Hi
Yesterday I went onto a site via Google which I have used before to download
a particular printer service manual.
A message popped up to say that AVG had found virus like activity. But first
of all I haven't got AVG on that computer and it wasn't the norm AVG message
just a plain windows dialogue box.
Being curious I clicked on the message and the page came up with an Explorer
like window showing Hard drives DVD roms etc. and the bottom of the page
showing virus's which it had supposedly found. Eventually another box came
up showing these virus's and with a button saying Remove All.
At this point I closed Internet Explorer. I ran Malware Bytes and MS
Security essentials which both scanned OK.
As I suspected this was how my clients were getting these Fake Antivirus
programs, I plugged in a second hand computer and proceeded to go through
the same procedure.
This time I went further and clicking Remove All took me to a save or run
dialogue. I went through the same procedure with Firefox and it gave the
same results.
I then went a stage further and saved and ran the executable and sure enough
on restarting the computer the Fake Antivirus Program was well and truly
embedded.
I went into safe mode. Installed Malware bytes from a pen drive and it
successfully removed the Virus.
This weekend if I have time I intend to see if it does the same with Google
Chrome. I will also reinstall windows on the second hand machine just in
case.
Incidentally I tried the link to the printer manual and found that it
linked to the virus pages randomly approximately 1 in 30 clicks.
If anyone is interested in looking at the sites. Then these are the links
to the Virus pages. Alternatively send me an email with your email address
I will send some pictures of the dialogues and pages.
Link to Printer Manual.
http://www.google.co.uk/url?sa=t
<http://www.google.co.uk/url?sa=t&source=web&cd=19&ved=0CFsQFjAIOAo&url=http
%3A%2F%2Fwww.scribd.com%2Fdoc%2F37852023%2FSM-C5650-5750-5850-5950&ei=LNl4Te
rkF9SChQfJ_ODeBg&usg=AFQjCNHJvhDz18kvTAZ2kMmJO5SGeg3Iow>
&source=web&cd=19&ved=0CFsQFjAIOAo&url=http%3A%2F%2Fwww.scribd.com%2Fdoc%2F3
7852023%2FSM-C5650-5750-5850-5950&ei=LNl4TerkF9SChQfJ_ODeBg&usg=AFQjCNHJvhDz
18kvTAZ2kMmJO5SGeg3Iow
In history was a link to:
http://174.127.70.195/8545/4544
Which took me to:
http://8f0518.nevilguard2.com/defender/?f87076745a=wgwabl
<http://8f0518.nevilguard2.com/defender/?f87076745a=wgwabl&3cf21=mgalawmafm&
bb7=mwxxshqhgq&a7de3d5=3> &3cf21=mgalawmafm&bb7=mwxxshqhgq&a7de3d5=3
Today I was taken to a different URL:
http://antivirussites.com/index.php?06abQDU3QUbGX2+t/3A33ZKtKmtoMHU6Lg4OcHah
UVwAMpByRy/XftY62VQphMxXHnE=#sfgh20hfgGFYUHJtfgyuhjgHUIJ
Which wanted me to download a file called AntiSpyWareSetup.exe
Cheers
Peter Hart
Peter Hart Computers
--- StripMime Report -- processed MIME parts ---
multipart/alternative
text/plain (text body -- kept)
text/html
---
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/46f901cbe9e7$edc048b0$c940da10$@peterhart.demon.co.uk
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Peter,
Got hit with similar/same attack last week when I went to check in on
Vincent Bugliosi's site promoting his book.
Mostly recovered by restoring the XP machine to a prior checkpoint.
It caught my attention that the attack breezed right past MS Security
Essentials.
Bill
> Yesterday I went onto a site via Google which I have used
> before to download
> a particular printer service manual.
>
> A message popped up to say that AVG had found virus like
> activity. But first
> of all I haven't got AVG on that computer and it wasn't the
> norm AVG message
> just a plain windows dialogue box.
.
.
.
Peter Hart
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/D11B0B440FC74B04AD75D96743E00194@bills
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
On Wed, Mar 23, 2011 at 11:54 PM, Demon <peter@peterhart.demon.co.uk> wrote:
> As I suspected this was how my clients were getting these Fake Antivirus
> programs, I plugged in a second hand computer and proceeded to go through
> the same procedure.
>
> This time I went further and clicking Remove All took me to a save or run
> dialogue. I went through the same procedure with Firefox and it gave the
> same results.
>
> I then went a stage further and saved and ran the executable and sure enough
> on restarting the computer the Fake Antivirus Program was well and truly
> embedded.
>
> I went into safe mode. Installed Malware bytes from a pen drive and it
> successfully removed the Virus.
You need to be Really Careful when trying this sort of exercise. A
while back I had a fresh VirtualBox XP VM installed, so I decided to
play with a disposable image snapshot and try a similar exercise.
A short time later I got a nastygram from my ISP (Comcast) saying that
my access to port 25 (direct SMTP) was being shut down. Apparently,
just for the minute or so that I was experimenting my VM sent out
enough spam to raise a red flag at Comcast.
Tread carefully here...
dt
--
Dave Thayer
Denver, CO
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/AANLkTinY1=SQvfg9cN1qYWim=kOLCFtrhd+FQnQ2X0AX@mail.gmail.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
My wife called me in a panic a few days ago with the same message. She had
heard me talk about AVG so she called me right away. Thankfully I had
removed AVG from the system a few weeks ago when my contract with them
finally expired (that's a story for another thread) so I knew it was bogus.
