Wiki page
Bloodhound.Exploit.96 virus
Friday, November 27, 2009 by DPCloud | Discussion: WinCustomize Talk
I’m not really sure if I should contact someone about this or what so I thought I’d just post it.
Twice today I went to the Wiki page and was attacked by a virus named Bloodhound.Exploit.96. I know it’s a nasty virus as my daughter got it on my wife’s pc last year and she had to reformat.
Norton says it a Heuristic virus and gave it a high risk level.
I’m probably the least computer savvy in here so maybe this is no big deal but thought I should say something just incase.
Reply #2 Friday, November 27, 2009 5:20 PM
Thanks, Don. I go to the Wiki frequently. Really good of you to let us know about this. ![]()
*edit...went on irc, and it's being dealt with per Lantec
Reply #3 Friday, November 27, 2009 5:30 PM
I just wish there was an edit button for the first post so I could change it to its, I’ve been Zubazed.
Reply #4 Friday, November 27, 2009 5:37 PM
I suspect this was embedded in an ad, as I'm not seeing anything on the pages themselves (though there were a few pages of spam). That would be the easiest way to spread it. If you can identitfy the specific ad in use that would help a lot as we could then report that. Alternatively, if it was on a particular page, it would be good to know that (perhaps it was a false positive; we do have some pages relating to scripts).
Personally, I suggest not using IE would be a good start, but we're investigating. Another good idea is to set the XML kill bit as described in the workaround to this bulletin:
http://www.microsoft.com/technet/security/Bulletin/MS06-071.mspx
The update provided by Microsoft in that bulletin may also help protect against it.
Reply #5 Friday, November 27, 2009 6:00 PM
I didn’t click on any ads but I did visit the Xion download page, I didn’t download anything. Sorry I didn’t think about that until you mentioned ads.
Reply #6 Friday, November 27, 2009 6:30 PM
Depending on the ad served by the network, it might not be necessary to click on them - that's what makes browser exploits so dangerous. Many have embedded code of some kind, and if they can activate a vulnerable component . . .
The solution is not to allow the vulnerability, as otherwise any page you visit is potentially dangerous.
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Friday, November 27, 2009 5:00 PM
Thanks for letting us know...we'll pass it on as soon as we can.