<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jephens Tech. &#187; anti-virus</title>
	<atom:link href="http://www.jephens.com/tag/anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jephens.com</link>
	<description>Keeping Computers Happy Since 1997</description>
	<lastBuildDate>Tue, 22 Nov 2011 04:33:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Malware served from NY Times Website</title>
		<link>http://www.jephens.com/2009/09/13/beware-the-ny-times-website/</link>
		<comments>http://www.jephens.com/2009/09/13/beware-the-ny-times-website/#comments</comments>
		<pubDate>Sun, 13 Sep 2009 19:27:12 +0000</pubDate>
		<dc:creator>Jeff Knapp</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[defense]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malwarebytes]]></category>
		<category><![CDATA[new york times]]></category>
		<category><![CDATA[nytimes.com]]></category>
		<category><![CDATA[protection-check07.com]]></category>

		<guid isPermaLink="false">http://www.jephens.com/?p=209</guid>
		<description><![CDATA[I've gotten two calls from clients (OK, one was a client, the other my mother-in-law) saying they visited the NYTimes website and were attacked by malware. This is true, they were. My MIL said she was trying to read Maureen Dowd and got hit with a rogue anti-spyware application. I was able to CoPilot in [...]]]></description>
			<content:encoded><![CDATA[<p>I've gotten two calls from clients (OK, one was a client, the other my mother-in-law) saying they visited the NYTimes website and were attacked by malware.</p>
<p>This is true, they were. My MIL said she was trying to read Maureen Dowd and got hit with a rogue anti-spyware application. I was able to CoPilot in and clean things up. (There didn't seem much to clean up, I killed a running process of IE (she uses Chrome) and the scare-screen went away.</p>
<p>I sparked up an unpatchedWinXP Virtual Machine running IE6 and went to the NYT website, and was prompted immediately to install flash. I opted not to and surfed around the site, fighting the information bar's insistence that I install an ActiveX Control.</p>
<p>So, I gave in and voila!</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_1.jpg"></a></p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_11.jpg"><img class="alignnone size-medium wp-image-217" title="protection-check07.com dialog" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_11-300x226.jpg" alt="protection-check07.com dialog" width="300" height="226" /></a></p>
<p>So, no matter how you answer, you're already stung.</p>
<p>Of course, your instinct is to click "Cancel" and you do, and then you're scared out of your wits when confronted with this page from protection-check07.com (don't go there!) and proceeds to make you think you're infected.</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_21.jpg"><img class="alignnone size-medium wp-image-218" title="protection-check07.com demo" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_21-300x226.jpg" alt="protection-check07.com demo" width="300" height="226" /></a><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_2.jpg"></a></p>
<p>But, if we take a second to look at the scare box, we see something is amiss...</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_4.jpg"><img class="alignnone size-medium wp-image-213" title="Local Drive" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_4-300x187.jpg" alt="Local Drive" width="300" height="187" /></a></p>
<p>We don't have an E: drive ... and the optical drive we have is a CD-Rom, not a DVD-RAM drive...</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_31.jpg"><img class="alignnone size-medium wp-image-219" title="My Computer" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_31-300x226.jpg" alt="My Computer" width="300" height="226" /></a><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_3.jpg"></a></p>
<p>The page that pops up is meant to scare you. The infections it reports are false -- the only infection you have (at the moment) is the webpage. If you go into taskmanager and find iexplorer.exe (or firefox.exe if you use Mozilla Firefox) and right-click on it and choose "End Process" that should make the pop-up go away.</p>
