Page 1 of 1

Doc, I think you've been hacked

Posted: Thu Jul 23, 2009 8:12 pm
by TheTodd
avast is telling me the following when I get here today:

File: http://emsadmin.ru/tm/
Mailware name: JS :D ownloader-AU [Expl]

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 6:10 am
by TheTodd
I see it in the code...down at the bottom. You in bed with the ruskies Doc. I know Josh wishes he was...at least in bed with one certain Ruskie.

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 6:25 am
by radbag
doc sold us all out to the ruskies?

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 7:56 am
by DocZaius
Thanks. I'll look into it.

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 7:58 am
by DocZaius
Has anyone else detected this? I see it in the code, but it appears to be on every page.

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 9:49 am
by radbag
i see nothing.

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 2:59 pm
by TheTodd
I've seen some web sites get hacked like that before and it ends up making calls to servers in China and then trying to run code on your box. I've witnessed it myself in a demo for a security suite where you go to a realtor site for an area in Idaho and you all the sudden have 6 more processes running on your system and your registry has been altered many times.

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 3:04 pm
by radbag
if you have it, would you typically run slower as a result?

Doc, I think you've been hacked

Posted: Fri Jul 24, 2009 6:56 pm
by TheTodd
It's possible. Run this:

http://housecall.trendmicro.com/