Viper Squad Ten

[ Tuesday, September 30, 2003 ]

Comments taken offline, hijacked or trojaned or summat.
Starbuck [11:19] Comments: 0 []
I've had to take the Commenting tool off-line for now.

After having some infected code drift through my browser last night, there's been a few funny things going on. There were Comments posted to my email and to the blog for the last 4 posts, without any actual text or sender or whatnot.

On trying to go into the Comment on the blog, my Zonealarm firewall kicked in, telling me that MSHTA.EXE (Microsoft (R) HTML Application host) was trying to contact the internet... scary, I thought. I looked at the top pane of the blank browser pop-up (there in place of the normal Comments pop-up), and it said something even more scary, about the site being "" or something, so I'm glad Zonealarm kicked in when it did...

A quick check on Google, and over to Spyware Info website, which says that "A file is dropped onto the infected system using ActiveX drive by, the file is run, and then immediately loads the Windows application MSHTA.EXE from the Windows folder. MSHTA.EXE is put into "hot standby", ready to accept HTA scripting within a web page and then EXECUTE what is embedded IN the page as if it were a program. In other words, this flaw makes it possible for a malicious website to embed trojans, worms and/or viruses directly into a web page and infect visitors using Internet Explorer."

Well, I'm downloading HTAStop2003, and am gonna see if this heap of junk web-browser works OK without active scripting and the rest, so we'll see what's what. Adaware hasn't picked up on anything, and my antivirus system states I'm no longer infected, so fingers crossed.

Be careful out there!

0 Comment(s):

Post your own Comment

[ Click HERE for the VSX front-page... ]

[ Previous Posts ]

MAME Jump!
Confessions Of A Dangerous Mind review
Doctor Who next incarnation thoughts (continued)
It's Friday night - that means DJ Tim
#Doctor Who, hey, in the Tardis#
Revolutions trailer description
Reloaded Trailer (editor's correction: Matrix REVO...
Web site woes
Personal Message Of Hate

[ Full Archives ]

[ Photowankery ]
This is a Flickr badge showing public photos from Starbuck Powersurge. Make your own badge here.