Flagged by IDS and Google Safebrowsing...

See: http://zulu.zscaler.com/submission/show/d211b8e8b134af6d0063117310540fff-1340628268
See: https://www.virustotal.com/url/1f12610c7e7065157c526a82ac45de257a33731b222d7579c697532e9f2d2437/analysis/1340628338/
See: http://www.google.com/safebrowsing/diagnostic?site=http://queerprocessdeliverermicrosoft.in/e8b3b3ddeb3a6799/setup.exe
See: http://urlquery.net/report.php?id=75036 IDS alert: ET EXPLOIT BMP with invalid bfOffBits
detection: http://minotauranalysis.com/search.aspx?q=e5b54e9d9a45c9b61fc5f847bdb66062
I get a 11004 [11004] Valid name, no data record (check DNS setup) there.
Has this malware been closed down?

polonus

I was playing a game during my lunch break on a site that I have never had a problem with. I like to play “escape the room” games at escapegames24.com. On one of the games, I clicked on the “play game” link and my Chrome browser went bananas. It appeared that two things happened at the same time. First AVast popped up and said:

avast! saved your computer from crashing

You just dodged a bullet

You may be wondering how you ended up with a virus, especially if you were visiting a ‘normal’ site. The latest research from the avast! Virus Lab shows that more than 80% of malware (viruses, spyware, and the like) spreads through legitimate websites, with only 1% coming from suspicious or ‘dodgy’ sites.
Good thing avast! had your back.

And in the browser window it said something about Windows Security and a bunch of text, some in RED, began scrolling down the browser window. When I clicked on the X to close the tab, it asked if I was sure I wanted to do that and then something about losing everything on my hard drive and crashing my computer. I said yes to close the tab since AVast had already halted whatever that was.

I have not turned off or restarted my computer. THAT was SCARY!

What is this thing???

I forgot this part:

Infection Details
URL: http://queerprocessrisksutility.in/favic
Process: C:\Documents and Settings\Director\Local…
Infection: URL:Mal

Some information above has been truncated. The url was something like: http://queerprocessrisksutility.in/favicon but I don’t remember the whole thing. I just remember seeing the word “favicon” close to the end.

Hi marianlibrarian,

What you describe here is a luckt escape from morst likely a scareware Fake AV. Through insecure scripts etc. malcreants mass infect legit sites through website software vulnerabilities (not fully updated and patched), these infested legit sites on their turn infest visitors that go there and also have vulberavle computers.
First issue to be protected is to always update your OS and third party software. Go here and check: http://secunia.com/vulnerability_scanning/online/
Webmasters also have a responsibility towards their visitors by keeping their website secure,

polonus

:slight_smile: Scareware - That’s a new one on me. It sure did work.

I will check out the link you provided. Thanks for your reply! Have a great day.

Edit:
I did a google search right after it happened and only one link appeared:

http://urlquery.net/report.php?id=77821

Then about an hour later there were more links, including this one:

http://urlquery.net/report.php?id=77868

They seem to support your Scareware theory. ~ :slight_smile:

Hi marianlibrarian,

Ever heard of ransomware? In this case, the malware installs itself, usually by the same means as above, and locks up your computer in worst case, and then requires payment to unlock it. It’s going around. That is why Secunia is needed more than ever. The online version is sufficient, and will help you stay ahead of the malware curve.