Page 1 of 1

Czechpornostars.com

PostPosted: Mon Apr 13, 2009 4:06 pm
by Redeye
Clicked in the banner and NOD 32 found a virus.

Re: Czechpornostars.com

PostPosted: Mon Apr 13, 2009 4:23 pm
by paroxysmia
Which banner? Maybe a false-positive.

Re: Czechpornostars.com

PostPosted: Mon Apr 13, 2009 4:28 pm
by Redeye
Main page one, can be try yourself:)

Re: Czechpornostars.com

PostPosted: Mon Apr 13, 2009 4:46 pm
by paroxysmia
NOD32 is surely overparanoid, it's a false-positive.

Re: Czechpornostars.com

PostPosted: Mon Apr 13, 2009 5:21 pm
by sbando
I tested it, I'm pretty sure it's just some script they're using that is blocked as malicious. Anyway, it's not our problem. If someone comes up with evidence, I'll remove the benner.

Re: Czechpornostars.com

PostPosted: Tue Apr 14, 2009 12:41 am
by hopless3
My Avira AV software said this

Virus: HEUR/HTML.Malware
Type: AHeAD Heuristic special detection
In the wild: No
Reported Infections: Low
Distribution Potential: Low
Damage Potential: Low
Static file: No

Re: Czechpornostars.com

PostPosted: Tue Apr 14, 2009 1:58 am
by paroxysmia
It's heuristic so completely probabilist detection. Many heuristic viruses are false-positive because algorithms fail.

Re: Czechpornostars.com

PostPosted: Tue Apr 14, 2009 5:28 am
by just_me
Their site was hacked. All of their pages contain an iframe pointing to a php script at an ip address belonging to a Seattle, WA school district.

In other words, it is not a false positive

Re: Czechpornostars.com

PostPosted: Tue Apr 14, 2009 10:02 am
by sbando
Ok, thank you, I'll remove it and drop them a line about it.
But it is in fact a form of hijacking, if you vjust clicked on the link nothing was installed.

Re: Czechpornostars.com

PostPosted: Wed Apr 15, 2009 5:18 am
by just_me
sbando wrote:Ok, thank you, I'll remove it and drop them a line about it.
But it is in fact a form of hijacking, if you vjust clicked on the link nothing was installed.

You should know better than that. :wink: When working properly, it bounces around and ends up launching a junk pdf file, without user interaction, into Adobe Reader from a server hosted in Russia. If the person is using an outdated version of Internet Explorer, Adobe Reader, or anti-virus software, you can bet something bad will be installed.

People out there are just finally learning to keep Windows & Internet Explorer updated, but they always neglect Java & Reader. So anyone who reads this, update your software :!:

Re: Czechpornostars.com

PostPosted: Wed Apr 15, 2009 10:47 am
by sbando
You're correct, it's hijacking, but the infection/fishing will eventually happen. in any case it's not a good thing. But it's not us, so I'll just remove it.