The forums would appear to have been hacked and an iFrame tag inserted in to documents.
This iFrame tries to load a virus, see this post in particular but also read the whole topic as I was trying to find out why I was having problems posting.
At first I didn’t see any alert but this was more to do with using firefox as it didn’t seem to be vulnerable to this attack, but when I tested using avant the web shield alerted as yours did.
Thankfully it appears fine now and the forums software has been updated to SMC 1.1.3 which had some security updates although it didn’t mention what these were.
I wasn’t paying much attention to what the changes were when I visited the site I was looking to see what security patches were listed to see if the problem we had was fixed with SMC 1.1.3.
Found this in my Firefox cache. The latest version of Firefox doesn’t seem to be vulnerable, but anybody visiting the forum with an older version may have been infected.
AVG Anti-Spyware may pick up the file in your Google cache if you use it and haven’t cleaned up the cache.
The name in the firefox cache will be different on every system as firefox doesn’t store the file using the same name, but generates a random file name and it doesn’t include a file type.
In my cache it was E580511Bd01, because of this change in the file name and no extension I don’t know how it would be activated (called or run) from within the firefox cache. Clearing the cache should remove the file and any potential for harm. AVG-AS found nothing else outside the cache.
First these were not on the avast forum but on another site, activated in an injected iframe tag. I suggest you read the other topic I created (link in my first post) if you haven’t already done so. It should give you a better idea of what happened.
Since I and I assume Frank have sent samples to avast they will be included in due course.
my guess was right. the virus came from this site. well while i was browsing this forum avast detected a virus w/a name sysszxc.exe but could’nt removed it. if you click “move to chest” a pop-up tells you that “avast can’t accessed the file because it is being used by another process”. you have to disconnect first and do the scan. it was categorized by avast as a worm. here’s the description:(i’ve got 4 of these)
name: 324123[1].htm
original location: C:\documents and settings\user\local settings\temporary internet files\content.IE5\ UVM98DB4
virus: CVE-2007-0038
the virus disabled my task manager preventing me to access it, even with all my security system alerted(winpatrol, avast, comodo FW). only spybot SD cleared my machine of this virus. it found kernelwind32.exe which avast did not(even w/thorough scan) spybot also fixed the task manager’s registry that was modified by this vius. don’t know if these 3 viruses are just actually one only with different names. BTW i disabled the web shield (maybe why i got infected). now im gonna activate the web shield from now on…
The forum software has an exploit and this vulnerability was used by the worm to infect from OTHER SITE.
If you disable WebShield, that’s the problem… Which is your Standard Shield sensibility?
Also, if avast can’t detect something, no provider will caught it… (for instance kernelwind32.exe).