Hi found a trojan horse here...

Hi malware fighters,

What is wrong with this script: htxp://a.l.yimg.com/a/lib/s6/srp_metro_yui3_201006181747.js
The requested URL was analyzed and found legitimate says M86 url scanner
When I view it with jsunpack, avast alerts: JS:ScriptDC-inf[Trj]
My WOT gives a browser exploit: http://www.mywot.com/en/scorecard/a.l.yimg.com
Wepawet gives it as benign: http://wepawet.iseclab.org/view.php?hash=0ef255b4701476022dfeb19106dc6aa5&t=1281208650&type=js
Also re: http://forum.avast.com/index.php?topic=55079.0
So you see, you can NEVER be OVERPROTECTED!!!

polonus

2010-08-07 21:27:38 (GMT 1)
File Name srp-metro-yui3-201006181747-js
File Size 33211 bytes
File Type Unknown file
MD5 Hash beeda59afd81d46548960747f765dd0d
SHA1 Hash 55057316ca1667a40dd1dfbaa283a6d1669e1054
Detections: 0 / 16 (0 %)
Status CLEAN

Hi Asyn,

I think I have found the culprit of the problem and the detection is for jsunpack (I have NoScript active there, so no issue),

polonus