ADULT.COM sponsoring trojan website..

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SmokeyTheBear
    ►SouthOfHeaven
    • Jun 2004
    • 28609

    #1

    ADULT.COM sponsoring trojan website..

    They (adult.com) are likely not aware of this, but i would suggest contacting this affliate asap .


    http://galleries.adult.com/reality/g...wm=MTgzMjo2OjU

    I notice alot of other well know websites that are affiliated with www.tv69.com / sexdirectory.com

    like sleazydream and madthumbs

    Aliases Trojan.JS.NoClose.e
    JS/NoClose.M
    JS/Noclose
    JS/NoClose.L



    JS/NoClose-G hides the browser window and, after 10 minutes, opens a pop-up window.
    The pop-up window will typically have a URL located at http://www.tv69.com/ and may contain sexual images or links to adult websites.
    A cookie flag is set to prevent the pop-up from being shown more than once in a 24 hour period.
    JS/NoClose-G typically arrives on the computer by browsing websites whose HTML pages contain the script.
    JS/NoClose-G is not particularly malicious, but its behaviour can be regarded as undesirable.




    Name JS/Fortnight-B
    Type Worm

    JS/Fortnight-B is a worm that attempts to spread by dropping a file that it sets as the signature file for Outlook Express 5.0. The file is dropped in the Windows folder and is called s.htm.
    JS/Fortnight-B sets the following registries:
    HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab
    HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\AdvancedTab
    to "1" and
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL
    \DefaultPrefix\
    to "http://www.pixpox.com/cgi-bin/click.pl?url="
    JS/Fortnight-B also creates a file in the Windows folder called hosts. The hosts file has the effect of subverting access to the following websites:
    *.mtree.com
    ads.sexplanets.com
    adultfriendfinder.com
    adultmegacash.com
    adv.sexcounter.com
    amc2.adultmegacash.com
    auto.search.msn.com
    c.fsx.com
    cart.penispill.com
    cash.helmy.com
    cgi.gammae.com
    click.passiondollars.com
    click.payserve.com
    click.silvercash.com
    clickcash.webpower.com
    clicks.filthyclicks.com
    clicks.nastydollars.com
    clicks.oxcash.com
    clicks.uni-cash.com
    clicks2.oxcash.com
    ctc.amateurpages.com
    ctc.japanesegirls.com
    cybererotica.com
    db.fetishcash.com
    db.smutcash.com
    dollartraffic.com
    gotd.stiffycash.com
    home.vividvip.com
    in.cybererotica.com
    in.paycounter.com
    join.pibcash.com
    link.siccash.com
    links.lifetimebucks.com
    lobby.sexlist.com
    media.fastclick.net
    network.nocreditcard.com
    network.nocreditcard.com
    partner.globill-systems.com
    partners.hotgold.com
    penismedical.net
    php.offshoreclicks.com
    php.offshoreclicks.com
    porndollar.com
    potd.oxcash.com
    programs.wegcash.com
    rd1.hitbox.com
    refer.ccbill.com
    referral.topbucks.com
    secure.2000charge.com
    secure.dpbill.com
    secure.dutchbilling.com
    secure.ibill.com
    secure.pswbilling.com
    secure.visionbill.net
    secure1.websitebilling.com
    select.2000charge.com
    stats.allliquid.com
    stats1.pussypayments.com
    the.sextracker.com
    track.oxcash.com
    traffic.acpay.com
    vip.mtree.com
    ww2.amateur-pages.com
    ww2.amateur-pages.com
    www.1shoppingcart.com
    www.adultbucks.com
    www.adultmovienetwork.com
    www.adultrevenueservice.com
    www.albionmedical.com
    www.asacp.org
    www.babylon-x.com
    www.bigpay.com
    www.big-penis.com
    www.blacksonblondes.com
    www.candidclicks.com
    www.cashforlink.com
    www.ccbill.com
    www.clickcash.com
    www.clubpix.com
    www.cybererotica.com
    www.cyberpatrol.com
    www.cybersitter.com
    www.danni.com
    www.deluxepass.com
    www.dibill.com
    www.dollars4babes.com
    www.dollartraffic.com
    www.eazybucks.com
    www.entertainmentcash.com
    www.eroticacash.com
    www.eroticcash.com
    www.fatclicks.com
    www.fatpockets.com
    www.freeezinebucks.com
    www.freeticketcash.com
    www.hawgscash.com
    www.herbalbucks.com
    www.herbalo.com
    www.hpic.com
    www.icra.org
    www.intergal.com
    www.iteens.com
    www.lightspeedcash.com
    www.makingitpay.com
    www.maturemoney.com
    www.maximumcash.com
    www.morepenis.com
    www.mtreexxx.net
    www.n69.com
    www.nastydollars.com
    www.netnanny.com
    www.nocreditcard.com
    www.oxcash.com
    www.penilesecrets.com
    www.penismedical.net
    www.penispill.com
    www.pillmedics.com
    www.pillscash.com
    www.pillsmoney.com
    www.platinumbucks.com
    www.pluspills1.com
    www.porndollar.com
    www.pornstardollars.com
    www.rsac.org
    www.safesurf.com
    www.scoreland.com
    www.sexfantasyzone.com
    www.sexhit.com
    www.signup.globill-systems.com
    www.spyglass.com
    www.stiffycash.com
    www.surfwatch.com
    www.thecashzone.com
    www.totally4freecash.com
    www.trueclicks.com
    www.tv69.com
    www.twistyscash.com
    www.webmastersmakemoney.com
    www.xpays.com
    www.xxxesscash.com
    www2.karupspc.com
    www2.seductiveamateurs.com
    JS/Fortnight-B exploits a vulnerability in the Microsoft VM ActiveX component.
    If an affected web page is opened, a JScript embedded on the page attempts to use the vulnerability in order to drop files on a local drive, change registry keys without the user's knowledge or perform any other malicious action on the local computer.
    For more details about the Microsoft VM ActiveX component exception vulnerability please see Microsoft Security Bulletin MS00-075.
    hatisblack at yahoo.com
  • Manowar
    jellyfish  
    • Dec 2003
    • 71528

