<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: asdf.exe / theonion.com in Security</title>
<link>http://www.dslreports.com/forum/r14196289</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 01:19:01 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 01:19:01 EDT</lastBuildDate>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14541342</link>
<description><![CDATA[<A HREF="/useremail/u/1208033"><b>trooper100</b></A> : it appears the the trojan horse is doing more thin would appears i left it on and did a Trace on  it  and  it  seems  that it has a healthy link. i  will post all in time when IM done logging it and and tracing its path it seams to be working its way around ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14541342</guid>
<pubDate>Sun, 09 Oct 2005 20:43:40 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14296657</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : i got this file too, and now my windows is a little bit malformed (???) don&#180;t know how to say... i&#180;m german... but it looks slightly damaged... small white stripes all over the symbols and programs (firefox, trillian, my taskbar) <br><br>could asdf.exe have done that??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14296657</guid>
<pubDate>Mon, 05 Sep 2005 09:22:13 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14284529</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>if the signature key is recognized as trusted by the end system that receives the applet.<HR></BLOCKQUOTE>The install will default to no trust, asking the user if they want to trust and run the signed applet.<br> </DIV><div class="bquote"><SMALL>said by RobertLudum :</SMALL><BR><BR><BLOCKQUOTE><SMALL>quote:</SMALL><HR><br>Well, One thing about Java is that any site can bypass the sandbox by signing the applet, and if the user <B>accepts the cert/ trusts it by clicking through</B>.<HR></BLOCKQUOTE></DIV>Exactly. People nowdays are careful about signed ActiveX, I wonder how many know this for signed Java applets?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14284529</guid>
<pubDate>Sat, 03 Sep 2005 06:38:00 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14280696</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>if the signature key is recognized as trusted by the end system that receives the applet.<HR></BLOCKQUOTE>The install will default to no trust, asking the user if they want to trust and run the signed applet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14280696</guid>
<pubDate>Fri, 02 Sep 2005 17:37:16 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14280599</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by gruntled2 :</SMALL><BR><BR>I believe that the sandbox cannot be bypassed by a Java applet, signed or no, except in flawed implementations (that is, this is a bug, not a feature). Updating to current versions should eliminate this issue.  <br> </DIV> <br><br>Sun disagrees with you?<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>JDK 1.1 introduced the concept of a "signed applet", as illustrated by the figure below. In that release, a correctly digitally signed applet is treated as if it is trusted local code if the signature key is recognized as trusted by the end system that receives the applet. Signed applets, together with their signatures, are delivered in the JAR (Java Archive) format. In JDK 1.1, unsigned applets still run in the sandbox.<HR></BLOCKQUOTE><br><br>&raquo;<A HREF="http://java.sun.com/j2se/1.3/docs/guide/security/spec/security-spec.doc1.html" >java.sun.com/j2se/1.3/docs/guide&middot;&middot;&middot;oc1.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14280599</guid>
<pubDate>Fri, 02 Sep 2005 17:21:12 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14280034</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I believe that the sandbox cannot be bypassed by a Java applet, signed or no, except in flawed implementations (that is, this is a bug, not a feature). Updating to current versions should eliminate this issue.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14280034</guid>
<pubDate>Fri, 02 Sep 2005 16:00:00 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14276721</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by gruntled2 :</SMALL><BR><BR>You shouldn't have to turn off Java, at least as long as you've updated. But Javascript -- which is a completely different technology, the name notwithstanding -- has historically had security issues. Security specialists typically suggest disabling Javascript except on trusted sites.<br><br>-dave<br> </DIV>Well, One thing about Java is that any site can bypass the sandbox by signing the applet, and if the user accepts the cert/ trusts it by clicking through. <br><br>That nailed quite a few people in the past with firefox.<br><br>As for javascript, it seems that almost every exploit needs it as a launch trigger point, so turning it completely off would give you protection yes, but might break some sites.<br><br>So to get the best of both worlds, you might play with selectively turning off certain js functions. This is possible in firefox,opera and IE.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14276721</guid>
<pubDate>Fri, 02 Sep 2005 06:38:03 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14276667</link>
<description><![CDATA[<A HREF="/useremail/u/984597"><b>sybille</b></A> : <div class="bquote"><SMALL>said by Justmeagin :</SMALL><BR><BR>I also got infected by the winsp3.exe problem immediately after downloading the newest release of Firefox.</DIV>Which version of Sun Java do you have installed? <br><br>Also, since it sounds like you're having trouble removing the infection, you might want to give the steps here a try:<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A><br>There are instructions for using a series of different scanners, as well as for what to do if the scanners don't do the job.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14276667</guid>
<pubDate>Fri, 02 Sep 2005 06:04:12 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14276283</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I also got infected by the winsp3.exe problem immediately after downloading the newest release of Firefox.  I will not take them to task due to the wonderful work they do, but someone has really dropped the ball on this one.  Actually, I really hope I'm wrong but at this point, I'm hooped. AVG sees it so does Trend, neither is effective at removing it and it shuts down Windows Beta Spyware checker very effectively.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14276283</guid>
<pubDate>Fri, 02 Sep 2005 02:56:03 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14274889</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : You shouldn't have to turn off Java, at least as long as you've updated. But Javascript -- which is a completely different technology, the name notwithstanding -- has historically had security issues. Security specialists typically suggest disabling Javascript except on trusted sites.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14274889</guid>
<pubDate>Thu, 01 Sep 2005 22:55:16 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14274599</link>
<description><![CDATA[<A HREF="/useremail/u/1039629"><b>DonoftheDead</b></A> : Sorry to take so long. I was(and am) using Sun Java ver. 1.4.2.08. At least 1.4.2.04. I think I d/l'ed an update not too long ago. But I know at the time the file was dropped on my box I was using 1.4.2.04 at least. Strange, it blew into town and then blew out. Who was that masked stranger? btw I turned off Java and Javascript]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14274599</guid>
<pubDate>Thu, 01 Sep 2005 22:20:47 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14270158</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Latest version appears to have auto alert for new updates, which should make life easier.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14270158</guid>
<pubDate>Thu, 01 Sep 2005 12:42:50 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14269080</link>
<description><![CDATA[<A HREF="/useremail/u/294296"><b>Worfus</b></A> : <div class="bquote"><SMALL>said by  sybille <A HREF="/useremail/u/984597"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>It would be interesting for people who have found a copy of the asdf.exe file on their disks to post which version of Sun Java they were using when the file was downloaded. This would help to determine if the Sun Java plug-in is the culprit in this case.<br> </DIV>I <STRIKE>have</STRIKE> had Sun Java v1.4.2_04(Build b05).<br><br>Java is one security aspect that I don't keep up on with regards to updates.  That will change now.  Thanks Sybille.<br><SMALL>--<br>"Confusion" will be my epitaph.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14269080</guid>
<pubDate>Thu, 01 Sep 2005 09:50:09 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14268586</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I concur with your assessment and am updating Java files. It's worth noting that Sun recommends deleting the old versions.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14268586</guid>
<pubDate>Thu, 01 Sep 2005 07:48:45 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14268205</link>
<description><![CDATA[<A HREF="/useremail/u/984597"><b>sybille</b></A> : <div class="bquote"><SMALL>said by  jig <A HREF="/useremail/u/279131"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR><div class="bquote"><SMALL>said by RS412   :</SMALL><BR><BR>So, at least in my experience so far, the sandbox has indeed been breached.<br> </DIV>1) could someone tell me what this seeming colloquialism means?</DIV> jig <A HREF="/useremail/u/279131"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, you posted while I was looking up links for my post.<br><br>Here's how the iDEFENSE advisory describes the problem:<br> <BLOCKQUOTE><SMALL>said by &raquo;<A HREF="http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities&flashstatus=true" >www.idefense.com/application/poi&middot;&middot;&middot;tus=true</A> :</SMALL><HR><B>II. DESCRIPTION</B><br>Remote exploitation of a design vulnerability in Sun Microsystems Inc.'s Java Plug-in technology allows attackers to bypass the Java sandbox and all security restrictions imposed within Java Applets.<br><br>A number of private Java packages exist within the Java Virtual Machine (VM) and are used internally by the VM. Security restrictions prevent Applets from accessing these packages. Any attempt to access these packages, results in a thrown exception of 'AccessControlException', unless the Applet is signed and the user has chosen to trust the issuer.<br><br>The problem specifically exists within the access controls of the Java to Javascript data exchange in web browsers using Sun's Java Plug-in technology. The vulnerability allows Javascript code to load an unsafe class which should not normally be possible from a Java Applet.<br><br><B>III. ANALYSIS</B><br>Successful exploitation allows remote attackers to execute hostile Applets that can access, download, upload or execute arbitrary files as well as access the network. A target user must be running a browser on top of a vulnerable Java Virtual Machine to be affected. It is possible for an attacker to create a cross-platform, cross-browser exploit for this vulnerability. Once compromised, an attacker can execute arbitrary code under the privileges of the user who instantiated the vulnerable browser.<br><HR></BLOCKQUOTE><br><br>In other words, the term "sandbox" just describes the restrictions placed on java applets, which prevent the applets from altering system files and so on. If the sandbox has been breached or broken, then java applets can do whatever they please on the system, as described above.<br><br>For example, the applet could download and run a trojan file. It is possible that this is how people have been infected with the adsf.exe file. But even if that is not the source of the infection being discussed in this thread, the vulnerability is serious enough that it is important for Sun java users to make sure their plug-in, etc. is the up-to-date, patched version.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14268205</guid>
<pubDate>Thu, 01 Sep 2005 04:18:55 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14268175</link>
<description><![CDATA[<A HREF="/useremail/u/984597"><b>sybille</b></A> : <div class="bquote"><SMALL>said by gruntled2  :</SMALL><BR><BR>I am running Java 2 Runtime Environment, Standard Edition 1.3.1; Default virtual Machine Version 1.3.1.b24; Java Plug-In 1.3.1_02</DIV>Are the people who have experienced this sure they are running the most recent version of Sun java?<br><br>There is a security advisory for JRE (the plug-in) and SDK (the development package) for versions <I>prior to</I> 1.4.2_06 and 1.3.1_13. See:<br>&raquo;<A HREF="http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1" >sunsolve.sun.com/search/document&middot;&middot;&middot;-57591-1</A><br><br> <BLOCKQUOTE><SMALL>said by the Sun advisory :</SMALL><HR>A vulnerability in the Java Plug-in may allow an untrusted applet to escalate privileges, through JavaScript calling into Java code, including reading and writing files with the privileges of the user running the applet.<br><HR></BLOCKQUOTE><br><br>In other words, the vulnerability does involve the breaking of the sandbox.<br><br>Also see: <br>&raquo;<A HREF="http://secunia.com/advisories/13271/" >secunia.com/advisories/13271/</A><br>&raquo;<A HREF="http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities&flashstatus=true" >www.idefense.com/application/poi&middot;&middot;&middot;tus=true</A><br>&raquo;<A HREF="http://www.kb.cert.org/vuls/id/760344" >www.kb.cert.org/vuls/id/760344</A><br><br>To check what version of Sun java is on a PC, Sun recommends that the following command be run:<br><B>% java -fullversion</B><br><br>Whether this particular vulnerability is responsible for the asdf.exe infection or not, it seems very important to make sure that the java plug-in being used is not one of the vulnerable versions.<br><br>Edit: It would be interesting for people who have found a copy of the asdf.exe file on their disks to post which version of Sun Java they were using when the file was downloaded. This would help to determine if the Sun Java plug-in is the culprit in this case.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14268175</guid>
<pubDate>Thu, 01 Sep 2005 04:00:17 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14268169</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : <div class="bquote"><SMALL>said by RS412 :</SMALL><BR><BR>So, at least in my experience so far, the sandbox has indeed been breached.<br> </DIV>1) could someone tell me what this seeming colloquialism means?<br><br>2) aren't you guys using an old version of java, or is that the version that runs with FF?<br><br>aside to justin: i misread your original post. you were asking about a separate program that was a keylogger.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14268169</guid>
