There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network printer problem ram registry router server slow software sound svchost.exe trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Spyware warning!

Reply  
Thread Tools
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 09:11 PM #1
Exclamation Spyware warning!
If you are hijacked to this website,
hit your "back button".


This one seems to affect all web browsers,
on all platforms, and is infecting many websites.

DO NOT INSTALL THIS!

If you have been hit by this, please run HJT, and
check for tracking cookies, as well.

AVAST! caught this one, but Norton's didn't.

I run Firefox 2.0.0.20 over Windows 2000,
and Konqueror 3.1.2 over KDE (Redhat linux).

This is yet another web virus.
Attached Thumbnails
Spyware warning!-10244_100.gif  
__________________
I have done so much, with so little, for so long: I can do anything, with nothing, forever!

Last edited by gyrgrls; 24-Apr-2009 at 09:18 PM.. Reason: lost attachment
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 09:27 PM #2
Is the internet safe anymore?
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 09:44 PM #3
To clarify:

The site itself is just pushing 'spyware'.

But my browser was hijacked, and I was taken to this site..

I will do a log dump, if needed.
But a HJT log won't be necessary.

I already got rid of the trojan (which was written
in Javascript)


Just a "head's up"
__________________
I have done so much, with so little, for so long: I can do anything, with nothing, forever!
Phantom010's Avatar
Computer Specs
Trusted Advisor with 24,994 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
24-Apr-2009, 10:06 PM #4
Quote:
AVAST! caught this one, but Norton's didn't.
Are you by any chance running two AV at the same time?

Are you saying you were redirected to the site prompting you to scan for drivers? Uniblue is a legitimate company, are you sure it was spyware and not a false positive from Avast?

Do you have more info on the threat?
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 10:45 PM #5
OK, what I have so far is this:

0A432217665C09080000001A
(rest snipped)


Uniblue might be legit,
but how did I get redirected there, even
running Firefox, under Linux, with pop-up
blockers enabled?

Many legitimate sites exist, but the piggy-backers
will harvest them. It's sick, really.

I am not even blaming Uniblue.
I just resent the fact that my browser was hijacked.

One can hardly surf the web without Javascript enabled,
yet this is a gaping security hole..

The minimum requirement for online banking is 48 bit SSL,
yet many sites run JS, wide open..

Just a heads-up

P.S.: I can make a fake https:// website. It's easy, really.
I have also hacked Win 98 via plain HTML code,
just to show it could be done (although NT seems more robust).

I do this, because, as a Unix system administrator,
I demand security. I actually try to hack into my own system,
in order to find any holes.

But this new Javascript exploit is REAL.

It is hole in JS, and not in the web browser, itself.


Be well.
__________________
I have done so much, with so little, for so long: I can do anything, with nothing, forever!
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 11:09 PM #6
OMG! I Can't believe it!
Marsha's site is still infected!

This is what it looks like,
in ASCII format: (it's not binary,
so It can't hurt you, displayed as-is,
as it is well obfuscated).

Last edited by Cookiegal; 03-May-2009 at 05:34 PM.. Reason: Removed code so users don't get alerts from their a/v programs
Phantom010's Avatar
Computer Specs
Trusted Advisor with 24,994 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
24-Apr-2009, 11:10 PM #7
Thanks for the info!
gyrgrls's Avatar
Computer Specs
Senior Member with 1,470 posts.
 
Join Date: Nov 2004
Location: Modesto, California
Experience: Hendrix
24-Apr-2009, 11:20 PM #8
Ouch!

I didn't mean to post malicious code.
But it came through my browser, and AVAST!
complained loudly, upon reading my own post.


I fixed it.

I "x'ed out" the first few bytes,
thereby deliberately corrupting the code,
so it can't execute.

I am so sorry....

BTW:
I didn't write this little goody. Someone else did,
and it is infecting websites like crazy...
__________________
I have done so much, with so little, for so long: I can do anything, with nothing, forever!

Last edited by gyrgrls; 25-Apr-2009 at 05:46 AM.. Reason: clarification
SIR****TMG's Avatar
Computer Specs
Distinguished Member with 47,676 posts.
 
Join Date: Aug 2003
Location: Corn Fields of OHIO
Experience: Einstein Jr. Indeed
26-Apr-2009, 02:28 PM #9
Thanks for the heads up
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:15 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.