware.com/index.html&#012;Connection: close&#012;Content-Type: text/html; charset=utf-8&#012;----------------------------------------------------------&#012;http://davieshardware.com/index.html&#012; &#012;GET /index.html HTTP/1.1&#012;Host: davieshardware.com&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://search.yahoo.com/search;_ylt=A0geu71amcRIz.wAaKil87UF?p=davies+hardware&amp;ei=UTF-8&amp;iscqry=&amp;fr=sfp&#012; &#012;HTTP/1.x 302 Found&#012;Date: Mon, 08 Sep 2008 03:46:24 GMT&#012;Content-Type: text/html; charset=iso-8859-1&#012;Transfer-Encoding: chunked&#012;Connection: keep-alive&#012;Server: Apache&#012;Location: http://87.248.180.90/in.html?s=ipw2&#012;----------------------------------------------------------&#012;http://87.248.180.90/in.html?s=ipw2&#012; &#012;GET /in.html?s=ipw2 HTTP/1.1&#012;Host: 87.248.180.90&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://search.yahoo.com/search;_ylt=A0geu71amcRIz.wAaKil87UF?p=davies+hardware&amp;ei=UTF-8&amp;iscqry=&amp;fr=sfp&#012;Cookie: visited=3&#012; &#012;HTTP/1.x 302 Found&#012;Date: Mon, 08 Sep 2008 03:49:39 GMT&#012;Server: Apache/1.3.39 (Unix) PHP/5.2.5 with Suhosin-Patch&#012;X-Powered-By: PHP/5.2.5&#012;Set-Cookie: visited=4&#012;Location: http://winxp-antivir-on-line-scan.com/1/?id=20586&#012;Connection: close&#012;Transfer-Encoding: chunked&#012;Content-Type: text/html&#012;----------------------------------------------------------&#012;http://winxp-antivir-on-line-scan.com/1/?id=20586&#012; &#012;GET /1/?id=20586 HTTP/1.1&#012;Host: winxp-antivir-on-line-scan.com&#012;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 SeaMonkey/1.1.12&#012;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5&#012;Accept-Language: en-us,en;q=0.5&#012;Accept-Encoding: gzip,deflate&#012;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&#012;Keep-Alive: 300&#012;Connection: keep-alive&#012;Referer: http://search.yahoo.com/search;_ylt=A0geu71amcRIz.wAaKil87UF?p=davies+hardware&amp;ei=UTF-8&amp;iscqry=&amp;fr=sfp&#012;Cookie: PHPSESSID=9c61627a737dfb6c3e220bbf40bab6fd&#012; &#012;HTTP/1.x 200 OK&#012;Date: Mon, 08 Sep 2008 03:46:27 GMT&#012;Server: Apache/1.3.41 (Unix) PHP/5.2.6&#012;X-Powered-By: PHP/5.2.6&#012;Expires: Thu, 19 Nov 1981 08:52:00 GMT&#012;Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0&#012;Pragma: no-cache&#012;Connection: close&#012;Transfer-Encoding: chunked&#012;Content-Type: text/html&#012;----------------------------------------------------------&#012;</textarea><!--end code block-->]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074091</guid>
<pubDate>Sun, 07 Sep 2008 23:49:25 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074077</link>
<description><![CDATA[<A HREF="/useremail/u/1531837"><b>Its a Secret</b></A> : Was this from a 'sponsored' link, or a regular link? That may provide another clue...<br><small>--<br>"In the future, that which is not mandatory will be illegal"</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074077</guid>
<pubDate>Sun, 07 Sep 2008 23:45:55 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074063</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> </div><br>Yes, it can be exploited in other search engines. See<br><br>&raquo;<A HREF="http://clsc.net/research/google-302-page-hijack.htm" >clsc.net/research/google-302-page-hijack.htm</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074063</guid>
<pubDate>Sun, 07 Sep 2008 23:43:34 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074057</link>
<description><![CDATA[<A HREF="/useremail/u/1056836"><b>ravencajun</b></A> : you wanted the link to malwarebytes?<br><br>[Mod Note: Removed! No .exes! &raquo;<A HREF="/forum/18?rules=Rules%3F">Posting Rules - Security</A> ]<br><br>edit: Opps  I am so sorry I grabbed the direct link instead of the site link which is what I meant to post, was definitely a mistake on my part.  :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074057</guid>
<pubDate>Sun, 07 Sep 2008 23:42:08 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21074012</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Why?<br><br>It is not Google, cause you can get the same results if you perform the <A HREF="http://search.yahoo.com/search;_ylt=A0geu71amcRIz.wAaKil87UF?p=davies+hardware&ei=UTF-8&iscqry=&fr=sfp">search on Yahoo</a> & open the site from there.<br><br>So if it is not Google & not Yahoo, then what?<br><br>And why is it that (sometimes) only the first time you attempt it, you are redirected.<br><br>davies has to be hacked, doesn't it?<br>Perhaps from a "gif"?  Perhaps dealing with this line, <b>onLoad="MM_preloadImages('images/sales_off-over.gif', ...</b><br><br>There are also various "MM" functions, like, <b>function MM_preloadImages()</b>.  Their usage (in general, I don't know about on this site) appear legit.<br><br>That part of the code is run by JavaScript.<br><br>But you are redirected in SeaMonkey with NoScript blocking JavaScript, so that makes me believe it has something to do with the onLoad & a "gif"?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21074012</guid>
<pubDate>Sun, 07 Sep 2008 23:32:43 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21073671</link>
<description><![CDATA[<A HREF="/useremail/u/1502125"><b>Millenniumle</b></A> : If you load Davies Hardware directly, then use the Google link, Davies loads instead of the bogus site.<br><br>XP Pro IE6 SP3, scripts disabled.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073671</guid>
<pubDate>Sun, 07 Sep 2008 22:20:20 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21073647</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : AT least this exploit is not remote code execution, and brings up the File Download Box:<br><br>[att=1]<br><br><div class="bquote"><small>said by  katarina <A HREF="/useremail/u/870884"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Edit:  You have to actually click on the link from the Google Search results to make it happen.  If you type the address in the IE address bar, you arrive at the proper site. </div><br>This is reminiscent the Google Referer exploit from last summer. In that one, the exploit worked by remote code execution: no download prompt. See here for an analysis. <br><br>&raquo;<A HREF="http://www.urs2.net/rsj/computing/tests/redirect" >www.urs2.net/rsj/computing/tests/redirect</A><br><br>---<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21073647?c=1347563&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG TITLE="47457 bytes" BORDER=0 WIDTH=569 HEIGHT=673 SRC="/r0/download/1347563~1c2d231128ee97f2e2b83484afee0601/googlexp-winantivir.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073647</guid>
<pubDate>Sun, 07 Sep 2008 22:15:14 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21073467</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : <div class="bquote"><small>said by  Doctor Four <A HREF="/useremail/u/197199"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>... while using Firefox with NoScript will stop nearly all of them.<br><br>Just in case something does get installed, Malware Bytes<br>Anti Malware seems to do a good job at removing these. </div>I was looking at NoScript today.  I just haven't done it yet.  I was also looking for Malware Bytes but was looking for a link to a valid download site.  I'm always afraid that when I search with Google for security software that a copy cat site will lead me astray and I will land in the wrong place and download the wrong thing.  <br><br>edit:  for clarification]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073467</guid>
<pubDate>Sun, 07 Sep 2008 21:44:25 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21073239</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : Search for "davieshardware"<br><br>Hudson Valley Commercial Hardware - Davies HardwareSupplier of commercial, industrial architectural and residential hardware. Serving Dutchess and surrounding counties for over 100 years.<br>xxx.davieshardware.com/ - 10k - Cached - Similar pages<br><br>Edit:  You have to actually click on the link from the Google Search results to make it happen.  If you type the address in the IE address bar, you arrive at the proper site.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073239</guid>
<pubDate>Sun, 07 Sep 2008 21:06:04 EDT</pubDate>
</item>

