From: David H. Lipman on
From: "FromTheRafters" <erratic(a)nomail.afraid.org>

| "~BD~" <BoaterDave(a)hotmail..co.uk> wrote in message
| news:Gq2dnSLnufNqEn3WnZ2dnUVZ7v-dnZ2d(a)bt.com...
>> BD made a post:

>> >> Here's the story!
>> >>
>> >>
>> hxxp://www.eutimes.net/2010/05/us-orders-blackout-over-north-korean-torpedoing-of-gulf-
>> of-mexico-oil-rig/
>> >>
>> >
>> > Dave,
>> > That is a bad web site. It tried to load a malware virus web site
>> > and I deleted it before it could infect my puter.
>> >
>> >

>> This is a posted response by Eagle on Scorched-Earth.

>> I've obfuscated the link as previously requested for such items.

>> Perhaps someone can check it out. It was found by Googling.

| Bad guys - - go get 'em Dave...

| hxxp://91.213.157.62/index.php?q=3654db04721f3e5a44993142c696db659110220

I get a 404 on that.



--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: FromTheRafters on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:hrrh0p02159(a)news4.newsguy.com...
> From: "FromTheRafters" <erratic(a)nomail.afraid.org>
>
> | "~BD~" <BoaterDave(a)hotmail..co.uk> wrote in message
> | news:Gq2dnSLnufNqEn3WnZ2dnUVZ7v-dnZ2d(a)bt.com...
>>> BD made a post:
>
>>> >> Here's the story!
>>> >>
>>> >>
>>> hxxp://www.eutimes.net/2010/05/us-orders-blackout-over-north-korean-torpedoing-of-gulf-
>>> of-mexico-oil-rig/
>>> >>
>>> >
>>> > Dave,
>>> > That is a bad web site. It tried to load a malware virus web site
>>> > and I deleted it before it could infect my puter.
>>> >
>>> >
>
>>> This is a posted response by Eagle on Scorched-Earth.
>
>>> I've obfuscated the link as previously requested for such items.
>
>>> Perhaps someone can check it out. It was found by Googling.
>
> | Bad guys - - go get 'em Dave...
>
> |
> hxxp://91.213.157.62/index.php?q=3654db04721f3e5a44993142c696db659110220
>
> I get a 404 on that.

I guess they've moved on already.


From: David H. Lipman on
From: "FromTheRafters" <erratic(a)nomail.afraid.org>

| "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
| news:hrrh0p02159(a)news4.newsguy.com...
>> From: "FromTheRafters" <erratic(a)nomail.afraid.org>

>> | "~BD~" <BoaterDave(a)hotmail..co.uk> wrote in message
>> | news:Gq2dnSLnufNqEn3WnZ2dnUVZ7v-dnZ2d(a)bt.com...
>>>> BD made a post:

>>>> >> Here's the story!
>>>> >>
>>>> >>
>>>> hxxp://www.eutimes.net/2010/05/us-orders-blackout-over-north-korean-torpedoing-of-
>>>> gulf-
>>>> of-mexico-oil-rig/
>>>> >>
>>>> >
>>>> > Dave,
>>>> > That is a bad web site. It tried to load a malware virus web site
>>>> > and I deleted it before it could infect my puter.
>>>> >
>>>> >

>>>> This is a posted response by Eagle on Scorched-Earth.

>>>> I've obfuscated the link as previously requested for such items.

>>>> Perhaps someone can check it out. It was found by Googling.

>> | Bad guys - - go get 'em Dave...

>> |
>> hxxp://91.213.157.62/index.php?q=3654db04721f3e5a44993142c696db659110220

>> I get a 404 on that.

| I guess they've moved on already.


Maybe they are using ad rotation and/or geo-ip location.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: FromTheRafters on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:hrrh0p02159(a)news4.newsguy.com...
> From: "FromTheRafters" <erratic(a)nomail.afraid.org>
>
> | "~BD~" <BoaterDave(a)hotmail..co.uk> wrote in message
> | news:Gq2dnSLnufNqEn3WnZ2dnUVZ7v-dnZ2d(a)bt.com...
>>> BD made a post:
>
>>> >> Here's the story!
>>> >>
>>> >>
>>> hxxp://www.eutimes.net/2010/05/us-orders-blackout-over-north-korean-torpedoing-of-gulf-
>>> of-mexico-oil-rig/
>>> >>
>>> >
>>> > Dave,
>>> > That is a bad web site. It tried to load a malware virus web site
>>> > and I deleted it before it could infect my puter.
>>> >
>>> >
>
>>> This is a posted response by Eagle on Scorched-Earth.
>
>>> I've obfuscated the link as previously requested for such items.
>
>>> Perhaps someone can check it out. It was found by Googling.
>
> | Bad guys - - go get 'em Dave...
>
> |
> hxxp://91.213.157.62/index.php?q=3654db04721f3e5a44993142c696db659110220
>
> I get a 404 on that.

On BD's supplied URL, I now get AntiVir's warning "...contains the
recognition pattern of the HTML/Infected.WebPage.Gen script virus..." I
suppose if I allowed access I would get another IP address now. Just
tried again and got the "Microsoft Security Assessment Tool" warning
that my PC is so full of viruses that it is oozing at the seams....No AV
warning this time (I didn't investigate the IP address this time).

When you find the box displayed, you can maximize the window by using
task manager and read the most recent IP address.


From: FromTheRafters on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:hrri8e021t9(a)news4.newsguy.com...

> Maybe they are using ad rotation and/or geo-ip location.

Doubtless. That page is ad intensive.