KatsBits Community

Game Editing => IMVU Creator Community => Topic started by: kat on October 19, 2010, 12:58:23 AM

Title: [imvu] Is IMVU spreading viruses & malware?
Post by: kat on October 19, 2010, 12:58:23 AM
IMPORTANT: only download IMVU from imvu.com (https://secure.imvu.com/next/download/), or from Google Play Store (https://play.google.com/store/apps/details?id=com.imvu.mobilecordova) or Apple Apps Store (https://itunes.apple.com/US/app/id919745844?mt=8).



Short answer "yes, IMVU is spreading viruses and malware".

Long answer is "no, it's not actually IMVU doing it".

IMVU isn't actually infecting your computer with a viruses, Google is. Actually Google isn't either but they're allowing certain individuals to post adverts into their Adwords and Adsense network that then get served into the advertising space services like IMVU make available to them (adverts that appear on product pages for example).
Quote
If the desktop app was downloaded from an official source the client will be free of viruses and other harmful malware. Only download or install IMVU from official sources (https://secure.imvu.com/next/download/).

The trouble is IMVU know this (they have been told about it several times by the community) but appear to think that infecting users computers with malware via their site is not an important enough of an issue to devote resources to the problem to get it fixed. And as GoogleAds generate a large amount of income for them given the size of the user base (10 or so million user visits per month generating page views into the tens of millions), they're not about to disable adverts across the site for the sake of a few damaged computers that have nothing to do with them.

Who's as risk from IMVU viruses?
The only people generally at risk of virus infection from IMVU are "Guest_" accounts because they are predominately exposed to outside, third-party advertising on IMVU. The only way to stop or block the display of harmful adverts (notwithstanding use of AdBlockers) is to buy an avatar name (https://www.imvu.com/promotions/name_registration/) or purchase one or more of the other premium upgrades/services (https://secure.imvu.com/store/index/).

What to do if an IMVU virus attacks
Depending on the attack, remember it's not specifically IMVU or Google doing this but the entity who published the advert, if this does happen use the "Ctrl+Alt+Del" shortcut to open Task Manager and find the entry for the browser being used and under attack, e.g. FireFox is listed as "firefox.exe", Google Chrome is "chrome.exe", Internet Explorer is "iexplore" or "Micosoft Edge" (note that Administrators Privileges may be needed to view the Task Manager), and then right-click selecting "End Task" from the options available.

Who is spreading viruses on IMVU?
The web sites in this instance spreading malware are www[.]stand-alone-guard[.]net and www1[.]macroguard18[.]in.

Fake infection report is actually just a clever bit of webpage javascript/CSS
(https://www.katsbits.com/imvu/virus/imvu-virus-infection-1.jpg)

IMVU virus/malware infection trying to coerce the user to install itself
(https://www.katsbits.com/imvu/virus/imvu-virus-infection-2.jpg)

Cancelling 'Security Analysis' installer still leaves the 'report' visible
(https://www.katsbits.com/imvu/virus/imvu-virus-infection-3.jpg)

Cancelling shows the supposed (fake) infected files
(https://www.katsbits.com/imvu/virus/imvu-virus-infection-4.jpg)

Trying to close the window, virus/malware trying to re-download and install
(https://www.katsbits.com/imvu/virus/imvu-virus-infection-5.jpg)
Title: Re: [imvu] Is IMVU spreading viruses & malware?
Post by: kat on October 28, 2010, 12:19:59 AM
A couple of other URL/IP addresses hijacking (these are not active links to the sites but 'flat' text)