Malware blocks access to Safer-Networking and other security sites

2009-01-25, 17:25
Sorry in advance if this is in the wrong forum - but I have recently been afflicted with a spyware/virus that launches pages from both IE and Firefox, and generally redirects you to pages that you were not trying to go to.

On top of all of this (as this was a new work laptop and I hadn't had the chance to put Spybot S&D - my favorite - on it yet), this bugger will prevent you from being able to access the safer-networking site, you can't even ping it. It completely blocks all internet traffic to this and other spyware programs' sites.

I finally was forced to put the IP and name into my HOSTS file, which allowed me to access the site to download Spybot and run it to *hopefully* clean my system.

For those who are not aware of the HOSTS file on Windows (I am sure that most on this forum are quite technically savvy, but I figured I would add this just in case), the file is normally located in:


It is a file called HOSTS (with no extension)

Open it with NOTEPAD and at the bottom (normally it should just have the entry for the localhost), you would enter onto a new line the IP for the safer-networking.org site and the name for the site (i.e. www.safer-networking.org) - the IP I have now is Once I did this, I was able to finally resolve and download Spybot to clean my computer.

In case anyone else runs into this problem, I hope this helps.


2009-01-25, 19:47
There are several infections that prevent users from seeking help.

Conficker/Banload/Downadup infection is the one in the news, everyone please make sure your computer is updated and patched. Specifically security update MS08-067 (http://www.microsoft.com/technet/security/bulletin/ms08-067.mspx).

Win32/Conficker.B (http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm:Win32/Conficker.B)


2009-01-26, 21:21
New guy on block. So this may be old news:

My wife works at Tufts University and their IT Security group advises a four day old virus DOWNADUP that blocks updates access to virus tools I assume such as Spybot . I have a bit more on it, but wanted to see if any awareness out there.


2009-01-27, 00:30
DOWNADUP/Conficker/Banload. Please see links in my post above. :)

It is not a four day old virus, F-Secure: Where is Downadup? (http://www.f-secure.com/weblog/archives/00001589.html)


2009-01-27, 02:23

2009-02-13, 12:44

- http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32/Conficker
"... Win32/Conficker is a worm that infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. Depending on the specific variant, it may also spread via removable drives and by exploiting weak passwords. It disables several important system services and security products and downloads arbitrary files. Microsoft strongly recommends that users apply the update referred to in Security Bulletin MS08-067* immediately. Microsoft also recommends that users ensure that their network passwords are strong to prevent this worm from spreading via weak administrator passwords..."
* http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx

Third party information on conficker
- http://isc.sans.org/diary.html?storyid=5860
Last Updated: 2009-04-11 18:15:39 UTC ...(Version: 9) - "(This will be updated as more information becomes public)... Removal Instructions, Removal Tools..." etc.

Conficker Eye Chart
> http://www.confickerworkinggroup.org/infection_test/cfeyechart.html

> http://www.secureworks.com/research/threats/downadup-removal/?threat=downadup-removal


2009-02-24, 18:22

- http://isc.sans.org/diary.html?storyid=5914
Last Updated: 2009-02-23 18:10:08 UTC - "Malware which comes with its own "hosts" file* to install in \system32\drivers\etc\hosts is pretty common. Usually, these changes are made with the intention to keep the infected system from updating its virus pattern files and OS patches - eg. by adding an entry that makes "update.microsoft.com" resolve to (localhost), and hence prevents the updater from connecting. A malware sample that we analyzed earlier -today- pulled a hosts file from txt<dot>kxwii<dot>com/ad.jpg. The file contains 200 or so domains that are reconfigured to point to ... but, surprisingly, not domains of commercial software. Rather, it looks like a turf war is in progress between malwares, and this particular species tries to null out the connections of the competition..."
* http://www.mvps.org/winhelp2002/hosts.htm