Goto the eInvesting Home Page
Home    Investing Forums    Edit Your Profile    Manage Your Portfolio    View the Rankings    Learn about the Simulator

Welcome to eInvesting! You've found the coolest stock market game on the web. At eInvesting you compete for monthly cash prizes while you interact, make virtual dollars, purchase items, and trade in the realistic stock market simulator. We make investing FUN!

Join now and and start trading right away!
Log In to make this message disappear!

 
  ::  Register  ::  Log in  ::  Log in to check your private messages
Purchase e$ Purchase e$ Virtual Store Virtual Store FAQ  FAQ      Search Search  
 
 
www.eInvesting.com Forum Index » The Stock Market

Auto download adware carries vicious payload


Post new topic Reply to topic
Auto download adware carries vicious payload « View previous topic :: View next topic »
Author Message
DaTuRtLeSZ
PostPosted: Sun Mar 06, 2005 3:47 pm Post subject: Auto download adware carries vicious payload Reply with quote

Investing Manager
Investing Manager

Joined: 14 Feb 2005

Posts: 277
This Month: 0
Location: USA
15213.41 e$

Net worth: 15,213.41
Portfolio Value: 0.00
Monthly Return:
0.00%
Trades this month: 0
Churn Rate: 0.00%

Items

Security experts issued a warning this morning after detecting infections caused by Searchmeup, the first adware to use the Exploit/LoadImage vulnerability which downloads itself onto computers without the user's permission.
Panda Software's PandaLabs warned that the pages from which Searchmeup are downloaded also contain a series of exploits to download other malware onto the computer, such as the Tofger.AT Trojan, which steals banking passwords, Dialer.BB and Dialer.NO, and adware called Adware/TopConvert.
Searchmeup is downloaded onto the computer when the user visits maliciously coded web pages. Once installed it changes the home page to that of a search engine that displays pop-ups every time it loads with the aim of installing spyware and diallers on infected computers.
Searchmeup affects computers running Windows 2003, XP, 2000, NT, Me and 98, and allows arbitrary code to be run.
It could be exploited by an attacker hosting a specially crafted cursor or icon on a malicious web page or HTML email. Microsoft has released a patch to correct this problem, and users are advised to install it immediately.

The web pages from which Searchmeup is downloaded also drop Tofger.AT onto computers, a Trojan which runs every time Internet Explorer is opened.
Tofger.AT keeps track of the user's internet activity, logging passwords for secure 'https' connections which are often used for connections with online banks. Once it has collected this information, Tofger.AT sends it to a remote server.
Searchmeup can also generate an error in the 'services.exe' file, informing users that the computer will be restarted in one minute.
After the restart, the computer operates perfectly. On some occasions Searchmeup can also display blue screen errors, and Tofger.AT can actually update itself to a new version.

"The Exploit/LoadImage vulnerability can be used on web pages or HTML email by crafting a special icon or image file that causes a buffer overflow that in turn can be used to take control of the user's computer," said Patrick Hinojosa, chief technology officer at Panda Software US.
"This can be very serious as the user does not have to do anything unusual like opening a suspicious attachment. This is what is sometimes referred to as a 'drive by' attack."
Luis Corrons, director of PandaLabs, added: "The appearance of Searchmeup is a sign of the continuous evolution of malware, and of spyware and adware in particular.
"The first stage was that adware reached computers as a component of a freeware application, then web pages appeared that installed adware on users' computers using ActiveX.
"Now they have gone a step further, as Searchmeup exploits a vulnerability that even virus creators had not used until now."
Back to top
Display posts from previous:
Post new topic Reply to topic Page 1 of 1

www.eInvesting.com Forum Index » The Stock Market » Auto download adware carries vicious payload
Jump to:  




Penny Stock Simulator | What are e$? | Forum Rules | FAQ | Manage Your eInvesting Portfolio | Privacy Policy | Links
PcTechTalk | Club-tC | Lost Discussion | World Class Designs | Xtreme Tuning | Statistical Trading | Advertise with eInvesting!


Before acting on any advice or program you find here at eInvesting.com we strongly recommend that you seek independent & professional legal, tax and investment advice as to whether it is suitable for your particular needs and circumstances. Failure to seek personally tailored, detailed, professional advice prior to acting could lead you to act contrary to your own best interests and could lead to loss of money. eInvesting.com is not responsible for your actions, so do it right!

Powered by:phpBB VERSION 59
© 2005, 2006 eInvesting.com