BleepingComputer.com: Windows Rogue virus

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Windows Rogue virus scared my daughter!

#1 User is offline   Capn Easy 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 549
  • Joined: 20-November 08
  • Location:New Jersey

Posted 28 October 2010 - 06:03 PM

We have a computer that's used (almost) exclusively by our kids. It had been hit a couple times by viruses, so, at my repeated urging, we finally made it a "Linux only" box. The kids have every functionality they need for school and recreation -- except Itunes. My wife is a Windows person, but still wanted to be the Admin on their computer. I didn't know that she hadn't installed NoScript. (We will!)

Tonight my daughter was on the computer doing research for a homework paper and was using a school site that linked to a science related site. All perfectly legit. As soon as she clicked on the link she was confronted by an official-looking warning screen from "Windows Web Security" that was claiming to find trojans, etc., on the "C:" (sic) hard drive, in folders like WINNT, etc.

My daughter freaked out a bit, but did exactly the right thing and called me upstairs. I told her we were in no danger -- it's Ubuntu ONLY and we don't have a C: drive, etc. I assume that the science site was hacked and that the malware executed a script within Firefox, but no actual virus could have been loaded (she doesn't have admin privileges) and it would be incompatible with Linux's file system and Operating System anyway. (But we cleared all of her browser history, cookies, etc., anyway.)

We also had a good laugh at the broken English warnings from the rogue anti-spyware!

I've linked a couple screen shots for the humor value. If I'm wrong about anything, please let me know!




Posted Image



Posted Image

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,367
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 October 2010 - 06:22 PM

Report it to the Site Administrator/Webmaster via the following:

Contact Us
Online Technical Support

> Email: support@factsonfile.com
> Phone: 1-800-322-8755 x. 4230

Online Sales Support

> Email: onlinesales@factsonfile.com
> Phone: 1-800-322-8755

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   Capn Easy 

  • Senior Member
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 549
  • Joined: 20-November 08
  • Location:New Jersey

Posted 28 October 2010 - 06:26 PM

Already on it. :thumbsup:

Also, since it was for a school paper and the link was on a school resource site, I've told her to notify her teacher. Other kids, using the popular brand of OS, could have been hit already.

This post has been edited by Capn Easy: 28 October 2010 - 06:29 PM


#4 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,367
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 28 October 2010 - 06:30 PM

Awesome work, and keep it up.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#5 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,588
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 29 October 2010 - 02:09 PM

Thanks Capn Easy!
Good selling point for Ubuntu and instructive, too. Already sent this to other Ubuntu users.

While NoScript would have blocked the malware, I have found that many users, especially the younger
ones, will not use it properly and just choose to allow scripts globally. Your post will help to convince
them to do otherwise. Hopefully.

#6 User is offline   pacificdenizen 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 61
  • Joined: 21-May 11

Posted 30 May 2011 - 08:27 PM

That is absolutely marvelous. :) You taught her well, too.

I will have to think about this.

#7 User is offline   NFD 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 19-June 11
  • Gender:Male

Posted 20 June 2011 - 12:22 AM

Heh. When I was about 6 a similar thing happened on an Ubuntu box I was using. I raised an eyebrow and killed the browser. (I guess that shows that I'm still a nerd today.)
I've heard of sites serving rogues in both Mac and Windows flavors through user agent sniffing. I wonder if any malware writers would even offhandedly think that this could happen, or even consider an "odd user agent" option. I hope they don't.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users