Virus alert!!

Status
Not open for further replies.
Quote:

127.0.0.1 xanjan.cn http://www.xanjan.cn


BBS software has modified TNS's message. Remove the http:// in the above line, to just indicate the hostname that starts with w

As he mentioned name resolution won't be done via DNS on these two sites since you computer will "already know them" as itself.
 
Last edited:
Soooooo, how did you get the Virus...??

Did you download something or just visit pages, or what??

Thanks & good luck...
 
Just visiting pages without the iframe security fix from Microsoft will get you with this one.

A plethora of scripting vulnerabilities are constantly out there. If you use Firefox, download noscript - kind of a PITA to use, but will greatly secure your computer from one of the largest attack vectors - javascript.
 
I went to juno.com a few weeks back and got hit with a virus. Actually, I think that just about every major website has had at least one issue over the years. A good AV/AS program is a must.
 
Add this to your hosts file on SQL servers & systems with MSDE installed. This won't protect you from getting the worm, but it will prevent the worm from working.

Code:




# SQL Injection Worm Nasty Hosts

# http://isc.sans.org/diary.html?storyid=4393&rss



127.0.0.1 www.winzipices.cn winzipices.cn

127.0.0.1 www.cnzz.com cnzz.com

127.0.0.1 51.la.com www.51.la.com www.51.la

127.0.0.1 s141.cnzz.com

127.0.0.1 bbs.jueduzuan.com www.jueduizuan.com
 
Originally Posted By: ToyotaNSaturn
Update:
http://isc.sans.org/diary.html?storyid=4393&rss

From that link:

Quote:
Fair warning, if you google this hostnames, you will find exploited sites that will try and reach out and "touch" you... even if you are looking at the "cached" page. Proceed at your own risk.

I viewed the cache of turbomopar.com (don't go there) and Trend Micro found the virus and quarantined it.
 
Status
Not open for further replies.
Back
Top Bottom