<pubDate>Thu, 01 Sep 2005 03:56:03 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14268115</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I am running Java 2 Runtime Environment, Standard Edition 1.3.1; Default virtual Machine Version 1.3.1.b24; Java Plug-In 1.3.1_02<br><br>I would be flabbergasted if this is a Java implementation issue; if the sandbox model is broken we're in deep trouble indeed.<br>*****************************************************<br>I too have just gotten rid of the asdf.exe virus (I hope). I use FF 1.0.6 and AOL (using IE 6), so I can't help with which one downloads the file. HiJackThis showed 2 alerts for a file called vtsts.dll I then tracked this through Google to the Download.Trojan virus. Norton found 2 instances of this while in safe mode, including the time.class file. However, after rebooting to normal, I still got pop-ups for winfixer and random searches on Lycos. Remembering that time.class is java, I opened control panel to the Java console and unchecked the option allowing it to be the default Virtual Machine for IE. So far, 3 hours later, no pop-ups. So, at least in my experience so far, the sandbox has indeed been breached.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14268115</guid>
<pubDate>Thu, 01 Sep 2005 03:30:41 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14267644</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I see no ads there. :) Proxo with Sidki's filters. I do see 15 toggle flash notations though. That is real overkill. :( I'm on Opera and I don't even have Flash for it or Fx. If I really want to view flash content on some site, I go use IE ...so I have to really want to see the Flash movie as I have to first lift the killbit for Flash for IE in Spyware Blaster. I think sites are stupid for using so much Flash. <br><SMALL>--<br>Around 2005 a sudden spark will catalyze a Crisis mood. The very survival of the nation will seem to be at stake.Sometime before 2025, America will pass through a great gate in history. The risk and promise will be very high. The Fourth Turning Wm. Straus</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14267644</guid>
<pubDate>Thu, 01 Sep 2005 01:06:18 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14267115</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : It seems The Onion has JUST re-done its entire web site, purposely adding tons more ads and abandoning their paid "Premium" service level.<br><br>They've also gone to some abomination of web design called "sifr" that manages to use the dreaded Flash SWF even more than normal humans thought possible -- for text headlines.  Hitting the page with AdBlock results in dozens of "ADBLOCK" tags next to every darned subheading.<br><br>See more at &raquo;<A HREF="http://www.subtraction.com/archives/2005/0830_making_new_f.php" >www.subtraction.com/archives/200&middot;&middot;&middot;ew_f.php</A><br><br>and discussion at &raquo;<A HREF="http://www.metafilter.com/mefi/44720" >www.metafilter.com/mefi/44720</A><br><br>To block this blatantly evil "sifr" nonsense, add "*/sifr.js" to your AdBlock file.  (Use */sifr.swf to get rid of all of it at The Onion, but the headlines won't appear.)<br><br>And my point is... is this merely coincidence?  I think not.<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14267115</guid>
<pubDate>Wed, 31 Aug 2005 23:53:53 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14266556</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I am running Java 2 Runtime Environment, Standard Edition 1.3.1; Default virtual Machine Version 1.3.1.b24; Java Plug-In 1.3.1_02<br><br>I would be flabbergasted if this is a Java implementation issue; if the sandbox model is broken we're in deep trouble indeed.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14266556</guid>
<pubDate>Wed, 31 Aug 2005 22:44:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14264441</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Gruntled2 and DonoftheDead,<br>Can you tell us what versions of Java you were using?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14264441</guid>
<pubDate>Wed, 31 Aug 2005 18:26:53 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14257282</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : &raquo;<A HREF="http://3dgpu.com/forums/lofiversion/index.php?t4976.html" >3dgpu.com/forums/lofiversion/ind&middot;&middot;&middot;976.html</A><br><br>NOD recognizes it as Win32/trojanDownloader.Small.NEU trojan. <br><br>Jotti's malware scan 2.99-TRANSITION_TO_3.00 <br><br>AntiVir Found TR/Dldr.Small.bhf <br>ArcaVir Found Trojan.Downloader.Small.Bhf <br>Avast Found nothing <br>AVG Antivirus Found nothing <br>BitDefender Found Trojan.Downloader.Small.GJ <br>ClamAV Found nothing <br>Dr.Web Found nothing <br>F-Prot Antivirus Found unknown virus (probable variant) <br>Fortinet Found W32/Dloader.AB-dldr <br>Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Small.bhf <br>NOD32 Found Win32/TrojanDownloader.Small.NEU <br>Norman Virus Control Found Sandbox: W32/Downloader; [ General information ]<br><br>* File length: 1550 bytes.<br><br>[ Changes to filesystem ]<br>* Creates file C:\1.exe.<br><br>[ Network services ]<br>* Downloads file from hXXp://66.159.17.156/rm/w.exe as c:\1.exe.<br><br>[ Security issues ]<br>* Starting downloaded file - potential security problem. <br><br>UNA Found nothing <br>VBA32 Found Trojan-Downloader.Win32.Small.bhf <br><br><B>Funny that cause i had ben trying to run IPCONFIG in the CMD and it never worked. As soon as i let NOD32 clean the Trojan, it works. Thus if you have that file, you may have a Trojan.</B> <br><br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14257282</guid>
<pubDate>Tue, 30 Aug 2005 21:51:40 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14255345</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : There are probably variants of it.<br><br>Perhaps some download spyware and another downloads a trojan...you never know :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14255345</guid>
<pubDate>Tue, 30 Aug 2005 15:35:27 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14255130</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I don't know that it is a keylogger, if I said so, then i was mistaken. It is a very small program that is a downloader stub, and who knows what it drags in if given the chance to execute. The guy who looked at my copy said that the site it downloads from was dead.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14255130</guid>
<pubDate>Tue, 30 Aug 2005 15:05:24 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14255028</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : justin:<br><br>you said in the beginning that this was a keylogger. others have stated that it is a downloader... i know that once it starts downloading things, a keylogger can be installed, but did you ever actually read a description that said it downloaded a keylogger, or did you catch it in the act?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14255028</guid>
<pubDate>Tue, 30 Aug 2005 14:52:17 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254918</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : It is of course always possible that I am mistaken.<br><br>In any event, I have taken the precaution of disabling prefetch. I would urge others to do the same.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254918</guid>
<pubDate>Tue, 30 Aug 2005 14:36:36 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254607</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Well, yes, I suppose prefetch could be used to download a malicious executable or a video of Bin Laden breakdancing, but unless the downloaded files are executed, they can do nothing at all. As far as I know, Firefox does not randomly execute prefetched files, however, and I'm not even sure it prefeches anything but html files. <br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254607</guid>
<pubDate>Tue, 30 Aug 2005 13:55:49 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254463</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by gruntled2 :</SMALL><BR><BR>To reiterate, yet again, I received this file via Firefox 1.0.6, which I have been using since it was released in July.<br><br>-dave<br> </DIV>Yes I know you are reiterating it :) but security is a tricky beast and so are malware and trojans. Unless someone can reproduce the problem with 1.0.6 I'm privately betting you are mistaken for some reason.<br>The installed base of 1.0.6 is large and malware authors react instantly to opportunities. It just doesn't feel like a standard install of 1.0.6(en) is currently vulnerable given the lack of confirmation and continued infection stories.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254463</guid>
<pubDate>Tue, 30 Aug 2005 13:38:40 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254407</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : To reiterate, yet again, I received this file via Firefox 1.0.6, which I have been using since it was released in July.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254407</guid>
<pubDate>Tue, 30 Aug 2005 13:31:15 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254112</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : no this is a red herring. Performance enhancements such as pre-fetech are nothing to do with security vulnerabilities. Whatever was the vector via old versions of firefox (I still feel it cannot be via new versions, as there is not sufficient interest in this infection) it would be nothing to do with any  more recent firefox options that improve rendering speed. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254112</guid>
<pubDate>Tue, 30 Aug 2005 12:47:55 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14254049</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : My point is not that prefetch places a download at root; my point is that prefetch could be used to download a bit of code that then places asdf.exe at c root, and then asdf.exe then attempts to download the payload]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14254049</guid>
<pubDate>Tue, 30 Aug 2005 12:40:38 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14253601</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : You're correct. Prefetch also doesn't download anything to C root. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14253601</guid>
<pubDate>Tue, 30 Aug 2005 11:34:13 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14252954</link>
<description><![CDATA[<A HREF="/useremail/u/1223778"><b>jp10558</b></A> : <div class="bquote"><SMALL>said by Gruntled2 :</SMALL><br><br>I think this could be an issue with prefetch in Mozilla/Firefox. Prefetch is turned on by default in Mozilla/Firefox. Basically, anything marked with a prefetched tag is brought down, and anybody can mark anything with a prefetch tag. To turn prefetching off, go to the address bar and type "about:config" and then scroll down to "network.prefetch-next". Double click on it to change the setting to False.<br> </DIV>But why would that cause the cached items to be able to attempt to make outgoing connections? Surely prefetch doesn't attempt to execute anything it downloads?<br><SMALL>--<br>Opera 8.02(Build 7680); Windows XP Pro SP2;Athlon 64 3400+; 1GB PC3200 DDR; 1M/128k DSL; NOD32(Version 2.5.25); Outpost Pro 2.7;Proxomitron 4.5j Grypen 8/28/05(Opera mod)</A>,GPG ID:0x0A1C6EE3</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14252954</guid>
<pubDate>Tue, 30 Aug 2005 09:58:40 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14252634</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I think this could be an issue with prefetch in Mozilla/Firefox. Prefetch is turned on by default in Mozilla/Firefox. Basically, anything marked with a prefetched tag is brought down, and anybody can mark anything with a prefetch tag. To turn prefetching off, go to the address bar and type "about:config" and then scroll down to "network.prefetch-next". Double click on it to change the setting to False.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14252634</guid>
<pubDate>Tue, 30 Aug 2005 09:01:32 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14247140</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : Another data point.<br><br>Routine scanning of my temp folder found a file 77dwr6zp.zip which contained asdf.exe . It doesn't seems to have being executed though.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14247140</guid>
<pubDate>Mon, 29 Aug 2005 14:18:20 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14243497</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : Ads I see on that fitwatch site:<br><br><div class="code"><PRE><span class="codetext">&lt;!-- FASTCLICK.COM POP-UNDER CODE v1.7e for fitwatch.com --&gt;<br>&lt;script language="javascript"&gt;&lt;!--<br>var doc=document;  var url=escape(doc.location.href); var date_ob=new Date();<br>doc.cookie='h2=o; path=/;';var bust=date_ob.getSeconds();<br>if(doc.cookie.indexOf('e=llo') &lt;= 0 &amp;&amp; doc.cookie.indexOf('2=o') &gt; 0){<br>doc.write('&lt;scr'+'ipt language="javascript" src="http://media.fastclick.net');<br>doc.write('/w/pop.cgi?sid=10991&amp;m=2&amp;v=1.7e&amp;u='+url+'&amp;c='+bust+'"&gt;&lt;/scr'+'ipt&gt;');<br>date_ob.setTime(date_ob.getTime()+43200000);<br>doc.cookie='he=llo; path=/; expires='+ date_ob.toGMTString();} // --&gt;<br>&lt;/script&gt;<br>&lt;!-- FASTCLICK.COM POP-UNDER CODE v1.7e for fitwatch.com --&gt;</SPAN></PRE></DIV><br><div class="code"><PRE><span class="codetext">&lt;!-- FASTCLICK.COM 120x600 and 160x600 SkyScraper CODE for fitwatch.com --&gt;<br>&lt;script language="javascript" src="http://media.fastclick.net/w/get.media?sid=10991&amp;m=3&amp;tp<br> *=7&amp;d=j&amp;t=n"&gt;&lt;/script&gt;<br>&lt;noscript&gt;&lt;a href="http://media.fastclick.net/w/click.here?sid=10991&amp;m=3&amp;c=1" target="_bla<br> *nk"&gt;<br>&lt;img src="http://media.fastclick.net/w/get.media?sid=10991&amp;m=3&amp;tp=7&amp;d=s&amp;c=1"<br>width=160 height=600 border=1&gt;&lt;/a&gt;&lt;/noscript&gt;<br>&lt;!-- FASTCLICK.COM 120x600 and 160x600 SkyScraper CODE for fitwatch.com --&gt;<br><br>(*) WARNING 2 long line(s) split</SPAN></PRE></DIV><br><div class="code"><PRE><span class="codetext">&lt;!-- FASTCLICK.COM 468x60 v1.4 for fitwatch.com --&gt;<br>&lt;script language="Javascript"&gt;&lt;!--<br>var i=j=p=t=u=x=z=dc='';var id=f=0;var f=Math.floor(Math.random()*7777);<br>id=10991; dc=document;u='ht'+'tp://media.fastclick.net/w'; x='/get.media?t=n';<br>z=' width=468 height=60 border=0 ';t=z+'marginheight=0 marginwidth=';<br>i=u+x+'&amp;sid='+id+'&amp;m=1&amp;f=b&amp;v=1.4&amp;c='+f+'&amp;r='+escape(dc.referrer);<br>u='&lt;a  hr'+'ef="'+u+'/click.here?sid='+id+'&amp;m=1&amp;c='+f+'"  target="_blank"&gt;';<br>dc.writeln('&lt;ifr'+'ame src="'+i+'&amp;d=f"'+t+'0 hspace=0 vspace=0 frameborder=0 scrolling=no&gt;<br> *');<br>if(navigator.appName.indexOf('Mic')&lt;=0){dc.writeln(u+'&lt;img src="'+i+'&amp;d=n"'+z+'&gt;&lt;/a&gt;');}<br>dc.writeln('&lt;/iframe&gt;'); // --&gt;&lt;/script&gt;&lt;noscript&gt;<br>&lt;a href="http://media.fastclick.net/w/click.here?sid=10991&amp;m=1&amp;c=1"  target="_blank"&gt;<br>&lt;img src="http://media.fastclick.net/w/get.media?sid=10991&amp;m=1&amp;d=s&amp;c=1&amp;f=b&amp;v=1.4"<br>width=468 height=60 border=1&gt;&lt;/a&gt;&lt;/noscript&gt;<br>&lt;!-- FASTCLICK.COM 468x60 v1.4 for fitwatch.com --&gt;<br><br>(*) WARNING 1 long line(s) split</SPAN></PRE></DIV><br>I will take a look at these ads, to see if there's any suspicious code.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14243497</guid>
<pubDate>Sun, 28 Aug 2005 23:19:16 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14242739</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Should have also noted that the "Allow web sites to install software" option is not checked.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14242739</guid>
<pubDate>Sun, 28 Aug 2005 21:40:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14242527</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : While I keep javascript disabled in IE, I have enabled both Java and Javascript in Firefox.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14242527</guid>
<pubDate>Sun, 28 Aug 2005 21:06:46 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14242475</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : Thanks for coming back :) Do you have java and/or javascript enabled and on that day?<br><br>Cudni<br><SMALL>--<br>What is now proved was once only imagined.</BR>Help yourself so God can help you</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14242475</guid>
<pubDate>Sun, 28 Aug 2005 21:00:36 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14242459</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Apologies; I'm the guy who posted the report about 1.0.6 being vulnerable; I had to race out of town for a family emergency Friday and just now regained Internet access. Here are the details: My box is WinXP AMD Althon with all critical patches installed. The system is running both anti-virus and a software firewall (behind a hardware firewall). I've been running Firefox 1.0.6 since it was released in July. On Wednesday, August 24, I went to &raquo;<A HREF="http://www.fitwatch.com/caloriecounter.html" >www.fitwatch.com/caloriecounter.html</A> to find out how many calories in a large order of fries (long story). Other common vectors, such as mail or instant mesaging were not active. Moments after visiting the site, my software firewall reported that asdf.exe was trying to access the Internet. I denied access and began researching the issue. After concluding that I could safely delete the files, I did so. <br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14242459</guid>
<pubDate>Sun, 28 Aug 2005 20:58:54 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14241979</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <br>It really bothers me that we're five pages into this and 3.6 gazillion page views and search hits, and we have almost no documentation or live samples, other than the "dead" issue reported by the kind BOClean folks (and thank you for that guys).<br><br>I would ask Kevin to return to the thread long enough to answer some of the seemingly valid questions his report raises, particularly regarding the infection vector and what version(s) of what browser(s) may still be vulnerable to this effect.<br><br>And to the contrary, if the vector is NOT a new one, then please simply let us know which one it was....<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14241979</guid>
<pubDate>Sun, 28 Aug 2005 19:53:10 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14241065</link>
<description><![CDATA[<A HREF="/useremail/u/1039629"><b>DonoftheDead</b></A> : Just an update. I upgraded Suse and FF during the during installation. I didn't go on the Net until FF was v1.0.6. I never let FF d/l any plugins when it asks. I went to a Kaffeine d/l site and tried to d/l a plug-in. It didn't d/l the file I wanted, but it did drop asdf.exe on my box. Went back to site today. No problem. D/l'ed files I wanted without a hitch. Maybe it's over, now, with the "bad server" taken down. Could it be the Linux ver. of FF1.0.6 is vulnerable, the Windows ver. of FF1.0.6 isn't? Not an expert, just asking. Certainly a weird form of malware. Would like to know how it got on my Suse9.2 box. Not worried, just curious.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14241065</guid>
<pubDate>Sun, 28 Aug 2005 17:44:20 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14240588</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : It is funny how one problem with an older version of the browser (I don't buy that the problem is 1.0.6 yet) has someone declaring the poor state of firefox security when new versions of the full default install of IE are hacked almost monthly :)<br><br>By the way, searches for asdf.exe hitting this topic are 50% MSIE (latest version) and 50% firefox. Of the 50% firefox, 50% are older versions doing the search. Many of the 1.0.6 visitors are curious visitors from topics at mozillazine, etc.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14240588</guid>
<pubDate>Sun, 28 Aug 2005 16:28:08 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14238927</link>
<description><![CDATA[<A HREF="/useremail/u/346145"><b>barky</b></A> : In my experience, most people switched to FF because it was generally considered to be a "secure" browser. In fact, I clearly remember the average DSLR FF advocate using security as the number one reason to switch from IE. I've setup plenty of non tech savy people with FF, because I believed it to be fairly secure. With the number of advisories comming out on FF, and now this issue, I won't be recommending FF as an IE replacement anymore. I think the fox had its time, but popular use has caught up with it. I really like that FF is standards compliant, but it lacks mature development on the security side. I've had good luck with IE locked down (Avant is my primary), but still use FF for web development (and still will). Personally, I'm a little scared to browse the innerweb on the fox now.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14238927</guid>
<pubDate>Sun, 28 Aug 2005 12:24:17 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237946</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : I don't think it's very patronizing to acknowledge the fact most users don't know even the basics of computer security, nor that when software has flaws, software companies should fix them as soon as possible. The John and Jane Users that know me personally seem fairly grateful of my help, and after listening to me, they seldom need any help again. <br><br>DCS ProcessGuard is a very good tool in the right hands, and I own a license. However, for the average user that doesn't know that mssmgs.exe is malware instead of a legit application, ProcessGuard isn't nearly as useful. It's not a panacea. As for BOClean, yes, I have seen cases where people have gotten infected running BOClean. BOClean is a well-regarded anti-malware, but it's not perfect - nothing is. <br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237946</guid>
<pubDate>Sun, 28 Aug 2005 08:48:34 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237904</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I may be "eccentric" ;) but you are the patronizing one. :) I wouldn't want to be Jane or John Doe and know you. <br><br>As for BoClean and Process Guard, they come as close as possible to being "god" as any security device ever has. Have you ever heard of anyone running BoClean who got infected? <br><SMALL>--<br>Around 2005 a sudden spark will catalyze a Crisis mood. The very survival of the nation will seem to be at stake.Sometime before 2025, America will pass through a great gate in history. The risk and promise will be very high. The Fourth Turning Wm. Straus</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237904</guid>
<pubDate>Sun, 28 Aug 2005 08:34:03 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237874</link>
<description><![CDATA[<A HREF="/useremail/u/984597"><b>sybille</b></A> : Interesting info,  Cudni <A HREF="/useremail/u/917630"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, thanks.<br><br>Looking at the list, it seems to me that although the advisory has been updated, it still does not concern releases of Firefox after 1.0.4. So the current release, 1.0.6, ought to be OK.<br><br>Another reason to keep things updated.....:)<br><br>Edit: but I guess this would not account for what  DonoftheDead <A HREF="/useremail/u/1039629"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> has reported?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237874</guid>
<pubDate>Sun, 28 Aug 2005 08:24:35 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237873</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Most folks use Fx because they like it. Security isn't that important of a reason to use Fx. It is NOT the reason people use Fx. If I liked IE, I would use it. Simple as that. I don't like IE. I like Fx but not a great deal. It is better though than IE. Mozilla is the best browser but it lacks an essential extension. Opera costs too much. Which is the most secure? I don't know and don't care. Fx does itself harm by this campaign to claim it is superior security wise.<br><br>If I was as concerned as you appear to be, I would simply buy BoClean and be done with it. :) (Oh...and of course make sure I have either Process Guard or KIS 2006 which has a Process Guard).<br> </DIV>Riiiight. I suppose no one has changed from IE to Fx because Fx is, or was, less vulnerable to drive-by-downloads of badware of the day than IE. Fact is, many people do use Fx because they think it's more secure than IE. You have an annoying habit of trying to project your own, often quite eccentric, opinions on other people. Just because you don't use Fx for security reasons doesn't mean other people don't, either. <br><br>I'm not concerned for my own security, which I feel confident in, but I am concerned for the security of John and Jane User. BOClean is no computer security Jesus, protecting from all malware known to man. If there's a hole in Fx that can be fixed, it should be fixed as soon as possible to protect users. Simple as that. Since this would seem to be the (one of) the first cases of drive-by-downloads in Fx, this is an important issue that deserves all the attention it can get.<br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237873</guid>
<pubDate>Sun, 28 Aug 2005 08:24:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237821</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Most folks use Fx because they like it. Security isn't that important of a reason to use Fx. It is NOT the reason people use Fx. If I liked IE, I would use it. Simple as that. I don't like IE. I like Fx but not a great deal. It is better though than IE. Mozilla is the best browser but it lacks an essential extension. Opera costs too much. Which is the most secure? I don't know and don't care. Fx does itself harm by this campaign to claim it is superior security wise.<br><br>If I was as concerned as you appear to be, I would simply buy BoClean and be done with it. :) (Oh...and of course make sure I have either Process Guard or KIS 2006 which has a Process Guard).<br><SMALL>--<br>Around 2005 a sudden spark will catalyze a Crisis mood. The very survival of the nation will seem to be at stake.Sometime before 2025, America will pass through a great gate in history. The risk and promise will be very high. The Fourth Turning Wm. Straus</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237821</guid>
<pubDate>Sun, 28 Aug 2005 07:55:49 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237806</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : &raquo;<A HREF="http://www.securityfocus.com/bid/14242/discuss" >www.securityfocus.com/bid/14242/discuss</A><br>"..<br>The Mozilla Foundation has released 12 security advisories specifying security vulnerabilities in Mozilla Suite, Firefox, and Thunderbird.<br><br>These vulnerabilities allow attackers to execute arbitrary machine code in the context of the vulnerable application, bypass security checks, execute script code in the context of targeted Web sites to disclose confidential information; other attacks are also possible. .."<br><br>and<br>&raquo;<A HREF="http://www.securityfocus.com/bid/14242/info" >www.securityfocus.com/bid/14242/info</A><br><br>Cudni<br><SMALL>--<br>What is now proved was once only imagined.</BR>Help yourself so God can help you</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237806</guid>
<pubDate>Sun, 28 Aug 2005 07:46:32 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237794</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : I strongly disagree. If this malware isn't functional anymore, that doesn't mean the exploit used by it isn't a very serious problem. Users of Firefox mostly have a strong faith in the security of their browser, and since this exploit seems to affect even the most up-to-date versions of Fx, it's a very critical problem. Any other malware could use the same exploits used here, even if asdf.exe is non-risk. This is a very serious problem, and the exploit needs to be identified and the vulnerability patched asap.<br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237794</guid>
<pubDate>Sun, 28 Aug 2005 07:41:49 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237772</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : Thanks for the info. Do you know how the file gets dropped on the system?<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237772</guid>
<pubDate>Sun, 28 Aug 2005 07:31:49 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237751</link>
<description><![CDATA[<A HREF="/useremail/u/898206"><b>K McAleavey</b></A> :  Sorry to see this is still ongoing. We looked into this several days ago, and it's a dead file, although we covered it anyway. I'm going to post SPECIFICS since the link is *dead* and cannot function.<br><br> "ASDF.EXE" is hard-coded to go to a specific IP and download a specific file. When first discovered a few days ago, the site was torn down and the IP itself is "unassigned" and therefore SAFE to specify here ...<br><br> ASDF is a downloader which attempts to retrieve:<br><br>&raquo;<A HREF="http://66.159.17.156/rm/w.exe" >66.159.17.156/rm/w.exe</A><br><br>W.EXE is "VXGAME15" as known to BOClean, a "casino" hijacker which would have installed "SORTED LINKS" (associated with IST) on the affected machine, replete with desktop icons and all for "Poker" and some porn sites. No desktop icons, no infection. "VXGAME" was a little IST escapade to find the most talented script kiddies who could write "undetectables" and was part of a rather large contest to see who could infect the most and the fastest. Contest remains ongoing, and the "VXGAME" and "VXDIALER" series of events are continuing.<br><br>66.159.17.156 was registered to:<br><br>Williams Communications, Incorporated WCG-BLK-2 (NET-66-159-0-0-1) <br>                                  66.159.0.0 - 66.159.31.255<br>IIC Internet WLCO-TWC874610-IICINT (NET-66-159-16-0-1) <br>                                  66.159.16.0 - 66.159.20.255<br><br># ARIN WHOIS database, last updated 2005-08-27 19:10<br><br> Upon notification of the activities to Williams Communications, the site was torn down within 30 minutes and GONE.<br><br> So if the file exists, just delete it, nothing to see here and we covered the downloader as well as what it wanted to download. Game over for these kids at least. Bottom line, no risk anymore. Usual suspects, nothing to see.  :)<br><SMALL>--<br>Kevin McAleavey support@nsclean.com (Makers of BOClean anti-malware protection)&raquo;<A HREF="http://www.nsclean.com" >www.nsclean.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237751</guid>
