<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: foxnews.com infected?&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22225362</link>
<description></description>
<language>en</language>
<pubDate>Fri, 24 May 2013 04:58:18 EDT</pubDate>
<lastBuildDate>Fri, 24 May 2013 04:58:18 EDT</lastBuildDate>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22367178</link>
<description><![CDATA[anon posted : I got similar infection from DrudgeReport.com (on 2 different occasions);  All IPs traced back to Ukraine.<br><br>Please note people - you may think you removed it, but really did not.  Malwarebytes and others do not detect Rootkits.  You should run ROOTKITREVEALER.  I thought I had cleaned this, and I had really not.  There was  a deep and nasty rootkit involved here.  Only way to remove was to boot off a Windows CD, and delete hidden drivers.  I would be willing to bet that half the people think they clean this stuff and its not really clean.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22367178</guid>
<pubDate>Sun, 10 May 2009 12:53:16 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22343323</link>
<description><![CDATA[karateckie posted : <div class="bquote"><small>said by <a href="/profile/197199" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=197199');">Doctor Four</a>:</small><br><br>Although this sounds like a simple answer, it is really a case of throwing the baby out with the bathwater. And malvertisements aren't solely found on music streaming sites or those owned by Rupert Murdoch. <br><br>Any site that uses an advertiser which accepts an ad campaign on short notice without doing some investigation into the ad buyers can get hit by this; Google's Doubleclick ad network, one of the largest, got hit last year sometime.<br></div>I agree with you Doctor. I know of a few sites with similar issues lately (there was a recent article I found...from early April...about the same issue with Yahoo). It's interesting about the playlist.com thing. I use that site and will have to keep an eye on it. Anyway, we have a very large network where it would be a nightmare to migrate everyone to Firefox and train them to use no script. While I use the same setup at home and on my computers at work, it's not a viable solution in our environment.<br><br>However blocking ads is a great solution! Unfortunately, we are in the middle of working out how to block them (we used to block them through our web filtering provider..which has changed). They new web filtering provider can't/won't block ads. I suppose it's the nature of the provider, being a free service they advertise on their sites and thus don't want to provide ad blocking. Other options are hosts files (but maintaining them in a large network...ugh), not to mention sending Dequests to 127.0.0.1 take awhile to time out, and if put in a DNS server can seriously cripple it with many clients.<br><br>Anyway...the end result is for the time being, Fox News is blocked. We haven't seen issues from other sites at this point, and eventually it will be unblocked.<br><br>I think the real issue lies in the websites who allow advertising on their site. They need to take some responsibility in what they are displaying, whether it comes from their own servers or not. The end result is that Fox, Yahoo, Google and others are being poorly represented when someone browses to what they believe should be a solid, and trusted site, only to get a virus. Companies need to demand accountability from the ad providers that pay them to display ads.<br><br>In the meantime...to minimize risks we'll block any site that we have issues with, as well as research better alternative to blocking ads :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22343323</guid>
<pubDate>Tue, 05 May 2009 15:06:28 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22334835</link>
<description><![CDATA[La Luna posted : <div class="bquote"><small>said by <a href="/profile/243195" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=243195');">fatness</a>:</small><br><br>At least 2 people did earlier in this thread:<br><br>&raquo;<A HREF="/forum/r22225362-foxnewscom-infected~start=60">foxnews.com infected?</A><br>&raquo;<A HREF="/forum/r22261812-">Re: foxnews.com infected?</A><br><br>Like you said, memory is the first thing to go. ;)<br> </div>ahhh shaddup you old monkey.  :D :D<br><small>--<br><b><i>You can chain my body to the earth, but still my spirit flies!</i><br> <br><A HREF="http://www.thereligionofpeace.com/">13,143 DEADLY TERROR ATTACKS SINCE 9/11</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22334835</guid>
<pubDate>Sun, 03 May 2009 21:59:47 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22334755</link>
<description><![CDATA[fatness posted : At least 2 people did earlier in this thread:<br><br>&raquo;<A HREF="/forum/r22225362-foxnewscom-infected~start=60">foxnews.com infected?</A><br>&raquo;<A HREF="/forum/r22261812-">Re: foxnews.com infected?</A><br><br>Like you said, memory is the first thing to go. ;)<br><small>--<br><A HREF="http://www.dslreports.com/r0/download/1370721~74256f2b8b4b5b881ae82d211fa2c6ad/couch.jpg">goodbye dad</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22334755</guid>
<pubDate>Sun, 03 May 2009 21:43:43 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22334218</link>
<description><![CDATA[La Luna posted : So after all of this, is the site still infected? Did anyone let them know there was a problem?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22334218</guid>
<pubDate>Sun, 03 May 2009 19:28:24 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22334126</link>
<description><![CDATA[Doctor Four posted : <div class="bquote"><small>said by <a href="/profile/1640095" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1640095');">karateckie</a>:</small><br><br>Just a note to add:<br>We've had several users at our company affected by this same issue. Before today there were 3, and now as of today there were 2 more. This prompted us to temporarily block foxnews.com. Though we know the issue is not limited to Fox nor is it directly the fault of foxnews.com, all of our virus issues in the last week and a half have come from browsing to this site. Hours spent solving virus problems + ease of blocking Fox = no more foxnews.com.<br> </div>Something similar happened last week at our company, though not with foxnews.com. There was a malvertisement at playlist.com (a music streaming site, I believe), which infected or attempted to infect several users. As a result, streaming audio sites are banned until IT can find a way to block the malicious ads that are hijacking users.<br><br>Although this sounds like a simple answer, it is really a case of throwing the baby out with the bathwater. And malvertisements aren't solely found on music streaming sites or those owned by Rupert Murdoch. <br><br>Any site that uses an advertiser which accepts an ad campaign on short notice without doing some investigation into the ad buyers can get hit by this; Google's Doubleclick ad network, one of the largest, got hit last year sometime.<br><br>A better solution is using Firefox with a hosts file and NoScript. I do this on my home PC, and while I have encountered attempts at getting redirected by malvertisements, they have never succeeded due to that combination. The redirect usually ends up on a blank page.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22334126</guid>
<pubDate>Sun, 03 May 2009 19:03:58 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22328967</link>
<description><![CDATA[Oleg posted : For those who got hit does it affects Firefox with adbock plus or just IE? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22328967</guid>
<pubDate>Sat, 02 May 2009 12:12:07 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22327555</link>
<description><![CDATA[anon posted : my mom recently played a video on fox news and soon after a virus installed itself onto our comp. my security center says it was from the ip 72.95.109.11(Malaysia)... she was watching a vid about teens hijacking a car. i dont know the direct link but when i searched the ip in wich  where the trojan came from i found this forum...leve my IP alone you mean malasians!!!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22327555</guid>
<pubDate>Fri, 01 May 2009 23:54:51 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22303291</link>
<description><![CDATA[karateckie posted : Just a note to add:<br>We've had several users at our company affected by this same issue. Before today there were 3, and now as of today there were 2 more. This prompted us to temporarily block foxnews.com. Though we know the issue is not limited to Fox nor is it directly the fault of foxnews.com, all of our virus issues in the last week and a half have come from browsing to this site. Hours spent solving virus problems + ease of blocking Fox = no more foxnews.com.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22303291</guid>
<pubDate>Mon, 27 Apr 2009 15:50:17 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22298614</link>
<description><![CDATA[MGD posted : Interesting report on the norton.com forums, which has a link back to this thread. <A HREF="http://community.norton.com/norton/board/message?board.id=nis_feedback&message.id=48418">A poster stated</a> that while on this foxnews.com page yesterday 04/24: &raquo;<A HREF="http://www.foxnews.com/story/0,2933,517738,00.html" >www.foxnews.com/story/0,2933,517738,00.html</A> they then clicked the link to the full story at UK site of The Sun newspaper: >http://www.thesun.co.uk/sol/homepage/news/article2389814.ece?OTC-RSS&ATTR=News (several of the same adservers as foxnews.com), and Norton immediately flagged a bloodhound.pdf.10 virus. This will be dificult to duplicate because it depends on the rotating adds, probably flash, and the user config.<br><br>Though not a direct foxnews.com vector, the interesting issue is that the attempt matches a pdf exploit that  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> documented in an earlier post. <br><br>I believe that this multiple opportunistic format, utilizing exploited adds on high traffic sites, will become an epidemic. Apparently it has not been established, or at least published, whether they are pushed by rogue advertisers within the system, or are from hacked exploited flash adds. There is no doubt that there are several ongoing campaigns to create massive botnets of infected machines. Though I posted the socks C&C for a global inventory of hijacked PCs "Socksps.ru", which was located on the call home IP of the pdf exploit that  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> posted, the second of the three domains located there "stopgam.cn" is labeled "BOT" and also has a login:<br><br>[att=1]<br><br>See: &raquo;<A HREF="http://www.google.com/search?q=trojan.alupko&hl=en&safe=active&sa=2" >www.google.com/search?q=trojan.a&middot;&middot;&middot;ive&sa=2</A><br><br>Incidentally, just mentioning the mere existence of "Socksps.ru" and its purpose, is a violation of their stated Rules / TOS.<br><br>[att=2]<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/22298614?c=1423433&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="13850 bytes" BORDER=0 WIDTH=368 HEIGHT=361 SRC="/r0/download/1423433~ff91827bf5c53515ee0e0afc5ca7b9f2/stopgam_cn_login.jpg"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width="1%">&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22298614?c=1423434&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="69510 bytes" WIDTH=600 HEIGHT=353 SRC="/r0/download/1423434.thumb600~0691592aee594587a7e1b2cb6272369b/socksps.ru_rules1.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22298614</guid>
<pubDate>Sun, 26 Apr 2009 15:04:11 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22292178</link>
<description><![CDATA[La Luna posted : <div class="bquote"><small>said by <a href="/profile/243195" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=243195');">fatness</a>:</small><br><br>Oops. Thank you for catching that. <br> </div>It's ok, I know the eyes aren't what they used to be.  :D<br><small>--<br><b>1/20/09 The Beginning of the End<br> <br><A HREF="http://www.thereligionofpeace.com/">13,100 DEADLY TERROR ATTACKS SINCE 9/11</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22292178</guid>
<pubDate>Fri, 24 Apr 2009 20:51:26 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22290276</link>
<description><![CDATA[anon posted : I am interested in removal, the infection runs pretty deep.  I am sitting here in safe mode xp_sp3.  I can delete the rundll references in regedit (hklm/sw/m/cv/run/), hit refresh and they appear again.  To me that says one of the main windows components is infected.  Could this lead to lsas being compromised?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22290276</guid>
<pubDate>Fri, 24 Apr 2009 14:09:50 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22289441</link>
<description><![CDATA[Bill G posted : My parents PC was infested by this. It actually caused it to crash. Thankfully I was able to recover all of their files using Ghost. <br><br>Nasty thing.<br><br>I did combofix as well as Malwarebytes but honestly, the thing just crashed when I tried to run Superantispyware which they always work magically for me. not this time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22289441</guid>
<pubDate>Fri, 24 Apr 2009 11:28:22 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22288446</link>
<description><![CDATA[jadedkisses posted : Thank you secured655!  I appreciate your time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22288446</guid>
<pubDate>Fri, 24 Apr 2009 05:54:21 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22288046</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/1350120" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1350120');">Graycode</a>:</small><br><br>..Why no mention of <b>adsonar.com</b> ?  The foxnews pages are splattered with scripting for them.  Their script <b>www<i>.</i>foxnews.com/js/adsonar.js</b> is one that injects <b>iframe</b>s into the pages being viewed.  Foxnews also includes script hxxp://js.adsonar.com/js/adsonar.js and references ads.adsonar.com<br><br>I happen to block things from adsonar.com and they're also included in MVPS and HP_HOSTS.<br> </div>Indeed, adsonar references are all over the fox pages.<br><br>adsonar lists Foxnews.com as one of the locations they have access to advertise on <A HREF="http://www.quigo.com">adsonar aka quigo.com</a>   Maybe the relationship is something other than a third part vendor. <br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22288046</guid>
<pubDate>Fri, 24 Apr 2009 01:04:32 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22288008</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/429050" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=429050');">La Luna</a>:</small><br><br>Whether it's been cleaned up today, I don't know.<br> </div>I have been monitoring random pages on foxnews on and off since early on 04/21, and have not experienced any incidence of the malware. Not a testimonial that it is clean, though I have not seen any other reports of malware either during that time.<br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22288008</guid>
<pubDate>Fri, 24 Apr 2009 00:48:44 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22287768</link>
<description><![CDATA[fatness posted : Oops. Thank you for catching that. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22287768</guid>
<pubDate>Thu, 23 Apr 2009 23:26:39 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22287179</link>
<description><![CDATA[La Luna posted : <div class="bquote"><small>said by <a href="/profile/243195" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=243195');">fatness</a>:</small><br><br>....The article says Fox got rid of it.<br>  <blockquote><small>quote:</small><hr>............a brief analysis of the campaign which now appears to have been removed by FoxNews. <hr></blockquote><br><br> </div>That article was posted on 4/15...I think we know from this thread that the problem was still going on even in the last day or two. <br><br>Whether it's been cleaned up today, I don't know.<br><small>--<br><b>1/20/09 The Beginning of the End<br> <br><A HREF="http://www.thereligionofpeace.com/">13,100 DEADLY TERROR ATTACKS SINCE 9/11</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22287179</guid>
<pubDate>Thu, 23 Apr 2009 21:24:39 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22286594</link>
<description><![CDATA[anon posted : jadedkisses, I'm no expert, but I'll try to answer your questions. <br><br>1. It's called scareware because, the infection scheme is to trick the unwary user into enabling the malware to get into his/her machine by scaring them with an message that appears legit. It informs them of bogus problems found on their computer. Click 'here' to fix this problem. That click leads to a successful infection of the computer.<br>What can happen varies, from a simple browser homepage hijack to worse. Usually the scheme wants the user to buy some bogus security software, which is usually malware as well.<br>2. Hard to say where your trojans came from. One helpful tool for updating all of your SW is secunia PSI available here:<br>&raquo;<A HREF="http://secunia.com/vulnerability_scanning/personal/" >secunia.com/vulnerability_scanning/personal/</A> <br>Java seems to be a special case where updating to current version will not remove older vulnerable version(s). They need to be removed via add remove programs.<br>3. Real experts have posted on this thread and given me sufficient reason to block foxnews.com in avast.<br>Until a consensus (here) shows the site to be clean, the block remains (FWIW, this is a personal choice, others should do as they are comfortable with). Based on reports it seems that major news sites (CNN etc) seem to be experiencing these problems more frequently, so apply caution when visiting these sites.<br>A little OT, but I hope helpful.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22286594</guid>
<pubDate>Thu, 23 Apr 2009 19:28:55 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22286237</link>
<description><![CDATA[acid343211 posted : <div class="bquote"><small>said by <a href="/profile/243195" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=243195');">fatness</a>:</small><br><br>The article says Fox got rid of it.<br>  <blockquote><small>quote:</small><hr>............a brief analysis of the campaign which now appears to have been removed by FoxNews. <hr></blockquote><br><br> </div>Fatness,I think people need to still be careful of that site i won't trust it.<br><small>--<br>Visit-<br>www.liveleak.com/view?i=e32_1231680425</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22286237</guid>
<pubDate>Thu, 23 Apr 2009 18:17:12 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22282664</link>
<description><![CDATA[jadedkisses posted : I am a novice and would like to ask some questions if I may.  I was on Foxnews and had the popup appear days ago.  I didn't click on anything.  I was just reading the front page (Foxnews.com)<br><br>1. Do they call it scareware because it just scares you and nothing can happen?<br><br>2.  I posted my hijack log in Security Cleanup and I had some trojans? in Java.  Would this have come from that popup on Fox?  Or I picked it up somewhere else? [My Java was not up to date]<br><br>3.  I've read this whole thread, those links (and the znet one) and it's all gibberish to me.  I know that article states fox got rid of the virus (or whatever it's called) but have you brave folks checked it out yourselves?  I would like to go there but want to be sure it's gone.<br><br>Thanks so much for your time.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22282664</guid>
<pubDate>Thu, 23 Apr 2009 01:12:32 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22279238</link>
<description><![CDATA[fatness posted : Thanks for posting that. Here's the direct link to the story: &raquo;<A HREF="http://blogs.zdnet.com/security/?p=3140" >blogs.zdnet.com/security/?p=3140</A><br>Apparently it was reported on other sites as well as this one.<br><br>&raquo;<A HREF="http://whiskeyfire.typepad.com/whiskey_fire/2009/04/warning-antivirus-2009-ad-on-fox-news-site.html" >whiskeyfire.typepad.com/whiskey_&middot;&middot;&middot;ite.html</A><br>&raquo;<A HREF="http://www.wilderssecurity.com/showthread.php?p=1444510" >www.wilderssecurity.com/showthre&middot;&middot;&middot;=1444510</A><br><br>The article says Fox got rid of it.<br> <blockquote><small>quote:</small><hr>............a brief analysis of the campaign which now appears to have been removed by FoxNews. <hr></blockquote><br><small>--<br><A HREF="http://www.dslreports.com/r0/download/1370721~74256f2b8b4b5b881ae82d211fa2c6ad/couch.jpg">goodbye dad</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22279238</guid>
<pubDate>Wed, 22 Apr 2009 14:09:06 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22275424</link>
<description><![CDATA[tdrake2175ds posted : There was a story on ZDNet about Fox News being hit by malvertising ads:<br><br>&raquo;<A HREF="http://updates.zdnet.com/tags/malvertising.html" >updates.zdnet.com/tags/malvertising.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22275424</guid>
<pubDate>Tue, 21 Apr 2009 21:12:34 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22274609</link>
<description><![CDATA[anon posted : When running Vista with UAC off and IE sandbox off, can surfing foxnews infect the system directly, with no clicks on the banner window? I am patched up to a month ago. With Firefox?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22274609</guid>
<pubDate>Tue, 21 Apr 2009 18:50:54 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22272190</link>
<description><![CDATA[Graycode posted : <div class="bquote"><small>said by <a href="/profile/666842" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=666842');">MGD</a>:</small><br><br>Foxnews.com offers a comprehensive list of advertiser options: &raquo;<A HREF="http://advertise.foxnews.com/creative-specs/" >advertise.foxnews.com/creative-specs/</A> and also the following Approved Third Party Vendors:<br><br>Atlas<br>Doubleclick<br>Eyeblaster<br>Eyewonder<br>Klipmart<br>Pointroll<br>Unicast<br>Zedo<br><br>Ref: &raquo;<A HREF="http://advertise.foxnews.com/creative-specs/third-party-vendors/" >advertise.foxnews.com/creative-s&middot;&middot;&middot;vendors/</A><br> </div>Why no mention of <b>adsonar.com</b> ?  The foxnews pages are splattered with scripting for them.  Their script <b>www<i>.</i>foxnews.com/js/adsonar.js</b> is one that injects <b>iframe</b>s into the pages being viewed.  Foxnews also includes script hxxp://js.adsonar.com/js/adsonar.js and references ads.adsonar.com<br><br>I happen to block things from adsonar.com and they're also included in MVPS and HP_HOSTS.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22272190</guid>
<pubDate>Tue, 21 Apr 2009 12:13:13 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22271850</link>
<description><![CDATA[mysec posted : <div class="bquote"><small>said by <a href="/profile/510041" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=510041');">planet</a>:</small><br><br>  <blockquote><small>quote:</small><hr>1) Scripting disabled. (Javascript, not Java).<hr></blockquote><br><br>Wow, so in this case scripting is disabled. I thought javascript would be needed.</div><br>Ooops - a booboo - that should be reversed, of course! Thanks for noticing that!<br><br>Javascript is required, and with it disabled, <b>none</b> of those exploits at Foxnews work.<br><br>Sorry for the confusion. I changed that in my post.<br><br><div class="bquote"><small>said by <a href="/profile/510041" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=510041');">planet</a>:</small><br><br>So, if the pdf loads in the browser window, then a software FW configured properly should request permission for adobe to access the net, is this correct? </div><br>That is correct.<br><br><div class="bquote"><small>said by <a href="/profile/510041" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=510041');">planet</a>:</small><br><br>And, what if you are using the latest adobe reader, 9.1, is this exploit still possible? </div><br>No, nor are any of the exploits against IE possible if patched.<br><br>The problem, of course, is that many exploits go unpatched for a while after they are released in the wild. The recent PDF exploit, if you remember: it was several weeks before a patch was released.<br><br>Patching, updating, are certainly preventative measures. Someone mentioned using a Hosts file. The important thing is that everyone understand what they are protecting against and insure that their security setup provides appropriate preventative measures. <br><br>This is not always easy because often advisories about a new exploit don't give a lot of information, so you have to do some research.<br><br><div class="bquote"><small>said by <a href="/profile/307353" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=307353');">Sentinel</a>:</small><br><br>I have Firefox with NoScript and I also don't have Adobe PDF Reader installed on my PC at all. I also have KPF but it does not register anything trying to get in or out. </div><br>This exploit works only against the PDF reader, so even if the PDF file loaded in the browser, nothing would happen without the Adobe Reader being installed.<br><br>You may remember the most recent PDF exploit used some type of image rendering engine in the Adobe Reader. Foxit also uses something similar and there was concern amongst Foxit readers that they might be vulnerable. Foxit support insured users on their forum that Foxit uses a different engine and was not susceptible to the current exploit. <br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22271850</guid>
<pubDate>Tue, 21 Apr 2009 11:10:31 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22271329</link>
<description><![CDATA[Sentinel posted : I wonder if this could be another thing I am doing that blocks this behavior.<br><br>I have Firefox with NoScript and I also don't have Adobe PDF Reader installed on my PC at all. I also have KPF but it does not register anything trying to get in or out.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22271329</guid>
<pubDate>Tue, 21 Apr 2009 09:39:35 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22271026</link>
<description><![CDATA[planet posted :  <blockquote><small>quote:</small><hr>1) Scripting disabled. (Javascript, not Java).<br><br>If I enable Javascript in Firefox's Options and in Opera's Preferences, nothing happens: this exploit (and the WinAntiVirus exploit) fails at this point.<hr></blockquote><br>Wow, so in this case scripting is disabled. I thought javascript would be needed.<br><br>So, if the pdf loads in the browser window, then a software FW configured properly should request permission for adobe to access the net, is this correct? <br><br>And, what if you are using the latest adobe reader, 9.1, is this exploit still possible?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22271026</guid>
<pubDate>Tue, 21 Apr 2009 08:25:00 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22270715</link>
<description><![CDATA[mysec posted : <div class="bquote"><small>said by Comment by Anita in VA   :</small><br><br> April 18th, 2009 at 6:52 am <br>Good morning fellow bloggers&#150;<br><br>I have a quick question&#150;have any of you experience, when first accessing the Greenroom Blog, a Windows Explorer popup windows, saying you need to run a virus scan on your computer?...<br><br>jimmy/all&#150;yes, that was actually the FakeAlert Trojan&#150;<br><br>other bloggers&#150;if you also got that popup, run a REAL virus scan of your computer, <br><b><br>even if you X&#146;d out of it. You&#146;re probably now infected with the FakeAvAlert Trojan </b><br></div><br>This is just <b>wrong</b> since it's pretty much agreed that the user/victim has to click in the download box to get the trojan onto the system. <br><br>Am I interpreting correctly her statement? If so, how misleading and unnecessarily fear-provoking such a statement is for her readers.<br><br>This notion came up last year when new exploits of WinAntiVirus surfaced, and in a long thread, <b> bcastner <A HREF="/useremail/u/693977"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></b> made it clear that this is not a drive-by download exploit.<br><br>Much has been written and commented on concerning the much feared drive-by download. From my viewpoint, these types of  exploits are very easy to prevent when proper security is in place. Most of the time they need to bypass several security measures before achieving success.<br><br>By the way, the term "drive-by" limits the exploits to web sites. Notice that Microsoft uses the more comprehensive phrase, "Remote Code Execution:"<br><br>&raquo;<A HREF="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;014.mspx</A><br><div class="bquote">The vulnerabilities could allow remote code execution if a user <b>views a specially crafted Web page</b> using Internet Explorer</div><br>&raquo;<A HREF="http://www.microsoft.com/technet/security/Bulletin/MS09-009.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;009.mspx</A><br><div class="bquote">The vulnerabilities could allow remote code execution if the user <b>opens a specially crafted Excel file</b>.</div><br>In both cases, malicious code executes "remotely" - automatically.<br><br>PDF exploits in the wild fall into both categories:<br> <br><blockquote><br>&#8226;the one on the Fox News site is web-based<br><br>&#8226;others arrive by email where the user/victim decides to open the file. <br></blockquote><br>The end result is the same: code in the PDF file calls out to a server hosting malware which is then downloaded to the user/victim's computer.<br><br>The Fox News PDF web-based exploit is a good example of remote code execution. In order for it to succeed, 4 requirements must be in place. I'll summarize from previous posts.<br><br><b>1)</b> Scripting enabled. (Javascript, not Java). <br><br>If I disable Javascript in Firefox's Options and in Opera's Preferences, nothing happens: this exploit (and the WinAntiVirus exploit) fails at this point.<br><br><b>2)</b> The PDF file must load into the browser. If the browser is configured to Prompt for a Download...<br><br>[att=1]<br><br>... the user is in the same position as with the WinAntiVirus exploit: to be victimized, the user must consent to download.<br><br>In both cases, the reaction should be: Hey, I didn't go looking for this. CANCEL. With the fake antivirus exploit, the suggestion is to close the browser process in Task Manager.<br><br><b>3)</b> The 3rd requirement for the PDF exploit by remote code execution is that the Acrobat Reader must connect out to the internet to retrieve the malware. Outbound firewall monitoring will permit only those applications previously authorized by the user. The PDF Reader, of course, should not be given free access to the internet:<br><br>[att=2]<br><br><b>4)</b> Finally, the trojan must be able to download/install without anything blocking it. The most secure protection for these types of exploits is some type of White Listing which blocks <b>ALL</b> unauthorized executable files that attempt to download/install:<br><br>[att=3]<br><center><br><div class="bquote">File load.exe received on 04.17.2009 08:39:38 (CET)<br>Sunbelt 3.2.1858.2 2009.04.17 InfoStealer.Snifula.a (v)</div></center><br>Other solutions include running in a non-Administrator account; configuring Software Restriction Policies.<br><br>If this malicious PDF arrived by email and the user opened it, note that proper security at steps <b>3)</b> and <b>4)</b> would block the exploit from succeeding.<br><br>I hope you can see why Remote Code Execution Exploits should be the easiest to prevent. Look at all of the hurdles necessary to jump before the exploit is successful. <br><br>While something certainly needs to be done about stopping the occurrence of exploits on web pages, nonetheless for people with proper security protection and policies in place, they are an annoying nuisance rather than a threat.<br><br>----<br>rich<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22270715?c=1421744&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="24981 bytes" BORDER=0 WIDTH=577 HEIGHT=514 SRC="/r0/download/1421744~7dc0037ee6beb81637316c510eba886a/ff-pdfPrompt.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22270715?c=1421746&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="23620 bytes" BORDER=0 WIDTH=553 HEIGHT=536 SRC="/r0/download/1421746~aa21749c66aa0a5bcc079a0859daf4da/ff-acroKerio.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22270715?c=1421747&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="28053 bytes" BORDER=0 WIDTH=559 HEIGHT=693 SRC="/r0/download/1421747~8493f6f04b3ded6b51a809e0007cdd70/ff-acroKerioAe.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22270715</guid>
<pubDate>Tue, 21 Apr 2009 04:10:59 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22270302</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/424692" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=424692');">FiOS Dan</a>:</small><br><br><div class="bquote"><small>said by <a href="/profile/307353" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=307353');">Sentinel</a>:</small><br><br>...I use a hosts file to block ads as well.</div>Methinks that's the ticket.<br> </div>That may be one of several reasons why some users were never exposed, nor triggered any other alerts. I spent some time checking the add rotations and noticed that several of the domains showed up as blocked in several hosts files. As a first line of defense, that may have prevented many AV, and script blockers from barking.<br><br>Foxnews.com offers a comprehensive list of advertiser options: &raquo;<A HREF="http://advertise.foxnews.com/creative-specs/" >advertise.foxnews.com/creative-specs/</A> and also the following Approved Third Party Vendors:<br><br>Atlas<br>Doubleclick<br>Eyeblaster<br>Eyewonder<br>Klipmart<br>Pointroll<br>Unicast<br>Zedo<br><br>Ref: &raquo;<A HREF="http://advertise.foxnews.com/creative-specs/third-party-vendors/" >advertise.foxnews.com/creative-s&middot;&middot;&middot;vendors/</A><br><br>I spent several hours reviewing the top banner adds, many are flash, but not all. One issue that I noted is that there were several complaints of infection attempts while on <b>blogs.foxnews.com</b> which appears to have less adds than the other pages.<br><br>For example, posters on "FOX News Blogs &raquo; Alisyn in the Greenroom" noted the following on 04/18<br><br> <blockquote><small>quote:</small><hr>Comment by Anita in VA <br>April 18th, 2009 at 6:52 am <br>Good morning fellow bloggers&#150;<br><br>I have a quick question&#150;have any of you experience, when first accessing the Greenroom Blog, a Windows Explorer popup windows, saying you need to run a virus scan on your computer?<br><br>I had it happened last saturday, when on work travel, from my work computer, and then again this morning, from my home computer.<br><br>Comment by Jimmy <br>April 18th, 2009 at 6:54 am <br>yes Anita&#133;..it a shame&#133;ran my program&#133;no infections&#133;.they bother you to try to grt you to buy their program&#133;.do not load the program<br><br>Comment by Anita in VA <br>April 18th, 2009 at 6:59 am <br>jimmy/all&#150;yes, that was actually the FakeAlert Trojan&#150;<br><br>other bloggers&#150;if you also got that popup, run a REAL virus scan of your computer, even if you X&#146;d out of it. You&#146;re probably now infected with the FakeAvAlert Trojan<br><br>Alisyn/Foxnews&#150;<br>Please scan your website pages, it was definitely a link/ad on your pages that produced the popup that infects with the FakeAVAlert Trojan.<br><hr></blockquote><br><br>Ref: &raquo;<A HREF="http://greenroom.blogs.foxnews.com/2009/04/18/saturday-morning-15/" >greenroom.blogs.foxnews.com/2009&middot;&middot;&middot;ning-15/</A><br><br>I hope that Fox comes forward and informs the public of its findings. I believe it is important that the exploit vector is made public so that everyone can be aware of the methods that are used.<br><br>This epidemic has affected many high traffic sites, irrespective of the content. Cybercriminals are not selective. However, the compromising of such a high value target warrants some disclosure of the facts, in order to mitigate additional potentil targets, and address issues with third party advertisers.<br><br>Fox's own stats list:<br><br>13.5 Million Unique users per month<br><br>615 Million Page views per month<br><br>That is a significant potential exposure. One can debate how many visitors come from fully patched updated systems, and are savvy enough to weave through the fake screens if exposed.<br><br>One interesting side note, while vetting the top banner adds last night, a non flash advertisement came up for E*TRADE. There was absolutely no nefarious activity associated with it. However, it was impossible to perform any vetting of the source. The properties of the add appeared to link to a subdirectory of Lorentrio.com which is hosted in Holland on a Leaseweb IP 94.75.216.152 <br><br>The initial concern was the entire anonymonity of the set up. <br><br>There are 10 domains hosted on IP 94.75.216.152: <br><br>01.  Alitasis.com <br>02.  Idatrinity.com <br>03.  Junstring.com <br>04.  Kemerlane.com <br>05.  Lacoste-ads.com <br>06.  Lorentrio.com <br>07.  Mosdao.com <br>08.  Namlean.com <br>09.  Nokia-corp.com <br>10.  Tornadomb.com <br><br>One would assume that "Nokia" could be a copyright issue. The eyebrow raiser is that all of these domains were registered within the last month or so. All appeared to be registered using ICANN Registrar: <br><br>DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A <br>PUBLICDOMAINREGISTRY.COM <br><br>In addition, they were all registered using a cloaking service PrivacyProtect.org:<br><br>Such as:<br><br> <blockquote><small>quote:</small><hr>Registration Service Provided By: REGISTER SERVICES<br>Contact: +001.8882106539<br><br>Domain Name: LORENTRIO.COM <br><br>Registrant:<br>    PrivacyProtect.org<br>    Domain Admin        ()<br>    P.O. Box 97<br>    Note - All Postal Mails Rejected, visit Privacyprotect.org<br>    Moergestel<br>    null,5066 ZH<br>    NL<br>    Tel. +45.36946676<br><br>Creation Date: 29-Mar-2009  <br>Expiration Date: 29-Mar-2010<br><hr></blockquote><br><br>Again, nothing appeared wrong with the add, however, in most other circumstances the above criteria would be cause for concern. Though not necessarily unusual in these circumstances, but all the domains contain a "deny all" robots.txt file. Who are these people ??<br><br>As  Cometcom1 <A HREF="/useremail/u/1637908"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> noted to me, and I believe it was also mentioned in Dancho Danev's blog, Google's safe browsing diagnostic of foxnews.com notes the site as not suspicious. It is somewhat ambiguous as they do note that:<br><br> <blockquote><small>quote:</small><hr>"Malicious software is hosted on 3 domain(s), including 2mdn.net/, s3.wordpress.com/, llnwd.net/."<br><hr></blockquote><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/68/89368.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/68/89368-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://www.google.com/safebrowsing/diagnostic?site=http%2a//foxnews.com" >www.google.com/safebrowsing/diag&middot;&middot;&middot;news.com</A><br>Snapped 2009-04-21 00:45:11 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br>If you check Google's analysis of one of the above three:<br>s3.wordpress.com, it shows:<br><br> <blockquote><small>quote:</small><hr><b>Has this site hosted malware?</b><br><br>Yes, this site has hosted malicious software over the past 90 days. It infected 1 domain(s), including foxnews.com/.<br><hr></blockquote><br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/69/89369.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/69/89369-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://www.google.com/safebrowsing/diagnostic?site=s3.wordpress.com/" >www.google.com/safebrowsing/diag&middot;&middot;&middot;ess.com/</A><br>Snapped 2009-04-21 00:44:54 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br>I hope the focus can remain on the current stage of this epidemic and systemic organized cyber crime, and not on what the content of the infested high traffic website du-jour is. This problem will continue to invade the entire internet until concerted efforts are made to go after the money, and the commercial and financial systems that are utilized to support it.  <br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22270302</guid>
<pubDate>Tue, 21 Apr 2009 00:49:29 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22270016</link>
<description><![CDATA[La Luna posted : It seems that CNN was affected with a malware issue just last summer:<br><br>&raquo;<A HREF="http://blog.mxlab.be/2008/08/04/cnn-daily-top-10-leads-users-to-site-hosting-malware/" >blog.mxlab.be/2008/08/04/cnn-dai&middot;&middot;&middot;malware/</A><br><br>Apparently no one is immune when it comes from the outside rather than within (which has been foolishly implied here).<br><small>--<br><b>1/20/09 The Beginning of the End<br> <br><A HREF="http://www.thereligionofpeace.com/">13,079 DEADLY TERROR ATTACKS SINCE 9/11</a></b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22270016</guid>
<pubDate>Mon, 20 Apr 2009 23:32:20 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22269808</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by milvos :</small><br><br>.... I have been getting this up with the fake virus scan for a few days now. And want to know whether it is something on my computer or whether this is coming from sites I am visiting. When I leave my computer idle for while it seems to come up. <br><br>Any help appreciated.<br> </div>One rudimentary test is to disconnect the internet connection from the computer. Restart it, open your web browser and see if the popups still come up. You may not even have to open a web browser. If popups come up, or your browser attempts to connect to another website, then it is likely that malware is present in your computer. <br><br>MGD]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22269808</guid>
<pubDate>Mon, 20 Apr 2009 22:54:13 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22269315</link>
<description><![CDATA[FiOS Dan posted : <div class="bquote"><small>said by <a href="/profile/307353" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=307353');">Sentinel</a>:</small><br><br>...I use a hosts file to block ads as well.</div>Methinks that's the ticket.<br><small>--<br><i>Courage is being scared to death but saddling up anyway.</i><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22269315</guid>
<pubDate>Mon, 20 Apr 2009 21:24:57 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22268686</link>
<description><![CDATA[anon posted : I have been reading all this and maybe am no great with virus, adware, spyware etc.<br><br>I have been getting this up with the fake virus scan for a few days now. And want to know whether it is something on my computer or whether this is coming from sites I am visiting. When I leave my computer idle for while it seems to come up. <br><br>Any help appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22268686</guid>
<pubDate>Mon, 20 Apr 2009 19:32:16 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22267539</link>
<description><![CDATA[acid343211 posted : Easy Fix block the site and Disable Downloading on your PC.<br><br>Now when i go to the Site it gives me a Red screen Blocked by Administrator.<br><small>--<br>Visit-<br>www.liveleak.com/view?i=e32_1231680425</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22267539</guid>
<pubDate>Mon, 20 Apr 2009 16:28:05 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22267451</link>
<description><![CDATA[MGD posted : <div class="bquote"><small>said by <a href="/profile/1295721" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1295721');">mysec</a>:</small><br><br>....<br>Note that this is an Acrobat Reader exploit, not a browser exploit. The browser just loads the PDF file. This exploit works in all browsers. Be sure and configure your file types to Prompt for Download, or "Always Ask"<br>..<br>----<br>rich<br> </div>Great write up !<br><br>I was particularily interested in this driveby:<br><br> <blockquote><small>quote:</small><hr>[Adobe Reader 6.0 from your computer wants to <br>connect to plathost.ru [78.109.25.217], port 80]<br><hr></blockquote><br><br>as that location has come to my attention on several occasions.<br><br>IP 78.109.25.217<br><br>appears to be hosting 3 domains: &raquo;<A HREF="http://whois.domaintools.com/78.109.25.217" >whois.domaintools.com/78.109.25.217</A><br><br>1.  Nevervhudo.ru  &raquo;<A HREF="http://whois.domaintools.com/nevervhudo.ru" >whois.domaintools.com/nevervhudo.ru</A><br><br>2.  Socksps.ru &raquo;<A HREF="http://whois.domaintools.com/Socksps.ru" >whois.domaintools.com/Socksps.ru</A> <br><br>3.  Stopgam.cn &raquo;<A HREF="http://whois.domaintools.com/Stopgam.cn" >whois.domaintools.com/Stopgam.cn</A> <br><br>Due to the name, Socksps.ru aroused some curiosity, however, the main page only offers a log in:<br><br>[att=1]<br><br>If one can overcome that restriction an account holder can purchase the use of compromised machines around the globe to use as a secure proxy:<br><br>[att=2]<br><br>This may be where some of the compromised victim machines are leveraged for additional income:<br><br>The master list of available for rent machines is several pages long:<br><br>[att=3]<br><br>You can sort the available hijacked machines by country, and then buy access, daily or monthly to mask your true origin for any nefarious purpose:<br><br>USA:<br><br>[att=4]<br><br>UK:<br><br>[att=5]<br><br>Iran:<br><br>[att=6]<br><br>Note the banner add for "carding Conference" at cashing.cc:<br><br>This may be where the compromised extracted financial data ends up for sale:<br><br>[att=7]<br><br>It appears that the only way to obtain a log in account in order to use the services of Socksps.ru is to contact ICQ 431278403<br><br>Or you can resond directly to his promotion on forum.zloy.org a cyber criminals one stop shop for carding, hacking exploits, money transfers, banking etc.<br><br>His translated add posting on the forum.zloy.org for Socksps.ru services is here:<br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/57/89357.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/57/89357-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://translate.google.com/translate?hl=en&sl=ru&u=http%2a//forum.zloy.org/showthread.php%3Fp%3D4613363&ei=PsHsSe_1FIeItAOJh7TgAQ&sa=X&oi=translate&resnum=1&ct=result&prev=/search%3Fq%3Dicq%2B431278403%26hl%3Den" >translate.google.com/translate?h&middot;&middot;&middot;6hl%3Den</A><br>Snapped 2009-04-20 16:11:32 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br>The main zloy.org page is translated here:<br><br><div class="borderless siteshot"><small><A TITLE="Zoom" HREF="http://i.dslr.net/urls/58/89358.png"><IMG BORDER=0 SRC="http://i.dslr.net/urls/58/89358-big.gif" width=280 height=202></A><br>&raquo;<A HREF="http://translate.google.com/translate?js=n&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fforum.zloy.org%2F&sl=ru&tl=en&history_state0=" >translate.google.com/translate?j&middot;&middot;&middot;_state0=</A><br>Snapped 2009-04-20 16:13:50 <A HREF="/faq/7513" TITLE="Snap-shot of URL"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/information.png" border=0 width=16 height=16></A><br></small></div><br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/22267451?c=1421537&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="2393 bytes" BORDER=0 WIDTH=358 HEIGHT=304 SRC="/r0/download/1421537~47be7740816b68092fbbf531ad0ac4b7/socksps.ru_login.png"></A></TD><TD ALIGN=CENTER BGCOLOR=#FFFFFF nowrap width="1%">&nbsp;</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421539&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="76165 bytes" WIDTH=600 HEIGHT=611 SRC="/r0/download/1421539.thumb600~5813152c32ca5a5ec77d637b69454cea/socksps.ru.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421540&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="49805 bytes" WIDTH=600 HEIGHT=519 SRC="/r0/download/1421540.thumb600~db2836c32e44c6438d8df702bd5fb5fd/socks_assorted.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421541&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="88162 bytes" WIDTH=600 HEIGHT=530 SRC="/r0/download/1421541.thumb600~64b1d7840ef4a29f1918770fe3abb053/socksps.ru_US.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421542&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="51800 bytes" WIDTH=600 HEIGHT=526 SRC="/r0/download/1421542.thumb600~280e74392be4811a649123adab8c18a8/socks_uk.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421543&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="53890 bytes" WIDTH=600 HEIGHT=498 SRC="/r0/download/1421543.thumb600~ee917d82fd367ebf0a9837305a1fe2c6/socksps.ru_iran.png/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22267451?c=1421544&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="97160 bytes" WIDTH=600 HEIGHT=417 SRC="/r0/download/1421544.thumb600~8a8e9edc196e7b82e9ec6a4c3b41615f/cashing_cc.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22267451</guid>
<pubDate>Mon, 20 Apr 2009 16:14:27 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22267252</link>
<description><![CDATA[acid343211 posted :  <blockquote><small>said by <a href="/profile/825971" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=825971');">kpatz</a>:</small><hr>Internet Explorers addon Shockwave Flash vs.3 found to be linking to the FormSpy website hosted at IP address 81.95.109.11 This addon tries to send your private information to attackers IP 72.95.109.11 (Malaysia) <hr></blockquote><br><br> <blockquote><small>quote:</small><hr>IP address country: 81.95.109.11<br>IP address country      flag Czech Republic<br>IP address state: &#9;Hlavni Mesto Praha<br>IP address city: &#9;Praha <hr></blockquote><br><br> <blockquote><small>quote:</small><hr>IP address 72.95.109.11<br>IP country code:  &#9; US<br>IP address country: &#9;flag United States<br>IP address state: &#9;Maine<br>IP address city: &#9;Orono<br>IP address latitude: &#9;44.879101<br>IP address longitude: &#9;-68.733002<br>ISP of this IP [?]: &#9;Fairpoint Communications<br>Organization: &#9;Fairpoint Communications <hr></blockquote><br><small>--<br>Visit-<br>www.liveleak.com/view?i=e32_1231680425</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22267252</guid>
<pubDate>Mon, 20 Apr 2009 15:37:31 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22267195</link>
<description><![CDATA[anon posted :  <blockquote><small>quote:</small><hr>The fake antivirus exploit prompts for a download in IE, Opera, and Firefox because the download is an executable file for which these browsers prompt by default. I showed Opera in a previous post.<hr></blockquote><br><br>Ok, so there is a download prompt and you get a chance to cancel the whole thing, in those cases where it attempts to make you download an exe file instead of serving a browser or plugin exploit. That is good news. :) <br><br> <blockquote><small>quote:</small><hr>The other exploits I found are automatically triggered (drive-by download):<br><br>IE exploits against the browser as I showed in the previous post.<br><br>PDF exploit in Firefox. This is from a previous exploit. Note that it is Acrobat calling out for the trojan and not Firefox:<br><br>Note that this is an Acrobat Reader exploit, not a browser exploit. The browser just loads the PDF file. This exploit works in all browsers. Be sure and configure your file types to Prompt for Download, or "Always Ask"<hr></blockquote><br><br>Ok, so the actual drive-by downloads (no user consent required) of this badware are based on exploits in either the browser or some other related program like PDF viewers, as usual. And the PDF exploits you can stop just by having the browser prompt for download of pdf files instead of opening them in the proper program, or even just by not giving the PDF viewer permission to go online when your firewall prompts for it. Good news, again!<br><br>Thanks for all the advice, guys, I think I understand how this thing operates now. If I got it right, this thing is not a threat as long as you <br>- have your browser set to prompt for download for exes, pdfs etc instead of having the browser run them at once, and cancel any suspicious, unwanted downloads, and<br>- have a fully patched browser that isn't vulnerable to the browser exploits this thing tries, such as the latest Opera version. <br><br>Or in other words, it's a pretty basic baddie. Sounds like I'm good to go, and have nothing to worry about this malware. It should be easy to avoid this thing: just keep the browser patched (and preferably use Opera) and have it set to prompt for downloading stuff, or disable all the pointless plugins we don't need like Adobe Reader etc.  <br><br>Still, Foxnews should get their ads cleaned right the F now. It's inexcusable for a big outfit like that to serve crapware via ads. I wonder if a popup blocker would help against these things. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22267195</guid>
<pubDate>Mon, 20 Apr 2009 15:29:09 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22267114</link>
<description><![CDATA[bobince posted :  <blockquote><small>quote:</small><hr>Be sure and configure your file types to Prompt for Download, or "Always Ask"<hr></blockquote><br><br>You can also disable the plugin for all browsers from Reader's &#147;Edit->Preferences->Internet->Display PDF in browser&#148; option, or use a different PDF reader that doesn't install a plugin. (Who wants to read a PDF stuck inside a browser window anyway?)<br><br>As always, if you aren't using a plugin, remove it, and you'll reduce the attack surface of your browser and the number of things you have to worry about keeping updated. Do you really need PDF, Java, QuickTime and Real plugins? Probably not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22267114</guid>
<pubDate>Mon, 20 Apr 2009 15:12:16 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266943</link>
<description><![CDATA[anon posted : Does this malware require java ? No Java = no infection?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266943</guid>
<pubDate>Mon, 20 Apr 2009 14:44:13 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266827</link>
<description><![CDATA[Airborne29th posted : Has this been cleaned? Ive gone all through foxnews on our test computer to see if our antivirus will catch it, and nothing is coming up.. Either that or its silently being stopped, tried with adblock plus and without, IE and Firefox.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266827</guid>
<pubDate>Mon, 20 Apr 2009 14:27:45 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266791</link>
<description><![CDATA[mysec posted : The fake antivirus exploit prompts for a download in IE, Opera, and Firefox because the download is an executable file for which these browsers prompt by default. I showed Opera in a previous post. Here are IE and Firefox:<br><br>[att=1]<br><br>[att=2]<br><br>The other exploits I found are automatically triggered (drive-by download):<br><br>IE exploits against the browser as I showed in the previous post.<br><br>PDF exploit in Firefox. This is from a previous exploit. Note that it is Acrobat calling out for the trojan and not Firefox:<br><br>[att=3]<br><br>Note that this is an Acrobat Reader exploit, not a browser exploit. The browser just loads the PDF file. This exploit works in all browsers. Be sure and configure your file types to Prompt for Download, or "Always Ask"<br><br>Opera:<br><br>[att=4]<br><br>Firefox:<br><br>[att=5]<br><br>----<br>rich<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22266791?c=1421511&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="56666 bytes" WIDTH=600 HEIGHT=610 SRC="/r0/download/1421511.thumb600~6e2d6be06be6442d6d9e0f0a4f17979a/foxnewsIEprompt.gif/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22266791?c=1421512&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="38043 bytes" BORDER=0 WIDTH=581 HEIGHT=609 SRC="/r0/download/1421512~754c9034dd1fcdc04e46b16ee2d2d0a8/foxnewsFFprompt.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22266791?c=1421513&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="29582 bytes" WIDTH=600 HEIGHT=673 SRC="/r0/download/1421513.thumb600~e7c6f546954172b87b043c4aaf2468a3/ff-cnExploit.gif/thumb.jpg" ALT="Click for full size"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22266791?c=1421516&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="23820 bytes" BORDER=0 WIDTH=449 HEIGHT=273 SRC="/r0/download/1421516~62ec87b08416f7e21fa2a23ba4e32e9e/PDFpromptOpera.gif"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22266791?c=1421517&ret=L2ZvcnVtL3IyMjI1MTAyMC54bWw%3D"><IMG TITLE="17696 bytes" BORDER=0 WIDTH=458 HEIGHT=284 SRC="/r0/download/1421517~1f7e43e9c180870be69522e0c0169ace/PDFpromptFF.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266791</guid>
<pubDate>Mon, 20 Apr 2009 14:20:11 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266785</link>
<description><![CDATA[moonpuppy posted : <div class="bquote"><small>said by HowDoesItWork :</small><br><br> <br>So it could infect you without requiring any form of consent from the user? Now that is weird. For IE, I wouldn't be surprised, but if Firefox or Opera would do the same, that would be strange. I'm further confused because mysec on the previous page posted that with Opera, it does pop up a download prompt, and if you cancel the download, it can't infect you. <br> </div>Part of the infection can be done with PDF documents. Adobe even put out a warning that they wouldn't have a fix for a month.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266785</guid>
<pubDate>Mon, 20 Apr 2009 14:19:21 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266731</link>
<description><![CDATA[Carnivore posted : I got this popup last night when I visited foxnews.com with IE8, and the fake virus scan began in a new window.<br><br>I forced the browser closed as quickly as I could with task manager, and ran a real scan with AVG 8.5 which appeared to be clean.  <br><br>Does anyone know if AVG effectively detects this infection, and/or what other steps should be taken to ensure this thing didn't get its tentacles into my system?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266731</guid>
<pubDate>Mon, 20 Apr 2009 14:11:07 EDT</pubDate>
</item>

<item>
<title>Re: foxnews.com infected?</title>
<link>http://www.dslreports.com/forum/Re-foxnewscom-infected-22266556</link>
<description><![CDATA[anon posted :  <blockquote><small>quote:</small><hr>Yes, for clarification, If you decline the scan, it will do the fake scan anyway and impose a full screen in your browser. If you then choose "cancel" for the recommended install, it will proceed with the download. The warning that the user will get is from their system alerting them to the dangers of allowing an .exe file to run. They should be able to use their system at that point to block the install. However, prior to that point, "cancel" and "no" means "Yes".<hr></blockquote><br><br>Now I feel a little stupid, but I still don't understand how it works. It's business as usual that the popup has a bogus cancel button and the X close window button, and it tries to make you download their crapware anyway. But unless the browser does something completely wrong, there should eventually be a download prompt and you should then be able to cancel the whole thing, so it can't infect your system. If this isn't the case with this particular crapware, I would sure like to know how it accomplishes this feat, technically. There are exploits, but unless it uses an unknown, unpatched zero day vulnerability, that shouldn't work against a fully patched browser and plugins... <br><br> <blockquote><small>quote:</small><hr>Fully patched OS, IE, Java, FLASH, etc. I saw multiple popups and I did not click no but the "X" of the window. When I realized what was happening, I immediately shut the laptop down HARD. I pressed the power button until it shut off completely and restarted the system with the wi-fi off. When I saw no activity, I turned the wi-fi back on and immediately headed here to do some cleaning and that's when I found the issues I mentioned earlier. I then posted here about it.<hr></blockquote><br><br>So it could infect you without requiring any form of consent from the user? Now that is weird. For IE, I wouldn't be surprised, but if Firefox or Opera would do the same, that would be strange. I'm further confused because mysec on the previous page posted that with Opera, it does pop up a download prompt, and if you cancel the download, it can't infect you. <br><br>So, is there something in Opera that prevents this thing from insta-infection without any user consent that doesn't exist in IE or even Firefox? Hate to ask that many questions, but I don't understand the technique that this thing could possibly use to infect you instantly <i>without you accepting a download</i>, and then executing that download... aside from unpatched vulnerabilities. I wonder if the people infected by this were running as admin...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-foxnewscom-infected-22266556</guid>
<pubDate>Mon, 20 Apr 2009 13:41:24 EDT</pubDate>
</item>

</channel>
</rss>
