Subscribe to Windows IT Pro
October 15, 2011 09:22 AM

How to Avoid Browser Hijack Viruses

Windows IT Pro
InstantDoc ID #140563
Rating: (0)
I recently watched a local TV news report about the latest crop of browser hijack viruses, which are disguised as antivirus programs. For example, in the “Antivirus 2009” attack (Figure 1), a security alert pops up telling you that it’s running a scan, after which it gives you the bad news that your computer is infected with viruses and other malware. Figure 2 shows a more generic “Message from web page” attack, which notifies you that there are signs of viruses and malware on your computer. Some of these disguised programs try to get you to purchase a program that will remove the malware, whereas others tell you that you can download a free removal program. Either way, if you try to download the program, your machine will become infected with a single click. (Here is the TV news report about the browser hijack viruses.)

Figure 1: “Antivirus 2009” attack
Figure 1: “Antivirus 2009” attack


Bennett-WIN164Fig 2-sm_0
Figure 2: Generic “Message from web page” attack


To thwart these attacks, the TV news report advises you to “close out the web browser immediately.” Anyone who has experienced this type of attack knows that you can’t close the browser by any normal means. The only apparent exit strategy is to click something on the hijacked screen, such as a Cancel, Exit, or No Thanks button. When clicked, the machine becomes infected.

There are countless anti-malware products and how-to articles on the web that provide complicated disinfection procedures. However, there are two best-practice lines of defense as well as other solutions, including one easy procedure that I use.

On newer Windows OSs (e.g., Windows 7, Windows Vista), one best practice is to keep User Access Control (UAC) enabled. When it’s enabled, an attack program will trigger a UAC prompt because the program is trying to perform an operation that requires Administrator-level permissions. The user must be savvy enough to press the No button when presented with the UAC dialog box.

The other best practice is to not set the user account type to Administrator. With that said, some legacy line of business (LOB) software won’t run unless the user has administrative privileges. Similarly, some nonlegacy utilities require administrative privileges, such as backup software that uses Microsoft Volume Shadow Copy Service (VSS) snapshots.

In addition to these two best practices, there are other safe-browsing solutions, including antivirus software that lets you browse in “sandbox” sessions. (In these sessions, you lose OS functionality such as cut and paste.) Alternatively, you can do your browsing on a virtual machine (VM) that’s isolated from the Windows OS.

I use a technique that doesn’t require additional software and lets you keep the user account type set to Administrator. Suppose that you receive a warning message like that in Figure 2 on a computer running Windows 7. First and foremost, don’t click anything in the open browser window or open a new browser session. Instead, follow these steps:

1.     Check the program icons in the taskbar (or tap the Tab key while holding down Alt) to see if there are additional bogus dialog boxes or forms being spawned by the initial unwanted browser hijack program. Figure 3 shows an additional Windows form that was an offspring of the “Message from web page” attack. You can’t see this form running on the main screen because it’s hidden underneath the Message from webpage dialog box.
Bennett-WIN164Fig 3-sm_0
Figure 3: Taskbar icon for the “Message from web page” attack

2.     Click Ctrl+Alt+Delete to bring up Windows Task Manager.

3.     On the Applications tab, find the Internet Explore (IE) application that reflects the URL you can see in the infected IE window’s address bar. Right-click the offending IE application and select Go To Process. You’ll be taken directly to the instance of IE that’s under attack in the Processes tab.

4.     Click the End Process button.

Related Content:

ARTICLE TOOLS

Comments
  • bretabennett
    5 months ago
    Dec 14, 2011

    Just a test comment.

  • bretabennett
    5 months ago
    Dec 02, 2011

    Typo: 2011 was 2001.

  • bretabennett
    5 months ago
    Dec 02, 2011

    Opps! I forgot to mention in my last 11/29/2001 post that after the Alt_F4 keystroke, , the test environment was infected with JS:Downloader-AWN [Trj]. That's trojan downloader.

  • bretabennett
    6 months ago
    Nov 29, 2011

    I just added a screen shot of yesterday's "Congratulations! You just won a free . . ." browser hijack back at http://www.bretabennett.com/pubstuff/utils.htm . Look for "Additional Browser Hijack Sample Pictures" and the "Click Here" button.

    Btw, I setup a test environment and tested the "Alt_F4" theory against this malware using the Chrome web browser. Unfortunately, Alt_F4 did not terminate/kill the browser process. Apparently the hijack was able to use the Alt_F4 keystroke as an Enter keystroke and loaded the next malware web page. So to date, only the kernel level Alt_Ctl_Del keystroke combination seems to elude the hijack attacks.

  • bretabennett
    6 months ago
    Nov 28, 2011

    Today I was using the Chrome browser. I already had about six tabbed sessions going. I opened up another empty tab and mis-typed something in the browser's url field. It brought up one of those "Free iPad" hijacks. I used the Ctl_Alt_Del procedure, but with Chrome, it killed all the tabbed sessions at once. Also - If you right click on Chrome's top boarder, you can select it's proprietary "Task Manager". However, that did not work because the hijack in progress does not let you click on anything in the browser session, except the hijack dialog box.

    I then took another look at my IE9 setup to see why with IE9, I can kill a specific tab process in Windows' Task Manager. In IE's Internet Options > Advanced, I have enabled Security > "Enable memory protection to help mitigate online attacks". By default, that is NOT enabled (big mistake by Microsoft imho on that one). Btw, if you disabled DEP on you Windows OS, it will be greyed out. See http://www.vistax64.com/tutorials/120778-dep-enable-disable.html

    Later . . .

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.