Page 1 of 2 12 LastLast
Results 1 to 10 of 11
Like Tree1Likes

Thread: My computer Online Scan

  1. #1
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752

    My computer Online Scan

    Received an email from my cousin which contains only a single link and nothing else.
    hxxp://cee.toko.edu.tw/23i352.html

    First I get a notice with the following message:
    Warning!!! Your computer contains various signs of viruses and malware programs presence. Your system requires immediate anti viruses check! System Security will perform a quick and free scanning of your PC for viruses and malicious programs
    Clicking OK and it shows an animation of My Computer with virus being detected from a simple scan.



    After the scanning has finished, shows the following message:
    DANGER!!!
    Viruses was found on your computer!
    Click 'OK' to install free System Security Antivirus
    Then prompts to download a 2.2MB freesystemscan.exe.
    [WARNING] DO NOT DOWNLOAD OR RUN THE FILE WITH THE NAME ABOVE!

    I haven't analyze what freesystemscan.exe does because lack of time. Might just do it later and update this post.

  2. #2
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Looks really dodgy to be honest and not one i would or intend to run.. might interest blue.dot.. even the warning is OTT, thank you for the heads up Raymond..
    Stutz Bearcat

  3. #3
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Yeah, I've gotten this same thing myself Raymond. I've never done anything, but close it out and run a security scan on my system to check for nasty little surprises.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  4. #4
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Thanks for the heads up Ray . Kindaa old method but cool .
    I don't need to know everything, I just need to know where to find it, when I need it.

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Thanks Raymond for info When I try to browse URL, KIS warns me and classify it as malicious URL. If I ignore the warning, I am forwarded to my country Google home page (not my default home page). It seems that above threat has something related to Google like Google redirect threat?
    Windows 7 SP1 Ultimate x86 + KIS 2011 (11.0.2.556 b.a.c.d) + Sandboxie Paid (3.54) + Deep Freeze Standard (7.20.020.3398)

  6. #6
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    Ah the old Rogueware infection technique. I have a few of these files. One of them even has the AVG icon and calls itself Dr. Web Antivirus.

  7. #7
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Just did a little test of that url --> First Detected by Avast HTML:RedirME-inf . That url contains another redirecting url hxxp://gr....ooppd.in.ua/go.php also detected in urlvoid (rate 5 ) . This page the redirect you to hxxp://software-...e.co.cc/scan1/187. That scans I think. I can't go further lack of time. Got some work. Hope Ray would describe more specific .

  8. #8
    Experienced User
    Overall activity: 0%

    Join Date
    May 2010
    Posts
    3,271
    Liked
    155 times
    Points
    6,541
    Raymond provided URL redirects to hxxp://grkkkkbbbooppd.in.ua/go.php. Reported at MBAM forum here: New Rogue

  9. #9
    grr
    grr is offline
    Experienced User
    Overall activity: 2.0%

    Join Date
    Jan 2010
    Location
    India
    Posts
    2,665
    Liked
    13 times
    Points
    38,657
    Thanks Ray.
    I got into a similar trap last year..
    I'm the Beauty and you are the Beast.

  10. #10
    Verified Member
    Overall activity: 7.0%

    Join Date
    Feb 2009
    Posts
    37
    Liked
    0 times
    Points
    3,383
    Quote Originally Posted by Raymond View Post
    Received an email from my cousin which contains only a single link and nothing else.
    hxxp://cee.toko.edu.tw/23i352.html

    First I get a notice with the following message:
    Clicking OK and it shows an animation of My Computer with virus being detected from a simple scan.



    After the scanning has finished, shows the following message:
    Then prompts to download a 2.2MB freesystemscan.exe.
    [WARNING] DO NOT DOWNLOAD OR RUN THE FILE WITH THE NAME ABOVE!

    I haven't analyze what freesystemscan.exe does because lack of time. Might just do it later and update this post.
    They are just spam...!! Your system might not have contained any virus ..! But it will show as it contains virus and make you to download and install their antivirus which they may need ask to pay or it will be a big spam ,adware etc...

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 32
    Last Post: 10-17-2010, 04:35 AM
  2. Get a FREE Online Virus Scan
    By froilan in forum Spyware/Viruses
    Replies: 13
    Last Post: 10-16-2010, 10:56 AM
  3. Learn to Build a Computer Online!
    By Amature Programmer in forum General Forum
    Replies: 6
    Last Post: 12-19-2009, 04:29 AM
  4. SUPERAntiSpyware Online Safe Scan
    By thathagat in forum Spyware/Viruses
    Replies: 12
    Last Post: 09-18-2009, 08:11 PM
All times are GMT +8. The time now is 09:44 AM.