dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
10
share rss forum feed

kpatz
MY HEAD A SPLODE
Premium
join:2003-06-13
Manchester, NH
reply to moonpuppy

Re: foxnews.com infected?

I was playing around in the VM, emailing a friend of mine, and noting the crazy "warnings" that my cool new anti-virus has been warning me of.

Here's a couple:
quote:
Internet Explorers addon Shockwave Flash vs.3 found to be linking to the FormSpy website hosted at IP address 81.95.109.11 and installing FOrmSpy using an old VBS/Psyme exploit targeting Internet Explorer. These websites are believed to have been penetrated and modified by hackers. VBS/Psyme can be deleted proactively in Internet Explorer (IE). This is a detection for a malware that was discovered in the wild on July 24, 2009 (PST). Its installer was proactively detected as New Malware.ag (now Downloader-AXM). This addon tries to send your private information to attackers IP 72.95.109.11 (Malaysia)
So, they detect malware that won't be discovered for another 3+ months.
quote:
"Windows Meta File Vulnerability - Vulnerability"
"The vulnerability itself is regarded as extremely critical (the highest possible rating). As yet, there is no patch for this vulnerability. Exploit this vulnerability are Trojan-Downloaders, which install other Trojan programs on the victim machine. At the moment, Trojan programs are being downloaded from unionseek.com and iframeurl.biz. New modifications of these programs may appear".
I'll leave the VM running overnight and then see if it's harder to remove tomorrow.
--
To ISPs: Leave our ports alone! If I want ports blocked, I'll do it myself, thank you.


08034016
Hallo lisa Aus Amerika
Premium
join:2001-08-31
Byron, GA
said by kpatz:
Internet Explorers addon Shockwave Flash vs.3 found to be linking to the FormSpy website hosted at IP address 81.95.109.11 This addon tries to send your private information to attackers IP 72.95.109.11 (Malaysia)
quote:
IP address country: 81.95.109.11
IP address country flag Czech Republic
IP address state: Hlavni Mesto Praha
IP address city: Praha
quote:
IP address 72.95.109.11
IP country code: US
IP address country: flag United States
IP address state: Maine
IP address city: Orono
IP address latitude: 44.879101
IP address longitude: -68.733002
ISP of this IP [?]: Fairpoint Communications
Organization: Fairpoint Communications
--
Visit-
www.liveleak.com/view?i=e32_1231680425