Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » New Variant Of Intrusive Online Scanner
Search Topic:
Uniqs:
1456
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 4 May 2008 »
« Conerning The On Going Denial of Service Attacks Today.  
AuthorAll Replies

Gas Guzzler

join:2005-09-17
Los Angeles, CA


1 edit
New Variant Of Intrusive Online Scanner

It calls itself xponlinescanner.com and I was hit twice today while visiting the NY Post newspaper wesbsite.

Its some kind of malware that tricks you to install some fake antispyware program. It appears on legitimate websites.

We saw these kind of browser highjackers last year too.

One of the old security threads that discussed the problem is this one:
»YouTube - Major League Baseball Strikes out

To test how this behaves on your system go here:
xponlinescanner.com/2008/1/freescan.php?aid=77011816
(edited)


Anav
Sarcastic Llama? Naw, Just Acerbic
Premium
join:2001-07-16
Dartmouth, NS

1 edit
What are you recommending we test????
Or does that link show how to remove??


tomazyk

join:2006-12-04
No DO NOT test that link. It is link to XPAntivirus - rogue antivirus. They offer you a free scan of your system - which of course tells you that your computer is not safe and then they offer you installation of their antivirus. DO NOT INSTALL IT.


Millenniumle

join:2007-11-11
Fredonia, NY

reply to Gas Guzzler
...

The link opens two successive script windows telling us their product is needed and safe. Then a page opens indicating a scan was performed, finding three nasties. Then a succession of more script windows open prompting to download and run their product. The download is a 65K file full of what is no doubt a bundle of joy.

The exploit here is the user.


ahulett
Life Without Walls
Premium
join:2003-02-02
Bellevue, WA

reply to Gas Guzzler
Re: New Variant Of Intrusive Online Scanner

More information on this rogue security product:

Microsoft Malware Protection Center
Program:Win32/XPAntiVirus
»www.microsoft.com/security/porta···ntiVirus


--
Aaron Hulett | Senior Spyware Researcher | Microsoft Malware Protection Center
This posting is provided "AS IS" without warranty, and confers no rights.


Anav
Sarcastic Llama? Naw, Just Acerbic
Premium
join:2001-07-16
Dartmouth, NS

reply to tomazyk
Not to worry Toma, My intention was too highlight poorly worded advice or suggestion in a security thread. Asking people to test this is bordering on ............

I was hoping a MOD would notice but I guess this week I am clearly meant to be disappointed (my Habs lost last night and are out of the playoffs :-( )

THanks for the link ahulett.
--
Ain't nuthin but the blues! "Albert Collins".
Leave your troubles at the door! "Pepe Peregil" De Sevilla. Just Don't Wifi without WPA, "Yul Brenner"

LlamaWorks Equipment


tomazyk

join:2006-12-04
Yes I thought that was your intention with both questions. With my post I only wanted to warn less experienced users from doing foolish thing.

Reimer

join:2006-08-14
Toronto, ON

1 edit
reply to Gas Guzzler
Hmm, Firefox blocks it from even loading at all.


Jesse2

join:2006-07-22
canada
Erm...do i have the virus? I tested out your link and NOD32 did not stop it. I exited it right away and it changed the look of my browser.

AM I SAFE?!


tomazyk

join:2006-12-04
If you didn't run the installer then you should be safe. Check in Add/Remove programs if you have XPAntivirus listed. If so follow the link in ahulett's post for instructions on removing nastie.
Forums » Up and Running » Security » SecuritySecurity Software Updates - 4 May 2008 »
« Conerning The On Going Denial of Service Attacks Today.  


Wednesday, 11-Nov 01:01:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [125] Moto Sold About 100,000 Droids
· [95] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [68] Government Will Release Some Telco Wiretap Lobbying Documents
· [62] Verizon's Hanging Up On Rural America
· [50] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [32] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [24] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· [Rant] windows 7 is the most retarded os ever and its broke to [Rants, Raves, and Praise]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] 3.2.2 Rogue [World of Warcraft]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Slow speed lately? [TekSavvy]
· Rental modem -> Purchased modem procedure [Comcast HSI]
· Telus supports CRTC's NN and UBB [TekSavvy]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]