What also got my attention was even if AVG found something, why would it
need to download something (an update?) to continue? That isn't how it
updates itself. Had I actually had AVG running, and not been paying
attention, I may have fallen for it especially when I'm on the phone and
can't see the screen. I'm sure that is what they are counting on...
The web is NOT a safe place.
Lou
-----Original Message-----
From: profoxtech-bounces@leafe.com [mailto:profoxtech-bounces@leafe.com] On
Behalf Of Demon
Sent: Wednesday, March 23, 2011 10:54 PM
To: profoxtech@leafe.com
Subject: [NF] Fake Antivirus Software
Hi
Yesterday I went onto a site via Google which I have used before to download
a particular printer service manual.
A message popped up to say that AVG had found virus like activity. But first
of all I haven't got AVG on that computer and it wasn't the norm AVG message
just a plain windows dialogue box.
Being curious I clicked on the message and the page came up with an Explorer
like window showing Hard drives DVD roms etc. and the bottom of the page
showing virus's which it had supposedly found. Eventually another box came
up showing these virus's and with a button saying Remove All.
At this point I closed Internet Explorer. I ran Malware Bytes and MS
Security essentials which both scanned OK.
...
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/02b401cbea2f$6e869f70$4b93de50$@com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
These fake AVs are getting more and more common ... one of the dangers
of browser-based apps looking more and more like desktop apps/
--
Alan Bourke
alanpbourke (at) fastmail (dot) fm
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/1300977019.26628.1433398837@webmail.messagingengine.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
If you use Firefox, you should install the NoScript add-on. So many of these attacks come in from 3rd party javascript that get dropped on a vulnerable website.
--
rk
-----Original Message-----
From: profoxtech-bounces@leafe.com [mailto:profoxtech-bounces@leafe.com] On Behalf Of Lou Syracuse
Sent: Thursday, March 24, 2011 10:26 AM
To: profoxtech@leafe.com
Subject: RE: [NF] Fake Antivirus Software
The web is NOT a safe place.
Lou
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/DF1EEF11E586A64FB54A97F22A8BD04419225924DC@ACKBWDDQH1.artfact.local
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
Author: MB Software Solutions, LLC
Posted: 2011-03-24 11:48:47 Link
On 3/24/2011 10:26 AM, Lou Syracuse wrote:
> My wife called me in a panic a few days ago with the same message. She had
> heard me talk about AVG so she called me right away. Thankfully I had
> removed AVG from the system a few weeks ago when my contract with them
> finally expired (that's a story for another thread) so I knew it was bogus.
>
>
> What also got my attention was even if AVG found something, why would it
> need to download something (an update?) to continue? That isn't how it
> updates itself. Had I actually had AVG running, and not been paying
> attention, I may have fallen for it especially when I'm on the phone and
> can't see the screen. I'm sure that is what they are counting on...
>
> The web is NOT a safe place.
I think the malware writers are becoming more clever. I had a coworker
almost get duped by System Defender, which looks almost the same as
Windows Defender!
--
Mike Babcock, MCP
MB Software Solutions, LLC
President, Chief Software Architect
http://mbsoftwaresolutions.com
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/4D8B67DF.9030002@mbsoftwaresolutions.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.
It's a jungle out there and when they do catch the perps, it's a slap on the
wrist.
----- Original Message ----
From: "MB Software Solutions, LLC" <mbsoftwaresolutions@mbsoftwaresolutions.com>
To: ProFox Email List <profox@leafe.com>
Sent: Thu, March 24, 2011 11:48:47 AM
Subject: Re: [NF] Fake Antivirus Software
On 3/24/2011 10:26 AM, Lou Syracuse wrote:
> My wife called me in a panic a few days ago with the same message. She had
> heard me talk about AVG so she called me right away. Thankfully I had
> removed AVG from the system a few weeks ago when my contract with them
> finally expired (that's a story for another thread) so I knew it was bogus.
>
>
> What also got my attention was even if AVG found something, why would it
> need to download something (an update?) to continue? That isn't how it
> updates itself. Had I actually had AVG running, and not been paying
> attention, I may have fallen for it especially when I'm on the phone and
> can't see the screen. I'm sure that is what they are counting on...
>
> The web is NOT a safe place.
I think the malware writers are becoming more clever. I had a coworker
almost get duped by System Defender, which looks almost the same as
Windows Defender!
--
Mike Babcock, MCP
MB Software Solutions, LLC
President, Chief Software Architect
http://mbsoftwaresolutions.com
[excessive quoting removed by server]
_______________________________________________
Post Messages to: ProFox@leafe.com
Subscription Maintenance: http://leafe.com/mailman/listinfo/profox
OT-free version of this list: http://leafe.com/mailman/listinfo/profoxtech
Searchable Archive: http://leafe.com/archives/search/profox
This message: http://leafe.com/archives/byMID/profox/880602.81887.qm@web31401.mail.mud.yahoo.com
** All postings, unless explicitly stated otherwise, are the opinions of the author, and do not constitute legal or medical advice. This statement is added to the messages for those lawyers who are too stupid to see the obvious.