User Tag List

Results 1 to 2 of 2
  1. #1
    Banned - lol Scooter's Avatar
    Join Date
    Apr 2007
    Location
    Ontario, Canada
    Posts
    835
    Likes Received
    0
    Trading Score
    0 (0%)



    0
    OK, so this is the scenario.

    You're surfing websites.

    Suddenly, you get a popup that looks like a warning from your computer or security program: "Warning! Your computer is infected! "X" number of viruses detected!" And it's not Norton, or McAfee, or your normal program.

    You're prompted to start a security scan or to remove the viruses. And that's your fatal mistake.

    Because by clicking ANYWHERE on the popup - even on the "close" or "X" button to close the window - you have triggered a script that installs a trojan. Fooling you into installing it is called the "social engineering" approach of spreading malware.

    If this ever occurs, hit the Esc key to close the popup - or open Task Manager (ctrl-alt-del) in Windows and kill your browser, iexplore.exe or firefox.exe to stop the downloader. Run Crap Cleaner to erase your web cache and temporary files and cookies.

    Here's a few examples of the programs you might encounter, with screenshots.
    http://www.f-secure.com/weblog/archives/00001509.html

    The other famous method of installing a trojan is when you go to a site to view a video and get a message similar to: "You cannot play this video because you are missing the codec to play it. Click here to install it."

    What do these do?

    In my first example, I encountered the Antivirus2008 trojan - oddly enough - on a customer's Macintosh computer. She had clicked repeatedly on the popup thinking it was genuine. Her browser was acting funny. Upon investigation I discovered that in her Downloads folder she had 48 copies of the trojan. It was unable to run as a program on the Mac however and was contained. If it had been a Windows PC, the virus would have hijacked her web browser so that any site she tried to visit would take her to the site of Antivirus XP 2008, where she would have had to pay a ransom to get a removal tool. This is a classic (and very nasty) fraud trojan.

    In the second, I dealt with a customer who had become infected with the OSX.RSPlug.A trojan after presumably clicking to download a codec. Although this is a special variant for Macs (and easily removable), PC's can also be infected by other forms of it. This changes the DNS server settings of the computer so that web pages load VERY slowly. The reason for this is that all your web traffic is detoured through a malicious server between your computer and the site you are trying to reach. The aim is to harvest your sensitive information - including banking info and personal details for identity theft.

    So do NOT click on popups and do not fall for prompts to install codecs. If you suspect your computer may be infected, IMMEDIATELY disconnect your internet connection and boot into Safe Mode in Windows and run a trusted virus scan.
    This thread is currently associated with: Apple, MAC Cosmetics, Microsoft
    Last edited by Scooter; Mon, Oct 6th, 2008 at 08:00 PM.

    Linux Registered User #426194


  2. #2
    Smart Canuck Kitty77's Avatar
    Join Date
    May 2008
    Location
    Alberta
    Posts
    3,202
    Likes Received
    708
    Trading Score
    41 (100%)




    Good information, Thanks!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •