Author Topic: Beware fake IE 7 downloads  (Read 5744 times)

0 Members and 1 Guest are viewing this topic.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Beware fake IE 7 downloads
« on: March 29, 2007, 11:24:00 PM »
Quote
There is spam out there that tries to get you to download IE 7. It’s fake, of course. When you click on the image, you are then offered to download a trojan (Sunbelt Sandbox analysis here, VirusTotal results here). Antivirus coverage is mediocre.

http://sunbeltblog.blogspot.com/2007/03/beware-fake-ie-7-downloads.html
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Beware fake IE 7 downloads
« Reply #1 on: March 29, 2007, 11:35:37 PM »
Thanks for the heads up Frank.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline BJ_GeOrgE

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 350
  • prevention is better than cure
Re: Beware fake IE 7 downloads
« Reply #2 on: March 29, 2007, 11:44:43 PM »
Quote
There is spam out there that tries to get you to download IE 7. It’s fake, of course. When you click on the image, you are then offered to download a trojan (Sunbelt Sandbox analysis here, VirusTotal results here). Antivirus coverage is mediocre.

http://sunbeltblog.blogspot.com/2007/03/beware-fake-ie-7-downloads.html

...thnx for the info..i've downloaded IE 7 but the genuine fortunately!!!
OS:Windows 7 Professional 64-bit SP1
Antivirus: Avast Free v8.0.1497/Firewall: Windows Firewall/On Demand: Malwarebytes Free Edition/Other tools: CCleaner

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Beware fake IE 7 downloads
« Reply #3 on: March 29, 2007, 11:50:22 PM »
Didn't think you guys would fall for it, but maybe avast! will want to get a sample from somewhere.



     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
Re: Beware fake IE 7 downloads
« Reply #4 on: March 30, 2007, 04:09:43 AM »
Please, improve detection...
The best things in life are free.

Offline BJ_GeOrgE

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 350
  • prevention is better than cure
Re: Beware fake IE 7 downloads
« Reply #5 on: March 30, 2007, 07:51:34 AM »
Didn't think you guys would fall for it, but maybe avast! will want to get a sample from somewhere.





maybe its a false positive..many high rated AV(bitdefender,NOD32,MCafee) dont detect it..if its not a false positive..then we have a major lack of detection...  8)
OS:Windows 7 Professional 64-bit SP1
Antivirus: Avast Free v8.0.1497/Firewall: Windows Firewall/On Demand: Malwarebytes Free Edition/Other tools: CCleaner

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
Re: Beware fake IE 7 downloads
« Reply #6 on: March 30, 2007, 08:10:11 AM »
BJ_GeOrgE,

That does not put you in the easy chair, my friend, saying "Oh this must be a FP", because certain malcreants will test their new malware against detection by the major AV vendors, and go well beyond their radar. And that could be just what you have here. That is why the big AV names leave you with a vulnerability window that stands just a trifle more than ajar where new 0-days are concerned. We call that the vulnerability window. In a later stadium all catch up. But not at first.
That is why most of us here use a combination of one standard resident AV solution (Avast) and some non-resident scanning (ClamWin, f-prot, DrWeb's, McAfee's stinger) to get protection against the broadest range of threats. We combine that with other security measures and a bit of good sense and attitude, and that seems to do the job. But what FwF has done here, should be performed on every (major) download. And if virustotal alerts thrice, I would not like to have it on my 'puter for the life of me, because I simply would not trust it. Once bitten twice shy, ye know. And that is the attitude.

polonus
« Last Edit: March 30, 2007, 08:14:52 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline BJ_GeOrgE

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 350
  • prevention is better than cure
Re: Beware fake IE 7 downloads
« Reply #7 on: March 30, 2007, 01:20:10 PM »
BJ_GeOrgE,

That does not put you in the easy chair, my friend, saying "Oh this must be a FP", because certain malcreants will test their new malware against detection by the major AV vendors, and go well beyond their radar. And that could be just what you have here. That is why the big AV names leave you with a vulnerability window that stands just a trifle more than ajar where new 0-days are concerned. We call that the vulnerability window. In a later stadium all catch up. But not at first.
That is why most of us here use a combination of one standard resident AV solution (Avast) and some non-resident scanning (ClamWin, f-prot, DrWeb's, McAfee's stinger) to get protection against the broadest range of threats. We combine that with other security measures and a bit of good sense and attitude, and that seems to do the job. But what FwF has done here, should be performed on every (major) download. And if virustotal alerts thrice, I would not like to have it on my 'puter for the life of me, because I simply would not trust it. Once bitten twice shy, ye know. And that is the attitude.

polonus

ure right polonus..sry but i'm relaxed coz i think i have the right attitude..i mean i know how to avoid viruses from getting in my pc..i download only fron trusted sites and i know that the danger still exists..but i like living risky..  8)
OS:Windows 7 Professional 64-bit SP1
Antivirus: Avast Free v8.0.1497/Firewall: Windows Firewall/On Demand: Malwarebytes Free Edition/Other tools: CCleaner