New Web Attack Hijacks Your Clipboard

So what does this new Web attack do? It places a link (that is difficult to delete) to a Web site selling fake security software in your clipboard. The infection automatically flushes your clipboard any time you copy or cut text to it and replaces it with the bogus link.
What has security experts concerned is its potential to become widespread. The software has been found on both Macs and PCs and even targets users of alternative browsers such as Firefox. This new attack is particularly hard to protect yourself and defend against, especially considering the attack's proven ability to lurk in plain sight on legitimate Web sites.
Some users have reported success in thwarting the attack by simply killing Firefox from the task manager or rebooting but, as always, we recommend up-to-date security software; including virus protection and spyware protection. The truly paranoid can stop the attack before it happens by installing Flashblock, an add-on for Firefox that will prevent any Flash-based content from loading without your specific consent. [From: BBC]





Disney World Scammers Scored Four Years of Free Vacations
Rookie Cop Reportedly Berated, Called 'A Rat' For Arresting Off-Duty Officer
Walmart Ending Membership in Conservative Group
Stranger's Kiss Keeps 16-Year-Old From Committing Suicide
Apple CEO Tim Cook interview at D10: the liveblog
How I Went Bankrupt at 23
Can a New Guy Save Best Buy?
Rodents Run Amok at Upstate New York Walmart
Woman Claims Kangaroo Stalked Her for 2 Days, Then Attacked
Beyonce 60-Pound Weight Loss: Queen B Flaunts New Figure During Comeback Concert Series















Comments
27
Subscribe to commentsDennisAug 19th 2008 7:16PM
I found and deleted XP2008!
Its hiding in afile on windows explorer that starts with rh_-------something. Then, you can delete the entire program. Unfortunetly, I found it too late!
CAug 19th 2008 8:27PM
When I got this, I went to system retore and restored my computer to the previous day. It worked.
Paul T. KaylorAug 19th 2008 9:16PM
I recieved the same thing, only I'm not very computer savvy, and thought it was a message from the freindly computer people. I clicked on it and let it run a scan on my computer and found all these problems that needed fixing. I then paid to have it fix my computer properly. Then it happened again and again, and today I'm sitting here using my brand new IBM computer, because my other one is so screwed up now it won't do anything I want. Were lucky to have friends who are computer savvy.
fayAug 19th 2008 7:53PM
I have found this in 2 computers so far. first time I hadnt seen it before and it downloaded a bunch of viruses and spyware before I figured out what to do. beware using the restore some of these virus it downloads copy themselves to the restore folder. the only way to get rid of those is turn off restore and run your antivirus program. for what I had here. it downloads itself to your running antivirus program. and makes itself look like an update to the same. after it ran for several days on my freinds computer who had dsl by the way. he cut it off. it still managed to download some real nasties. he was looking up a medicine by the way. we had to reformat that computer because of all the files that were deleted. do a reinstall etc. 2nd time it hit my own computer with my roommate on it. so we shut it down right away till I got home to deal with it. first I rebooted in safe mode. f5 f8 or f10 depending on your computer. then delete the file it installs on the desktop. in my case it comes in as antivirus 2008 pro. wants you to buy but of course that button does nothing. go to add remove programs and try to uninstall your antivirus program. after that I went to start run and typed in regedit , then go to HKEY_current user open up and go to software. then look for YOUR antivirus program. you will find it has entered itself in a subdirectory of your antivirus program. delete the entire key.
you will want to reinstall your antivirus program I use avast home edition and reinstalled it from a dvd I copied it to for emergencies. it cleaned up the rest of the virus when I set it to run on reboot. please note. it may take more than one time running your adaware and antivirus programs to get rid of this thing and the viruses/adware it downloads. run them untill they report clean. if you catch it fast enough you CAN save your files and computer. normally you DONT edit the registry and microsoft will tell you that if you do so you invalidate your copy of windows. however this IS the fastest and safest way I have found to get rid of this. also please note I DID turn off the restore before I did the reboot to run avast. it nearly always finds wingen32 worm. or trojan and they DO copy to the restore files which means it keeps coming back. also we were using explorer and winxp pro on both infected computers. the 2nd site was one my roomate was looking up a problem for my car. so you can find it anywhere. and it comes in really fast. spybot DOES catch it and stop it but it DOES come in and appear to be an update to your antivirus program. best case KNOW when your computer is Doing the update. mine is like the first 8 seconds or so I am signed on. so if you get an update notification at a time NOT your regular time and are running spybot then DENY it.
Hope this helps.
csummers1968Aug 19th 2008 7:47PM
Hmmm, have a mac .... won't open exe files .... have come across this saying I had all these viruses on my hard drive and proceeded to show me a fake Windoze my computer folder with all kinds of stuff then proceeded to download an exe file . My Mac said " sh!!!!!t...dis is bullsh!t jack ......get da fnck outta here ya windoze piece of sh!t !!!!"
dallasAug 19th 2008 8:06PM
good god i am a new user (window vista premeium)last comp was legand486 with window3.1 never on line with it (D.O.S.officesystem)i am on line with new system now lot to learn finaly got wife into it email+picts is what finaly did it how much danger am i in?we are on dial up(slow but all we no)dont use my space only HI 5 and AOL no movies just email and AOL news and pepsi rebates stuff like that safe set is always on i dont surf much and wonder how much danger is there for limited users like us thanks for any info you might have I LIKE THIS SYSTEM only other comp was commedor 64 and vic20 besides the 486 i still have them all never had any virus and no nothing about them or the risk wife will freak out if we have problems it took 20years to get us online thank you
CathyAug 20th 2008 8:26AM
I got this when I purchased my new laptop; it was very hard to get rid of, but I finally downloaded Spybot SD and that worked great. It's also free, but donations are accepted. I tried a couple of other programs, but they either didn't find the virus or could not remove it.