PDA

View Full Version : sophdream.com


dummy1977
07-13-2006, 03:02 AM
sophdream.com drops a bloody trojan just by clicking into the site.

No, I'm not paranoid. I have KAV 6.0. Thankfully, I just installed it days ago.

Don't believe it?

first, goto
http://www.sophdream.com

then, goto

http://www.kaspersky.com/virusscanner



not worth the risk, eh?

and they are asking people to pay. If I had a review site, there's no way in hell I'd let something like that slide just for some extra $. well.. If I had a porn review site..i'd probably be the type to do just that. anyway.

thanks

thankfully, the internet generation grew up, and there ARE trustworthy sites that we can turn to.

07-13-2006, 03:07 AM
Suspected: Trojan program Trojan-Downloader.JS.gen (modification) C:\WINDOWS\Temporary Internet Files\Content.IE5\U8P2RTGX\prv9182636[1].php 664 bytes
Suspected: Trojan program Trojan-Downloader.JS.gen (modification) C:\WINDOWS\Temporary Internet Files\Content.IE5\WL2R0TQ3\prv9182636[1].php 664 bytes



yeah...I know it's IE.. firefox kept freezing today and I had to switch.

07-13-2006, 07:26 AM
:oops:

Jeppe
07-13-2006, 01:10 PM
Sorry that you are having trouble with the site.

But how can you tell that it was specifically that site? I don't know why you think neither us nor the webmaster of that site would be interested in infecting anybody's machine with some trojan.

Rajit25
07-14-2006, 03:38 AM
i agree i think... :oops:

dummy77
07-14-2006, 03:31 PM
It's not your fault, I didn't have any malware issues with this review site here or mean to imply the admins here were in on deceiving users; it seems to be a friendly community and it's nice to have a free service that puts time into lengthy reviews..

but..
I can tell it's specifically that specific p-or&n site I mentioned, because I have live protection from KAV 6 and upon instnatly upon clicking on that sepcific site (and no other similar instance before, and none other after) it caught the trojan dropper. Upon 3-4 more trials with the same exact instant results (i.e. (Click specific hyperlink, *boom* the dropper is caught) (with one or two more of that sites' preview pages trying to drop it yet again).

as far as I know, the evidence is still there for anyone to check and follow up on and confirm this or debunk it. All it takes is a proof of concept run to find out, if one has the proper protection.

y av 6.0 pro and not the online scanner, but they used the same date of definitions.


[quote="Jeppe"]Sorry that you are having trouble with the site.

But how can you tell that it was specifically that site? I don't know why you think neither us nor the webmaster of that site would be interested in infecting anybody's machine with some trojan.

Jeppe
07-14-2006, 06:21 PM
No problem, I'll email our contact at the site and let him know about it. I doub't he is aware of it or has done it on purpose. I'll try to get it sorted out and post my progress here.

Thanks for making me aware of it!