hk.www404.cn:53/ads.js
Posted on May 10, 2008 under Security, Uncategorized |This JS/Downloader.Agent virus is keep changing it’s location.
Now source code of every web page show these lines at the top of page.
<script src=”xx http://hk.www404.cn:53/ads.js xx ” language=”javascript”></script> [ xx added intently don't visit this linke.]
If your network is also facing the same problem then then best suggestion that change your ISP. In fact this the only solution of this problem.
If you can’t change your ISP then at least do not use Internet Explorer. If you are using Internet Explorer 6 or older version then chances of getting infected is high.
I always use FireFox, Because it is faster and secure. You can download it from following link:
UPDATE:
Latest injected code is:
iframe src=’http://net.jopppqq.com/ad/vip.htm’ width=100 height=1, so now the virus is hosted on jopppqq.com.












May 11th, 2008 at 1:49 am
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/Feature - STEP NC–The End Of G-Codes?July 2000. In the not-too-distant future, the only machine [...]
May 11th, 2008 at 4:15 am
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/ONLamp.com — Rolling with Ruby on RailsRefresh your browser to see a page similar to Figure 35. a [...]
May 15th, 2008 at 4:53 pm
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/ Javascript Redirects: Download javascripts for redirects from Java …Learn how to use javascript to [...]
May 18th, 2008 at 3:49 am
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/ [...]
May 19th, 2008 at 3:36 am
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/Java Tester - Installing JavaAs part of the java installation, a SunJavaUpdateSched program is added [...]
May 23rd, 2008 at 5:33 pm
Just reinstall Internet Explorer or install Internet Explorer 7. This should do the trick!
May 25th, 2008 at 5:23 am
[...] at top of each page:< script src=??? http://u.asdafdgfgf.com /ads.js ??? language=???javascript??? http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/...
May 25th, 2008 at 5:24 am
~ Dhiru, Did you tried this?? If it worked ?? I don’t think it will.
May 26th, 2008 at 4:49 pm
I reinstalled Internet Explorer but the problem still persists … I also use “mozilla firefox” and “opera” but the script is added to all pages…
May 26th, 2008 at 7:05 pm
Change your ISP. That’s what I think is the only solution of it.
May 29th, 2008 at 1:56 pm
Changing ISP would be hard! Yea and i have tried to use different browsers but same result. I think we should bring this threat to the notice of Kaspersky and Norton!
June 1st, 2008 at 12:47 am
well…I used a program “ARProtect” , this program help you to detect which PCs in your red is infected really, so I found that my computer did not have the virus if not that another PC in my network was infected and it have the real virus (this PC infects to all PCs in my network) ….so the only thing to do is disconnect the real infected computer from the network ….so if you want to know which computer is infecting your Internet..download the program “ARProtec”..in the coming days I will tell you that happened…
June 6th, 2008 at 11:09 pm
I Found my system/network to be infected with this Trojan … Then i thought if this spreads via ARP then clearing your arp cache and protecting your would be a good option and it works for me
and btw I use Comodo FW Pro 3
June 7th, 2008 at 11:58 pm
well.. now my pc is clean.. and I didn’t have to change my ISP
June 14th, 2008 at 4:36 am
Salam
This virus is in LAN no in ISP. This virus use ARP Spoofing Tec for redirect LAN Treffic from this path LAN > LAN Gateway > Internet to LAN > Infected PC > LAN Gateway > Internet.
For virus identification you should use “arp -a” command in cmd.
If there is(or are) MAC address same with “gateway MAC address” this computer(s)infected with this virus.
June 15th, 2008 at 12:36 am
how i can kill or stop this virus
June 16th, 2008 at 5:15 pm
@ hamid reza, please tell me clearly how to identify if a computer in a network is infected by this virus. Tell me how to use ARPprotect mentioned above
July 1st, 2008 at 7:57 am
Same thing what hamid told…
There will be a computer connected to your LAN with a different IP but it will have the same MAC Address of that of your Gateway. You must talk to your ISP and deal with the PC that is infected. All the Network Traffic Passes through the infected computer and hence the JS Virus is infected in the browser page that is requested!
July 4th, 2008 at 5:22 am
virus changed its code to http:// mx.content-type.cn: 443 / f / index.htm
DONT OPEN IT
be aware from this trojan