Results 1 to 12 of 12

Thread: Web graphics used to spread viruses through IE

  1. #1
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.

    Web graphics used to spread viruses through IE

    Ok, ok, IE is in trouble, and so am i now... and im gonna have to change to another browser now. Either that or put up my IE Internet security settings to High and put up with this DAMN "your current internet security settings may cause this page to load incorrectly" ms pop up box..

    Ok, so i guess the question is thus, what browser should i go for, wait, be for you say FIREFOX!, are there any other popular browsers out their to think about ?
    Also is FireFox deffo not affected by this new method of spreading viruses through web graphics ?

    Finaly my AVG Resident Shield keeps briging up a pop up box saying there is a "Virus, Trojan horse Dialer.7.AS Found in C;\System Volume information\..."
    And says to run AVG test to cure it, but even a complete test do not detecte it. What should i do ?

    Cheers, Dave.
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

  2. #2
    Pink & Fluffy! Elmo's Avatar
    Join Date
    Jul 2003
    Location
    Glarsgow
    Posts
    3,234
    Thanks
    0
    Thanked
    6 times in 6 posts
    i used to have that problem with AVG.
    turn ur system restore off ( control panel -> system -> system restore), close all connections to the internet, run a full AVG scan, then turn system restore back on.

    Thats what i used to have to do with AVG, so try it. I've now changed to norton and had zero problems

  3. #3
    HEXUS.net Webmaster
    Join Date
    Jul 2003
    Location
    UK
    Posts
    3,108
    Thanks
    1
    Thanked
    0 times in 0 posts
    Spreading a virus through a web graphic is not new, it;s been done for years. The 1 pixel gif is even used by web sites to maintain session functionality and is an accepted method of doing this across several backend systems. Whilst IE is more susceptible to virii than other browsers e.g. Firefox, good anti-vrus software should be sufficient to allow you to use IE if you want.

    If you're still considering another browser then the main contender to Mozilla is Opera at http://www.opera.com

  4. #4
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    I assume Dave is referring to this - a new trojan which tries to take advantage of several patched IE vulnerabilities and 2 that have not previously been seen.

    However, while the javascript trojan is inserted in the appended footer for every page served by an infected web server, it can't execute if it is attached to images.

    - Will the javascript attached to images be executed?
    No. The javascript attached to images is harmless. It's the JavaScript attached to the .htm or .html files that gets executed, forcing the browser to connect to the Russian site.
    Seems the only seen incarnation of this virus is to silently install the "I-Lookup" toolbar, and SANS are not aware of any web servers currently (still) infected.

    Some AV products will pick up the trojan - AVG picks up the proof of concept one from the site linked to by SANS, for example.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  5. #5
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.
    I don't know what this Dialer.7.AS thing is, and im only bringing it up becuase a week ago a AVG Full scan actually detected this Dialer thing as did SpyBot-S&D, spybot-s&d said it removed it and AVG said it moved part of the Dialer thing to it's Virus valt and "Healed" the rest, it only healed it instead of totally removing the dialer thing because apparently access was denied or sommet, So i thought the prob was fix, but now the box just keeps poping up. So obviously it's not fixed.
    Elmo i'll try what waht u suggested and see it that helps.

    PS, I forget to ask be for, when you install a new browser like Firefox, do you need to uninstall IE or sommet ? If so, how ? as IE is not in my add/remove list only a patch for IE is listed there called "Internet Explorer Q831167"

    Cheers, Dave.
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

  6. #6
    HEXUS.net Webmaster
    Join Date
    Jul 2003
    Location
    UK
    Posts
    3,108
    Thanks
    1
    Thanked
    0 times in 0 posts
    no need to uninstall IE

  7. #7
    Senior Member
    Join Date
    Jul 2003
    Location
    3rd Rock from the sun..
    Posts
    463
    Thanks
    15
    Thanked
    4 times in 3 posts
    • Dave_07's system
      • Motherboard:
      • MSI X99A Gaming 7
      • CPU:
      • Intel Core i7 5930k (6 core) @ 4.3Ghz
      • Memory:
      • 16Gb Corsair DDR4 2800Mhz
      • Storage:
      • 2x 500Gb SSD's (Raid 0)
      • Graphics card(s):
      • 2x SLI MSI GTX 980
      • PSU:
      • EVGA 1000w PSU
      • Case:
      • Corsair C70
      • Operating System:
      • Windows 7 Pro 64Bit
      • Monitor(s):
      • G-Sync AOC G2460PG 1080p and LG Flatron W2261VP
      • Internet:
      • 17.5Mb Broadband.
    Is there any way to stop this IE pop up box "your current internet security settings may cause this page to load incorrectly" ??
    Intel Core i7 5930k @ 3.7Ghz Turbo
    MSI X99A Gaming 7
    16Gb Corsair DDR4 2667Mhz
    2x SLI MSI GTX 980
    2x 500Gb SSD's (Raid 0)
    EVGA 1000w PSU
    Windows 7 Pro 64Bit
    G-Sync AOC G2460PG 1080p
    LG Flatron W2261VP

  8. #8
    listen to escape fails :) luap.h's Avatar
    Join Date
    Jan 2004
    Posts
    569
    Thanks
    4
    Thanked
    2 times in 2 posts
    Quote Originally Posted by Dave_07
    Ok, so i guess the question is thus, what browser should i go for, wait, be for you say FIREFOX!, are there any other popular browsers out their to think about ?
    I'm finding opera a joy to use, though it isn't completely compatible with all web pages, so you find yourself going back to IE now and again. Opera has some neat features which you miss like crazy when you use something else. Kinda like going back to a mouse with no scroll wheel! The mouse gestures are pure genius

  9. #9
    HEXUS.net Webmaster
    Join Date
    Jul 2003
    Location
    UK
    Posts
    3,108
    Thanks
    1
    Thanked
    0 times in 0 posts
    Firefox has mouse gestures as well via it's extensions library

  10. #10
    Senior Member Kezzer's Avatar
    Join Date
    Sep 2003
    Posts
    4,863
    Thanks
    12
    Thanked
    5 times in 5 posts
    I thought it's impossible to uninstall IE? All it does is remove shortcuts iirc

  11. #11
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts
    Quote Originally Posted by KeZZeR
    I thought it's impossible to uninstall IE? All it does is remove shortcuts iirc
    You are indeed correct, it's integrated with Windows.

    Back in the 98 days, when there was uproar about IE's integration, MS said that windows 98 simply couldn't run without IE. Somebody did a bit of fiddling and proved them shamefully wrong by stripping out IE entirely, leaving windows 98, but without any IE features. The interface was, of course, much more like windows 95, but the kernel under the bonnet was still 98...

    /pub trivia.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  12. #12
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,026 times in 677 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS
    IE depends on a big ol' file called mshtml.dll, which does all the rendering duties. recent versions of Explorer depend on this file to work. 98lite pulled out the file & used the 95 version of explorer

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Which graphics card? (<£60)
    By ajbrun in forum Graphics Cards
    Replies: 22
    Last Post: 06-06-2004, 05:30 PM
  2. Replies: 14
    Last Post: 28-02-2004, 09:47 AM
  3. Help me! (SN41G2 + ati graphics)
    By GDad in forum PC Hardware and Components
    Replies: 6
    Last Post: 18-09-2003, 01:16 PM
  4. New graphics card...(Budget)
    By TomWilko in forum Graphics Cards
    Replies: 20
    Last Post: 08-09-2003, 05:14 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •