Tom's Guide > Forum > CPU & Components > CPUs > VIRUS ON THG?

VIRUS ON THG?

Forum CPU & Components : CPUs - VIRUS ON THG?

TomsGuide.com: Over 800,000 questions and answers to address all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Came to the homepage this morning, asked me to install an ActiveX (now thats new???). Clicked, and bang. Virus. WTF??????????


Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Bloodhound.Exploit.109

Sponsored Links
Register or log in to remove.
- 0 +

Discovered: January 3, 2007
Updated: February 13, 2007 1:03:05 PM
Type: Trojan Horse, Worm, Virus
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Bloodhound.Exploit.109 is a heuristic detection for Apple QuickTime RTSP URI Remote Buffer Overflow Vulnerability (as described in BID 21829).
ProtectionInitial Rapid Release version January 3, 2007
Latest Rapid Release version January 3, 2007
Initial Daily Certified version January 3, 2007
Latest Daily Certified version January 3, 2007
Initial Weekly Certified release date January 10, 2007
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat AssessmentWildWild Level: Low
Number of Infections: 0 - 49
Number of Sites: 0 - 2
Geographical Distribution: Low
Threat Containment: Easy
Removal: Easy
DamageDamage Level: Low
DistributionDistribution Level: Low

Writeup By: Costin Ionescu

http://www.symantec.com/enterprise [...] p.jsp?doci d=2007-010315-5708-99

------------------------------ E6600 @3.33Ghz | P5W DH Deluxe @370Mhz FSB | Thermalright Ultra-120 | MSI x1900xt | 2GB OCZ Plat Rev2 @740Mhz, 4-4-4-12 | Seagate Barracuda 320GB | 3DMark06: 6461 (5902 stock) | PCMark05: 8552 (6950 stock) | Temps: 45 Idle, 70 Load
Reply to fishboi
- 0 +

It appears to be gone now, but I did run into it earlier.

Reply to Jim_L9
- 0 +

Nope, it's still there...

Reply to chedrz

It just happenned to me, I got the activeX popup, I didn't click it and IE just crashed.

Reply to turboflame

tut tut tom :p

------------------------------ e6600(b3) @3.33ghz stock V (30idle-40/45load_| 4gb@1:1 | 512mb 4870@780/3800 | msi p35 neo2-fr | antec900 | Auzentech X-Plosion | samsung 226bw
Reply to perham3d

I didn't run into it.

Reply to Heyyou27
- 0 +

I'm using FireFox, it doesn't have ActiveX :)

Reply to aevm
- 0 +

aevm wrote :

I'm using FireFox, it doesn't have ActiveX :)



yea, Firefox!

how fast you have your Q6600?

I just got mine "reinstalled", new mobo, my old board was the 680i SLI AR version that wouldn't go over 1200FSB, so got it RMA swapped for the A1. I pulled a late night and got it back and running already at 3.0Ghz at default voltage.

can't wait to get home and really start pushing it, hoping for 3.6Ghz like my old C2D but would be happy with 3.3 or so. :bounce:

------------------------------ Evga X58 3XSLI : i7 920 @ 4.2Ghz :GTX295+ x 2 :12GB XMS3 Dominator 8-8-8-21 1600 :XFi Fatal1ty:150GB WD VelociRaptor: 150GB Raptor: 4TB WD 32MB x4: Monsoon Vigor III: Lian Li P80 (black): BFG 1Kw PS: 37" Westinghouse 1080p 8ms :Vista64bit
Reply to warezme

I ran into the bloodhound exploit this week (maybe it was on THG???). It's the first time in a LONG time that I can remember my anti virus popping up saying it had quarantined something...

Reply to ben72227

When I opened tomshardware.com this morning, I didn't click on any bars at the top of the page but Trend Micro immediately found a virus named XML_HACK.AO in a .mov file in my temporary internet files. On the Trend site it said Quicktime 7.1.3 was vulnerable to this so I immediately updated to 7.2 and deleted my browser cache.

Like one of the guys above said, this is the first time my virus scanner has detected a virus in a long time.

Reply to MisterChef

I also just detected the Bloodhound.Exploit.109 virus about 5 minutes ago. I guess it came from here. This is not the first time THG has been infected with a virus... Gotta love their security and competence.

Reply to orangegator

It's been reported! Thanks - 3rd party banner ads, I think.

------------------------------
The Edge... There is no honest way to explain it because the only people who really know where it is are the ones who have gone over. - HST

Reply to Jake_Barnes

i'm using firefox and the virus message didn't pop up althoguh somtimes lately i get this message when i access THG from firefox ....

"access to http://www.tomshardware.com/us/ is forbidden" something similar to posted message.

recently asus website was hecked so i wouldn't be surprissed that the same thing happens to tomshardware.


on the other hand nice to report such thing lets support THG for their good work by being patient. Keep it up THG

Reply to juvealert

Time Module Object Name Threat Action User Information
8/8/2007 11:01:36 AM IMON file
Name: http://www.google-counter.com/cgi- [...] =347186945 6
Threat:
Exploit.Multi.Qtp.B trojan
Action
Connection terminated

To note, I am also using firefox 2.0.0.6 and NOD32 picked it up.

Reply to metalfandragula
- 0 +

it seems to be gone now?

------------------------------ Fredi
Reply to Fredi

juvealert wrote :

i'm using firefox and the virus message didn't pop up althoguh somtimes lately i get this message when i access THG from firefox ....

"access to http://www.tomshardware.com/us/ is forbidden" something similar to posted message.

recently asus website was hecked so i wouldn't be surprissed that the same thing happens to tomshardware.


on the other hand nice to report such thing lets support THG for their good work by being patient. Keep it up THG



I had got the forbidden message several times over the past few weeks. I haven't seen it at all this week.

Reply to hawkeye22

I have been getting the "Forbiden" message everyday for the past week.

Reply to rsetter1
- 0 +

Has someone from THG responded and come back with an explanation?

------------------------------ E6600 @3.33Ghz | P5W DH Deluxe @370Mhz FSB | Thermalright Ultra-120 | MSI x1900xt | 2GB OCZ Plat Rev2 @740Mhz, 4-4-4-12 | Seagate Barracuda 320GB | 3DMark06: 6461 (5902 stock) | PCMark05: 8552 (6950 stock) | Temps: 45 Idle, 70 Load
Reply to fishboi
- 0 +

ey... me!

see my question above. Some banner as suspected, but I can't be sure if it's gone for good...
I have to assume that no more reports mean it's all OK now...

------------------------------ Fredi
Reply to Fredi
- 0 +

wtf? man i'm glad i have vista 64 bit. But seriously, whats the deal? Toms with freaking viruses on its site?

------------------------------ e6600(3.0ghz 1.325v) on Noctua U12F,XFX 680i mobo, EVGA 640mb 8800gts, Modded antec 900 for CM, 1tb(2x500gb wd re2)+150gb raptor, Vista home premium 64 bit, mx 5000 K+M, dual sammy's 19(193p+)+22(226bw "s" ), z5500+HD595's, xfi plat, 850watt enermax Galaxy
Reply to eric54
- 0 +

I agree with eric54. WTF response is that? Viruses on a tech site and no real explanation for what happened?

What does it actually do for those who may have been infected? If people havent gotten a warning message, it probably means they're infected. How serious is it etc etc.

Just some thoughts. I'm fine - I picked it up early this AM, but maybe some other people are concerned.

------------------------------ E6600 @3.33Ghz | P5W DH Deluxe @370Mhz FSB | Thermalright Ultra-120 | MSI x1900xt | 2GB OCZ Plat Rev2 @740Mhz, 4-4-4-12 | Seagate Barracuda 320GB | 3DMark06: 6461 (5902 stock) | PCMark05: 8552 (6950 stock) | Temps: 45 Idle, 70 Load
Reply to fishboi
- 0 +

Nope the error is still there... I tried to access the site this morning August 11 2007 @ 740am but got the Site is forbidden 403 message....

Reply to ITZ

Having not used Interturd Exploiter for even longer than I've not been to either the UK or USA website should I be concerned? [:mousemonkey:2]

Reply to mousemonkey

Still getting the "access to http://www.tomshardware.com/us/ is forbidden" with firefox.