<item>
<title>Re: winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21073203</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Not all AV software can detect fraudware site redirects, or<br>their install attempts. And the scan attempts are always<br>bogus, anyway. <br><br>And as long as you didn't click on anything, you're probably<br>OK. There was likely a hijacked ad on the search results, or<br>it could have been a spammed or fake blog that matched on <br>the search results. Best thing to do when one of these comes<br>up is to use the Task Manager to kill IE.<br><br>A hosts file will prevent many of these redirects, while<br>using Firefox with NoScript will stop nearly all of them.<br>Just in case something does get installed, Malware Bytes<br>Anti Malware seems to do a good job at removing these.<br><br>What site did you click on the Google search? If you could,<br>post the URL as hxxp...etc like the other one.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21073203</guid>
<pubDate>Sun, 07 Sep 2008 21:00:16 EDT</pubDate>
</item>

<item>
<title>winxp-antivir-on-line-scan</title>
<link>http://www.dslreports.com/forum/remark,21072962</link>
<description><![CDATA[<A HREF="/useremail/u/870884"><b>katarina</b></A> : Clicking on a Google search result took me to the following site instead of the expected site.  <br><br>hxxp://winxp-antivir-online-scan.com/1/?id=20586<br><br>There was not a peep from either Avast or Windows Defender.  I disconnected from the internet and ended the tasks from task manager.<br><br>Should there have been some type of notice from one or the other when it "appeared" that my system was being scanned?<br><br>XP Home SP2<br>IE 7<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/21072962?c=1347528&ret=L2ZvcnVtL3IyMTA3NDA5MS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="142574 bytes" WIDTH=600 HEIGHT=360 SRC="/r0/download/1347528.thumb600~4698d9eb63404d8e824c88324e83e7a5/winxp-antivir-on-line-scan.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21072962</guid>
<pubDate>Sun, 07 Sep 2008 20:10:33 EDT</pubDate>
</item>

</channel>
</rss>
