CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 941
Comments: 25
block bottom
spacer spacer

HTML Dldr.Iframe.DP and more on lakenormanguide

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Boomslang

Cadet
Cadet


Joined: Sep 18, 2007
Posts: 8
Location: USA

PostPosted: Fri Jul 18, 2008 11:12 pm    Post subject: HTML Dldr.Iframe.DP and more on lakenormanguide
Reply with quote

hxxp://lakenormanguide.com

Immediately upon visiting Antivir warns about HTML/Dldr.Iframe.DP and I also noticed some sort of Active-X attempt later(?) if you ignore and continue on. I didn't mess with it any further.

My remote user had AVG 7.5, which detected this site but every time I cleaned it, it would not remove the browse tab from IE7. For a while I thought there was some nastier infection but turns out it was AVG interfering so I finally had to go into the registry to get rid of tab that had the site open.

I e-mailed the hosting company about this site but they misunderstood my first e-mail. I replied and put it as plainly as I could.

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 54
Location: South Carolina, USA

PostPosted: Sat Jul 19, 2008 8:31 am    Post subject:
Reply with quote

first, let me say that i am not an "expert", or an "expert-researcher"..

i went to "lakenormanguide.com", but no webpage was displayed, except for the usual "page cannot be found", or whatever it is, so i thought that the website had been taken down.. none the less, i later found that antivir had silently quarantined a file from there.. interestingly, when i tried to delete the quarantined file, i wasn't allowed to delete it, but was told that the file was in use.. i then scanned my computer and antivir flagged the "HTML/Dldr.Iframe.DP" file in "c/documents and settings/all users/avira/antivir/temp/webguard"!

when i looked in the antivir/temp/webguard folder, i couldn't see any file, there.. eventually, i closed "webguard" and "avguard", and i was then able to delete the quarantined file, and the "antivir/temp/webguard" folder was showing as being "empty"..

this kind of ties in with your seeing the tab remaining, in firefox, i think.. it was strange, not being able to delete the quarantined file and finding the "HTML/Dldr.Iframe.DP " file in the "webguard" folder..

i did full scans with various programs and none of them reported anything odd, now..

the "lakenormanguide.com" website is now saying "we have been hacked", so the issue, there, is being addressed.. personally, i wish the problem, there, was still active.. i wanted to report this issue to avira, where the file didn't seem to be properly handled by antivir..

on my computer, i have been noticing that antivir, or antivir's "webguard", has been silently quarantining some files, like the "HTML/Dldr.Iframe.DP " file.. i have adjusted my settings so that maybe that will not continue happening, but, instead, i will always see an alert before anything is quarantined..

Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:30 pm    Post subject:
Reply with quote

Hi. I'm the owner of lakenormanguide.com. I took down the site as soon as I became aware of this problem. A visitor emailed me, and sure enough AVG fired up as soon as I hit the site. I tried to look at the index file to see what was going on but AVG wouldn't allow it so I deleted it, locally and on the server.

FYI, the site is hosted by IPower. All my sites on ipower have been hacked repeatedly, usually using a javascript eval(...) statement to redirect or embed an iframe, they've also used redirects in htaccess.

Thanks to CastleCops for "making cybercriminals unhappy" ... I'd like to see them a lot worse off than unhappy!

-Nigel

P.S. "Boomslang" rings a bell, I just got back from a month in South Africa.

Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:53 pm    Post subject:
Reply with quote

Hi. I'm the owner of lakenormanguide.com. I took down the site as soon as I became aware of this problem. A visitor emailed me, and sure enough AVG fired up as soon as I hit the site. I tried to look at the index file to see what was going on but AVG wouldn't allow it so I deleted it, locally and on the server.

FYI, the site is hosted by IPower. All my sites on ipower have been hacked repeatedly, usually using a javascript eval(...) statement to redirect or embed an iframe, they've also used redirects in htaccess.

Thanks to CastleCops for "making cybercriminals unhappy" ... I'd like to see them a lot worse off than unhappy!

-Nigel

P.S. "Boomslang" rings a bell, I just got back from a month in South Africa.

Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:56 pm    Post subject:
Reply with quote

Hi. I'm the owner of lakenormanguide.com. I took down the site as soon as I became aware of this problem. A visitor emailed me, and sure enough AVG fired up as soon as I hit the site. I tried to look at the index file to see what was going on but AVG wouldn't allow it so I deleted it, locally and on the server.

FYI, the site is hosted by IPower. All my sites on ipower have been hacked repeatedly, usually using a javascript eval(...) statement to redirect or embed an iframe, they've also used redirects in htaccess.

Thanks to CastleCops for "making cybercriminals unhappy" ... I'd like to see them a lot worse off than unhappy!

-Nigel

P.S. "Boomslang" rings a bell, I just got back from a month in South Africa.

Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:56 pm    Post subject:
Reply with quote

Hi. I'm the owner of lakenormanguide.com. I took down the site as soon as I became aware of this problem. A visitor emailed me, and sure enough AVG fired up as soon as I hit the site. I tried to look at the index file to see what was going on but AVG wouldn't allow it so I deleted it, locally and on the server.

FYI, the site is hosted by IPower. All my sites on ipower have been hacked repeatedly, usually using a javascript eval(...) statement to redirect or embed an iframe, they've also used redirects in htaccess.

Thanks to CastleCops for "making cybercriminals unhappy" ... I'd like to see them a lot worse off than unhappy!

-Nigel

P.S. "Boomslang" rings a bell, I just got back from a month in South Africa.

Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:57 pm    Post subject:
Reply with quote



Last edited by newclear on Sat Jul 19, 2008 5:01 pm, edited 1 time in total
Back to top
View users profile Send private message
newclear

Cadet
Cadet


Joined: Jul 19, 2008
Posts: 6
Location: USA

PostPosted: Sat Jul 19, 2008 4:58 pm    Post subject:
Reply with quote

Hi. I'm the owner of lakenormanguide.com. I took down the site as soon as I became aware of this problem. A visitor emailed me, and sure enough AVG fired up as soon as I hit the site. I tried to look at the index file to see what was going on but AVG wouldn't allow it so I deleted it, locally and on the server.

FYI, the site is hosted by IPower. All my sites on ipower have been hacked repeatedly, usually using a javascript eval(...) statement to redirect or embed an iframe, they've also used redirects in htaccess.

Thanks to CastleCops for "making cybercriminals unhappy" ... I'd like to see them a lot worse off than unhappy!

-Nigel

P.S. "Boomslang" rings a bell, I just got back from a month in South Africa.

P.P.S. PHP file type gone in Firefox, each time I click submit on this post I get the file download dialog. Hoping the Firefox update fixes it.

Back to top
View users profile Send private message
redwolfe_98

Corporal
Corporal


Joined: Dec 16, 2003
Posts: 54
Location: South Carolina, USA

PostPosted: Mon Jul 21, 2008 1:04 pm    Post subject:
Reply with quote

i wish i could get a sample of the malware, to submit to avira..

Back to top
View users profile Send private message
Kayracc

Trooper
Trooper


Joined: Jul 07, 2008
Posts: 17


PostPosted: Mon Jul 21, 2008 1:47 pm    Post subject:
Reply with quote

unless it's something new i've sent a few of these around, and to avira Wink

however i had short access to the page, and then went out and owner had it down right after

but avira was detecting it

Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer