GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   XP exploit on either Torrentz or TorrentSpy (https://gfy.com/showthread.php?t=765247)

Matt 26z 09-01-2007 05:03 AM

XP exploit on either Torrentz or TorrentSpy
 
First I went to TorrentSpy and then Torrentz.

Upon loading torrentz.com my firewall immediately caught mshtml2.exe attempting to connect to the internet.

The file was located in C:\Documents and Settings\Owner\Local Settings\Temp and it was just created, but I went immediately from TorrentSpy to Torrentz so I don't know which one put it there.


Here is the IP info it was trying to connect to:

Search results for: 63.251.135.24

Internap Network Services NETBLK-PNAP-11-99 (NET-63-251-0-0-1)
63.251.0.0 - 63.251.255.255
ClickSpring LLC INAP-BSN-CLICKSPRING-0971 (NET-63-251-135-0-1)
63.251.135.0 - 63.251.135.63


I have XP all up to date, so I'm not sure how this got on there and ran on it's own.

Matt 26z 09-01-2007 05:33 AM

Looks like I posted too soon.

"C:\Program Files\ISM" was also created by this and the following files tried to connect:

ism.exe
abacus.isprime.com

ismmodule3.exe
76.9.9.190

76.9.9.190 also goes to
OrgName: ISPrime, Inc.
OrgID: IPRM
Address: 25 Broadway
Address: 6th Floor, Suite #2
City: New York
StateProv: NY
PostalCode: 10004-1086
Country: US

Klen 09-01-2007 05:43 AM

No such things here,i double checked all system folders and cant found anything.Probaly beacuse nod32 kills such things.

KimJI 09-01-2007 06:00 AM

mshtml2.exe is a ad-ware. You must have installed it at some point prior to this

StuartD 09-01-2007 06:03 AM

Either you downloaded those files or you're using IE and your security settings are seriously slacking!

Matt 26z 09-01-2007 06:10 AM

Quote:

Originally Posted by KimJI (Post 13018747)
mshtml2.exe is a ad-ware. You must have installed it at some point prior to this

No, the file creation date is right then.

This might be from a rogue advertiser in the rotation, so it's not going to happen on every single visit. I recall the same thing happening on MySpace some time ago. Millions were infected.

headless ghost 09-01-2007 06:13 AM

you are in some seriously deep shit
go here
http://www.google.com/search?hl=en&q...=Google+Search
you may need to replace the hard drive or even the computer.
don't forget to have your ISP reverse flush the lines to be sure you get rid of all of it.

Matt 26z 09-01-2007 06:20 AM

Quote:

Originally Posted by StuartD (Post 13018752)
or you're using IE and your security settings are seriously slacking!

I don't even remember when the last time was that this happned to me, so if my settings are so unsecure you'd think this would be an often occurance.

Everything is marked either prompt or disable except these....


Run ActiveX controls and plug-ins: Enable

Script ActiveX controls marked safe for scripting: Enable

Active scripting: Enable

Allow paste operations via script: Enable

Scripting of Java applets: Enable


Should I set the first one to prompt instead?

StuartD 09-01-2007 06:23 AM

Quote:

Originally Posted by Matt 26z (Post 13018781)
I don't even remember when the last time was that this happned to me, so if my settings are so unsecure you'd think this would be an often occurance.

Everything is marked either prompt or disable except these....


Run ActiveX controls and plug-ins: Enable

Script ActiveX controls marked safe for scripting: Enable

Active scripting: Enable

Allow paste operations via script: Enable

Scripting of Java applets: Enable


Should I set the first one to prompt instead?

You should NEVER have "run activex controls" set to enable.... sites can just do as they please with your system the moment you hit them. They can essentially take full control!

Anything to do with active x should be by prompt only.

KimJI 09-01-2007 06:24 AM

Quote:

Originally Posted by Matt 26z (Post 13018781)


Should I set the first one to prompt instead?


always, same goes for
Scripting of Java applets: Enable
and
Active scripting: Enable

and make sure you PC is updated with the latest patches, including your IE

potter 09-01-2007 06:29 AM

Quote:

Originally Posted by headless ghost (Post 13018770)
you are in some seriously deep shit
go here
http://www.google.com/search?hl=en&q...=Google+Search
you may need to replace the hard drive or even the computer.
don't forget to have your ISP reverse flush the lines to be sure you get rid of all of it.

??? You don't know very much about computers do you? No software can ruin a hard drive or entire computer. Software cannot "infect" hardware.

Matt 26z 09-01-2007 06:31 AM

Now that I think about it, I had to switch at least one of those to enable to get an online virus sanner to work. I'm pretty sure it was Norton's, because I had never used that one before. It wasn't Kaspersky, Panda, BitDefender or TrendMicro. I had always used those without problems.

So it's ironic that a security company would say their online scan doesn't work with your current settings (I had it/them on prompt), then you make the changes to get the virus scanner to work and you get infected. That right there is evidence that the security companies WANT you to get infected so you'll buy their products.

KimJI 09-01-2007 06:53 AM

Quote:

Originally Posted by potter (Post 13018803)
??? You don't know very much about computers do you? No software can ruin a hard drive or entire computer. Software cannot "infect" hardware.


Welcome to 2004, the year "root kits" were discovered.


All times are GMT -7. The time now is 09:12 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123