No problem with IE but the spybot plug-in (Browser Helper) is saying that it blocked one bad address.

Reply to HyperBladeST

Firefox + Linux = no worries, I click on .exe attachments for fun.

Reply to MoNeY3865
- 0 +

mousemonkey wrote :

Having not used Interturd Exploiter for even longer than I've not been to either the UK or USA website should I be concerned? [:mousemonkey:2]

:lol: :lol: :lol: :lol:

Quote :

Firefox + Linux = no worries, I click on .exe attachments for fun.

:lol: :lol: :lol: :lol:

Reply to Zorg

HyperBladeST wrote :

Still getting the "access to http://www.tomshardware.com/us/ is forbidden" with firefox.

No problem with IE but the spybot plug-in (Browser Helper) is saying that it blocked one bad address.



I'm using FF 2.0.0.6 (and Mozilla 1.7.x) - and I've never had any of those problems. There are lot's of false positives with some hurestics functions. But, I've never seen any of these issues some (only a few actually) are reporting.

------------------------------
The Edge... There is no honest way to explain it because the only people who really know where it is are the ones who have gone over. - HST

Reply to Jake_Barnes
- 0 +

Well, that explains the strange random 403 errors I got earlier in the week trying to go to the THG home page. It never asked me to download an ActiveX control though, and NAV never alerted me to anything. All I saw was the 403 error or the website not responding one.

I am using IE 7.1.xxxxx.

Reply to DXRick

eric54 wrote :

wtf? man i'm glad i have vista 64 bit. But seriously, whats the deal? Toms with freaking viruses on its site?



You do realize that Vista 64-bit (unless it's IA64, which I *highly* doubt) runs 32-bit code, right? Internet Explorer 7 does apparently run in a kind of a chroot jail of sorts and if you are smart and don't run as Administrator, the virus may not have been able to do much. If you run as Administrator like most people, then the virus could have trashed all of your user files without even tripping UAC. You'd have been in the same boat as any other Windows user. UAC would have only been tripped if you didn't shut it off and the virus tried to change some system settings or files, which is the only thing that Vista would have done differently than any other Windows OS.

Quote :

Firefox + Linux = no worries, I click on .exe attachments for fun.



MoNeY3865: I also use Firefox on x86_64 Linux, but you should know as well as I do that it's not invulnerable; in fact, far from it. Yes, an .exe binary cannot run by default on a Linux machine as an ELF file cannot execute on a Windows machine. But if you have WINE installed as many do, there's a chance that the virus would have enough Windows compatibility DLLs to execute and carry out its functions. Oops! The joke is on YOU then if you double-click it and WINE runs is. Don't play around with viruses unless you know what you're doing, and that usually involves a "disposable" machine with a stout firewall tracking and blocking access to anything on the network or Internet to analyze what it's doing, a decompiler, and other tools to analyze the mechanism of action and propagation and the code of the virus. If you're clicking on the .exes for fun, my guess is that you're not doing this.

Also, Firefox on Linux is usually as vulnerable to exploits as Firefox on Windows as the program is largely similar. Java, Flash, etc. are just as vulnerable as they are much the same program. Granted then the virus would have to know what to do to a Linux machine afterwards and most don't, but the vector still remains. They could still DDOS Firefox at least. Linux and UNIX machines are high-value targets as they are much more useful if cracked than a Windows box (due to what tools are on them), and I can't tell you how many hits on my firewall I see of people looking for port 22 (SSH.) Linux may be more secure by design than Windows, but NEVER get complacent. If you ever get rooted, you'll realize this in a second. I've never been rooted, but I've known people that have been- our local LUG server was- and it is a real big pain to have that happen.

------------------------------ Upcoming Overdue Build: Dual-socket workstation, ~32 GB DDR3, OS on a fast SSD, high-end GPU, all wrapped up in a huge tower case. Coming H2 2011.

Yes, I am actually still running the Pentium III 1.0B Coppermine in the picture.
Reply to MU_Engineer
Tom's Guide > Forum > CPU & Components > CPUs > VIRUS ON THG?
Go to:

There are 12 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Google ads