Internet Explorer

Status
Not open for further replies.

anth0ny

Member
Dec 20, 2001
132
0
0
This is more or less a rant so I didn't post into the software forums. I used to think Internet Explorer was pretty secure. I had IE 7 and all XP patches applied.

Well yesterday I get a fake spyware program pop up on my desktop called Spyware Protect 2009. My browser was also hijacked with an addon called iehelper.exe. Well after some googling I find out that this has been getting installed by the Conficker virus. There were lots of news articles on Google just within the past week talking about how Conficker was installing the Weladec virus which then installs sysguard.exe which is the Spyware Protect 2009. The whole idea was to earn some money or credit info from the huge botnet they have control of.

I had no problem getting rid of this using Malwarebytes. I then download and installed Avira because my NOD32 subscription was up as of March 26th and no longer updated and it did not catch this or anything else I was describe next.

Well Avira finds C:\Documents and Settings\Ant\Local Settings\Temp\install[1].exe and a few other copies in other locations calling it 'TR/Crypt.ZPACK.Gen Trojan'. This is after getting rid of the sysguard.exe crap. So this is not the conficker virus but what a coincidence that it installs Spyware Protect 2009 around the same time as Conficker.

So where did this come from? I've been puzzled the past three days over this. Well today, like I sometimes do, I go to my main index page on my personal domain. There is nothing on there except a php hit counter and displays a simple number on the screen and nothing else. Well just this afternoon, I get popup from Avira saying my homepage had 'HTML/Crypted.Gen - Malware'.

I log into my ftp account and view the source code on the index.php page. It has a encrypted javascript code which is a 1x1 pixel iframe that redirects to http://bitsinfoware.net (which is 404 now). This was added after the last body & html tags of the page. Google comes up with almost nothing except a forum post about this domain redirecting to a php file and force installing an install.exe through IE. The trojan Avira found was install[1].exe. So this is how it got on my computer. It's all coming together now.

On my domain, I had a subdirectory with Wordpress installed. I bought a different domain for the $1.00 special from godaddy with the intention of starting a blog about fishing in Houston. I was just testing Wordpress out to see how well it worked. Well I guess I googled the address at work instead of typing it into the address bar. I guess google cached the page and it would come up deep in search results.

All I had on the page was the default 'Hello World' post. Well someone or possibly a trojan posted a message on the blog with a weird message.
It said"
Comment:
Yo!, please, help.
Why is molly maguire's ale house closed for business?

Thenks, bro. I am vaiting for answer!!! "
Wordpress automatically sends the admin an email asking to authorize the message for posting onto the blog. I clicked the admin link and it went to my page. The wordpress page was infected with the virus redirect as well. Damn, it got me. This is pretty damn elaborate. I guess someone took advantage of an exploit in Wordpress and manage to inject the malicious javascript into every php page on my domain. I could see them doing this and leaving it be but actually sending me a message to infect me as well... well damn. I need a drink while I install Windows 7 and firefox.

/end paranoid rant
 

anth0ny

Member
Dec 20, 2001
132
0
0
cliffs: haxored by my own domain =(

Also, if you have wordpress, check the source code of your pages.
 

Nik

Lifer
Jun 5, 2006
16,101
2
56
Originally posted by: clamum
tl;dr

IE security blows, amirite?

No but close! His point (well made) is that most IE users are retards and end up screwing themselves over.

 
Status
Not open for further replies.
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |