This is topic Can just visiting a website foul up your computer? in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=006450

Posted by Mike Blakesley (Member # 26) on 06-14-2011, 10:41 PM:
 
So, I was looking at the internets on my work PC today (which has MalWareBytes installed) and up pops their little info box saying "MalwareBytes has blocked access to the potentially malicious website 000.00.000.000." (I don't remember the actual numbers.)

Well I've seen this a thousand times, don't know if it's always blocking the same site, but I was real curious what that site was, so I typed those numbers into my "other" work PC -- the one that has every kind of antivirus known to man on it, not to mention an expensive service contract -- and it immediately popped up with a box saying I was the "Montana winner" and to "Click OK to create your account." And, the hard drive started to churn like it was saving files. And of course there was no way out of the site except to click the OK. So, I immediately just turned the computer off and rebooted without clicking.

After rebooting it seemed to work fine, was able to surf the net normally (so far at least), but I'm just wondering....did I do any damage? Is it possible to damage a machine by just going to a site? And why didn't the ultra-protected computer stop me from going to that site?
 
Posted by Frank Cox (Member # 6258) on 06-14-2011, 10:56 PM:
 
Anti-virus and so on is a catch-up game; by its very nature you're always chasing the tail lights of the newest Windows exploit (or Adobe exploit, etc.)

Why do you think that stuff is being continuously updated?

As a Windows user, you're taking the chance of being the lucky winner of the latest-and-greatest, before your aftermarket security of choice knows about it.

And there are a lot of very smart people working on the next big thing in malware.
 
Posted by Robert E. Allen (Member # 1351) on 06-14-2011, 11:05 PM:
 
I'm no computer geek but from what I have learned if it is a website you are not familiar with, did not sign up for or are suspicious of get out of there.
 
Posted by Frank Angel (Member # 248) on 06-15-2011, 12:27 AM:
 
Short answer, sure it can, especially if you are lured to a site that is bogus and made to look like a legit site, which is the favorite hacker ploy. How can going to Film-Tech be harmful. Well, if someone has copied the pages down to the most minute detail and you think you are safe, you are had. Trick is to see that stuff coming, especially if you are asked to click on a URL link -- that can take you anyplace. Go there yourself to the URL that you KNOW is legit, never from an email link.

The fact is, once you are connected to the internet, you are vulnerable, more or less depending how good your anti-virus software is, how good your firewall is and how vigilant you are in keeping all this stuff updated (MaleWareBytes, btw, is a very good app). Of course not every time anti-maleware returns a "blocking" message means that it's blocking something that's actually dangerous or just something it thinks is "suspicious" activity. Even Microsoft sending updated information can be seen as potentially dangerous. All anti-ware have to walk the fine line between stopping stuff you want and need, thus making you go mad, and catching the pig turds out there who are constantly looking to do evil, either by steal stuff from you or just doing stuff to annoy the shit out of you for the fun of it.

One of the things I have been doing now for quite awhile is to stop ALL those convenient things that keep ports open to the outside world like the Weather app, HP updates, Adobe updates, etc. Any of those little apps that let a site have access to your system have the potential of letting hackers do the same.

I have also put a shortcut to the Ethernet Connection function Enable/Disable toggle on my Desktop so that when I am working on things that don't require an internet connection (which I found is MOST of the time -- you'd be surprised how much you can do off=-line), I just click on the icon and Disable the internet connection. No matter how clever the hackers are, if you are not connected to the internet, there is no stronger anti-virus firewall than that. When I want to go back on line, it's a click away. I never leave my computer open to the internet for no good reason; before I used to leave it on and connect to the internet sometimes days at a time....not good; it's like leaving the door to your house unlocked all the time. Now I either turn it off completely or Disable the internet connection.
 
Posted by Frank Cox (Member # 6258) on 06-15-2011, 02:49 AM:
 
NAT is not a firewall, but I recommend that everyone (especially folks running Windows) never connect their computer directly to their modem. Always use a router, even if you have only one computer.

Many routers also have a reasonably decent firewall built in, and routers are cheap.
 
Posted by Greg Anderson (Member # 235) on 06-15-2011, 09:02 AM:
 
The answer is yes. Sometimes you have to click on their pop-up window to "activate" their malicious software but sometimes your computer is infected just by landing on a web page.
 
Posted by Sam Graham (Member # 2889) on 06-15-2011, 09:12 AM:
 
You did the right thing by quickly shutting down without clicking anything. As long as your anti-malware is scanning your system regularly and everything seems fine, you're probably okay.
 
Posted by Mark Lensenmayer (Member # 134) on 06-15-2011, 11:25 AM:
 
Just to be safe, I would suggest running a full disc scan from MALWAREBYTES. Be sure to get the latest updates...that program updates frequently.

I agree that you did the right thing by just shutting down before the thing hopefully could take hold. You probably hit one of those sites that does a fake disc scan and then wants to sell you a program to fix all of the errors. These are getting very common and have even popped up in Mac land.
 
Posted by Edward Havens (Member # 4715) on 06-15-2011, 11:35 AM:
 
quote: Mike Blakesley
And of course there was no way out of the site except to click the OK.
Couldn't you have exited the browser completely without clicking OK?
 
Posted by Mike Blakesley (Member # 26) on 06-15-2011, 12:02 PM:
 
Ed - I tried that and the "x" was disabled.
 
