Virus threat detected on PH?
Virus threat detected on PH?
Author
Discussion

Mr AJ

Original Poster:

1,247 posts

200 months

Wednesday 3rd March 2010
quotequote all
Quick one for you guys, Just tried logging in now and got a virus warning coming up. Could just be a false alarm, But i thought you may like to know about it just incase.

Came up as i switched from the forum homepage to the 'login' section. I doubt its picking something up on the laptop as this is the mrs new one from 3, Only delivered a few hours ago and this is its first time connecting to the internet - Via a 3 Dongle not our home network so doubtful its detected something on one of the other PC's. Only other website open was the Sky billing center, which had been static for a while.

Don't want to cause any alarm with any other members as it could just be a false alarm, So if when one of the admins has seen this post you want to remove it/move it out of public eye more than welcome to do so. S/S included so you can see what i saw. Appologies about the size, like i said new laptop so nothing on to deal with images at the moment just glorious MS Paint!.


Xenocide

4,286 posts

237 months

Thursday 4th March 2010
quotequote all
That's a russian IP address:

82.69.243.92.in-addr.arpa name = 92.243.69.82.addr.datapoint.ru

the MSBlast worm does a similar lookup. I'd do a scan with another AV engine and see if it comes up with anything.

RacingPete

9,197 posts

233 months

Thursday 4th March 2010
quotequote all
Have you installed any software on the laptop since you got it, any of that shareware or a third party software?

DCOM exploits are not specifically related to a website, I think the coincidence is that this is the first time you connected to the web (or long enough) and thus the worm (that this is) tried to fire up or connect to your new laptop and was spotted by Avast.

It isn't a specific problem with PH and that page has nothing on it that would cause this message (the ad you display is from Virgin Media and is served through well known servers).

I am not sure how this worm has got onto your machine, but it might be worth just reviewing all the patches from windows and maybe looking at turning DCOM off as it isn't really needed for most users.

More info here -> http://www.grc.com/freeware/dcom.htm