Author Topic: virus website  (Read 2649 times)

0 Members and 2 Guests are viewing this topic.

trinket

  • Guest
virus website
« on: June 26, 2009, 06:00:01 AM »
This is that computer lethal website I was talking about. It supposedly was to contain some sort of interview information on Korean celebrities and their ridiculous affinity towards plastic surgery (yes the topic is ludicrous, but that's not the point), but was instead loaded with disgusting, disdainful pictures and of course, viruses.

And, being the complete computer git that I am, I accidentally re-clicked the link while trying to copy the link location (my touchpad is very sensitive) -_-.... so of course, I have been reinfected with the malware...oh what joy.

  hxxp://imtsinghua.com.cn/2008/04/10/peekaboo/

(I should have realized the "peekaboo" part sounded highly suspicious to the point that it seemed almost promiscuous.. how silly of me x_x)

I'm hoping Avast adds this to their list, so naive people like me are more careful.



Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: virus website
« Reply #1 on: June 26, 2009, 12:36:45 PM »
-= There seems to be weird inline script..

function setCookie(name, value, expire) {
window.document.cookie = name + "=" + escape(value) + ((e...

-= Some sort of infection..
« Last Edit: June 26, 2009, 12:38:40 PM by -= Fenrir =- »
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: virus website
« Reply #2 on: June 26, 2009, 09:12:02 PM »
Hi -= Fenrir =- ,

This is the infection: Sign of "HTML:Agent-L [Expl]" has been found there.
Clean out your temp files using ATF Cleaner: http://www.atribune.org/ccount/click.php?id=1

Download then run JavaRa and have it remove all old Sun Java installations:
http://raproducts.org

You can get the latest Sun Java JRE here:
http://www.java.com/en/download/manual.jsp

Then run Secunia: Online Software Inspector to detect insecure versions installed:
http://secunia.com/software_inspector

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!