Talk About Network

Google


Register and Login
Nick
Password
Register create new account Sign up is FREE and you can post replies, new topics, bookmark posts and more!
Recover lost password


Graphics > IBM's Data Explorer > Re: Santa Claus...
Latest [ Topics | Posts ] Archive Post A New Topic Post a Reply
<< Topic < Post Post 3 of 4 Topic 14 of 31
Post > Topic >>

Re: Santa Clause like you have never seen him before

by Spamless <Spamless@[EMAIL PROTECTED] > Dec 31, 2004 at 03:28 AM

On 2004-12-30, Dr. J <nobody@[EMAIL PROTECTED]
> wrote:
> Folks,  in its regular scan of my computer, my anti virus program
detected
> virus "bloodhound.exploit.21" on this webpage.  Do yourself a favor and
run
> your anti virus program if you visited this site.
>
> Shame on you paddy
>
>
><joshz@[EMAIL PROTECTED]
> wrote in message
news:i4yAd.609046$nl.394505@[EMAIL PROTECTED]
>> Santa Clause like you have never seen him before, this is a must see
for
> everyone http://paddy.home.comcast.net/

I believe that bloodhound.exploit.21 is a fairly generic term for an
attempt
to load something without your knowledge. Hopefully it caught the hta
file in your startup group (before it ran and downloaded the xp.exe file)


When it was up ...

  There is nothing much here. Just a picture. Then 214 blank lines.
  Then ... an [object] tag running:
    Javascript to write out an inclusion (do***ent.write)
    of the vbscript file http://paddy.home.comcast.net/writehta.txt
  Once that is included on the page, it creates a file with text
  (vbscript). That file is an ADODB.Recordset (filled with the vbscript
  commands to get the file http://paddy.home.comcast.net/xp.exe
and
  save it to 
   C:\Do***ents and Settings\All Users\Start
Menu\Programs\Startup\OfficeOSA.exe)

  The ADOBB.Recordset (with the commands to get xp.exe) is then written
out
  to C:\Do***ents and Settings\All Users\Start
Menu\Programs\Startup\MicrosoftOffice.hta

  So it looks like on the next boot, the MicrosoftOffice.hta
  is run to get the xp.exe file and save to OfficeOSA.exe and on
  the next boot, that is run (being in the startup group)

Bad paddy ...
 




 4 Posts in Topic:
Re: Santa Clause like you have never seen him before
"Dr. J" <nob  2004-12-30 22:52:59 
Re: Santa Clause like you have never seen him before
Doug Laidlaw <laidlaws  2004-12-31 10:45:17 
Re: Santa Clause like you have never seen him before
Spamless <Spamless@[EM  2004-12-31 03:28:52 
Re: Santa Clause like you have never seen him before
"Fred A. Miller"  2005-01-01 05:57:43 

Post A Reply:
  Go here to Signup

AddThis Feed Button


About - Advertising - Contact - Frequently Asked Questions - Privacy Policy - Terms of Use - Signup

Contact
tan12V112 Thu Nov 20 2:34:53 CST 2008.