Saturday, January 29, 2011

False positive?





Got this popup while surfing on 2+2. I did not press OK, in fact I was even scared to close it myself. Instead I opened up Windows Task Manager and ended the application from there. It listed itself as AVG - Windows Explorer, but in fact is malware trying to install itself when activated.

I found this on the interwebs (links intentionally deleted) :


The malware comes from this link : http:// XXXXXXXX.com/

XXXXXXXX redirects to YYYYYYYY.com in my case. The site displays a popup via JavaScript which says: "AV8 has found suspicious activity on your pc and will perform some action on your pc." It does fake virus scan, displays a fake Windows Security Alert, and then downloads a variant of Win32/Kryptik.IMZ trojan:

http:// YYYYYYYY.com/load/ZZZZZZZZZ.exe



2 comments:

Memphis MOJO said...

I was even scared to close it myself. Instead I opened up Windows Task Manager and ended the application from there.

You're a wise man.

There's a shortcut. Hold down the alt key, then press F4. That will close whichever window is active.

ReclusesCorner said...

Just but a Mac ?!