<pubDate>Sun, 28 Aug 2005 07:19:02 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237242</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : <div class="bquote"><SMALL>said by AnonymousAnderson :</SMALL><BR><BR>Hey guys,<br><br>I found asdf.exe in my c:\ directory, I've been using both IE and Firefox all day and both have crashed at some stage in the day so I couldn't tell you which dropped the file in there.<br><br>Upshot: even after deleting asdf.exe ipconfig is broken and won't run properly (running ipconfig /all just flashes a blank MS-DOS box on the screen for a second).<br><br>Any ideas?<br> </DIV>If the file should reappear PLEASE submit it for analysis by following the guidelines here: &raquo;<A HREF="/faq/security/8428#submit">Security</A><br><br>Thanks :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237242</guid>
<pubDate>Sun, 28 Aug 2005 02:26:58 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14237013</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hey guys,<br><br>I found asdf.exe in my c:\ directory, I've been using both IE and Firefox all day and both have crashed at some stage in the day so I couldn't tell you which dropped the file in there.<br><br>Upshot: even after deleting asdf.exe ipconfig is broken and won't run properly (running ipconfig /all just flashes a blank MS-DOS box on the screen for a second).<br><br>Any ideas?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14237013</guid>
<pubDate>Sun, 28 Aug 2005 01:27:55 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14234432</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : I wrote a filter for this<br><br>This will work unless they have used Javascript to break up the sentence structure, or they have encoded it :(<br><br>It's very hard to match encoded/broken up versions, but I'll try to revise the filter.<br><br>EDIT: Made it somehow match broken up versions.<br><br>Since whatever's after name and src can be anything, I'm focusing on the name and src tags themselves.<br><br>For example, if iframe's name tag is broken up as<br><br><div class="code"><PRE><span class="codetext">document.write ('na');<br>document.write ('me');</SPAN></PRE></DIV><br>or<br><br><div class="code"><PRE><span class="codetext">document.write ('n');<br>document.write ('a');<br>document.write ('m');<br>document.write ('e');</SPAN></PRE></DIV><br>or<br><br><div class="code"><PRE><span class="codetext">document.write ('nam');<br>document.write ('e');</SPAN></PRE></DIV><br>Similarily, iframe's src tag will be detected if it's broken up as:<br><br><div class="code"><PRE><span class="codetext">document.write ('sr');<br>document.write ('c');</SPAN></PRE></DIV><br><div class="code"><PRE><span class="codetext">document.write ('s');<br>document.write ('r');<br>document.write ('c');</SPAN></PRE></DIV><br>It may produce some false positives, but still, who would make a website contain one of the above combinations?<br><br>Let me tell you, this filter's not going to be nice to look at ;)<br><br>I will work now on encoded versions of "name=" and "src="<br><br>EDIT2: Now matches hex encoded "name" and "src"<br><br>'%6E%61%6D%65' = 'name' in hex<br><br>Matches:<br><br><div class="code"><PRE><span class="codetext">document.write( unescape ('%6E%61%6D%65') );</SPAN></PRE></DIV><br><div class="code"><PRE><span class="codetext">document.write( unescape ('%6E%61') );<br>document.write( unescape ('%6D%65') );</SPAN></PRE></DIV><br>Etc...<br><br>EDIT3: Now matches Unicode<br><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/882701~c76b9e137a9901de55a64226422f2c90/filter.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>filter.zip</big></A> <small>552 bytes</small><br>Proxomitron Filter<br><small>(filter.txt)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14234432</guid>
<pubDate>Sat, 27 Aug 2005 17:24:33 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14234058</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : Did some research: http://www.lurhq.com/iframeads.html<br><br>"IFRAME Vulnerability Being Exploited Through Banner Ads"<br><br>Could this be the method asdf.exe is being downloaded?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14234058</guid>
<pubDate>Sat, 27 Aug 2005 16:13:07 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233546</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : For what it is worth only one anon referer so far (last twenty minutes) has firefox (1.0.1), the rest (19 of them) are using IE 6.0. All were searching google for asdf.exe info.<br><br>I suppose asdf.exe is a popular downloader now, involved in more than one exploit, not specifically a firefox/opera thing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233546</guid>
<pubDate>Sat, 27 Aug 2005 14:36:15 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233497</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : Ah, I see...<br><br>Well, if anyone knows of a specific URL that is serving asdf.exe, tell me ;)<br><br>EDIT: I have written this Proxomitron filter to detect ASDF (to aid my search):<br><br><div class="code"><PRE><span class="codetext">&#91;Patterns&#93;<br>Name = "ASDF hunter"<br>Active = TRUE<br>Limit = 4<br>Match = "asdf"<br>Replace = "asdf"<br>          "$ALERT(asdf detected on:\n\n\u)"</SPAN></PRE></DIV><br>I've also disabled URL Filtering on my IPCop server, disabled AdBlock and NoScript and disabled my HOSTS file. We'll see how it goes.<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233497</guid>
<pubDate>Sat, 27 Aug 2005 14:27:35 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233434</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  KyeU <A HREF="/useremail/u/923463"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Did anyone ever discover the code to this exploit?<br><br>I'm doing some searching of my own right now, but it'd save me lots of time if someone already got the exploit code stored up somewhere :)<br> </DIV>Not that I know of. People tend to find asdf.exe after they have visited several pages, or a page that has ad-server rotation. So going back doesn't necessarily re-infect.<br><br>I would imagine if you know a site is serving the bad page you can trigger it eventually, and capture the URLS involved. That is, if they are still up and infecting.<br><br>Anon referers to this topic are still growing (sorry to those that could not read page 2 due to an anon reader forum display bug here!) but a lot of them are referers from topics at security forums pointing here, rather than actual newly infected.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233434</guid>
<pubDate>Sat, 27 Aug 2005 14:18:14 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233359</link>
<description><![CDATA[<A HREF="/useremail/u/923463"><b>KyeU</b></A> : Did anyone ever discover the code to this exploit?<br><br>I'm doing some searching of my own right now, but it'd save me lots of time if someone already got the exploit code stored up somewhere :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233359</guid>
<pubDate>Sat, 27 Aug 2005 14:07:52 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233225</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  RobertLudlum <A HREF="/useremail/u/1143581"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote">The referrer views on this topic are still growing. I believe they are from people with older versions of firefox.<br> </DIV>You're getting the useragents from the servers logs? Curiouser and curiouser.<br> </DIV>No, But I just turned on something that will be collecting exact user agents for people who google this topic. We'll see what it says by the end of today.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233225</guid>
<pubDate>Sat, 27 Aug 2005 13:48:26 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14233191</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  Tuulilapsi <A HREF="/useremail/u/665380"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><BR><BR>What about this, then?<br><br> <BLOCKQUOTE><SMALL>said by Donofthedead :</SMALL><HR>I was running Suse 9.2,FF 1.0.6. and got one of these dropped in my home directory as user. I forgot to mention I had my settings at: Java and javascript turned on, install s/w turned off, Load images on (for originating site off), Block Popups on. A javascript thing ?<HR></BLOCKQUOTE><br> </DIV>Hm, that is correct, I was thinking windows. but perhaps the asdf.exe was there from before. Before the firefox upgrade? The timestamp on asdf.exe is key.<br><br>The anon user posted in mozillazine as well:<br>&raquo;<A HREF="http://forums.mozillazine.org/viewtopic.php?t=310439" >forums.mozillazine.org/viewtopic&middot;&middot;&middot;t=310439</A><br>that he "confirms" that asdf.exe can be downloaded by 1.0.6]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14233191</guid>
<pubDate>Sat, 27 Aug 2005 13:44:01 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232903</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>One disappointing note: I wrote to theonion.com pointing out that this was a problem, giving them most of the info they would need to complain to whatever advertising network they use.<br> </DIV>Well visiting the site with adblock shows the possible source as &raquo;<A HREF="http://adtrafficmp.com" >adtrafficmp.com</A> . It's already blocked with Adblock+ filtersetg . Possibly any decent regexp filter will catch it too. Not sure about hosts lists, probably blocked already.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232903</guid>
<pubDate>Sat, 27 Aug 2005 12:52:57 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232658</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I don't yet believe it can attack firefox 1.0.6 - one anonymous post here, with no detail, is no confirmation AT ALL that 1.0.6 has such a major problem.<br><br>Especially since people have asked the anonymous person for <br>details and none are forthcoming.<br></DIV>Well Donofthedead reported it on Suse 9.2,FF 1.0.6. <br><br><div class="bquote">The referrer views on this topic are still growing. I believe they are from people with older versions of firefox.<br> </DIV>You're getting the useragents from the servers logs? Curiouser and curiouser.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232658</guid>
<pubDate>Sat, 27 Aug 2005 12:15:39 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232657</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : What about this, then?<br><br> <BLOCKQUOTE><SMALL>said by Donofthedead :</SMALL><HR>I was running Suse 9.2,FF 1.0.6. and got one of these dropped in my home directory as user. I forgot to mention I had my settings at: Java and javascript turned on, install s/w turned off, Load images on (for originating site off), Block Popups on. A javascript thing ?<HR></BLOCKQUOTE><br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232657</guid>
<pubDate>Sat, 27 Aug 2005 12:15:34 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232605</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  RobertLudlum <A HREF="/useremail/u/1143581"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>If Noscript doesn't and it works on firefox (latest version) and more, then we are really facing a serious threat here.<br> </DIV>I don't yet believe it can attack firefox 1.0.6 - one anonymous post here, with no detail, is no confirmation AT ALL that 1.0.6 has such a major problem.<br><br>Especially since people have asked the anonymous person for details and none are forthcoming.<br><br>The referrer views on this topic are still growing. I believe they are from people with older versions of firefox.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232605</guid>
<pubDate>Sat, 27 Aug 2005 12:07:10 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232563</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by  richrf <A HREF="/useremail/u/150641"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Hi,<br><br>As far as I have been able to glean so far from this thread, ProcessGuard was able to detect and stop this exploit. Is this correct? Also, has anyone determined whether the FireFox extension NoScript is able to stop this exploit? Thanks for any info.<br> </DIV>It seems that it's not really catching the specific exploit , rather it's noticing an unknown process that hasn't being whitelisted starting. <br><br>This exploit is probably javascript or Java based, so Noscript should stop it. If Noscript doesn't and it works on firefox (latest version) and more, then we are really facing a serious threat here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232563</guid>
<pubDate>Sat, 27 Aug 2005 11:58:11 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232357</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>I use Process Guard and Fx 1.0PR on my host box (1.0.6 on my virtual box). I also use Proxo on both boxes. If this is coming from ads...well, I don't see ads.  I'm not convinced I need to upgrade Fx and I used RIP to permanently zap the ad here telling me I need to upgrade Fx.<br>--<HR></BLOCKQUOTE><br><br>You probably already know this but RIP hides the Ads it doesn't really stop them from being downloaded unlike Adblock.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232357</guid>
<pubDate>Sat, 27 Aug 2005 11:16:15 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232330</link>
<description><![CDATA[<A HREF="/useremail/u/839237"><b>purelander</b></A> : <div class="bquote"><SMALL>said by  richrf <A HREF="/useremail/u/150641"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Hi,<br><br>As far as I have been able to glean so far from this thread, ProcessGuard was able to detect and stop this exploit. Is this correct? Also, has anyone determined whether the FireFox extension NoScript is able to stop this exploit? Thanks for any info.<br> </DIV>the exploit comes from the ad-servers, so the best defence is to use hpguru host file, or ad blocking programs that use Eric   Howes's block lists. there is nothing better than blocking the ad hosts.<br><SMALL>--<br>"I'm sure we all agree that we ought to love one another, and I know there are people in the world that do not love their fellow human beings , and I hate people like that!" - Tom Lehrer</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232330</guid>
<pubDate>Sat, 27 Aug 2005 11:10:40 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14232130</link>
