Unsolved

This post is more than 5 years old

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

32227

August 26th, 2013 16:00

Beware fake "Critical Updates" from your browser

The update announcements sure look real enough... see pictures in the full article:

http://blog.malwarebytes.org/intelligence/2013/08/fake-browser-updates-going-rampant/ 

Comment:  What's really scary... but the "tip-off" to me... is that these updates REFUSE to let you bypass them!!!   The legitimate browser updates from IE, Chrome, FF would never make such a demand!

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

August 26th, 2013 22:00

That blog report is scary - as I read it one can't close the bogus alerts, the webpage, or the browser!

The report however is a bit lacking in instructions on how to manage this problem should one encounter it. I distrust any buttons or upper right hand Xs in unexpected alerts or pop-ups, and avoid clicking any of them to close such a popup.

It appears that having active scripting disabled in your browser will prevent this scenario, but I doubt it would work after the fact, since a browser restart is required. And most folks find scripting too useful to disable across the board.

Having NoScript or MBAM Pro enabled/running would seem to be preventative, but again not much help after the fact. Surfing with SandboxIE should also prevent infection.

Would simultaneously pressing Alt-F4 keys work? That used to be a fairly safe way to close any open program (including browsers) but with this threat I don't know.

Would killing the browser in your Task Manager  work?

I would probably just use CTRL-Alt-Del  to shut down the PC if  I ran across this, and pray that it worked. After a restart, run a few security scans ASAP.

 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 27th, 2013 05:00

"Would simultaneously pressing Alt-F4 keys work? That used to be a fairly safe way to close any open program (including browsers) but with this threat I don't know."

Alt-F4 --- a command sequence which I never remember --- closes the current window.   In IE --- at least for me --- this has the same impact as hitting the X button in the upper-right-hand corner:   It tries to close IE.

Since the particular malware under discussion attempts to prevent the user from exiting the browser unless/until the "update" is applied, I would **speculate** that using Alt-F4 would not be successful here.  (If anyone [BB?] has definitive knowledge in this case, it would be appreciated.)

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 27th, 2013 05:00

"Would killing the browser in your Task Manager  work?"

I went back to re-read the article.   It ends with the answer:

There’s an easy way to get rid of the browser lock: simply open up Windows’ Task Manager and terminate any process belonging to your browser:

  • iexplore.exe for Internet Explorer
  • chrome.exe for Google Chrome
  • firefox.exe for Mozilla Firefox

When you open up your browser again, make sure not to restore the previous session(s) as that would take you right back to the locked page.

I don't recall if that was in the article originally, or if they updated it with that information.

========

 

Addendum:  The Windows Task Manager can be accessed in at least 3 different ways:

1)  Press CTRL+ALT+DELETE, and then click Task Manager.

2)  Right-click an empty area of the taskbar, and then click Task Manager.

3)  Press CTRL+SHIFT+ESC.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

August 27th, 2013 05:00

Joe wrote:  "I would probably just use CTRL-Alt-Del  to shut down the PC if  I ran across this, and pray that it worked. After a restart, run a few security scans ASAP."

I'm not sure how you meant this.   if you meant it literally, using Ctrl-Alt-Del to immediately shut down the PC, I would have to disagree... doing so and rebooting may simply complete/seal the malware's installation.

But if you meant use Ctrl-Alt-Delete to access the task manager, kill the browser processes, and only then shut-down the PC, perhaps.   My preference --- after killing the browser processes via Task Manager, would be:

1) Since the article indicated the executables would be placed in the downloaded program files folder, I'd look there to see what I could find.   If found, I'd rename those files, including removing the executable extension.

2) I'd then run my security scan(s), starting with MBAM ---- BEFORE ever rebooting.   I'd want to nip this in the bud, rather than giving it the opportunity to "seal-in" its damage upon a reboot.

3) If MBAM didn't find any problem... I might consider running another scan (SAS? (*) )... and then I'd go back to the downloaded program files folder to delete the files that I had renamed.     (*) I don't see scanning with my anti-virus, since it was active at the time of infection... and if the malware got through its real-time protection, I doubt it would then be picked-up by an on-demand scan [unless/until its database is updated]. 

4) Only then would I risk a reboot.

 

 

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

August 27th, 2013 11:00

I suspect you are correct ky:

"Therefore it is correct to say that the safest option is to to Ctrl+Alt+Del and kill the process. This is safe because (in Windows) Ctrl+Alt+Del is a secure key combination that can only be intercepted by the OS, so it can't trigger any Javascript in the browser (it can't trigger anything actually)."
http://security.stackexchange.com/questions/38024/what-is-the-safest-way-to-close-a-popup-window

1 Message

January 22nd, 2014 01:00

When you attempt to close the page, you get a prompt that acts as a way to disable the normal process of shutting down your browser. This trick consists of two pieces:

  • a function that loops 100 times (this number is arbitrary) and calls out an iframe
  • the iframe that loads the warning window

For some odd reason, the malware author associated the files with the Pidgin chat client. One would expect they would try to spoof Microsoft, Mozilla, etc. See more on:

See more on:

[Potentially malicious link removed]

4 Apprentice

 • 

20.5K Posts

January 23rd, 2014 18:00

The above information by frances reid was copied verbatim from here: http://blog.malwarebytes.org/online-security/2013/08/fake-browser-updates-going-rampant/ .  For more information please visit HERE or post your questions in this forum.

No Events found!

Top