    #2
    tv69.com is a TCG domain.

    Comment

    • SmokeyTheBear
      ►SouthOfHeaven
      • Jun 2004
      • 28609

      #3
      pixpox is using steelecash and fleshlight

      http://click.silvercash.com/b_count/b_t.cgi?id=1009
      hatisblack at yahoo.com

      Comment

      • AlienQ - BANNED FOR LIFE
        best designer on GFY
        • Mar 2003
        • 30307

        #4
        Or possibly swapping out Affiliate code?

        Comment

        • SmokeyTheBear
          ►SouthOfHeaven
          • Jun 2004
          • 28609

          #5
          Originally posted by Manowar
          tv69.com is a TCG domain.

          hmm well i would wonder then why is tv69.com doing this ??
          hatisblack at yahoo.com

          Comment

          • ElvisManson
            Looking California
            • Feb 2001
            • 5476

            #6
            Originally posted by SmokeyTheBear
            hmm well i would wonder then why is tv69.com doing this ??
            pixpox.com is registered in Norway, but admin is in Armenia?..I think..the registrar looks a little wonky to me.

            Comment

            • Basic_man
              Programming King Pin
              • Oct 2003
              • 27360

              #7
              Weird.. Lens, check this out !
              UUGallery Builder - automated photo/video gallery plugin for Wordpress!
              Stop looking! Checkout Naked Hosting, online since 1999 !

              Comment

              • webair
                Confirmed User
                • Feb 2002
                • 8531

                #8
                probably be better served e-mail them directly than posting here first no?


                ~ Webair Dedicated Cloud Serversâ„¢ ~ WEBAIR VSYSâ„¢ Virtual Hosting Platform ~ Superior CDN Network ~
                ~ Managed Dedicated hosting Specialists ~ DISCOUNT DOMAIN NAMES! ~ WEBAIR FUSION IO MANAGED CLOUD SERVERS! ~


                ICQ: 243116321 - TWITTER - @WEBAIRINC - E-Mail: [email protected]

                Comment

                • Doctor Dre
                  Too lazy to set a custom title
                  • Jan 2001
                  • 51692

                  #9
                  There will be some major drama :P
                  Originally posted by rayadp05
                  I rebooted, deleted temp files, history, cookies and everything...still cannot view the news clip. All I see is that fucking gay ass music video from "Rick Roll". Anyone else have a different link to the news clip?