<description><![CDATA[<A HREF="/useremail/u/150641"><b>richrf</b></A> : Hi,<br><br>As far as I have been able to glean so far from this thread, ProcessGuard was able to detect and stop this exploit. Is this correct? Also, has anyone determined whether the FireFox extension NoScript is able to stop this exploit? Thanks for any info.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14232130</guid>
<pubDate>Sat, 27 Aug 2005 10:23:46 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14231128</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : is there a good writeup on what asdf.exe is and what it does? i know i've seen it before on a computer i cleaned, but i don't remember finding lots of info on it.<br><br>-jig]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14231128</guid>
<pubDate>Sat, 27 Aug 2005 02:19:32 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14231043</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I'd also like to know if adblocking stops it. I bet it doesn't get through Proxo with current configs from Sidki, Grypen, etc.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14231043</guid>
<pubDate>Sat, 27 Aug 2005 01:55:05 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14230756</link>
<description><![CDATA[<A HREF="/useremail/u/526408"><b>jimmie</b></A> : <div class="bquote"><SMALL>said by  jp10558 <A HREF="/useremail/u/1223778"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote">What I don't get is how this would be run via Opera... I've never had Opera autorun anything in my entire experiance with it. Also, is adblocking a mitigating factor with this?<br> </DIV>I don't know it came through opera, just that it did not come through firefox. Security on this system is lacking, no real time virus or spyware protection,just a linksys router and windows firewall. It was also a couple of months behind on critical updates at the time. I didn't find the asdf.exe until a couple of days after it was created and am not sure what would have been happening at that time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14230756</guid>
<pubDate>Sat, 27 Aug 2005 00:50:28 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14226802</link>
<description><![CDATA[<A HREF="/useremail/u/1039629"><b>DonoftheDead</b></A> : I was running Suse 9.2,FF 1.0.6. and got one of these dropped in my home directory as user. I forgot to mention I had my settings at: Java and javascript turned on, install s/w turned off, Load images on (for originating site off), Block Popups on. A javascript thing ?<br>Edit: I was all over the the Net looking for text files on what were secure sites dealing with FAH(which I believe is not the source). But I was going to non-FAH sites that looked ok. I went to a site to d/l and Lib file and a text file. I believe I could have gotten it there. It was the ony site where I d/l'ed anything.FWIW:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14226802</guid>
<pubDate>Fri, 26 Aug 2005 14:46:03 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14226686</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Correct, Ezboards serve (a lot of) ads. We need confirmation on the Javascript settings of those who got infected just to be sure this is a script exploit. If this affects Opera as well, then it's really getting interesting. <br><br>I've been on lookout for asdf.exe, running a Firefox 1.03 here (dug it up from my so called archives), but so far I haven't found diddly squat. It's typical, really. When you want to get infected, you won't, but when you least expect it...<br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14226686</guid>
<pubDate>Fri, 26 Aug 2005 14:31:57 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14226356</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : this might have been going on for awhile<br>&raquo;<A HREF="http://p103.ezboard.com/fezboardfrm98.showMessageRange?topicID=2646.topic&start=1&stop=20" >p103.ezboard.com/fezboardfrm98.s&middot;&middot;&middot;&stop=20</A><br>"...<br> Some of our people got infected and some did not.<br><br>We have managed to glean the following.<br><br>Some did not get infected because their antivirus warned them of a trojan attack.<br><br>Some only got asdf.exe and not the other two files.<br><br>Others got all three files. asdf.exe, 1.exe and w.exe. ..."<br><br>edit: and a FF got infected on that board. ezboard serves adds does it not?<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14226356</guid>
<pubDate>Fri, 26 Aug 2005 13:45:45 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14226353</link>
<description><![CDATA[<A HREF="/useremail/u/1223778"><b>jp10558</b></A> : <div class="bquote"><SMALL>said by  jimmie <A HREF="/useremail/u/526408"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Not sure about firefox. asdf.exe was dropped onto my C drive (not my system drive) and I do not use firefox. I didn't know it was there until a couple of days later when I opened IE (I use opera 8.02) and got a popup which led me to find a bho named pmnno.dll which could not be deleted even in safemode. A scan picked up asdf.exe which may or may not be related as the pmnno.dll was not created until I opened IE.<br> </DIV>What I don't get is how this would be run via Opera... I've never had Opera autorun anything in my entire experiance with it. Also, is adblocking a mitigating factor with this?<br><SMALL>--<br>Opera 8.02(Build 7680); Windows XP Pro SP2;Athlon 64 3400+; 1GB PC3200 DDR; 1M/128k DSL; NOD32(Version 2.5.25); Outpost Pro 2.7;Proxomitron 4.5j Grypen 7/26/05(Opera mod)</A>,GPG ID:0x0A1C6EE3</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14226353</guid>
<pubDate>Fri, 26 Aug 2005 13:45:28 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14226016</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : Could you expand a bit more on your confirmation of FF exploit?<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14226016</guid>
<pubDate>Fri, 26 Aug 2005 12:58:45 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225998</link>
<description><![CDATA[<A HREF="/useremail/u/526408"><b>jimmie</b></A> : Just saying that it's not only firefox.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225998</guid>
<pubDate>Fri, 26 Aug 2005 12:56:50 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225971</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I can confirm this exploit affects Firefox 1.0.6.<br><br>-dave]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225971</guid>
<pubDate>Fri, 26 Aug 2005 12:52:29 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225970</link>
<description><![CDATA[<A HREF="/useremail/u/526408"><b>jimmie</b></A> : Not sure about firefox. asdf.exe was dropped onto my C drive (not my system drive) and I do not use firefox. I didn't know it was there until a couple of days later when I opened IE (I use opera 8.02) and got a popup which led me to find a bho named pmnno.dll which could not be deleted even in safemode. A scan picked up asdf.exe which may or may not be related as the pmnno.dll was not created until I opened IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225970</guid>
<pubDate>Fri, 26 Aug 2005 12:52:26 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225759</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  Cudni <A HREF="/useremail/u/917630"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>i make 286 referrers in that post ;)<br><br>Cudni<br> </DIV>Yeah and don't forget that is only those who recognized the infection perhaps through zone alarm, and searched google or whatever, and clicked the link to this topic.<br>I would guess that for every 1 that did that, there are 10 that didn't catch it or if they did, didn't visit this topic. A lot of people use firefox now but still don't bother with zonealarm or processguard, or click 'yes' to everything zonealarm says.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225759</guid>
<pubDate>Fri, 26 Aug 2005 12:25:05 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225741</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : i make 286 referrers in that post ;)<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225741</guid>
<pubDate>Fri, 26 Aug 2005 12:22:17 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225738</link>
<description><![CDATA[<A HREF="/useremail/u/517760"><b>catseyenu</b></A> : Ouch! :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225738</guid>
<pubDate>Fri, 26 Aug 2005 12:21:49 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14225667</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : Inbound referrers today for this topic, all searching about asdf.exe (the links are truncated don't bother clicking em)<br><br>30 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=mozilla-sea" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;illa-sea</A>..<br>28 &raquo;<A HREF="http://www.google.com/search?hl=en&q=asdf.exe&btng=google+se" >www.google.com/search?hl=en&q=as&middot;&middot;&middot;oogle+se</A>..<br>16 &raquo;<A HREF="http://www.google.com/search?hl=en&q=asdf.exe" >www.google.com/search?hl=en&q=asdf.exe</A><br>13 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&sm=yahoo%21+search" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;1+search</A>..<br>6 &raquo;<A HREF="http://www.google.co.uk/search?hl=en&q=asdf.exe&btng=google+" >www.google.co.uk/search?hl=en&q=&middot;&middot;&middot;=google+</A>..<br>6 &raquo;<A HREF="http://forums.stltoday.com/viewtopic.php?t=282847" >forums.stltoday.com/viewtopic.php?t=282847</A><br>5 &raquo;<A HREF="http://www.google.com/search?client=firefox-a&rls=org.mozill" >www.google.com/search?client=fir&middot;&middot;&middot;g.mozill</A>..<br>5 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&fr=fp-tab-web-t&to" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;web-t&to</A>..<br>4 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&ei=utf-8&fr=fp-tab" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;r=fp-tab</A>..<br>4 &raquo;<A HREF="http://www.google.ca/search?hl=en&q=asdf.exe&meta=" >www.google.ca/search?hl=en&q=asdf.exe&meta=</A><br>4 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe" >www.google.com/search?hl=en&lr=&q=asdf.exe</A><br>4 &raquo;<A HREF="http://www.google.com/search?sourceid=mozclient&ie=utf-8&oe=" >www.google.com/search?sourceid=m&middot;&middot;&middot;tf-8&oe=</A>..<br>4 &raquo;<A HREF="http://www.google.fi/search?hl=fi&q=asdf.exe&btng=google-hak" >www.google.fi/search?hl=fi&q=asd&middot;&middot;&middot;ogle-hak</A>..<br>3 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&prssweb=search&ei=" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;arch&ei=</A>..<br>3 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe&btng=searc" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;ng=searc</A>..<br>3 &raquo;<A HREF="http://www.google.com/search?hl=en&q=win32.sillydl.tq&btng=g" >www.google.com/search?hl=en&q=wi&middot;&middot;&middot;q&btng=g</A>..<br>3 &raquo;<A HREF="http://www.google.co.uk/search?q=asdf.exe&sourceid=mozilla-s" >www.google.co.uk/search?q=asdf.e&middot;&middot;&middot;ozilla-s</A>..<br>3 &raquo;<A HREF="http://www.google.co.uk/search?hl=en&q=asdf.exe&meta=" >www.google.co.uk/search?hl=en&q=&middot;&middot;&middot;xe&meta=</A><br>2 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&ei=utf-8&fr=fp-tab" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;r=fp-tab</A>..<br>2 &raquo;<A HREF="http://www.google.ca/search?hl=en&q=asdf.exe&btng=google+sea" >www.google.ca/search?hl=en&q=asd&middot;&middot;&middot;ogle+sea</A>..<br>2 &raquo;<A HREF="http://www.google.com/search?q=win32.sillydl.tq&sourceid=moz" >www.google.com/search?q=win32.si&middot;&middot;&middot;ceid=moz</A>..<br>2 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>2 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&hl=en&lr=&start=0&sa" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;art=0&sa</A>..<br>2 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe" >www.google.com/search?q=asdf.exe</A><br>2 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient-ff&ie=utf-8&" >www.google.com/search?sourceid=n&middot;&middot;&middot;e=utf-8&</A>..<br>2 &raquo;<A HREF="http://search.yahoo.com/bin/search?p=win32.sillydl.tq" >search.yahoo.com/bin/search?p=wi&middot;&middot;&middot;llydl.tq</A><br>2 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>2 &raquo;<A HREF="http://www.google.es/search?sourceid=navclient&hl=es&q=asdf%" >www.google.es/search?sourceid=na&middot;&middot;&middot;&q=asdf%</A>..<br>2 &raquo;<A HREF="http://www.google.com/search?sourceid=mozclient&ie=utf-8&oe=" >www.google.com/search?sourceid=m&middot;&middot;&middot;tf-8&oe=</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&sm=yahoo%21+search" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;1+search</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?ei=utf-8&fr=slv1-&p=asdf.exe" >search.yahoo.com/search?ei=utf-8&middot;&middot;&middot;asdf.exe</A><br>1 &raquo;<A HREF="http://www.comcast.net/qry/websearch?cmd=qry&safe=on&query=g" >www.comcast.net/qry/websearch?cm&middot;&middot;&middot;&query=g</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=+asdf.exe&sourceid=mozilla-se" >www.google.com/search?q=+asdf.ex&middot;&middot;&middot;zilla-se</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&ie=iso-8859-1&safe=of" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;&safe=of</A>..<br>1 &raquo;<A HREF="http://it.search.yahoo.com/search?p=dldr.small.bhf&ei=utf-8" >it.search.yahoo.com/search?p=dld&middot;&middot;&middot;ei=utf-8</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=virus+%22asdf.exe%2" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;df.exe%2</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=mozilla-sea" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;illa-sea</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=%22asdf.exe%22&sourceid=mozil" >www.google.com/search?q=%22asdf.&middot;&middot;&middot;id=mozil</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=what+is+asdf.exe" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;asdf.exe</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&safe=off&rls=cndb%2cc" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;cndb%2cc</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=%22asdf.exe" >www.google.com/search?hl=en&q=%22asdf.exe</A><br>1 &raquo;<A HREF="http://www.comcast.net/qry/websearch?cmd=qry&safe=on&query=%" >www.comcast.net/qry/websearch?cm&middot;&middot;&middot;&query=%</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=%2b%22asdf.exe%22&fr=fp-tab" >search.yahoo.com/search?p=%2b%22&middot;&middot;&middot;r=fp-tab</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=%22asdf.exe%22&btng=goo" >www.google.com/search?hl=en&q=%2&middot;&middot;&middot;btng=goo</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?ie=utf-8&oe=utf-8&sourceid=desk" >www.google.com/search?ie=utf-8&o&middot;&middot;&middot;eid=desk</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe+what+is+it" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;at+is+it</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?num=100&hl=en&lr=&safe=off&c2co" >www.google.com/search?num=100&hl&middot;&middot;&middot;off&c2co</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&ei=utf-8&fr=fp-tab" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;r=fp-tab</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?fr=sbc-web&tab=&p=asdf.exe&bt" >search.yahoo.com/search?fr=sbc-w&middot;&middot;&middot;f.exe&bt</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=mcafee+%2basdf.exe&spel" >www.google.com/search?hl=en&q=mc&middot;&middot;&middot;exe&spel</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hs=wmq&hl=en&lr=&client=firefox" >www.google.com/search?hs=wmq&hl=&middot;&middot;&middot;=firefox</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=trojan-downloader.win32" >www.google.com/search?hl=en&q=tr&middot;&middot;&middot;er.win32</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=%2b%22asdf.exe%22&ei=utf-8&" >search.yahoo.com/search?p=%2b%22&middot;&middot;&middot;i=utf-8&</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=what+is+asdf.exe%3f" >www.google.com/search?hl=en&q=wh&middot;&middot;&middot;f.exe%3f</A><br>1 &raquo;<A HREF="http://www.google.com/search?q=trojan-downloader.win32.small" >www.google.com/search?q=trojan-d&middot;&middot;&middot;32.small</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=firefox&sta" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;efox&sta</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&hl=en&lr=&safe=off&r" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;fe=off&r</A>..<br>1 &raquo;<A HREF="http://www.adelphia.net/google/index.php?q=asdf.exe&x=30&y=8" >www.adelphia.net/google/index.ph&middot;&middot;&middot;x=30&y=8</A><br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&start=0&start=0&ie=u" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;t=0&ie=u</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&sm=yahoo%21+search" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;1+search</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=firefox+%22asdf%22&btng" >www.google.com/search?hl=en&q=fi&middot;&middot;&middot;%22&btng</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&hl=en&sa=n&tab=gw" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;n&tab=gw</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe+&btng=sear" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;tng=sear</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?complete=1&hl=en&q=asdf.exe&btn" >www.google.com/search?complete=1&middot;&middot;&middot;.exe&btn</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe+keylogger&" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;ylogger&</A>..<br>1 &raquo;<A HREF="http://www.google.com.br/search?hl=pt-br&q=asdf.exe&meta=" >www.google.com.br/search?hl=pt-b&middot;&middot;&middot;xe&meta=</A><br>1 &raquo;<A HREF="http://www.google.ca/search?client=firefox-a&rls=org.mozilla" >www.google.ca/search?client=fire&middot;&middot;&middot;.mozilla</A>..<br>1 &raquo;<A HREF="http://www.google.com.mx/" >www.google.com.mx/</A><br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.mamma.com/mamma?qtype=0&query=trj%2fdownloader.eg" >www.mamma.com/mamma?qtype=0&quer&middot;&middot;&middot;oader.eg</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?fr=ush-yop&p=+win32.sillydl.t" >search.yahoo.com/search?fr=ush-y&middot;&middot;&middot;illydl.t</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&btn=yahoo%21+searc" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;21+searc</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=%2b+%22asdf.exe%22+" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;.exe%22+</A>..<br>1 &raquo;<A HREF="http://www.google.co.nz/search?hl=en&q=asdf.exe&meta=" >www.google.co.nz/search?hl=en&q=&middot;&middot;&middot;xe&meta=</A><br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&fr=ieas-dns" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;ieas-dns</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=%22asdf.exe%22" >www.google.com/search?hl=en&q=%22asdf.exe%22</A><br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.fr/search?hl=fr&q=small.bhf&meta=lr%3dlang" >www.google.fr/search?hl=fr&q=sma&middot;&middot;&middot;r%3dlang</A>..<br>1 &raquo;<A HREF="http://www.google.ca/search?hl=en&q=what+is+asdf.exe&meta=" >www.google.ca/search?hl=en&q=wha&middot;&middot;&middot;xe&meta=</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=downloader.ab" >www.google.com/search?hl=en&q=downloader.ab</A><br>1 &raquo;<A HREF="http://www.google.com/search?num=100&hl=en&lr=&safe=off&q=%2" >www.google.com/search?num=100&hl&middot;&middot;&middot;off&q=%2</A>..<br>1 &raquo;<A HREF="http://www.google.dk/search?q=asdf.exe&hl=da&meta=" >www.google.dk/search?q=asdf.exe&hl=da&meta=</A><br>1 &raquo;<A HREF="http://www.google.com.mx/search?q=asdf.exe&hl=es" >www.google.com.mx/search?q=asdf.exe&hl=es</A><br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.ca/search?hl=en&q=generic+downloader.ab&me" >www.google.ca/search?hl=en&q=gen&middot;&middot;&middot;er.ab&me</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=mozilla&sta" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;illa&sta</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&q=asdf%2eexe" >www.google.com/search?sourceid=n&middot;&middot;&middot;df%2eexe</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=drwtsn32+%22-e%22" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;%22-e%22</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&hs=0mc&client=firefox-a&r" >www.google.com/search?hl=en&hs=0&middot;&middot;&middot;efox-a&r</A>..<br>1 &raquo;<A HREF="http://www.google.de/search?hl=de&q=dr+watson+firefox+%2b1.0" >www.google.de/search?hl=de&q=dr+&middot;&middot;&middot;x+%2b1.0</A>..<br>1 &raquo;<A HREF="http://www.google.fr/search?hl=fr&q=asdf.exe&btng=rechercher" >www.google.fr/search?hl=fr&q=asd&middot;&middot;&middot;chercher</A>..<br>1 &raquo;<A HREF="http://www.google.com.sg/search?sourceid=navclient-ff&ie=utf" >www.google.com.sg/search?sourcei&middot;&middot;&middot;f&ie=utf</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=%2b+%22asdf.exe%22&btng" >www.google.com/search?hl=en&q=%2&middot;&middot;&middot;%22&btng</A>..<br>1 &raquo;<A HREF="http://www.altavista.com/web/results?itag=ody&q=asdf.exe&kgs" >www.altavista.com/web/results?it&middot;&middot;&middot;.exe&kgs</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&q=asdf.exe&btng=googl" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;ng=googl</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&hl=en&lr=&rls=gglg,g" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;s=gglg,g</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=asdf.exe&sm=yahoo%21+search" >search.yahoo.com/search?p=asdf.e&middot;&middot;&middot;1+search</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?as_q=&num=50&hl=en&btng=google+" >www.google.com/search?as_q=&num=&middot;&middot;&middot;=google+</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=symantec+asdf.exe&sourceid=mo" >www.google.com/search?q=symantec&middot;&middot;&middot;rceid=mo</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=mozclient&num=50&scori" >www.google.com/search?sourceid=m&middot;&middot;&middot;50&scori</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=dldr.small.bhf&sm=yahoo%21+" >search.yahoo.com/search?p=dldr.s&middot;&middot;&middot;ahoo%21+</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&ie=iso-8859-1&q=remov" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;&q=remov</A>..<br>1 &raquo;<A HREF="http://www.google.ca/search?q=asdf.exe&sourceid=mozilla-sear" >www.google.ca/search?q=asdf.exe&&middot;&middot;&middot;lla-sear</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=mozilla-sea" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;illa-sea</A>..<br>1 &raquo;<A HREF="http://64.233.187.104/search?q=cache:3es_skf3o4ij:iggy.gnome" >64.233.187.104/search?q=cache:3e&middot;&middot;&middot;gy.gnome</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=de&q=asdf.exe&btng=suche&lr=" >www.google.com/search?hl=de&q=as&middot;&middot;&middot;uche&lr=</A><br>1 &raquo;<A HREF="http://www.google.co.uk/search?client=firefox-a&rls=org.mozi" >www.google.co.uk/search?client=f&middot;&middot;&middot;org.mozi</A>..<br>1 &raquo;<A HREF="http://www.google.de/search?hl=de&q=asdf.exe&btng=google-suc" >www.google.de/search?hl=de&q=asd&middot;&middot;&middot;ogle-suc</A>..<br>1 &raquo;<A HREF="http://www.google.co.uk/search?q=%22asdf.exe%22&sourceid=moz" >www.google.co.uk/search?q=%22asd&middot;&middot;&middot;ceid=moz</A>..<br>1 &raquo;<A HREF="http://www.google.ch/search?hl=de&q=asdf.exe&btng=google-suc" >www.google.ch/search?hl=de&q=asd&middot;&middot;&middot;ogle-suc</A>..<br>1 &raquo;<A HREF="http://www.google.dk/search?hl=da&q=win32.sillydl.tq&btng=go" >www.google.dk/search?hl=da&q=win&middot;&middot;&middot;&btng=go</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hs=d1h&hl=en&lr=&client=firefox" >www.google.com/search?hs=d1h&hl=&middot;&middot;&middot;=firefox</A>..<br>1 &raquo;<A HREF="http://www.google.no/search?hl=no&q=asdf.exe&btng=s%c3%b8k&m" >www.google.no/search?hl=no&q=asd&middot;&middot;&middot;c3%b8k&m</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.nl/search?hl=nl&q=asdf.exe&btng=google+zoe" >www.google.nl/search?hl=nl&q=asd&middot;&middot;&middot;ogle+zoe</A>..<br>1 &raquo;<A HREF="http://www.google.de/search?hl=de&hs=jl2&client=firefox-a&rl" >www.google.de/search?hl=de&hs=jl&middot;&middot;&middot;fox-a&rl</A>..<br>1 &raquo;<A HREF="http://www.google.co.uk/search?sourceid=navclient&ie=utf-8&r" >www.google.co.uk/search?sourceid&middot;&middot;&middot;=utf-8&r</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&rls=atsa%2catsa%3a200" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;sa%3a200</A>..<br>1 &raquo;<A HREF="http://www.google.nl/search?q=asdf.exe&start=0&start=0&ie=ut" >www.google.nl/search?q=asdf.exe&&middot;&middot;&middot;=0&ie=ut</A>..<br>1 &raquo;<A HREF="http://www.google.nl/search?q=asdf.exe&sourceid=mozilla-sear" >www.google.nl/search?q=asdf.exe&&middot;&middot;&middot;lla-sear</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&lr=&safe=off&q=%22asdf.ex" >www.google.com/search?hl=en&lr=&&middot;&middot;&middot;2asdf.ex</A>..<br>1 &raquo;<A HREF="http://www.google.de/search?hl=de&q=trojan-downloader.win32" >www.google.de/search?hl=de&q=tro&middot;&middot;&middot;er.win32</A>...<br>1 &raquo;<A HREF="http://www.google.com/search?q=%22asdf.exe%22&btng=search&hl" >www.google.com/search?q=%22asdf.&middot;&middot;&middot;earch&hl</A>..<br>1 &raquo;<A HREF="http://www.google.co.uk/search?hl=en&q=trojan-downloader.win" >www.google.co.uk/search?hl=en&q=&middot;&middot;&middot;ader.win</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=asdf.exe%3f" >www.google.com/search?hl=en&q=asdf.exe%3f</A><br>1 &raquo;<A HREF="http://www.google.fr/search?sourceid=navclient&ie=utf-8&rls=" >www.google.fr/search?sourceid=na&middot;&middot;&middot;f-8&rls=</A>..<br>1 &raquo;<A HREF="http://www.google.fi/search?as_q=&num=10&hl=fi&btng=google-h" >www.google.fi/search?as_q=&num=1&middot;&middot;&middot;google-h</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?sourceid=navclient&ie=utf-8&rls" >www.google.com/search?sourceid=n&middot;&middot;&middot;tf-8&rls</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?hl=en&q=firefox+asdf.exe&btng=g" >www.google.com/search?hl=en&q=fi&middot;&middot;&middot;e&btng=g</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=+win32.sillydl.tq&sourceid=mo" >www.google.com/search?q=+win32.s&middot;&middot;&middot;rceid=mo</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=%22asdf.exe%22&fr=fp-tab-we" >search.yahoo.com/search?p=%22asd&middot;&middot;&middot;p-tab-we</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/bin/search?p=asdf.exe" >search.yahoo.com/bin/search?p=asdf.exe</A><br>1 &raquo;<A HREF="http://search.yahoo.com/search?_adv_prop=web&x=op&ei=utf-8&f" >search.yahoo.com/search?_adv_pro&middot;&middot;&middot;=utf-8&f</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?ei=utf-8&fr=slv1-iy&p=generic" >search.yahoo.com/search?ei=utf-8&middot;&middot;&middot;=generic</A>..<br>1 &raquo;<A HREF="http://search.yahoo.com/search?fr=fp-pull-web-t-174&p=asdf.e" >search.yahoo.com/search?fr=fp-pu&middot;&middot;&middot;p=asdf.e</A>..<br>1 &raquo;<A HREF="http://iggy.gnomeblog.com/blog" >iggy.gnomeblog.com/blog</A><br>1 &raquo;<A HREF="http://search.yahoo.com/search?p=win32.sillydl.tq&prssweb=se" >search.yahoo.com/search?p=win32.&middot;&middot;&middot;ssweb=se</A>..<br>1 &raquo;<A HREF="http://ca.search.yahoo.com/search?fr=slv1-rog&p=asdf.exe" >ca.search.yahoo.com/search?fr=sl&middot;&middot;&middot;asdf.exe</A><br>1 &raquo;<A HREF="http://64.233.183.104/search?q=cache:3qnyakdtbf8j:iggy.gnome" >64.233.183.104/search?q=cache:3q&middot;&middot;&middot;gy.gnome</A>..<br>1 &raquo;<A HREF="http://a9.com/asdf.exe" >a9.com/asdf.exe</A><br>1 &raquo;<A HREF="http://www.google.com/search?hl=it&q=dldr.small.bhf&lr=" >www.google.com/search?hl=it&q=dl&middot;&middot;&middot;.bhf&lr=</A><br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&sourceid=mozilla-sea" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;illa-sea</A>..<br>1 &raquo;<A HREF="http://www.google.com/search?q=asdf.exe&hl=en&hs=4a0&lr=&cli" >www.google.com/search?q=asdf.exe&middot;&middot;&middot;&lr=&cli</A>..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225667</guid>
<pubDate>Fri, 26 Aug 2005 12:11:35 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14225245</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  Tuulilapsi <A HREF="/useremail/u/665380"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Yea, but if we can locate even one of the sites and locate the actual ad that's doing this, we'll find the infected adserver. <br> </DIV>Well, one way would be to install an old copy of firefox, processguard, and clear cookies and repeatedly type theonion.com (logging the requests with the web-developer plugin) until asdf.exe turns up.<br><br>That is if that ad server is still compromised. My asdf.exe of a few days ago contains a download URL (that asdf.exe would try to use to bootstrap the malware onto your machine) that is no longer active.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225245</guid>
<pubDate>Fri, 26 Aug 2005 11:11:34 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14225210</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Yea, but if we can locate even one of the sites and locate the actual ad that's doing this, we'll find the infected adserver. <br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225210</guid>
<pubDate>Fri, 26 Aug 2005 11:06:00 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14225172</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  Tuulilapsi <A HREF="/useremail/u/665380"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Have you identified the source of the file? Was it from theonion.com, too, or from another source? Do you have Java and Javascript disabled or enabled in Firefox?<br><br>Edit: Damn, Cudni, you're fast. ;)<br> </DIV>If this thing is coming from a compromised ad server as I think is very likely, then theonion.com would be only one of perhaps many name sites that are getting the bad javascript/html combo through ad server ad rotation.<br><br>disgruntled: are you sure the date on the asdf.exe file is after the date you upgraded to 1.0.6?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14225172</guid>
<pubDate>Fri, 26 Aug 2005 11:01:28 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14224964</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Have you identified the source of the file? Was it from theonion.com, too, or from another source? Do you have Java and Javascript disabled or enabled in Firefox?<br><br>Edit: Damn, Cudni, you're fast. ;)<br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224964</guid>
<pubDate>Fri, 26 Aug 2005 10:33:06 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14224962</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : Do you know or suspect the site you possibly got it through?<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224962</guid>
<pubDate>Fri, 26 Aug 2005 10:32:55 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14224914</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Sorry for anonymous post, just been researching this myself: I got this dropped in through Firefox 1.0.6, latest version with "Allow Websites to install software" unchecked. Something is seriously wrong here.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224914</guid>
<pubDate>Fri, 26 Aug 2005 10:25:39 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14224694</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : It is the bbr instant message checker, probably an early version before it was taken over properly.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224694</guid>
<pubDate>Fri, 26 Aug 2005 09:49:08 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14224594</link>
<description><![CDATA[<A HREF="/useremail/u/1253694"><b>vlad_so</b></A> : Justin, this plugin (from your install.log) looks suspicious:<br><br>     Install completed successfully  --  2004-12-10 14:17:57<br><br>-------------------------------------------------------------------------------<br>&raquo;<A HREF="http://s116948610.onlinehome.us/bbrim_v0.6.1p.xpi" >s116948610.onlinehome.us/bbrim_v0.6.1p.xpi</A>  --  2005-04-02 20:09:45<br>-------------------------------------------------------------------------------<br><br>Any ideea what it is supposed to be? The link is dead, BTW.<br><br>Vlad]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224594</guid>
<pubDate>Fri, 26 Aug 2005 09:30:06 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14224569</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I've been watching the referer logs and increasing numbers of people per day are finding this topic via google.<br><br>To all of those people<br>a) make sure you and your friends have updated to the latest firefox<br>b) if you are searching for asdf.exe it is probably because zonealarm blocked it. Delete it. Otherwise, do a complete system scan.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224569</guid>
<pubDate>Fri, 26 Aug 2005 09:23:47 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14224052</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Hmm, so 1.0.6. would possibly be vulnerable to this thing too? This needs more attention.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14224052</guid>
<pubDate>Fri, 26 Aug 2005 07:08:46 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14220491</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : an A/V guy around here found it was a minor variation of a previously known trojan with a downloading URL that is currently offline.<br><br>As to what ad server was infected and whether it is still happening, who knows, but there are a number of recent google hits for firefox and asdf.exe. Zone alarm is the safety net for some people (asdf.exe is trying to...) but I prefer processguard.<br><br>As for theonion, I didn't really expect a reply. What companies reply promptly to unsolicited email anymore? Email, like snail mail, is rendered nearly useless by junk.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14220491</guid>
<pubDate>Thu, 25 Aug 2005 18:59:01 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14220380</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : But you're  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> goddamit.  Seriously.  They really should listen.  You've got one of the most popular tech sites in the world.  Time for a front page appearance?<br><br>I'm also surprised that more of the regulars haven't chimed in trying to help out on this.  <SMALL>Yes, CJ, I'm looking at you, but not in that way. :) </SMALL><br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14220380</guid>
<pubDate>Thu, 25 Aug 2005 18:43:04 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14220349</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I guess it has occured to the gangs than monetize zombie nets that the fastest way to get them spread is by tricking legit sites, especially via the murky world of online advertising.<br><br>One disappointing note: I wrote to theonion.com pointing out that this was a problem, giving them most of the info they would need to complain to whatever advertising network they use.<br><br>I didn't even get a reply. At least not so far (2 days).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14220349</guid>
<pubDate>Thu, 25 Aug 2005 18:38:38 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14219989</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : Reading this topic reminds me of the time that Falk AG's<br>ad servers were infected by the Bofra/iFrame exploit <br>several months ago, and just visiting a site like the UK <br>Register (they used Falk AG as one of their advertisers)<br>could get you infected. <br><SMALL>--<br>"Kayura or Badamon, whichever you are, you should know that I will never give up this battle. By the will of the Ancient, I shall succeed!" - Shuten (Anubis) from the Ronin Warriors.To RIAA/MPAA - You can sue but you can't catch everyone!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14219989</guid>
<pubDate>Thu, 25 Aug 2005 17:55:00 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14219787</link>
<description><![CDATA[<A HREF="/useremail/u/461260"><b>deadi</b></A> : I have to wonder, are any malware, trojan removers or antivirus progams detecting Firefox vulnerabilties?<br><br>Edit: I should rephrase that or ask the question, Is anyone keeping track of malware written to attack Firefox and are there definitions to detect them?<br><br><SMALL>--<br>ERROR:Bad Command Or File Name, Go Stand In Corner.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14219787</guid>
<pubDate>Thu, 25 Aug 2005 17:29:54 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14219697</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I think this infection via some bad ad server must be widespread.<br> </DIV>I dunno.  This thread's the 4th or 5th Google hit for "asdf.exe".  Usually by now we'd see a bunch of anonymous posters with the same complaint...?<br><br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14219697</guid>
<pubDate>Thu, 25 Aug 2005 17:18:24 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14219673</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : yes, probably. But it wouldn't do any good as the exe is a windows trojan downloader of some kind.<br><br>I think this infection via some bad ad server must be widespread.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14219673</guid>
<pubDate>Thu, 25 Aug 2005 17:14:46 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe on Suse9.2</title>
<link>http://www.dslreports.com/forum/remark,14219351</link>
<description><![CDATA[<A HREF="/useremail/u/1039629"><b>DonoftheDead</b></A> : Runnin' Suse9.2 with Firefox1.0.6. I found a compressed file named asdf.exe. Suse didn't recognize the format and did nothing with it. I couldn't open it (unrecognized format thing) I chucked it and no problems so far. The only sites I went to were related to FaH on Linux. Not sure which one d/l'ed the file. Could this be the same thing? Could it get into a Linux box through Firefox? Just curious.:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14219351</guid>
<pubDate>Thu, 25 Aug 2005 16:33:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14216678</link>
<description><![CDATA[<A HREF="/useremail/u/670907"><b>howardfine</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>explorer.exe is not the same as iexplore.exe<HR></BLOCKQUOTE><br>Yes, I know, but explorer.exe is part of windows and, as you said, windows is IE based.  All window panes are IE based.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14216678</guid>
<pubDate>Thu, 25 Aug 2005 10:29:31 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14216663</link>
<description><![CDATA[<A HREF="/useremail/u/665380"><b>Tuulilapsi</b></A> : Well, what do you know - Javascript exploits! :D<br><br>The first thing I do to any browser I use is kill Java and Javascript. This is why I do it.<br><br>(As a side note, were you surfing as admin, Justin? Because I don't see why a regular user account should even have write access to C root.)<br><br><SMALL>--<br><I>And lead me not into temptation - for I can find my way there myself easily enough.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14216663</guid>
<pubDate>Thu, 25 Aug 2005 10:26:43 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14216453</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  howardfine <A HREF="/useremail/u/670907"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>You run IE.  Windows Explorer is IE based as are most windows you run.  Most browsers use ActiveX to some degree.  You just don't realize you're running IE.<br> </DIV>windows is IE based but explorer.exe is not the same as iexplore.exe and the "windows that are explorer based" are just viewing my local file folders and running the systray etc. There are no infection vectors via browser hijacks if you rename iexplore and just use explore for viewing file folders, instead of starting up the full thing for web pages.<br><br>I don't use any programs that use IE DLLs as an html preview pane, either.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14216453</guid>
<pubDate>Thu, 25 Aug 2005 09:47:14 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14215256</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Actually I was considering going back to 0.8 which was the last really good version.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14215256</guid>
<pubDate>Thu, 25 Aug 2005 02:28:08 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214994</link>
<description><![CDATA[<A HREF="/useremail/u/294296"><b>Worfus</b></A> : <div class="bquote"><SMALL>said by  Ryan F <A HREF="/useremail/u/706695"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Worfus <A HREF="/useremail/u/294296"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>Edit: Forgot to mention I'm using IE not FF.</DIV>Have you ever had Firefox installed? If so, what version and when?<br> </DIV>No, never installed on this machine.<br><SMALL>--<br>"Confusion" will be my epitaph.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214994</guid>
<pubDate>Thu, 25 Aug 2005 01:29:38 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214980</link>
<description><![CDATA[<A HREF="/useremail/u/706695"><b>Ryan F</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Fx 1.0PR<br> </DIV>There's really no point in running a version that out of date.   There are over <A HREF="http://www.mozilla.org/projects/security/known-vulnerabilities.html">25 critical exploits</A> in 1.0PR - it's only a matter of time until one affects you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214980</guid>
<pubDate>Thu, 25 Aug 2005 01:27:41 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214904</link>
<description><![CDATA[<A HREF="/useremail/u/706695"><b>Ryan F</b></A> : <div class="bquote"><SMALL>said by  Worfus <A HREF="/useremail/u/294296"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Edit: Forgot to mention I'm using IE not FF.</DIV>Have you ever had Firefox installed? If so, what version and when?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214904</guid>
<pubDate>Thu, 25 Aug 2005 01:12:51 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214899</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : I use Process Guard and Fx 1.0PR on my host box (1.0.6 on my virtual box). I also use Proxo on both boxes. If this is coming from ads...well, I don't see ads. :D I'm not convinced I need to upgrade Fx and I used RIP to permanently zap the ad here telling me I need to upgrade Fx.<br><SMALL>--<br>Around 2005 a sudden spark will catalyze a Crisis mood. The very survival of the nation will seem to be at stake.Sometime before 2025, America will pass through a great gate in history. The risk and promise will be very high. The Fourth Turning Wm. Straus</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214899</guid>
<pubDate>Thu, 25 Aug 2005 01:12:06 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214761</link>
<description><![CDATA[<A HREF="/useremail/u/294296"><b>Worfus</b></A> : I had the same program dropped in my root directory last night at 11:37.  ZA stopped it from running.  I clicked DENY because I didn't expect anything new to be connecting.  I was in a hurry, looking up info on an infection in a relatives computer (ironic, huh?) so I went on about my business and later forgot about it.<br><br>This evening I get home to see that NAV found the file and was at a dialog box asking what to do with it.  So, sorry to say I'm glad you got it first Justin but at least I could confirm that it wasn't a FP and out it went.<br><br>Another example of "Thanks to Justin and the members of this community for this fine site."<br><br>At the time the file arrived, I was at startup.iamnotageek.com and there must have been an ad or popup that went to media.fastclick.net as it was also displayed at that time.<br><br>I'll assume that an email to the media.fastclick people wouldn't do any good since I don't have any "real" evidence outside of corresponding times.<br><br>Edit: Forgot to mention I'm using IE not FF.<br>Yes, go ahead, everybody can tell me I had it coming then.  :)<br><SMALL>--<br>"Confusion" will be my epitaph.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214761</guid>
<pubDate>Thu, 25 Aug 2005 00:47:00 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214540</link>
