January 23, 2008 12:50 PM PST

Danger Will Robinson - don't watch that video

I got a taste today of the ever present danger that is the Internet. A client of mine is often in the news, so I watch for articles using Google Alerts. Once a day, I'm sent an email listing the new web pages Google found that contain my client's name. After doing this for well over a year without incident, Google today included a malicious web page in the list of those referencing my client. The page tried to install malicious software on my computer. Hopefully the details of the scam, described below, will educate anyone not yet sufficiently skeptical about life on the Internet.

Initially, Google sent me to
clarkjohnlzl22.blogspot.com
which purported to mention my client by name. It doesn't. But it does have a big video box with the usual Play button on it. Clicking the Play button, at least as of this writing, takes you to
gift-vip.net/videos/?name=crystal+children
Recently it took me to
gift-vip.net/videos/?name=steve+harvey+bald
On another computer, it took me to
websoft-a.com/download/504/411/0/

Update. January 24, 2008: The next day, the Google Alert email linked to another malicious web page peggynoonztj46.blogspot.com. Just like the clarkjohnlzl22 phony blog, this site too had a video that required the installation of software from gift-vip.net

The video doesn't play, but instead generates the error window shown below.


Clicking anywhere in this error window leads you down a dangerous path. There is almost no getting away from the nagging to install the software. For example, clicking Cancel, just results in nags similar to those below (one is from Firefox, one from IE6).



Here again, clicking Cancel or the official "X" does nothing useful. These prompts also prevent access to other open Firefox tabs. The only way to get out of this is to kill your web browser. But, clicking the "X" in the top right corner of the browser window does nothing (technically, the install prompts are modal). Normally you can right click on the task bar entry for a program and close the program from there. That too, doesn't work in this case.

To kill your browser in Windows XP, use Task Manager (see my prior posting Task Manager - useful enough to run all the time). Right click on the task bar and select Task Manager from the pop-up menu, then navigate to the Applications tab. Click on your web browser in the list of active applications, then click on the End Task button at the bottom of the window.

In the interest of research, I downloaded the file. Don't try this at home. Needless to say, I didn't install the software. Instead I had it analyzed at VirusTotal.com a great web site that analyzes a single file with many different antivirus products. (for more see Can you trust that file?).

As is usual at VirusTotal, some antivirus programs found the file to be malicious, others gave it clean bill of health. Among those that felt the software was safe were NOD32, BitDefender, Ewido and eTrust-Vet. Most products however, considered the file malicious. Among them were:

AntiVir 7.6.0.48 2008.01.23 HEUR/Malware
Avast 4.7.1098.0 2008.01.23 Win32:DNSChanger-SF
AVG 7.5.0.516 2008.01.23 Generic_c.FTY
ClamAV 0.91.2 2008.01.23 Trojan.DNSChanger-2168
F-Secure 6.70.13260.0 2008.01.23 Trojan.Win32.DNSChanger.aqd
Kaspersky 7.0.0.125 2008.01.23 Trojan.Win32.DNSChanger.aqd
McAfee 5214 2008.01.23 Puper.gen.d

There are two lessons here. First, any one anti-malware product can only provide so much protection. Second, any software that is pushy about getting itself installed, you don't want.


Update. January 25, 2008. As a couple people commented below, another point here is that you are safer by not running Windows. The comments were about Macs but the same can be said about Linux.

See a summary of all my Defensive Computing postings.

Recent posts from Defensive Computing
The main problem with Windows Vista
Foxit PDF reader v2.3 updated with bug fixes
Cringely's iPhone Gripes
A warning about IE8 and Windows XP SP3
Be safer than NASA: Disable autorun
Add a Comment (Log in or register) 9 comments
by spilledenvironment January 24, 2008 1:14 PM PST
Hee hee. I went to that link. Just don't click the image that looks like a YouTube video. Hehh... they get trickier every day.!!
Reply to this comment
by ruminator January 24, 2008 1:22 PM PST
Oh, didn't you know? This blogger doesn't believe any software is mature until at least 18 months...so to be extra safe with Internet software...I figure he'll be using IE 7 sometime in 2011. Check back then for the latest bugs on old software that no one's using.
Reply to this comment
by SCSNSE January 24, 2008 6:13 PM PST
I have encountered this very same virus, and what I do since I'm lazy is click "OK" to download it and simply stop the download immediately afterwords before it finishes. Works for me.
Reply to this comment
by Wild Eep January 24, 2008 7:14 PM PST
I have a mac, and it's pretty funny on it.
I opened the blog, clicked the youtube window on it (which by the way looks like a 50% quality jpeg) and was lead to a youtube source copy. On that page, there was a windows XP style window (on my mac) that was embedded in the webpage. It immediately started downloading the "video codec" (a .exe) and then I canceled it.
I love it when I see those xp/2000 style popup windows, while I smile at my beautiful Aqua. Stupid malware-ers
Reply to this comment
by BetterthanurX January 25, 2008 1:15 AM PST
Haha, i love how i just did all these on my mac and i saw an XP style window and the file could not wait to be downloaded to my HDD. Its a .exe file though so no dice. I love OSX/Unix
Reply to this comment
by stephonboggs1 January 27, 2008 4:18 AM PST
How do I get rid of the program?
Reply to this comment
by cps1321 January 27, 2008 11:40 AM PST
Tried to download the file today and my installation of NOD32 3.0.621.0 with virus signature database 2825 (Jan 27, 2008) detected the file as potential malware and terminated the connection. Since I just came across this article today, I'm curious what engine and virus definition of NOD32 didn't detect it.
Reply to this comment
by mhinnewyork January 28, 2008 8:53 AM PST
to: cps1321
I wrote this posting on the 23rd and was using NOD32 v3 with definitions dated the 23rd.
Michael Horowitz
Reply to this comment
by JPSerino August 31, 2008 3:51 PM PDT
I have had great results every time I caught a malware trojan, virus or whatever, by running Stop Sign. Between that and McAfee from AOL, I can remove anything that comes up. Also, running a registry cleaner helps delete the residual commands that seem to remain from some deleted programs.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

About Defensive Computing

Michael Horowitz is an independent computer consultant and the author of several classes on Defensive Computing. He views Defensive Computing as taking steps, when things are running well, to avoid or minimize the inevitable problems down the road. It's about educating yourself to the level where you can make your own intelligent decisions about keeping your computers and data happy and healthy. If you depend on computers, yet are on your own, without an IT department or nearby nerd, this blog's for you. His personal web site is michaelhorowitz.com.

He is a member of the CNET Blog Network and is not an employee of CNET.

Disclosure.

Add this feed to your online news reader

Defensive Computing topics

Featured blogs

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    National Advertising trade group opposes Yahoo-Google search ad deal

    The Association of National Advertisers announces it has sent a letter to the top antitrust chief for the U.S. Department of Justice, issuing its objections to the controversial Yahoo-Google search ad partnership.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    DemoFall preview: 10 to watch

    If you can only watch 10 pitches from DemoFall, these would be good ones.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.