• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Hacked Antivirus Site Delivers a Virus

Polaris573

Senior Moderator
Joined
Feb 26, 2005
Messages
4,268 (0.59/day)
Location
Little Rock, USA
Processor LGA 775 Intel Q9550 2.8 Ghz
Motherboard MSI P7N Diamond - 780i Chipset
Cooling Arctic Freezer
Memory 6GB G.Skill DDRII 800 4-4-3-5
Video Card(s) Sapphire HD 7850 2 GB PCI-E
Storage 1 TB Seagate 32MB Cache, 250 GB Seagate 16MB Cache
Display(s) Acer X203w
Case Coolermaster Centurion 5
Audio Device(s) Creative Sound Blaster X-Fi Xtreme Music
Power Supply OCZ StealthXStream 600 Watt
Software Windows 7 Ultimate x64
The Web site for Indian antivirus vendor AvSoft Technologies has been hacked and is being used to install malicious software on visitors' computers, security researchers said last week. The download section of AvSoft's S-cop Web site hosts the malicious code, according to Roger Thompson, chief research officer with security vendor AVG. "They let one of their pages get hit by an iFrame injection," he said. "It shows that anyone can be a victim. ... It's hard to protect Web servers properly." The technique used on the site has been seen in thousands of similar hacks over the past few months. The attackers open an invisible iFrame Window within the victim's browser, which redirects the client to another server. That server, in turn, launches attack code that attempts to install malicious software on the victim's computer. The malicious software is a variant of the Virut virus family. The iFrame pages are commonly used by Web developers to insert content into their Web pages, but because it is possible to create an invisible iFrame window, the technology is often misused by hackers as a way to silently redirect victims to malicious Web sites.

AvSoft, based in New Delhi, sells an antivirus product called SmartCOP and has sold a second antivirus product called Smartdog. The company, which is not well-known in the U.S., also specializes in recovering data lost due to virus attacks. The company could not be reached for comment Thursday afternoon.

That data recovery service could come in handy for some, as Virut is known as a "parasitic infector" virus that is extremely difficult to remove. "It infects all of your programs on your local hard drives, and then it starts hitting your network drives as well the first time you run," Thompson said.

Fortunately, the malware used to install Virut exploits only well-known bugs, meaning that users who are running antivirus software on fully patched systems will probably not be infected by the attack in its current state, security experts say.

Nobody knows how the malware got onto the Web site in the first place. News of the hack was reported on the Full Disclosure security discussion list on Thursday.

McAfee Security Research Manager Dave Marcus believes that the site was compromised by exploiting a Web programming error, most likely in the site's SQL or PHP code. Security experts say that criminals have written automated programs that scour the Web for these types of flaws and then automatically infect sites, making this an increasingly common problem.

View at TechPowerUp Main Site
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
24,311 (3.75/day)
Location
London,UK
System Name WorkInProgress
Processor AMD 7800X3D
Motherboard MSI X670E GAMING PLUS
Cooling Thermalright AM5 Contact Frame + Phantom Spirit 120SE
Memory 2x32GB G.Skill Trident Z5 NEO DDR5 6000 CL32
Video Card(s) Asus Dual Radeon™ RX 6700 XT OC Edition
Storage WD SN770 1TB (Boot)|1x WD SN850X 8TB (Gaming)| 2x2TB WD SN770| 2x2TB+2x4TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White) {1xCorsair ML120 Pro|5xML140 Pro}
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Seasonic Focus GX-850 80+ GOLD
Mouse Logitech G502 X
Keyboard Duckyshine Dead LED(s) III
Software Windows 11 Home
Benchmark Scores ლ(ಠ益ಠ)ლ
thats very smart - the hackers are going after the source instead of the individuals & in doing that instead of infecting 1 person who passes the virus/trojan on to one person at the time they've literally 'napalmed' the public. not just 1 but thousands.

1 - hackers | 0 - Av soft. |
 
Joined
Oct 2, 2005
Messages
375 (0.05/day)
Location
Istanbul/Turkey
System Name GS43VR 7RE
Processor Core i7 7700HQ
Motherboard MSI GS43VR 7RE
Cooling Stock
Memory 8 GB DDR4 2400 MHz
Video Card(s) GTX 1060
Storage Samsung 950 PRO
Display(s) 14" IPS
Case Metal
Audio Device(s) Realtek ALC 898
Power Supply Adapter
Mouse Rival 100
Keyboard SteelSeries
Software Windows 10 Version 1703
I don't want to think how they explain that to their customers :D...



ummmh....eghh.....our site......was hacked......:laugh:
 
Joined
Dec 10, 2007
Messages
7,185 (1.15/day)
Location
Adelaide Australia
System Name Becca 2
Processor AMD A10 4600m quad core @ 2.3 ghz
Motherboard dunno
Cooling Logitech alto connect
Memory 16 Gig ddr3 1600mhz
Video Card(s) Ati HD 7660G + & 7470M
Storage 1 TB
Audio Device(s) onboard crap
Software Windows 7 Home Premium 64 bit with sp1
Never used em so dont really concern me ill just stick with pc cillan thankyou.
 
