Help - Search - Members - Calendar
Full Version: Same Old Same Old
Malwarebytes Forum > Research Center > Newest Rogue Threats
Matthew P
I haven't time to do any test or look to much but it seems to be the same as the rest. One a normal site (Fpsbanana.com) I was BANNER HIJACKED on a test pc accidentally. I was actually going to do something else but this happened. The test pc was 100% Clean not touched and I am sure it was a banner exploit and it was the second time this week on different PC's and different sites that it happened. Have Rouge Virus's Hit an all time high?




I plan one testing it later I assume its no different.

Will post when I get more info. Sorry.
Matthew P
Almost forgot their new domain is W W W (DOT) antimalwareproonlinescanv3 (DOT) C O M
MysteryFCM
Just posted a blog about this one a few minutes ago;

http://hphosts.blogspot.com/2009/06/roguer...gle-we-can.html
Matthew P
QUOTE (MysteryFCM @ Jun 8 2009, 02:02 AM) *
Just posted a blog about this one a few minutes ago;

http://hphosts.blogspot.com/2009/06/roguer...gle-we-can.html

Oh sorry I didn't know it was already posted. I haven't been keeping up with this stuff lately.

Also its personalantivirus Clone or w/e so it says on there contact page.
I hope my post wasn't a waste Sorry sad.gif

PS: I've used Malwarebytes for quite a while but never took the time to join the forum .... errm how do I edit my post? Unlike most forums I can't find the button ha sorry.
MysteryFCM
No apologies necessary wink.gif (I'd not posted it to the MBAM forums yet anyway, just my blog, so definately not a wasted posted wink.gif ).

I don't believe regular members can edit their posts here.
sho-dan
Hello
50+ posts is the magic number for the "Edit" button to appear . smile.gif
MysteryFCM
So that's why I see it! <g>
Matthew P
Well I guess that my Que to start posting! laugh.gif
Matthew P
I'd edit my post instead of double posting (which I hate) but I can't laugh.gif

Moving on the banner Hijacking Ad I believe came from clearbridge.org however many of there ads serve threw third parts from there. Such as tribalfusion, adbureau.net, and clicksor (Likely the bad one)

Clicksor was the Same one that I think got me on another site so It may have been threw them.

Also I find alot of these Rouge sites are hijacking entire sites such as one site that was a coffee shop site but on one of its pages was a whole page hosting the virus.It went something like EX :www.example.com/wp-post3813$#*DeathsonTvShowHouse

WP-Post Maybe it was hijacking WordPress. I dunno.

Regardless I told the owners of the site because there front page was find and one of the two sites that I found like that fixed the issue.

Any one else come across entire website hijacking's lately?
Matthew P
QUOTE (MysteryFCM @ Jun 8 2009, 07:30 PM) *

ohmy.gif Ouch Thats unfortunate, I here .edu sites use to get hijacked alot as well.
Matthew P
I wonder if the next domain will be AntiVirusproonlinescanv4.

Since est Domains has less bad activity since there recent err w/e you call it. Closure type thing. Who's the main hoster now?
TODAYNIC.COM Hosted this one.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.