<description><![CDATA[<A HREF="/useremail/u/229804"><b>B</b></A> : Three thoughts.<br><br>1.  I'm glad I upgraded to Moz 1.7.8 a while ago.<br><br>2.  ASDF.exe is not a typical random name; someone chose it (it's of course the keys under QWERTY).  Therefore we'll either see a lot more of it as this infection gains ground in the wild, or this attack was somehow targeted at  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.<br><br>There seems to be another recent infection over at &raquo;<A HREF="http://forums.spywareinfo.com/lofiversion/index.php/t54765.html" >forums.spywareinfo.com/lofiversi&middot;&middot;&middot;765.html</A><br><br>Sounds like a match -- and it put itself in Windows/Prefetch.<br><br>3.  I gotta take another look at ProcessGuard!<br><br>Good luck, Justin.  What punishment gets wreaked on the first person to send you to &raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/8428">I think my computer is infected or hijacked. What should I do?</A> ?<br>  <br>-- B<br><SMALL>--<br>In a realm outside causality and function</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214540</guid>
<pubDate>Thu, 25 Aug 2005 00:06:12 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14214271</link>
<description><![CDATA[<A HREF="/useremail/u/670907"><b>howardfine</b></A> : You run IE.  Windows Explorer is IE based as are most windows you run.  Most browsers use ActiveX to some degree.  You just don't realize you're running IE.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14214271</guid>
<pubDate>Wed, 24 Aug 2005 23:23:58 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14197762</link>
<description><![CDATA[<A HREF="/useremail/u/706695"><b>Ryan F</b></A> : Install log looks clean, so asdf.exe wasn't dropped through the XPI install or .jar unpacking processes.<br><br><A HREF="http://www.mozilla.org/security/announce/mfsa2005-43.html">MFSA 2005-43</A> combined with <A HREF="http://www.mozilla.org/security/announce/mfsa2005-37.html">MFSA 2005-37</A> (both fixed in 1.0.4) allows for the delivery and execution of arbitrary code. I bet that's what happened here and that would make this the first example I've seen of those in the wild :p<br><br>It can't be all bad though, I see that the move to 1.0.6 also  got you to upgrade to the latest version of my extension. :D<br><br>Edit: I'm guessing that this new feature is a result of your near-exploit experience? ;)<br>[att=1]<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/speak/slideshow/14197762?c=880096&ret=L2ZvcnVtL3IxNDE5NjI4OS54bWw%3D"><IMG TITLE="40644 bytes" BORDER=0 WIDTH=114 HEIGHT=130 SRC="/r0/download/880096~bec999b0808d3b8fde0afd9de1b2be62/oldver.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14197762</guid>
<pubDate>Tue, 23 Aug 2005 00:42:34 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14197498</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : I am fairly sure java did not start. I can usually tell when that starts up due to the long pause. But it is 1.4.1_01, anyway.<br><br>install log is attached.<br><br>IE is renamed and I don't even remember what I renamed it too, it could not run, and nothing else did, otherwise I'd have a processguard alert.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/880068~e3b72faf17b15f7bb4a880493531b257/install.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>install.zip</big></A> <small>7,032 bytes</small><br><small>(install.log)</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14197498</guid>
<pubDate>Tue, 23 Aug 2005 00:07:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14197089</link>
<description><![CDATA[<A HREF="/useremail/u/706695"><b>Ryan F</b></A> : Could you post your Java version and the contents of your Firefox install.log file (C:\Program Files\Mozilla Firefox\install.log)?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14197089</guid>
<pubDate>Mon, 22 Aug 2005 23:10:17 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196387</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : yeah but that notification says "Successful exploitation requires that the site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org")."<br><br>maybe there is a better exploit out now. One that is silent and deadly.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196387</guid>
<pubDate>Mon, 22 Aug 2005 21:31:59 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196367</link>
<description><![CDATA[<A HREF="/useremail/u/1173110"><b>sheiny</b></A> : <div class="bquote"><SMALL>said by  justin <A HREF="/useremail/u/1"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I'm also surprised there is a keylogger drop exploit floating around for firefox 1.0.3 .. anyone confirm that?<br><br>PS: ping theonion.com is 66.216.104.235 for me.<br> </DIV>There was the cross site scripting vulnerability in Firefox 1.0.3 and earlier.<br>&raquo;<A HREF="http://secunia.com/advisories/15292" >secunia.com/advisories/15292</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196367</guid>
<pubDate>Mon, 22 Aug 2005 21:30:16 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196345</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <div class="bquote"><SMALL>said by  kw <A HREF="/useremail/u/1023285"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I loaded the page in IE, and it loaded the premerical page, but no ad. It rendered the page with errors however. <br> </DIV>The premerical page probably rotates advertisers via cookies and whatnot. I think it is like a loaded gun with one bullet you may get, or may not.<br><br>I emailed the onion about it, maybe they can look into it.<br><br>If it happened to me (luckily caught by processguard) it must be infecting many many PCs per minute. I think many firefox users are not aware there are actual malware delivery vectors out there, that target older versions of the browser..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196345</guid>
<pubDate>Mon, 22 Aug 2005 21:26:45 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196300</link>
<description><![CDATA[<A HREF="/useremail/u/1023285"><b>kw</b></A> : I loaded the page in IE, and it loaded the premerical page, but no ad. It rendered the page with errors however. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196300</guid>
<pubDate>Mon, 22 Aug 2005 21:22:11 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196289</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : For what it is worth - I updated firefox to 1.0.6 and then went back to theonion.com<br><br>I got the "premercial" page that says "if you are not automatically redirected" and then the home page.<br><br>I think the "premercial" page is *supposed* to be an advertising page.<br><br>I posit that someone has managed to convince theonion.com to show firefox 1.0.3 or earlier (or IE probably) killing malware as adverts!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196289</guid>
<pubDate>Mon, 22 Aug 2005 21:20:09 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196271</link>
<description><![CDATA[<A HREF="/useremail/u/1023285"><b>kw</b></A> : Page opened just fine over here in Firefox. I got the redirect thing, and let it sit, and it took me to the page just fine. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196271</guid>
<pubDate>Mon, 22 Aug 2005 21:18:07 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196244</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : yep<br><br>ntiVir 6.31.1.0/20050822       found [TR/Dldr.Small.bhf]<br>Avast   4.6.695.0/20050822      found nothing<br>AVG     718/20050822    found nothing<br>Avira   6.31.1.0/20050822       found [TR/Dldr.Small.bhf]<br>BitDefender     7.0/20050822    found [Trojan.Downloader.Small.GJ]<br>CAT-QuickHeal   8.00/20050822   found [TrojanDownloader.Small.bhf]<br>ClamAV  devel-20050725/20050822 found nothing<br>DrWeb   4.32b/20050822  found nothing<br>eTrust-Iris     7.1.194.0/20050823      found nothing<br>eTrust-Vet      11.9.1.0/20050822       found [Win32.SillyDl.TQ]<br>Fortinet        2.41.0.0/20050823       found [W32/Dloader.AB-dldr]<br>F-Prot  3.16c/20050822  found [could be infected with an unknown virus]<br>Ikarus  0.2.59.0/20050822       found nothing<br>Kaspersky       4.0.2.24/20050823       found<br>[Trojan-Downloader.Win32.Small.bhf]<br>McAfee  4564/20050822   found [Generic Downloader.ab]<br>NOD32v2 1.1199/20050822 found [Win32/TrojanDownloader.Small.NEU]<br>Norman  5.70.10/20050818        found [W32/Downloader]<br>Panda   8.02.00/20050822        found [Trj/Downloader.EGF]<br>Sophos  3.96.0/20050822 found nothing<br>Sybari  7.5.1314/20050823       found [Win32.SillyDl.TQ]<br>Symantec        8.0/20050821    found nothing<br>TheHacker       5.8.2.092/20050822      found nothing<br>VBA32   3.10.4/20050822 found [Trojan-Downloader.Win32.Small.bhf]<br><br>And here is the sequence from processguard:<br><br>(visit theonion.com - crashes firefox)<br><br>Mon 22 - 20:38:50 [EXECUTION] "c:\windows\system32\dwwin.exe" was blocked from running<br>                  [EXECUTION] Started by "c:\program files\mozilla firefox\firefox.exe" [1432]<br>                  [EXECUTION] Commandline - [ c:\windows\system32\dwwin.exe -x -s 1072 ]<br>Mon 22 - 20:38:51 [EXECUTION] "c:\windows\system32\drwtsn32.exe" was blocked from running<br>                  [EXECUTION] Started by "c:\program files\mozilla firefox\firefox.exe" [1432]<br>                  [EXECUTION] Commandline - [ drwtsn32 -p 1432 -e 3024 -g ]<br><br>(restart firefox)<br><br>Mon 22 - 20:38:54 [EXECUTION] "c:\program files\mozilla firefox\firefox.exe" was allowed to run<br>                  [EXECUTION] Started by "c:\windows\explorer.exe" [1932]<br>                  [EXECUTION] Commandline - [ "c:\program files\mozilla firefox\firefox.exe"  ]<br><br>(visit theonion.com again - firefox tries to run asdf.exe dated 8:39pm)<br><br>Mon 22 - 20:40:21 [EXECUTION] "c:\asdf.exe" was blocked from running<br>                  [EXECUTION] Started by "c:\program files\mozilla firefox\firefox.exe" [5964]<br>                  [EXECUTION] Commandline - [ c:\asdf.exe ]<br><br>(I wig out and open a command line, and deny asdf.exe)<br><br>Mon 22 - 20:40:22 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run<br>                  [EXECUTION] Started by "c:\windows\explorer.exe" [1932]<br>                  [EXECUTION] Commandline - [ "c:\windows\system32\cmd.exe"  ]<br><br>(firefox crashes again because I denied asdf or because of theonion.com or both)<br><br>Mon 22 - 20:41:18 [EXECUTION] "c:\windows\system32\dwwin.exe" was blocked from running<br>                  [EXECUTION] Started by "c:\program files\mozilla firefox\firefox.exe" [5964]<br>                  [EXECUTION] Commandline - [ c:\windows\system32\dwwin.exe -x -s 536 ]<br>Mon 22 - 20:41:21 [EXECUTION] "c:\windows\system32\drwtsn32.exe" was blocked from running<br>                  [EXECUTION] Started by "c:\program files\mozilla firefox\firefox.exe" [5964]<br>                  [EXECUTION] Commandline - [ drwtsn32 -p 5964 -e 668 -g ]<br><br>(i re-open firefox to post here, and ping theonion.com to get an IP address)<br><br>Mon 22 - 20:41:25 [EXECUTION] "c:\program files\mozilla firefox\firefox.exe" was allowed to run<br>                  [EXECUTION] Started by "c:\windows\explorer.exe" [1932]<br>                  [EXECUTION] Commandline - [ "c:\program files\mozilla firefox\firefox.exe"  ]<br>Mon 22 - 20:52:29 [EXECUTION] "c:\windows\system32\cmd.exe" was allowed to run<br>                  [EXECUTION] Started by "c:\windows\system32\cmd.exe" [4712]<br>                  [EXECUTION] Commandline - [ c:\windows\system32\cmd.exe /s /d /c" dir " ]<br>Mon 22 - 20:53:35 [EXECUTION] "c:\windows\system32\ping.exe" was allowed to run<br>                  [EXECUTION] Started by "c:\windows\system32\cmd.exe" [4712]<br>                  [EXECUTION] Commandline - [ ping theonion.com ]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196244</guid>
<pubDate>Mon, 22 Aug 2005 21:14:54 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196223</link>
<description><![CDATA[<A HREF="/useremail/u/839237"><b>purelander</b></A> : i went to theonion.com, i didnt get any redirect message, no crash or any exe file, the page loaded in 5 seconds.<br><br>i use FF 1.0PR, see the attached log for theonion.com.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/r0/download/879968~959edf1ccd50377c8576049c8be3b3a8/onion.zip"><IMG  align=absmiddle TITLE="download" SRC="http://i.dslr.net/silk/compress.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>onion.zip</big></A> <small>3,124 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196223</guid>
<pubDate>Mon, 22 Aug 2005 21:12:25 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196217</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : The addy has been hacked, no telling what's on the server at this point in time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196217</guid>
<pubDate>Mon, 22 Aug 2005 21:11:32 EDT</pubDate>
</item>

<item>
<title>Re: asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196166</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : did you confirm that asdf.exe is malware?<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196166</guid>
<pubDate>Mon, 22 Aug 2005 21:05:04 EDT</pubDate>
</item>

<item>
<title>asdf.exe / theonion.com</title>
<link>http://www.dslreports.com/forum/remark,14196120</link>
<description><![CDATA[<A HREF="/useremail/u/1"><b>justin</b></A> : <B>update: to save reading this topic the executive summary: asdf.exe appears to be dropped onto c:\ by an exploit targetting firefox, at least old versions. The exploit will also attempt to run asdf.exe at which point asdf.exe tries to download more malware. The exploit appears to be delivered <I>from one or more banner-ad companies of the type used by name-brand sites such as theonion.com</I>. There is no firm evidence yet that it gets through firefox 1.0.6(en) although that is a possibility as nobody has offered an explanation of exactly how it gets through even older versions of firefox.</B><br><br>My original post continues:<br><br>most peculiar, perhaps someone can shed some light.<br><br>I use firefox, and processguard (great program).<br><br>I visited theonion.com and the home page, labelled as theonion, said "if you are not redirected click here". At that point firefox crashed and tried to run drwatson, and the other microsoft debugger (caught by processguard).<br><br>I restarted firefox (no problem) and went back to theonion.com. here is where it got weird:<br><br>processguard told me that firefox was trying to run c:\asdf.exe (a file 1550 bytes in size and dated 8:39pm). I denied it, and firefox crashed again via dr watson etc. This is the first time since installation of processguard months ago that it has caught some badware trying to execute.<br><br>My conclusion is the act of visiting theonion.com (the only site I visited at 8:39pm!) deposited this keylogger on c:\ The other possibility is that the act of closing some tabs at the crash point deposited the keylogger. But the tabs were benign sites: yahoo / dslr / theonion .. I have a short list of "sites visited today" and they are all legit big name sites.<br><br>Infected by theonion? by a big name site? Unlikely? seems very unlikely. But I can't think of any other explanation right now.<br><br>I'm also surprised there is a keylogger drop exploit floating around for firefox 1.0.3 .. anyone confirm that?<br><br>PS: ping theonion.com is 66.216.104.235 for me.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14196120</guid>
<pubDate>Mon, 22 Aug 2005 20:58:38 EDT</pubDate>
</item>

</channel>
</rss>
