Unsolved
This post is more than 5 years old
5 Journeyman
•
15.6K Posts
•
45K Points
2
32227
August 26th, 2013 16:00
Beware fake "Critical Updates" from your browser
The update announcements sure look real enough... see pictures in the full article:
http://blog.malwarebytes.org/intelligence/2013/08/fake-browser-updates-going-rampant/
Comment: What's really scary... but the "tip-off" to me... is that these updates REFUSE to let you bypass them!!! The legitimate browser updates from IE, Chrome, FF would never make such a demand!
No Events found!


joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
1
August 26th, 2013 22:00
That blog report is scary - as I read it one can't close the bogus alerts, the webpage, or the browser!
The report however is a bit lacking in instructions on how to manage this problem should one encounter it. I distrust any buttons or upper right hand Xs in unexpected alerts or pop-ups, and avoid clicking any of them to close such a popup.
It appears that having active scripting disabled in your browser will prevent this scenario, but I doubt it would work after the fact, since a browser restart is required. And most folks find scripting too useful to disable across the board.
Having NoScript or MBAM Pro enabled/running would seem to be preventative, but again not much help after the fact. Surfing with SandboxIE should also prevent infection.
Would simultaneously pressing Alt-F4 keys work? That used to be a fairly safe way to close any open program (including browsers) but with this threat I don't know.
Would killing the browser in your Task Manager work?
I would probably just use CTRL-Alt-Del to shut down the PC if I ran across this, and pray that it worked. After a restart, run a few security scans ASAP.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
1
August 27th, 2013 05:00
"Would simultaneously pressing Alt-F4 keys work? That used to be a fairly safe way to close any open program (including browsers) but with this threat I don't know."
Alt-F4 --- a command sequence which I never remember --- closes the current window. In IE --- at least for me --- this has the same impact as hitting the X button in the upper-right-hand corner: It tries to close IE.
Since the particular malware under discussion attempts to prevent the user from exiting the browser unless/until the "update" is applied, I would **speculate** that using Alt-F4 would not be successful here. (If anyone [BB?] has definitive knowledge in this case, it would be appreciated.)
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
2
August 27th, 2013 05:00
"Would killing the browser in your Task Manager work?"
I went back to re-read the article. It ends with the answer:
There’s an easy way to get rid of the browser lock: simply open up Windows’ Task Manager and terminate any process belonging to your browser:
When you open up your browser again, make sure not to restore the previous session(s) as that would take you right back to the locked page.
I don't recall if that was in the article originally, or if they updated it with that information.
========
Addendum: The Windows Task Manager can be accessed in at least 3 different ways:
1) Press CTRL+ALT+DELETE, and then click Task Manager.
2) Right-click an empty area of the taskbar, and then click Task Manager.
3) Press CTRL+SHIFT+ESC.
ky331
5 Journeyman
•
15.6K Posts
•
45K Points
2
August 27th, 2013 05:00
Joe wrote: "I would probably just use CTRL-Alt-Del to shut down the PC if I ran across this, and pray that it worked. After a restart, run a few security scans ASAP."
I'm not sure how you meant this. if you meant it literally, using Ctrl-Alt-Del to immediately shut down the PC, I would have to disagree... doing so and rebooting may simply complete/seal the malware's installation.
But if you meant use Ctrl-Alt-Delete to access the task manager, kill the browser processes, and only then shut-down the PC, perhaps. My preference --- after killing the browser processes via Task Manager, would be:
1) Since the article indicated the executables would be placed in the downloaded program files folder, I'd look there to see what I could find. If found, I'd rename those files, including removing the executable extension.
2) I'd then run my security scan(s), starting with MBAM ---- BEFORE ever rebooting. I'd want to nip this in the bud, rather than giving it the opportunity to "seal-in" its damage upon a reboot.
3) If MBAM didn't find any problem... I might consider running another scan (SAS? (*) )... and then I'd go back to the downloaded program files folder to delete the files that I had renamed. (*) I don't see scanning with my anti-virus, since it was active at the time of infection... and if the malware got through its real-time protection, I doubt it would then be picked-up by an on-demand scan [unless/until its database is updated].
4) Only then would I risk a reboot.
joe53
5 Journeyman
•
5.8K Posts
•
17.3K Points
2
August 27th, 2013 11:00
I suspect you are correct ky:
"Therefore it is correct to say that the safest option is to to Ctrl+Alt+Del and kill the process. This is safe because (in Windows) Ctrl+Alt+Del is a secure key combination that can only be intercepted by the OS, so it can't trigger any Javascript in the browser (it can't trigger anything actually)."
http://security.stackexchange.com/questions/38024/what-is-the-safest-way-to-close-a-popup-window
frances reid
1 Message
0
January 22nd, 2014 01:00
When you attempt to close the page, you get a prompt that acts as a way to disable the normal process of shutting down your browser. This trick consists of two pieces:
For some odd reason, the malware author associated the files with the Pidgin chat client. One would expect they would try to spoof Microsoft, Mozilla, etc. See more on:
See more on:
[Potentially malicious link removed]
Bugbatter
4 Apprentice
•
20.5K Posts
0
January 23rd, 2014 18:00
The above information by frances reid was copied verbatim from here: http://blog.malwarebytes.org/online-security/2013/08/fake-browser-updates-going-rampant/ . For more information please visit HERE or post your questions in this forum.