PDA

View Full Version : [ubuntu] funny virus


Alldan
June 29th, 2008, 04:08 AM
I searched for some lyrics and i followed a google link which may be a trap. I realized that but i pushed forward to see what's happening because i know that windows viruses cannot infect my ubuntu system.
75670

75671

75672

:lolflag:
enable activex...
backdoor.win32 virus detected...

75673

if you want to leave the site you simply cannot. it's for your own good..

75674

I searched what this antvrsinstall.exe does and found this:
http://www.prevx.com/filenames/986023548013910423-X1/ANTVRSINSTALL.EXE.html

I don't have wine or cedega installed
I use Mozilla 3.0 and the cookies are deleted when i close the browser
Now i wait to see if this "offer" reapears during web surfing or it was just a bad link.


Note: I downloaded the infected file and then scaned with Klamav, avast!4 avg7.5 and f-prot (all for linux, latest versions and updated virus signatures). All of them doesn't detect anything suspicious! The virus itself is not a problem on a Ubuntu station but linux antiviruses that i try doesn't appear to be efficient.
I copied the file on a stick and scanned the stick with BitDefender 2008 Total Security in windows and BitDefender detect it as Trojan.Fake.Alert.TE.
Avast!4 for windows didn't detect the virus

TWO
June 29th, 2008, 05:08 AM
I don't think you need to worry as that link can't do anything to your computer. It's the same old tripe you find. I don't imagine that that was one of the popular search results from a Google search right?

Just be careful about sites that you visit in future, particularly if using Windows.

Chayak
June 29th, 2008, 03:52 PM
It's just a social engineering site designed to get to you actually infect yourself.

On AV not picking it up. I work in malware research and I've seen a surprising amount of files not show up on any AV scans.http://www.virus-total.com has some interesting statistics.

todb
June 30th, 2008, 10:38 AM
I realized that but i pushed forward to see what's happening because i know that windows viruses cannot infect my ubuntu system.

So... just as an aside, as Firefox gets more popular, the above presumption will bite a lot of curiosity seekers some day. Firefox vulnerabilities do exist, and tend to be OS-agnostic.

Just saying -- poke around on known-bad malware sites at your own risk, no matter what your favorite OS/browser combination is. [-X

ChameleonDave
June 30th, 2008, 10:41 AM
... and tend to be OS-agnostic.
If they are based on the notion that knowledge of the existence of the OS is unknowable, then they are probably harmless. :)

todb
June 30th, 2008, 01:24 PM
If they are based on the notion that knowledge of the existence of the OS is unknowable, then they are probably harmless. :)

Harmless to the local OS? Okay -- though local file read/write can look awfully similar in Javascript.

Browser bugs can be not so harmless to your authenticated Gmail session, or your password store, or your XYZ add-on, or whatever else that you might consider private that you rely on browser security for.

All I'm saying is that the current security-relevant bug count for Firefox is practically unknowable and certainly nonzero (http://dvlabs.tippingpoint.com/blog/2008/06/18/vulnerability-in-mozilla-firefox-30), and visiting malware sites in the way the OP described is opt-in dangerous behavior regardless if the browser is running on Windows or Ubuntu.

/just being pedantic.
//troll +1

damis648
June 30th, 2008, 01:34 PM
That is pretty funny... i bet at least some people will fall for it.