I'm just curious why when I come here I'm getting attacks from this site (not necessarily your site, but linked to) when I go to ClubWRX Forum...
I keep getting multiple .jar files sent from the address below. It only happens when I come to this website...not sent from any other websites and this is with brand new OS installation as well.
I'm blocking these with NOD32 along with Vipre AV programs on multiple computers. So that's two programs that are catching things "linked to" it seems this website... McAfee and TrendMicro (for sure) are letting these through and then when I try to search you get sent through a .ru website on your searches...
I changed the link because I don't want someone clicking on them.
hxxp://220.127.116.11/x/midi.jar a variant of OSX/Exploit.Smid.B trojan connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files (x86)\Java\jre6\bin\java.exe.
hxxp://18.104.22.168/x/jar.jar multiple threats connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files (x86)\Java\jre6\bin\java.exe.
22.214.171.124 - Geo Information
IP Address 126.96.36.199
Location LV, Latvia
City Riga, 25 -
Organization DOCSIS IP pool for cable customers
ISP SIA IZZI COM
AS Number AS6851 BKCNET Autonomous System
Latitude 56°95'00" North
Longitude 24°10'00" East
Distance 1587.28 km (986.29 miles)