M

moto666

Guest
I think No matter what you choose!
One time they will catch U!
To many viruses out there...
I'm using "Avast"
It's free, it has a small CPU usage, everyday updated and looks sweet:D
O.k.-o.k. I'm serious
It's really fine!
So I'm also happy whit it!
What ever you chose, just use one:D:D:D
 
Joined
Oct 2, 2005
Messages
375 (0.05/day)
Location
Istanbul/Turkey
System Name GS43VR 7RE
Processor Core i7 7700HQ
Motherboard MSI GS43VR 7RE
Cooling Stock
Memory 8 GB DDR4 2400 MHz
Video Card(s) GTX 1060
Storage Samsung 950 PRO
Display(s) 14" IPS
Case Metal
Audio Device(s) Realtek ALC 898
Power Supply Adapter
Mouse Rival 100
Keyboard SteelSeries
Software Windows 10 Version 1703
If u ask me the best is kaspersky internet security

but ATM i use eset smart security
 
M

moto666

Guest
Hmm..
Special I don't think there is a best "To rule them all"
But Kaspersky is good!
:)
 

ex_reven

New Member
Joined
Sep 4, 2006
Messages
5,217 (0.78/day)
thats very smart - the hackers are going after the source instead of the individuals & in doing that instead of infecting 1 person who passes the virus/trojan on to one person at the time they've literally 'napalmed' the public. not just 1 but thousands.

1 - hackers | 0 - Av soft. |

I think youve made a mistake there.
It should be:

Assholes - 1, Everyone else - 0
 
Joined
Dec 10, 2007
Messages
7,185 (1.15/day)
Location
Adelaide Australia
System Name Becca 2
Processor AMD A10 4600m quad core @ 2.3 ghz
Motherboard dunno
Cooling Logitech alto connect
Memory 16 Gig ddr3 1600mhz
Video Card(s) Ati HD 7660G + & 7470M
Storage 1 TB
Audio Device(s) onboard crap
Software Windows 7 Home Premium 64 bit with sp1
Exactly i hope if they find out who did it they major jail time.
 

WarEagleAU

Bird of Prey
Joined
Jul 9, 2006
Messages
10,812 (1.60/day)
Location
Gurley, AL
System Name Pandemic 2020
Processor AMD Ryzen 5 "Gen 2" 2600X
Motherboard AsRock X470 Killer Promontory
Cooling CoolerMaster 240 RGB Master Cooler (Newegg Eggxpert)
Memory 32 GB Geil EVO Portenza DDR4 3200 MHz
Video Card(s) ASUS Radeon RX 580 DirectX 12 DUAL-RX580-O8G 8GB 256-Bit GDDR5 HDCP Ready CrossFireX Support Video C
Storage WD 250 M.2, Corsair P500 M.2, OCZ Trion 500, WD Black 1TB, Assorted others.
Display(s) ASUS MG24UQ Gaming Monitor - 23.6" 4K UHD (3840x2160) , IPS, Adaptive Sync, DisplayWidget
Case Fractal Define R6 C
Audio Device(s) Realtek 5.1 Onboard
Power Supply Corsair RMX 850 Platinum PSU (Newegg Eggxpert)
Mouse Razer Death Adder
Keyboard Corsair K95 Mechanical & Corsair K65 Wired, Wireless, Bluetooth)
Software Windows 10 Pro x64
I find this extremely hillarious and extremely brilliant at the same time.
 
Joined
Jan 8, 2008
Messages
1,941 (0.31/day)
Location
Pleasant Prairie, WI
System Name File Server
Processor 2600k
Motherboard idk
Cooling H110
Memory 20gb of something
Video Card(s) onboard!
Storage 2x120 SSD, (5x8tb)+(3x4tb) = 35 TB Z1 pool
Display(s) couple 4k 32s
Case cooler master something i think
Audio Device(s) does anyone bother with anything but onboard?
Power Supply Whatever OCZ PC Powercooling became. 1200 modular setup
Mouse MX Master 2x
Keyboard G710
Software FreeNAS
I find this extremely hillarious and extremely brilliant at the same time.

+1, it takes some tough work to do this.

But in no way do I agree with it. I do think the people should get punished. I doubt they would get jail time but a huge fine.

I have no respect for hackers. They do incredible work but its all for terrible reasons. If they spent that time and focus on something positive, they could probably do work like none other.
 
Joined
Oct 7, 2006
Messages
1,338 (0.20/day)
Processor e8200 3.93mhz@1.264v
Motherboard P5E3 Pro
Cooling Scythe Infinity
Memory 4gb of G.Skill Ripjaw 6-7-7-18@1404 and 1.62v
Video Card(s) HIS 5770 v2 940/1275mhz stock volts
Storage 1TB Hitachi
Display(s) Acer 22" Widescreen LCD
Case Blue Cooler Master Centurion
Audio Device(s) Onboard audio :(, and Klipsch 5.1 Pro Media's
Power Supply 650 Watt BFG
Software Vista 64 Ultimate
LOL my brother in law called and asked for help on their computer Thursday because it was acting up... guess what virus scan was on it!
 
Joined
Dec 10, 2007
Messages
7,185 (1.15/day)
Location
Adelaide Australia
System Name Becca 2
Processor AMD A10 4600m quad core @ 2.3 ghz
Motherboard dunno
Cooling Logitech alto connect
Memory 16 Gig ddr3 1600mhz
Video Card(s) Ati HD 7660G + & 7470M
Storage 1 TB
Audio Device(s) onboard crap
Software Windows 7 Home Premium 64 bit with sp1
well im glad i havnt used avsoft recently.
 
Last edited:

ChillyMyst

New Member
Joined
Jan 20, 2008
Messages
551 (0.09/day)
If u ask me the best is kaspersky internet security

but ATM i use eset smart security

eset/nod32 is rated higher then kaspersky in all tests i have seen, kasper is on, but it uses more system resorces(ram/cpu) then esets nod32 and smart security.

i have nod32 version3, its nice but has some buggs still under 64bit windows at least(missing tray icon is annoing.)

but its VERY young still, so im not to upset, i will likely go back to nod32 2.7 till the kinks in 3.x are worked out, eather way its still the best AV on the market!!!
 
Top