PDA

View Full Version : Mass 'scareware' attack hits 1.5M websites, still spreading



chicot60
04-03-2011, 08:28 PM
By Michael Winter, USA TODAY

A massive attack that's trying to scare computer users into visiting a bogus antivirus site has infected more than 1.5 million websites and continues to spread, according to an Internet security firm.

Several pages on Apple's iTunes store have been infected.

The so-called LizaMoon "SQL injection attack" began Tuesday and is being tracked by Websense. Such attacks redirect users by exploiting programming errors and poorly written code and scripts.

eWeek says the attack is "out of control ... with no end in sight." Nearly half the compromised sites are in the United States. Other affected countries include United Kingdom, Kuwait, India, Australia, Turkey, Brazil, Israel, Mexico, Taiwan and Chile.

VentureBeat writes that the attack "shows that malware is a bigger menace than ever and that many web sites aren't protected."



http://content.usatoday.com/communities/ondeadline/post/2011/04/mass-scareware-attack-hits-15m-websites-so-far/1?csp=hf

Bigpineguy Retired
04-03-2011, 08:32 PM
Exactly why everyone should have a anti virus and malware program, also a spybot program is nice to have as well....protect yourselves.!

BPG~

JCO
04-03-2011, 08:50 PM
Exactly why everyone should have a anti virus and malware program, also a spybot program is nice to have as well....protect yourselves.!

BPG~

I use one of these, never caught anything..:grr:

Nostradamus
04-03-2011, 09:52 PM
I caught this thing at 4 AM today and thought I was going to have to format. I can not say for sure where I picked it up but think it might have been on isohunt or another warez site I frequent often.

anyway , it shows up on your screen as a virus scanner and has a name like Win 7 antivirus. Does a bogus scan and then tries to convince you to buy the crap to clean off the crap it found. Difficult to get the thing off the screen but when you do is when the fun starts. I am using Zonealarm Security Suite and also have Malwarebytes for the nuisance type things.

Well I tried running Malwarebytes and it was disabled, so was Zonealarm. In fact every desktop shortcut, menu option and quick launch button were all dead in the water. I tried it in safe mode and it was no better. Starting to look like format time when I stumbled on the solution. I had some files on the desktop I wanted to save so I grabbed a flash drive to store them on and when it came up with menu I selected open to view files. It would let me navigate around that way and store the files I wanted. I also have a keyfinder program on that drive that comes in handy at times so I right click and select run as administrator and it worked.

Had an idea at this point, from the same windows explorer window I navigated to whyere malwarebytes is stored on the hard drive. right click and run as administraor and it updated and ran fine. It found 3 pieces of crap related to this attack. I then got control of zonealarm and took control of that the same way and did a complete scan and it picked off 2 more that was not there yesterday. Reboot and problem solved. The virus or bogus antivirus is not hard to get rid of but the trick is getting control of the thing to begin with. Hopefully this will help someone else who gets caught with this crap

Night Prowler
04-03-2011, 10:02 PM
maybe try renaming the exe's of your anti-viruses if you think you have been infected.....:noidea: