http://www.hexus.net/content/news/ne...lld19JRD0xNjIzThe P2Load.A worm redirects users to a fake Google website on an infected machine, delivering hacker-controlled search results to direct a user wherever the hacker pleases.
http://www.hexus.net/content/news/ne...lld19JRD0xNjIzThe P2Load.A worm redirects users to a fake Google website on an infected machine, delivering hacker-controlled search results to direct a user wherever the hacker pleases.
a good protection for this is to enable the read only config of HOSTS from spybot search & destroy.
my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net
thats what USB keys with all the kit you need on it are for Steve![]()
my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net
lol "Steve's 1337 hax0r tooz!!"![]()
my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net
I suspect the worm is also attempting to poson DNS entries. I am seeing a lot of traffic on the firewall logs on my home linux box. The probes are from a lot of different places which normaly means there is a virus out there.
Edit:
Today's logs show arround 700 probes from 351 different IP addreses. Looks like this one will be with us for a while.
Last edited by chrestomanci; 21-09-2005 at 02:39 PM. Reason: Update
There are currently 1 users browsing this thread. (0 members and 1 guests)