                  Comment

                  • SmokeyTheBear
                    ►SouthOfHeaven
                    • Jun 2004
                    • 28609

                    #10
                    Originally posted by webair
                    probably be better served e-mail them directly than posting here first no?
                    when my money is being stolen , i go for the fastest way to get it back. besides lens takes ages to answer e-mail and there are a ton of people affected besides just lens.
                    hatisblack at yahoo.com

                    Comment

                    • Sarabi
                      Registered User
                      • Nov 2003
                      • 14

                      #11
                      JS/NoClose-G hides the browser window and, after 10 minutes, opens a pop-up window.
                      The pop-up window will typically have a URL located at http://www.tv69.com/ and may contain sexual images or links to adult websites.
                      A cookie flag is set to prevent the pop-up from being shown more than once in a 24 hour period.
                      JS/NoClose-G typically arrives on the computer by browsing websites whose HTML pages contain the script.
                      JS/NoClose-G is not particularly malicious, but its behaviour can be regarded as undesirable.
                      This isn't a trojan that's doing anything harmful...it's just a timed blur that pops a console...what's the big deal? You have a choice to send to them console free.

                      It's the JS/Fortnight-B which is modifying registries and preventing access to that whole list of sites, tv69 included, and sending to http://www.pixpox.com/cgi-bin/click.pl?url= . It's whoever these pixpox people are that we should be worrying about

                      Comment

                      • pradaboy
                        sell me your banners
                        • Dec 2003
                        • 12931

                        #12
                        ooh that's def. not good
                        Media Buyer - Sell me your traffic!
                        FREE to register domains...
                        Better than 99% of the crap sold here!

                        Comment

                        • ElvisManson
                          Looking California
                          • Feb 2001
                          • 5476

                          #13
                          Originally posted by Sarabi
                          This isn't a trojan that's doing anything harmful...it's just a timed blur that pops a console...what's the big deal? You have a choice to send to them console free.

                          It's the JS/Fortnight-B which is modifying registries and preventing access to that whole list of sites, tv69 included, and sending to http://www.pixpox.com/cgi-bin/click.pl?url= . It's whoever these pixpox people are that we should be worrying about
                          Interesting disclaimer at the bottom of pixpox.com.

                          "The PIXPOX is in no way responsible for any damage as a result of linking to pages of other web sites, nor is The PIXPOX responsible for the content of the pages to which it links. "

                          Comment

                          • corvette
                            Confirmed User
                            • Oct 2001
                            • 7880

                            #14
                            smokey, whats a good way to get hold of you? i have been trying to for a while, preferably over phone
                            If you need a good company for check writing services, then check out checkissuing, and for webhosting, check out Phoenix NAP

                            Comment

                            • Dalai lama
                              Strength and Honor
                              • Jul 2004
                              • 16540

                              #15
                              Originally posted by Basic_man
                              Weird.. Lens, check this out !
                              You are so fucking dumb

                              A program you can trust.
                              Gallerybooster Run multiply TGPs of 1 script

                              Comment

                              • LauraLee
                                Confirmed User
                                • Sep 2003
                                • 3821

                                #16
                                Originally posted by Sarabi
                                This isn't a trojan that's doing anything harmful...it's just a timed blur that pops a console...what's the big deal? You have a choice to send to them console free.

                                It's the JS/Fortnight-B which is modifying registries and preventing access to that whole list of sites, tv69 included, and sending to http://www.pixpox.com/cgi-bin/click.pl?url= . It's whoever these pixpox people are that we should be worrying about
                                Thank you very much for clarifyiing that Sarabi.

                                Priority Payout
                                skype lauralee.bunker
                                LL's Email

                                Comment

                                • KMR Stitch
                                  I am cool
                                  • Jul 2003
                                  • 14494

                                  #17
                                  hmmm

                                  Comment

                                  • SmokeyTheBear
                                    ►SouthOfHeaven
                                    • Jun 2004
                                    • 28609

                                    #18
                                    Originally posted by corvett
                                    smokey, whats a good way to get hold of you? i have been trying to for a while, preferably over phone
                                    post your icq i will leave my number for you
                                    hatisblack at yahoo.com

                                    Comment

                                    • Rich
                                      So Fucking Banned
                                      • Jan 2003
                                      • 11486

                                      #19
                                      That's a TCG domain? That's impossible, they can do no wrong. Just ask all the guys who have TCG sigs.

                                      Comment

                                      • corvette
                                        Confirmed User
                                        • Oct 2001
                                        • 7880

                                        #20
                                        45471840
                                        If you need a good company for check writing services, then check out checkissuing, and for webhosting, check out Phoenix NAP

                                        Comment

                                        • SmokeyTheBear
                                          ►SouthOfHeaven
                                          • Jun 2004
                                          • 28609

                                          #21
                                          Originally posted by Sarabi
                                          This isn't a trojan that's doing anything harmful...it's just a timed blur that pops a console...what's the big deal? You have a choice to send to them console free.

