Slashdot Mirror


New York Times Site Pop-Up Says Your Computer Is Infected

Zott writes "Apparently, 'some readers' of the New York Times site are getting a bit more with their news: an apparently syndicated adware popup with a faux virus scan of the user's computer indicating they are infected, and a link to go download a fix now. It's entertaining when a Mac user gets it, but clearly downloading an .exe file isn't a good way to keep your computer clean ..." Update: 09/14 03:20 GMT by T : Troy encountered this malware, "and did basic forensics. Summary: iframe ad then series of HTML/JS redirects, ending at a fake virus scanner page with a "Scan" link (made to look like a dialog box button) that downloaded malware." Nice explanation!

21 of 403 comments (clear)

  1. It's very entertaining. by Anonymous Coward · · Score: 5, Insightful

    I think it's actually more entertaining when I don't get it at all on any platform, because I disabled javascript.

    1. Re:It's very entertaining. by PlusFiveTroll · · Score: 5, Interesting

      FF + Adblock is my way to avoid it (and still get the sites I need .js to run on).

      This crap has been going on for a few years now with the 'AntiVirus XP' scam (http://www.theregister.co.uk/2008/08/22/anatomy_of_a_hack/) that seems to strike major sites every few months. Just goes to show the ad distributers have no control ( or don't want it) over what goes in to their distribution network.
       
       

      Sad this is, people fall for it all the time :(

    2. Re:It's very entertaining. by Anonymous Coward · · Score: 5, Informative

      The newest version of the "Antivirus 2010" software is a pain in the ass to get rid of. It rootkits the system and makes manual removal pretty much impossible without a WinPE boot disk of some kind, and even then it's difficult to find all the instances. There's one tool I found to remove it and most of its kin, and that is combofix. It successfully cleans Antivirus 2010 and a host of other rootkit-based malware in a process I can only describe as "magic". I'm just posting this to help out others that have spent way too much time trying to get rid of this crap off of friend/family computers.

    3. Re:It's very entertaining. by Z34107 · · Score: 5, Informative

      I completely agree with "combofix rocks." My job at the college I attend is pretty much removing that virus 24/7 from student laptops, and I've learned a few things:

      1) McAfee sucks. We supply a copy of the Enterprise version to students, and a patched installation is required for internet access. Somehow, we're still inundated every semester with the latest flavor of AntiVirus ModelYear.

      2) ComboFix is amazing. It's simple, but it automates a lot of tools that are a bit of a pain to use on their own. Ten minutes, and most malware is somewhat neutered.

      3) MalwareBytes is amazing. ComboFix always misses stuff, but it lets us install MalwareBytes (also free) which finishes the job. I haven't seen any virus MB couldn't remove.

      It's usually faster to run ComboFix + MalwareBytes (half hour between the tools in most cases) than it is to nuke it from orbit and reinstall Windows. Unless you're paranoid, two programs will take care of your end of your extended family's implied social support contract.

      --
      DATABASE WOW WOW
    4. Re:It's very entertaining. by Z34107 · · Score: 5, Informative

      In a perfect world, we would do that, but we get too many machines in and out to make that feasible. Then, there's all the normal luser problems: I don't know where my files are, I have no install media, I have no keys, I deleted my recover partition to save space, etc.

      The foolproof way to remove the AntiVirus ModelYear rootkit is: Make a file-based image of the hard disk. By design, it hides from the file system, meaning it will not be included in a image made by a tool like ImageX from Microsoft's free WAIK. Gather an image and apply it to the same hard disk, and the rootkit's gone.

      If you're adventurous, ImageX lets you mount the image file on a clean PC to do offline scans of its files and registry hives. You can clean a computer without ever booting it.

      But, that's generally overkill. AntiVirus ModelYear rootkit isn't the nasty kind of hardware-hypervisor rootkit - it runs at kernel privileges. So does MalwareBytes. To be dangerous, it has to run at a higher privilege level than the removal tools.

      For family members that promise me food, I go the extra mile and do the clean install for them. Staff machines we just re-image.

      --
      DATABASE WOW WOW
  2. News? Where? by SilverHatHacker · · Score: 5, Interesting

    What exactly makes this different from any of the other hundreds of sites with the same popup? Is it just because this is a large, well-known website like the New York Times?

    --
    Funny may not give karma, but +5 Informative never made anyone snort coffee out their nose.
    1. Re:News? Where? by Jahava · · Score: 5, Informative

      What exactly makes this different from any of the other hundreds of sites with the same popup? Is it just because this is a large, well-known website like the New York Times?

      That's my impression. I think the interesting thing here is that the presumption that reputable websites have reputable advertisements has been violated. NYT's advertising policies include the following paragraph:

      The Times may decline to accept advertising that is misleading, inaccurate or fraudulent; that makes unfair competitive claims; or that fails to comply with its standards of decency and dignity.

      Granted, they don't outright state that the content is prohibited, but they do imply a stance against this type of advertising. This is a clear violation of that intention, and they took the appropriate response. I'd be most interested in knowing if this particular advertisement was intentionally approved, "slipped through" accidentally, or was injected illicitly (e.g., their advertising server was hacked, etc.).

  3. I saw it by HangingChad · · Score: 5, Funny

    But when it starts telling me the C:\ drive on my Linux box is infected it's hard to stop laughing.

    Still was a job to get rid of the circle jerk pop ups.

    --
    That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
    1. Re:I saw it by DoofusOfDeath · · Score: 5, Funny

      But when it starts telling me the C:\ drive on my Linux box is infected it's hard to stop laughing.

      You moron, it was complaining about your .wine directory!

  4. And they wonder... by PC+and+Sony+Fanboy · · Score: 5, Funny

    And they wonder - Why is print media dying?

    Because they can't adapt properly. Seriously guys, filter your ads!

    1. Re:And they wonder... by wampus · · Score: 5, Funny

      Yeah, I was sitting over breakfast reading the Sunday Times and this popped up. Doomed.

  5. Happened to my Parents by QuantumG · · Score: 5, Insightful

    What really annoys me is that these things are most effective because they use javascript alerts to freeze the browser. If you could just browse away from the crap, I could teach my parents just to ignore it.

    "Javascript alerts are not tab modal" has been a known bug in Firefox going on 9 years now. It's not just an annoyance, it's a security bug, fix it!

     

    --
    How we know is more important than what we know.
    1. Re:Happened to my Parents by Anonymous Coward · · Score: 5, Informative

      Would that be this one? That's pretty darned old. Reminds me a bit of the title text display bug that used to hit XKCD et al.

  6. Damn right by Anonymous Coward · · Score: 5, Funny

    but clearly downloading an .exe file isn't a good way to keep your computer clean ..."

    Absolutely, .com, .bat and .scr are the only way to go!

  7. In my day ... by PPH · · Score: 5, Funny

    ... if we wanted to catch a virus from the New York Times, we had to read a copy that some hobo had used for a blanket.

    Now you kids stay off my lawn!

    --
    Have gnu, will travel.
  8. Re:It happens on Linux too by eric31415927 · · Score: 5, Insightful

    Two years ago, I got my 67-year-old mother online with a Debian (stable) box for web browsing, emailing, and printing.
    At least twice in these two years, she has come across web pages warning that her operating system has been infected with a virus.
    The web pages make it look like she has an infected Windows system - similar to the link from the NYT web page.

    I reassure her each time that her computer has not been infected, and it is not likely to ever be infected so long as she is careful with her password.
    I would like Firefox (or in her case IceWeasel) to have a plugin to avoid loading pages that look like Windows Explorer.
    This would save people like my mother and businesses like the NYT from undue stress.

  9. CNN... by CryptoJones · · Score: 5, Informative

    has also been doing this for the past two days.

    --
    "Chance favors the prepared mind." ~Me
  10. HOSTS file and noscript by davidshewitt · · Score: 5, Insightful

    ...seem to do the trick for me. I put this huge list of malicious sites into my HOSTS file, so most ads never even show up. http://www.grc.com/sn/hosts_mvps_org.txt

    1. Re:HOSTS file and noscript by Rick17JJ · · Score: 5, Informative

      I have been using the latest version of the MVPS modified hosts file on both my Linux computer and on my Windows XP computer. However,instead of using the 06-14-06 version which davidshewitt linked to, I have been using the much newer Sept-02-2009 version instead. One link is for, what at the moment, is the latest version of the modified hosts file and the other link is to the installation instructions and general information.

      http://www.mvps.org/winhelp2002/hosts.htm
      http://www.mvps.org/winhelp2002/hosts.txt

      I recently also started using the NoScript add-on and also the Adblock Plus add-on for Firefox on both my Linux computer and on my Windows XP computer. But, perhaps using both the ad blocking host file, plus Adbock Plus, is redundant and unnecessary. With the NoScript ad-on, I occasionally click on the icon, which has now been added to the lower right corner of Firefox. After clicking on that, I can choose whether to temporarily or permanently allow a particular web site scripts.

      I do nearly all of my Internet browsing from my Linux box. But, when I occasionally actually dare to use my Windows XP computer to browse the Internet, I use Sandboxie to sandbox my default browser, which in my case happens to be Firefox. I am not an expert on any of this, and am not a regular Security Now listener, but here are a couple of episodes that are about Sandboxie.

      http://www.grc.com/sn/sn-172.htm
      http://www.grc.com/sn/sn-174.htm

  11. Re:Funny by Yvan256 · · Score: 5, Funny

    I've renamed my "Macintosh HD" to "C:" to accommodate the viruses, but they still won't run!

  12. Once again with the "nofix" by symbolset · · Score: 5, Interesting

    If you can confirm that there was malware on the system there is no cure except to start with a clean image - preferably one you stored with an imaging tool like the free Clonezilla prior to accessing any network at all or any untrusted media. Putting a clean image on can take 5-30 minutes, and is certain to remove all traces of infestation. It's actually quicker than scanning. Once you've got a confirmed hit your only business using a compromised machine is an inspection of the features that got the user into trouble so you can turn those off after you image, and capture for them a more suitable image.

    There's a tired old nag about no software being secure but really one thing is for certain: once an app has been running that's known to be infested it got there because the maker knew something the user didn't. Among the other things the user doesn't know are how many other applications the malware infested, how many running services were leveraged with local privilege escalation, how many rootkits of various sorts were installed. Most modern malware immediately upon installation scans the local system and sniffs the network. They look up components and download a cocktail of toxic code that's both tailored to the specific machine and randomly generated so as to be unique. There's a management system that auto-permutes millions of vile code variants every day, and uses a genetic algorithm to determine which of the little beasties is the most efficient. This is not your dad's malware ecosystem.

    Pretending to remove malware is nothing short of malpractice. All you're doing is helping the bad guys by pointing out which modules survive a cursory attempt at cleaning.

    --
    Help stamp out iliturcy.