Posted by Pete Lawrence (Member # 130) on 06-15-2011, 01:44 PM:
 
They are trying to force you to interact with the pop-up window. One way to get around that is to hold CTRL and ALT and press the DELETE key. The old Microsoft 'Three Finger Salute'. That used to do a reboot. In current versions of Windows it will allow you to bring up Task Manager and from there you can kill the browser in a couple of clicks or key strokes. Not as traumatic as a forced power off.
 
Posted by Barry Floyd (Member # 385) on 06-15-2011, 02:06 PM:
 
We use a program here at the office called "Sandboxie", and it basically isolates your web browser from all of the rest of your computer. We run both Internet Explorer and Mozilla from within the Sand Box, and it really does a good job keeping the crap out of our computers.

if you can't find that, I do what Pete suggested and shot down the program via Task Manager.
 
Posted by Monte L Fullmer (Member # 2797) on 06-15-2011, 02:39 PM:
 
Ya, I got caught as well on my laptop.

My AV didn't catch anything and my desktop was locked shut with an ad, ironically, to capture malware .. and I couldn't close it or get rid of it.

It had definitely controlled everything where I couldn't click on anything on the desktop-it would highlight but would not activate when click on the icons. Even when I tried to do an external boot using USB or CD drive, I was refused entry.

I might have found something else, but at the time, was rather frustrated and used the "recovery" section of my HD to wipe the HD clean and start over ..

Learned a serious lesson - back up files on a routine basis for I lost tonnage due to that freeze.

-monte
 
Posted by Steve Guttag (Member # 268) on 06-15-2011, 04:21 PM:
 
One thing that has served me pretty well is to use an off-brand browser...one like "Opera." Nobody writes nasties for it. Sure, it does not work on all sites but those are probably sites I'd rather not be on anyway so it is a natural filter.

So with using Opera, AVG (anti virus), IO bit's ASC, firewall set on max...I haven't picked up any bugs.

-Steve
 
Posted by Mike Blakesley (Member # 26) on 06-15-2011, 10:05 PM:
 
quote: Pete Lawrence
They are trying to force you to interact with the pop-up window. One way to get around that is to hold CTRL and ALT and press the DELETE key
I tried that too and it would not work either. The whole thing was completely unresponsive to anything, probably unless I clicked on that OK in the middle and then it would have been trouble city, I'm guessing.

Anyway, I did as suggested above and ran the full scan from MalWareBytes and it did turn up one infected item. I forget the full name but it started with "HiJack" so there's a pretty good chance that's the thing that tried to get me. So I think I'm out of the woods on this one.

Thanks all for the replies and advice.
 
Posted by Greg Anderson (Member # 235) on 06-15-2011, 10:26 PM:
 
I have helped two different persons in the last couple of months to remove a fake malware scanner from Vista. In each case, the virus has installed a desktop icon which was a shortcut to a program called defender.exe AND it already disabled the ability to run legitimate programs like the task manager, iTunes and Internet Explorer. I did a search (on another machine) for defender.exe and found useful advice on how to get rid of it with MalwareBytes. In one case, I had to find and run a program called rkill.exe to stop the virus from running and THEN allow me to run the task manager and other legitimate programs (before getting MalwareBytes installed)..
 
Posted by Bobby Henderson (Member # 840) on 06-16-2011, 10:01 PM:
 
I've seen plenty of computers hosed by malware just from the user visiting a website or even going to a site commonly visited that just happened to have an ad running that had a malicious script embedded in its code.

Anti-virus and anti-spyware applications are definitely stuck playing a catch up game. No web browsers are safe either. Google Chrome had a good rep for a long time, but now certain hacks can leap out of its "sandbox" and straight into the Windows kernel.

"Scare-ware" infections are pretty common, like the fake anti-virus software that attempts to get your credit card data and other personal information. I've seen a couple that simply couldn't be cleaned from the system. The only resort was to format C and reinstall Windows.

Some of this stuff still boils down to user error or risky browsing habits. Even with the latest updates to Windows, latest anti-virus definitions, etc. it's very risky to do things like file sharing, torrent downloading or viewing Internet porn. I suppose someone could run plug-ins like NoScript to add another layer of security, but even that is only going to get you so far.

If I wanted to do some risky web surfing and feel relatively safe about it I would do the surfing from some other device, like an Android tablet or perhaps a Mac mini hooked up to my HDTV set.
 
Posted by Frank Cox (Member # 6258) on 06-16-2011, 10:15 PM:
 
After a computer has had malware installed on it, the machine can no longer be trusted anyway. Sure, you managed to remove BadWareA with your trusty virus scanner, but what about BadWareB that was installed at the same time?

Think of it like someone breaking into your house and filling it with a series of clever booby traps. After removing how many traps will you allow your kids back into the house? How do you know that you haven't missed one?
 
Posted by Frank Angel (Member # 248) on 06-16-2011, 10:42 PM:
 
The college is looking at a program called Centurian that installs on computers that the students and interns use. Centurian SmartShield From what they've told me, it basically runs everything as a virtual machine and no matter what happens during a session where they are connected to the internet, when you reboot, the registry is restored to the exact same state as it was when you turned on your computer.

If you WANT something to change your registry, you have to use a key to let that happen. Sounds good in theory and maybe ok when interns are using a computer that you never want anything in it to change, at least not at their hands, but the question is, for people who actually do work that requires frequent legitimate changes, how badly will a program like that impact productivity?

How annoying will that be when you need to do stuff that requires changes, and more importantly what if you've picked up something without knowing it during the course of legitimate interaction on the internet and you allow a change but it contains a hidden virus? Seems to me it only affords absolute protection if you never want to allow anything to change your computer.
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2