Author Topic: [imvu] Is IMVU spreading viruses & malware?  (Read 7015 times)

0 Members and 1 Guest are viewing this topic.

Offline kat

  • Administrator
  • Hero Member
  • *
  • Posts: 1665
[imvu] Is IMVU spreading viruses & malware?
« on: October 19, 2010, 12:58:23 AM »
Short answer "yes, IMVU is spreading viruses and malware".

Long answer is "no, it's not actually IMVU doing it".

IMVU isn't actually infecting your computer with a viruses, Google is. Actually Google isn't either but they're allowing certain individuals to post adverts into their Adwords and Adsense network that then get served into the advertising space services like IMVU make available to them. The trouble is, IMVU know this (and have been told about it several times) but appear to  think that infecting your computer with malware via their site is not an important enough of an issue to devote resources to the problem to get it fixed. And as GoogleAds generate a large amount of income for them, they're not about to disable adverts across the site for the sake of a few damaged computers that have nothing to do with them.

The only people at risk of virus infection from IMVU are "Guest_" accounts, buying your name or purchasing one of the other 'premium' services means you don't see general advertising. If this does happen to you then you're going to need to use "Ctrl+Alt+Del" to open Task Manager and the right-click in the "iexplorer" entry and "End Task". Incidentally the web sites in this instance spreading this malware are www[.]stand-alone-guard[.]net and www1[.]macroguard18[.]in.

Fake infection report is actually just a clever bit of webpage javascript/CSS


IMVU virus/malware infection trying to coerce the user to install itself


Cancelling 'Security Analysis' installer still leaves the 'report' visible


Cancelling shows the supposed (fake) infected files


Trying to close the window, virus/malware trying to re-download and install

Offline kat

  • Administrator
  • Hero Member
  • *
  • Posts: 1665
Re: [imvu] Is IMVU spreading viruses & malware?
« Reply #1 on: October 28, 2010, 12:19:59 AM »
A couple of other URL/IP addresses hijacking (these are not active links to the sites but 'flat' text)
  • www2.profi-protection3.in
  • www2.scan-your-pc9.in
  • www1.main-avprotection31.in
  • http://178.162.147.21/
  • www2.besttools-of-security.com
  • www2.networkuzbaseguard.com
  • www1.securearitily.in
  • www2.secureaw.com
  • http://178.162.133.214/ythg/ythg/

 


Facebook Comments