Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 21, 2009, 12:55:10 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
336427
Posts
37221
Topics
84383
Members
Latest Member:
sysfocus
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Help - CIS
Anti Virus Help
Google result redirector malware - I'm infected; CIS did nothing!
« previous
next »
Pages:
[
1
]
Author
Topic: Google result redirector malware - I'm infected; CIS did nothing! (Read 538 times)
puddingpants
Comodo Member
Offline
Posts: 41
Google result redirector malware - I'm infected; CIS did nothing!
«
on:
November 06, 2009, 03:01:07 AM »
Hi all. To my horror, today I ran a Google search and clicked on a result, and was redirected to some money-generating "scareware" site. The search result's URL looked good on the screen, looked good in the status bar when I hovered the mouse over it, and works fine if I right-click the URL, select "Copy Link Location", then paste it in a new tab/window. But if I click it directly, I get redirected to scareware/ad-spam type pages. This only happens rarely though, the vast majority of search results work correctly.
I don't see how this can be anything but malware on my PC, and I'm VERY careful and have been running CIS since April, and I installed it on a known-clean new PC. I use Firefox only, latest version always, NoScript and AdBlock Plus in use and updated promptly, Windows XP Media Center Edition XP3 with all security updates always applied, always login as a limited user except for installs/updates, etc. And I'm not dumb, I'm a professional software engineer, and I know what not to do.
I restored my boot partition from a mid-October image (over 20 days ago), and the malware is STILL there and functional, so it's been there quite awhile now, without CIS ever noticing or alerting me. I scan daily and have CIS configured at nearly maximum security levels.
And CAV happily reports 0 malware found on all scans, and D+ never, that I can recall, gave me a single alert about the thing, and Comodo Firewall never caught anything either... and obviously this malware must be communicating with the outside world, to get its list of links, etc.
Now I'm likely going to have to blow away the machine's boot partition and restore it back to the manufacturer's factory default image, then spend days applying updates, patches, programs, configuring, etc.
Anyone have any idea how this might've happened, and why CIS can't find the thing? I'm considering downloading and running a scan with that "malwarebytes" scanner, turning off CAV's realtime mode while I do so. Anybody done that before? Does it work?
I'm not too happy with CIS right now. Has anyone encountered this, and can they help, or should I just blow the drive back to the factory image? If it's a nasty, deep, hidden rootkit (I don't see anything unusual in Task Manager or startup items, for instance!), I may have to.
«
Last Edit: November 06, 2009, 03:38:01 AM by puddingpants
»
Logged
cvsa
Comodo Family Member
Offline
Posts: 85
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #1 on:
November 06, 2009, 05:39:22 AM »
before formatting , try to use malwarebyte on your pc and tell us if it found something
Logged
AeoniAn
Comodo's Hero
Offline
Posts: 239
Protected & Armoured. COMODO is here!
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #2 on:
November 07, 2009, 08:11:32 AM »
Hi, puddingpants;
See this:
https://forums.comodo.com/virusmalware_removal_assistance/what_to_do_if_youre_infected_experience_rev3-t41380.0.html
Logged
CIS v573 full: Proactive, FW Custom, D+ Paranoid, IE normal, AV on-acc, heur med.
Sempron 3000+, MB MSI-7145, 2GB RAM
XP-SP3-Pro-BR x32 + W7-64 + Ubuntu LTS x64
ADM rights, Cable-PPPoA
PeerBlock v1.0+
A-SquaredAM + MBAM + SAS (w/o any real-time)
Zero, Nada, No-one single infecction > 47 months
DaRtH VaDeR.
Usability Study Member
Comodo's Hero
Offline
Posts: 1764
Everything in life comes to an end, exept life
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #3 on:
November 07, 2009, 09:57:49 AM »
HI,
my personal opinion on this is that it does not necessarily mean you have malware on your machine when you get "redirected" to a phising scareware site when clicking on a link in the google search engine result page.... If it was real malware you mostly always get redirected, because the creator of the malware wants you to get infected more, so even when copying the link you would get to a malware site, assuming you are real infected....
To get more clearness about your issue, you can try mcafee siteadvisor, linkscanner or wot firefox extension, to see what they "judge" about the specific site.. I would recommend you to try linkscanner, as it scans a site "real time". If any of these programs find the site dangerous, it is possible you got infected, especially when that specific site is an "attack site", which mostly exploits os en application bugs and contains drive by downloads... otherwise I would not worry that much....
When it is clear you are dealing with a dangerous site according to google or any of the suggesting security programs (Linkscanner, mcafee siteadvisor, wot), you need to check if you reduced the chance of infection:
* Have you clicked on anything on the site?
* Have you left information on the site?
if you answer the above questions with a "NO", you are good to go. Let us continue from here:
When it is a combination of a phising site and attack site:
* Are you logged in as a user with limited acces rights?
* If you use firefox, do you use security add-ons like noscript, ad block plus, better privacy, taco, and so on?
* If you use CIS, have you configured CIS with highest security settings? (for example paranoid mode..) or have you configured it in a way it would detect new threats?
* Do you keep your programs and main operating system up to date?
* Do you clean and scan you pc regularly?
If you answer the above questions mostly with "YES", you have minimized the effects of any malware that has entered your system in some way drastically!
To be sure, you can scan your system with different anti-malware programs of different security vendors who offer free scans or free on demand scanning programs.. Also there is the possibility to use system restore, before taking drastic measures as a back-up image!
Also check your system performance, running processes, and start-up entries and other important system areas. if everything runs "smoothly" I do not think you have to worry
I wish you a nice day!
Logged
DaRtH VaDeR says: "The path of success and progress is not to be reached by the things you have done, but by the things you will do, so think before you act,the voice of your history will confirm this fact.."
DaRtH VaDeR says: "Your system is as secure as the weakest link in your entire security"
puddingpants
Comodo Member
Offline
Posts: 41
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #4 on:
November 11, 2009, 01:07:11 AM »
Oh boy, do I feel silly.
CIS didn't detect any malware because I NEVER CAUGHT ANY!
I scanned my system with Malwarebytes and two rootkit scanners (GMER (see gmer.net) and F-Secure Blacklight), and found nothing. My pal visited some of the affected links I gave him, and he got the exact same evil redirects.... and he was using a Mac running Safari!
So I have no malware at all. The evil redirects are really "out there" on the web pages themselves.
I did some reading on the web and figured out what's going on.
Turns out that fraudsters have some new tricks. They'll take some currently-popular/hot search term(s), and will:
(1) make new webpages that contain text highly relevant to that search term (for example, stolen article text about the subject) and also contain a redirect to a "traffic management" URL.
and,
(2) compromise real (and vulnerable) webpages relevant to the search term, and put redirects on them that also lead to a "traffic management" URL.
The "traffic management" URL takes requests and redirects them to a randomly-chosen (or round-robin-chosen, or whatever algorithm is used) evil website it has in its list of evil websites.
These systems are smart, though. If the request's "HTTP Referrer" field doesn't contain "google.com", the redirect to the evil site doesn't occur. Instead, if the request was for a site of type (2) above, the user is sent to the real webpage. If type (1), since there's no "real webpage" at all, the user is redirected to some innocent site (in my experience, they sent me to CNN.COM's main page).
Since the administrators of the compromised real sites access their sites directly, and not through Google search result pages, they're unlikely to notice that their own sites have been compromised for quite some time!
Clever. Also, the systems will check all incoming requests' IP addresses against known security companies (Norton, Symantic or whoever) and will NOT do any evil redirects for those requests.
There are several articles about it on the web. Take note, folks. If you're getting redirected from seemingly-valid Google search results to evil sites, then you may NOT be infected with any malware (even if pasting the same URL into a fresh tab manually doesn't cause the redirects!)
This is something everyone ought to be aware of, so they don't potentially waste lots of time hunting down nonexistent malware on their PC.
Hope that helps. And thanks for the suggestions, guys. I like Malwarebytes. Since the free version has no realtime component, it plays nice with CAV, and gives me extra anti-malware confidence.
Logged
Beanie
Comodo's Hero
Offline
Posts: 525
The answer to 'What is the meaning of life?' is...
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #5 on:
November 11, 2009, 03:04:01 AM »
Quote from: puddingpants on November 11, 2009, 01:07:11 AM
Hope that helps. And thanks for the suggestions, guys. I like Malwarebytes. Since the free version has no realtime component, it plays nice with CAV, and gives me extra anti-malware confidence.
It's great software
Logged
Michael Withstand
Comodo's Hero
Offline
Posts: 255
Please read my sig. Thank you.
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #6 on:
November 12, 2009, 02:51:32 AM »
Thanks for the elaborate heads up really appreciate that
Logged
I'm a victim of severe persecution and harassment from people in power in Singapore. They defamed me as being mentally ill. Refusing any medication I've proceeded to finish a 7 semester degree from local(INA)U. They think their use of remote viewer is a perfect excuse that no such capability exist.
Chiron494
Comodo Family Member
Offline
Posts: 75
Re: Google result redirector malware - I'm infected; CIS did nothing!
«
Reply #7 on:
November 18, 2009, 12:28:20 AM »
If there is a link on Google that is malicious in any way they appreciate it if you report it at
http://www.google.com/safebrowsing/report_badware/
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.044 seconds with 19 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com