                                          It's the JS/Fortnight-B which is modifying registries and preventing access to that whole list of sites, tv69 included, and sending to http://www.pixpox.com/cgi-bin/click.pl?url= . It's whoever these pixpox people are that we should be worrying about
                                          Thanx sarabi , i jumped the gun thinking the two were related, they are not..
                                          hatisblack at yahoo.com

                                          Comment

                                          • Manowar
                                            jellyfish  
                                            • Dec 2003
                                            • 71528

                                            #22
                                            Originally posted by Rich
                                            That's a TCG domain? That's impossible, they can do no wrong. Just ask all the guys who have TCG sigs.
                                            Yeah, it was just a popup for a TCG domain. Nothing harmful

                                            The second thing is

                                            Comment

                                            • Diligent
                                              Confirmed User
                                              • Aug 2003
                                              • 1594

                                              #23
                                              SmokeyTheBear,

                                              it's great You keep an eye on some of all this shit!
                                              I get the feeling it's escalated quite much the last 6 months.

                                              Anyway, like I've always believed.. It's not shady sponsors that are behind stuff like this,
                                              it's a small number of shady webmasters & hackers.

                                              I wonder if they're networking since the problem is growing or if they "work" independently...

                                              I just hope some people with the right skills and knowledge can come up with
                                              some way to at least detect things like these efficiently.

                                              Otherwise it will probably not be pleasant for either us webmasters or the industry as a whole.

                                              Sponsors are going to end up with mostly "hacker-affiliates" when real
                                              webmasters leave them because, to them, it looks like the sites stop converting...
                                              ~¤~ MORE MONEY ~¤~ VOD? XoD! ~¤~
                                              ~¤~ ICQ# 9828 2461 ~¤~

                                              Comment

                                              • webmaster x
                                                Confirmed User
                                                • Mar 2004
                                                • 4400

                                                #24
                                                hmmm....
                                                Click 9500 FHG Text Descriptions--Only $89!

                                                Comment

                                                • SexDirectory
                                                  Registered User
                                                  • Oct 2004
                                                  • 11

                                                  #25
                                                  Originally posted by SmokeyTheBear
                                                  Thanx sarabi , i jumped the gun thinking the two were related, they are not..
                                                  Thanks for exonerating SexDirectory.com there Smokey.

                                                  SexDirectory.com has no spyware, no trojans and no worms.

                                                  On that note, even though the TGP is just starting off, anyone can feel free to submit some galleries. Just keep them quality, please.



                                                  Cheers

                                                  Comment

                                                  • hive
                                                    Worker Bee
                                                    • Apr 2003
                                                    • 90

                                                    #26
                                                    Any news on this yet? Someone has to know someone that can get info on this guy.

                                                    Comment

                                                    • xclusive
                                                      Too lazy to set a custom title
                                                      • Apr 2004
                                                      • 35218

                                                      #27
                                                      Not good and it's amazing a lot of the people that put this shit out would do a lot better financially if they did everything on the up and up...

                                                      I support MediumPimpin.com / Shemp's Outlawtgp.com /


                                                      Comment

                                                      • SmokeyTheBear
                                                        ►SouthOfHeaven
                                                        • Jun 2004
                                                        • 28609

                                                        #28
                                                        Originally posted by hive
                                                        Any news on this yet? Someone has to know someone that can get info on this guy.

                                                        silvercash is sponsoring him
                                                        hatisblack at yahoo.com

                                                        Comment

                                                        • Theo
                                                          HAL 9000
                                                          • May 2001
                                                          • 34515

                                                          #29
                                                          trjoans, the cancer of internet

                                                          btw,how can i develop one?

                                                          Comment

                                                          • Major (Tom)
                                                            So Fucking Banned
                                                            • Nov 2003
                                                            • 32492

                                                            #30
                                                            Smokey, u rock!

                                                            Duke

                                                            Comment

                                                            • SmokeyTheBear
                                                              ►SouthOfHeaven
                                                              • Jun 2004
                                                              • 28609

                                                              #31
                                                              Originally posted by DukeSkywalker
                                                              Smokey, u rock!

                                                              Duke
                                                              I didnt track this one down , but thanks..

                                                              The pixpox site is the roadmap to theft in the highest degree, and i wouldn't be suprised if they get a little visit..
                                                              hatisblack at yahoo.com

                                                              Comment

                                                              Working...