Czechpornostars.com

bugs, ideas, suggestions, complaints (Forum and EBI)

Moderators: robot, noproblemo

Czechpornostars.com

Postby Redeye on Mon Apr 13, 2009 4:06 pm

Clicked in the banner and NOD 32 found a virus.
Redeye
Legendary! Major Wynner
 
Posts: 1275
Joined: Tue Feb 10, 2009 9:38 am

Re: Czechpornostars.com

Postby paroxysmia on Mon Apr 13, 2009 4:23 pm

Which banner? Maybe a false-positive.
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Czechpornostars.com

Postby Redeye on Mon Apr 13, 2009 4:28 pm

Main page one, can be try yourself:)
Redeye
Legendary! Major Wynner
 
Posts: 1275
Joined: Tue Feb 10, 2009 9:38 am

Re: Czechpornostars.com

Postby paroxysmia on Mon Apr 13, 2009 4:46 pm

NOD32 is surely overparanoid, it's a false-positive.
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Czechpornostars.com

Postby sbando on Mon Apr 13, 2009 5:21 pm

I tested it, I'm pretty sure it's just some script they're using that is blocked as malicious. Anyway, it's not our problem. If someone comes up with evidence, I'll remove the benner.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT

Re: Czechpornostars.com

Postby hopless3 on Tue Apr 14, 2009 12:41 am

My Avira AV software said this

Virus: HEUR/HTML.Malware
Type: AHeAD Heuristic special detection
In the wild: No
Reported Infections: Low
Distribution Potential: Low
Damage Potential: Low
Static file: No
hopless3
board fly
 
Posts: 3859
Joined: Wed Jan 30, 2008 7:53 pm
Location: As long a the Police don't know I'm happy

Re: Czechpornostars.com

Postby paroxysmia on Tue Apr 14, 2009 1:58 am

It's heuristic so completely probabilist detection. Many heuristic viruses are false-positive because algorithms fail.
User avatar
paroxysmia
EBI's Illuminatus
 
Posts: 12579
Joined: Fri Aug 31, 2007 3:57 pm
Location: http://192.168.1.1/

Re: Czechpornostars.com

Postby just_me on Tue Apr 14, 2009 5:28 am

Their site was hacked. All of their pages contain an iframe pointing to a php script at an ip address belonging to a Seattle, WA school district.

In other words, it is not a false positive
User avatar
just_me
Legendary! Major Wynner
 
Posts: 1097
Joined: Fri Jul 11, 2008 3:27 am
Location: Chicago

Re: Czechpornostars.com

Postby sbando on Tue Apr 14, 2009 10:02 am

Ok, thank you, I'll remove it and drop them a line about it.
But it is in fact a form of hijacking, if you vjust clicked on the link nothing was installed.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT

Re: Czechpornostars.com

Postby just_me on Wed Apr 15, 2009 5:18 am

sbando wrote:Ok, thank you, I'll remove it and drop them a line about it.
But it is in fact a form of hijacking, if you vjust clicked on the link nothing was installed.

You should know better than that. :wink: When working properly, it bounces around and ends up launching a junk pdf file, without user interaction, into Adobe Reader from a server hosted in Russia. If the person is using an outdated version of Internet Explorer, Adobe Reader, or anti-virus software, you can bet something bad will be installed.

People out there are just finally learning to keep Windows & Internet Explorer updated, but they always neglect Java & Reader. So anyone who reads this, update your software :!:
User avatar
just_me
Legendary! Major Wynner
 
Posts: 1097
Joined: Fri Jul 11, 2008 3:27 am
Location: Chicago

Re: Czechpornostars.com

Postby sbando on Wed Apr 15, 2009 10:47 am

You're correct, it's hijacking, but the infection/fishing will eventually happen. in any case it's not a good thing. But it's not us, so I'll just remove it.
User avatar
sbando
Extinct
 
Posts: 9293
Joined: Tue Apr 10, 2007 8:25 pm
Location: Firenze, IT


Return to Mr. Fix it

Who is online

Users browsing this forum: No registered users and 2 guests