<p>If you click ANYWHERE on the page, it will prompt you to download a program:</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_5.jpg"><img class="alignnone size-full wp-image-221" title="Malware Downloader" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_5.jpg" alt="Malware Downloader" width="456" height="313" /></a></p>
<p>Seems reasonable -- you got a warning you were infected, and you want to download a file called "Scanner-75f_2015.exe" seems legit.</p>
<p>IT'S NOT.</p>
<p>(But you knew that by now, right?)</p>
<p>However, this is a clear indication of how a fully patched system gets compromised. Some buys ad space on a major website. They probably serve a lot of legit ads, but in a few instances, they serve illegitmate ads. In this case, they seem to be using Flash as an attack vector. Flash movie loads and redirects your browser to a rogue site, and they're off to the races.</p>
<p>Since I'm a professional, I downloaded the file -- I didn't run it -- and I submitted it to <a href="http://virscan.org">http://virscan.org</a> an online file scanner which tests a file against 37 of the leading anti-virus vendors.</p>
<p>Somewhat sadly, only 5 out of 37 scanners picked this up as malware:</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_6.jpg"><img class="alignnone size-medium wp-image-222" title="Malware Results" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_6-300x185.jpg" alt="Malware Results" width="300" height="185" /></a></p>
<p>I also ran the file thru VirusTotal.com which tests against 41 scanners, and 7 scanners turned up a positive on our file:</p>
<p><a href="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_8.jpg"><img class="size-large wp-image-224 alignnone" title="VirusTotal.com Results" src="http://www.jephens.com/wp-content/uploads/2009/09/xp_nyt_8-422x1024.jpg" alt="VirusTotal.com Results" width="422" height="1024" /></a></p>
<p>You can see the full report over on VirusTotal's site: <a href="http://www.virustotal.com/analisis/7bda9187e26b5a185501874b201731f12e3604c078408500abda83c35ef2fbe1-1252857630" target="_blank">http://www.virustotal.com/analisis/7bda9187e26b5a185501874b201731f12e3604c078408500abda83c35ef2fbe1-1252857630</a></p>
<p>The one thing that surprised me on the results was Microsoft's detection, trumping McAfee, Symantec, AVG and Clam-AV among many others. I've never considered MS a true player in the anti-malware landscape, but perhaps I will re-evaluate.</p>
<p>Kaspersky, and most othersecurity vendors, offers an <a href="http://usa.kaspersky.com/downloads/free-virus-scanner.php" target="_blank">online scan </a>of your system (requires Java). If you don't have an anti-virus product installed -- or even if you do -- you might want to visit a different security vendor site than the one you have to do a check. Belt and suspenders and all that.</p>
<p>(This piece of spyware also eluded my trustyMalwarebytes Anti-Malware (<a href="http://www.malwarebytes.org/">www.malwarebytes.org</a>) which should reinforce that no one piece of software can provide 100% protection.</p>
<p>There is no strong defense for this, as nothing you overtly do can cause it. Make sure your anti-virus is up to date, do regular scans of your computer -- but MOST importantly --keep backups.</p>
<p>As for the clients, one of them uses Norton GoBACK (since superceded in the marketplace by Ghost 14) , so they restored their machine back an hour before the infection occurred, went back to the NY Times site, got re-infected, restored AGAIN using GoBack, and then stayed away from the NY Times site. And my Mother-in-Law has been trained well and as soon as the box popped up, she called me and I was able to CoPilot into her machine and close IE before it did any damage... may you all be as lucky.</p>
<p>Further Info:</p>
<p><a href="http://ask.metafilter.com/132707/nytimes-spyware">http://ask.metafilter.com/132707/nytimes-spyware</a></p>
<p><a href="http://discussions.apple.com/thread.jspa?messageID=10197120&amp;tstart=0">http://discussions.apple.com/thread.jspa?messageID=10197120&amp;tstart=0</a></p>
<p><a href="http://forums.mozillazine.org/viewtopic.php?f=38&amp;t=1481195">http://forums.mozillazine.org/viewtopic.php?f=38&amp;t=1481195</a></p>
<p><strong>[UPDATE: 1:30 PM, Sunday Sept 13 - the NY Times site seems to have stopped serving the ad. Further attempts to get infected have proven unsuccessful.]</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jephens.com/2009/09/13/beware-the-ny-times-website/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

