[Latest] Possible Infection
-
Spybot encountered something yesterday i wasnt sure where it came from but i guess it was from tsp.
Thx for the warning anyway, i hope u will not have stupid attacks like this one again.
Regards
Mind -
i didnt get infected
idk why tho lolā¦maybe it was google chrome, or NOD32
i mean, im a comp geek but idk why im not infected
EDIT: When thinking of it, i blocked that site it tried redirecting me to anyways lol, explains it
-
Unfortunally, I bashed my registry till that I am not longer able to scan with Ad-Aware or Spybot without getting a crash.
But luckily, I canāt remeber that pages have poped up, PLUS, I am using NoScript (Paranoia!!) - And it saved me, I guess.
(But however, I got a āOut Of Rangeā crash again, but since I have this forā¦some weeks, I guess it is because of my Registry, HDD or RAM)
-
NoScript saved you. The whole thing was an iframe which had an incomplete address. On page execution, a small javascript would complete the script if a counter was set to a certain value. That means not everyone who visited the page have been infected and anyone with disabled Javascript would not have been infected.
-
Did it ask you to download & execute a file or did it use some browser flaw to do a drive by attack that didnāt require user interactions?
-
It was a flash thing, so allmost anyone with the flash plugins enabled could be infected.
-
im not infected
lol
-
It may be worth listing which programs detect the infection.
From above so far I guess Spybot does.
English version of above rootkit revealer
http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx -
Avast and Avira do to.
-
Was it an issue to do with Joomla being out of date or an addon likewise being insufficient?
-
Our version is not out of date and we run the latest patches, but still ā¦ we have an idea what caused it, we donāt know exactly witch bothers me somewhat.
-
Was *nix vulnerable as well, or was it Windows only?
-
Windows only.
I found out what it whas after i booted up in Linux and it started to ask me stuff about installing crap.
18/18