Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » New Variant Of Intrusive Online Scanner
Search Topic:
Uniqs:
1367
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 4 May 2008 »
« Conerning The On Going Denial of Service Attacks Today.  
AuthorAll Replies

Gas Guzzler

join:2005-09-17
Los Angeles, CA


edit:
March 22nd, @06:05PM

New Variant Of Intrusive Online Scanner

It calls itself xponlinescanner.com and I was hit twice today while visiting the NY Post newspaper wesbsite.

Its some kind of malware that tricks you to install some fake antispyware program. It appears on legitimate websites.

We saw these kind of browser highjackers last year too.

One of the old security threads that discussed the problem is this one:
»YouTube - Major League Baseball Strikes out

To test how this behaves on your system go here:
xponlinescanner.com/2008/1/freescan.php?aid=77011816
(edited)


Anav
Sarcastic Llama? Naw, Just Acerbic
Premium
join:2001-07-16
Dartmouth, NS

edit:
May 3rd, @12:50PM

What are you recommending we test????
Or does that link show how to remove??


tomazyk

join:2006-12-04
No DO NOT test that link. It is link to XPAntivirus - rogue antivirus. They offer you a free scan of your system - which of course tells you that your computer is not safe and then they offer you installation of their antivirus. DO NOT INSTALL IT.


Millenniumle

join:2007-11-11
Fredonia, NY

reply to Gas Guzzler
...

The link opens two successive script windows telling us their product is needed and safe. Then a page opens indicating a scan was performed, finding three nasties. Then a succession of more script windows open prompting to download and run their product. The download is a 65K file full of what is no doubt a bundle of joy.

The exploit here is the user.


ahulett
Equal Rights - It's Time
Premium
join:2003-02-02
Bellevue, WA

reply to Gas Guzzler
Re: New Variant Of Intrusive Online Scanner

More information on this rogue security product:

Microsoft Malware Protection Center
Program:Win32/XPAntiVirus
»www.microsoft.com/security/porta···ntiVirus


--
Aaron Hulett | Senior Spyware Researcher | Microsoft Malware Protection Center
This posting is provided "AS IS" without warranty, and confers no rights.


Anav
Sarcastic Llama? Naw, Just Acerbic
Premium
join:2001-07-16
Dartmouth, NS

reply to tomazyk
Not to worry Toma, My intention was too highlight poorly worded advice or suggestion in a security thread. Asking people to test this is bordering on ............

I was hoping a MOD would notice but I guess this week I am clearly meant to be disappointed (my Habs lost last night and are out of the playoffs :-( )

THanks for the link ahulett.
--
Ain't nuthin but the blues! "Albert Collins".
Leave your troubles at the door! "Pepe Peregil" De Sevilla. Just Don't Wifi without WPA, "Yul Brenner"

LlamaWorks Equipment


tomazyk

join:2006-12-04
Yes I thought that was your intention with both questions. With my post I only wanted to warn less experienced users from doing foolish thing.

Reimer

join:2006-08-14
Toronto, ON

edit:
May 4th, @08:30PM

reply to Gas Guzzler
Hmm, Firefox blocks it from even loading at all.


jesse2200

join:2006-07-22
Pickering, ON
clubs:
Erm...do i have the virus? I tested out your link and NOD32 did not stop it. I exited it right away and it changed the look of my browser.

AM I SAFE?!


tomazyk

join:2006-12-04
If you didn't run the installer then you should be safe. Check in Add/Remove programs if you have XPAntivirus listed. If so follow the link in ahulett's post for instructions on removing nastie.
Forums » Up and Running » Security » SecuritySecurity Software Updates - 4 May 2008 »
« Conerning The On Going Denial of Service Attacks Today.  


Tuesday, 02-Dec 14:54:35 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [106] AT&T Metered Billing Trial Hits Second Market
· [82] UDP BitTorrent Will Destroy The Interwebs!
· [59] Comcast Tries To Slow Verizon's Philly Entry
· [56] EFF Challenges Telecom Immunity
· [27] Cablevision Bumps HD Count To 68
· [22] Mega-ISPs, Consumer Advocates Demand Broadband Plan
· [17] FCC To Vote On Free National Wireless Broadband
· [15] Clearwire May Slow WiMax Build
· [14] Hawaii Telecom Files For Bankruptcy
· [8] Embarq Rejected Higher Offer
Most people now reading
· Is this a good thing for the net? [news,99366]
· [Rant] Bestbuy receipt checker [Rants, Raves, & Praise]
· Coalition Government Possible? [TekSavvy]
· Routing problem? [OptimumOnline]
· Basic 500 Price Increase! [Vonage]
· Java SE Runtime Environment (JRE) 6 Update 11 [Security]
· Upverting DVD players vs Blue ray DVD players. [General Questions]
· Level 80 PVP gear info? [World of Warcraft]
· Notice, new uTorrent Alpha may be able to evade throttling [TekSavvy]
· [WotLK] Starting the Rep Grind [World of Warcraft]