Drudgereport Putting Trojans out???

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Greg B
    So Fucking Banned
    • Jul 2001
    • 7014

    #1

    Drudgereport Putting Trojans out???

    Yo, I went to www.drudgereport.com and a trojan warning popped up!

    WTF? Here's a screencap.

    This happen to anybody else?
  • Harmon
    ( ͡ʘ╭͜ʖ╮͡ʘ)
    • Mar 2004
    • 20013

    #2
    Gertting nothing in IE. May want to dump the AOL browser sparky
    [email protected]

    Comment

    • bringer
      i have man boobies
      • Jul 2003
      • 13082

      #3
      nothing here either on both comps
      norton on 1 and mcafee on the other
      333-765-551

      Comment

      • AlienQ - BANNED FOR LIFE
        best designer on GFY
        • Mar 2003
        • 30307

        #4
        Ironic photo caption and headline.

        Comment

        • Twe Russ
          Confirmed User
          • Jan 2003
          • 3493

          #5
          Prolly spyware. ;)

          Contact information - ICQ: 7.9.0.3.0.0 · AIM: no roach · E-Mail: roachito || @ || gmail || . || com
          [Friend Finder - Geo Targeting & Incredible Site Ratio] - [Credit Card Traffic - Make $65 Per Join]

          Comment

          • Harmon
            ( ͡ʘ╭͜ʖ╮͡ʘ)
            • Mar 2004
            • 20013

            #6
            Originally posted by AlienQ
            Ironic photo caption and headline.
            Hahahah! I didn't notice that! Classic...
            [email protected]

            Comment

            • Greg B
              So Fucking Banned
              • Jul 2001
              • 7014

              #7
              Yep it's AOL but what gets me is AOL has all this spyware, anti-virus bs they tout. They caught it though.

              Don't know if it gets through the standard IE browser. If AOL caught it, I'll stick with AOL.

              Drudge has too many pop ups. He doesn't need them. His site is so damned popular he can charge through the roof.

              Comment

              • SmokeyTheBear
                ►SouthOfHeaven
                • Jun 2004
                • 28609

                #8
                Upon execution, this Trojan checks for the system?s Internet connection. It then creates new registry entries in order to lower the Internet security settings of the user?s default browser.

                This Trojan downloads files from the following URLs:


                http://static.topconverting.com/acti...nningsgame.exe
                http://static.topconverting.com/activex/tcupdater.exe
                http://static.topconverting.com/activex/180ax.exe
                http://static.topconverting.com/activex/optimize.exe
                http://static.topconverting.com/activex/games.exe
                It adds the following registry keys and entries:

                HKEY_CLASSES_ROOT\LOADER2.Loader2Ctrl.1


                HKEY_CLASSES_ROOT\LOADER2.Loader2Ctrl.1
                @ = "Loader2 Control"

                HKEY_CLASSES_ROOT\LOADER2.Loader2PropPage.1

                HKEY_CLASSES_ROOT\LOADER2.Loader2PropPage.1
                @ = "Loader2 Control"

                HKEY_CLASSES_ROOT\LOADER2.Loader2Ctrl.1\CLSID

                HKEY_CLASSES_ROOT\LOADER2.Loader2Ctrl.1\CLSID
                @ = "{79849612-A98F-45B8-95E9-4D13C7B6B35C}"

                HKEY_CLASSES_ROOT\CLSID\{38601801-2FF5-4A62-95DA-D2007161C1B4}

                HKEY_CLASSES_ROOT\CLSID\{38601801-2FF5-4A62-95DA-D2007161C1B4}
                @ = "Loader2 Property Page"

                HKEY_LOCAL_MACHINE\Software\Classes\LOADER2.Loader 2Ctrl.1
                @ = "Loader2 Control"

                HKEY_LOCAL_MACHINE\Software\Classes\LOADER2.Loader 2Ctrl.1\CLSID


                HKEY_LOCAL_MACHINE\Software\Classes\LOADER2.Loader 2Ctrl.1\CLSID
                @ = "{79849612-A98F-45B8-95E9-4D13C7B6B35C}"

                HKEY_LOCAL_MACHINE\Software\Classes\CLSID\
                {38601801-2FF5-4A62-95DA-D2007161C1B4}

                HKEY_LOCAL_MACHINE\Software\Classes\CLSID\
                {38601801-2FF5-4A62-95DA-D2007161C1B4}
                @ = "Loader2 Property Page"





                Analysis By: Carlo Panganiban

                Revision History:
                First pattern file version: 2.364.06
                First pattern file release date: Jan 21, 2005
                hatisblack at yahoo.com

                Comment

                • Greg B
                  So Fucking Banned
                  • Jul 2001
                  • 7014

                  #9
                  Smokey, one of my guys said the same thing.

                  It don't happen on IE only AOL browser which says to me that either AOL's security is better and catching it or that something else is going on. Why it would pop up during a Drudge load is unknown.

                  People have called into his show bitching about his popups and trojans or something but I thought they were joking.

                  Comment

                  Working...