-
1. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Mar 24, 2014 2:59 PM (in response to whjco)install_flashplayer_12_x32_64_msaa_aax_latest.exe.
is nothing that comes from here
http://download.macromedia.com/pub/flashplayer/current/support/install_flash_player_ax.exe
and
http://download.macromedia.com/pub/flashplayer/current/support/install_flash_player.exe
are the ONLY legitimate files for Flash Player FULL installers
But, NOTHING with "latest.exe" would be legit.
Do a "clean install" on any machine you believe is out of date. http://forums.adobe.com/message/4041846
Also look into TDSSKiller from Kaspersky to remove adware.
-
2. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 25, 2014 11:27 AM (in response to whjco)I downloaded and ran Kaspersky's TDSSKiller. It's not finding anything.
Any suggestions as to what to try next?
Thanks so much for your help!
Bill J.
-
3. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Mar 25, 2014 12:31 PM (in response to whjco)I've read about a router hack that redirects to the "update" page"
http://hackersnewsbulletin.com/2014/03/hackers-hacked-300000-wireless-routers-check-now.ht ml
It may or may not have affected you.
Stick to those links I provided.
They're your best bet.
-
4. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 25, 2014 12:57 PM (in response to Mike M)Mike,
Many thanks. I’ve downloaded and installed both versions of Adobe Flash as we’re using Explorer, Chrome and Firefox. The Kaspersky didn’t find anything, Malwarebytes didn’t find anything of any substance nor did our AVG Business AV software.
I ran the installation of both versions of Flash and it didn’t solve the problem
Whatever this thing is it’s propagating through the entire network domain and is now on all workstations in the domain. Not good stuff!
Bill Johnson
-
5. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 25, 2014 1:00 PM (in response to Mike M)Mike,
The router hack might be the problem. It would explain why it’s showing up in the whole network. I’ll look into that next.
Thanks!
Bill J.
-
6. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Lars123 Mar 25, 2014 1:50 PM (in response to whjco)Hi Bill,
I have the same problem, the adobe (malware)update comes up on internet explorer and firefox. I tried TDSSkiller but it didn't work.
I don't think its my router, because im on another network now and i still have te problem.
Lars D.
-
7. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 25, 2014 1:56 PM (in response to Lars123)Lars,
Thanks. I’m running in circles trying to get rid of this problem. Still haven’t had any luck.
Bill J.
-
10. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Mar 25, 2014 2:28 PM (in response to Lars123)What is the address in the bar when you see that?
Because that second shot shows a version (12.0.3.77) that doesn't exist.
-
12. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Mar 25, 2014 4:05 PM (in response to Lars123)It's fake.
-
13. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Madman45 Mar 25, 2014 4:47 PM (in response to Mike M)It's happening to mine now. Firefox seems okay for now though.
-
14. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 25, 2014 5:54 PM (in response to whjco)The router hack still seems to be the best explanation. However, does this mean that the redirect that could be in the router has caused the connected workstations to download malicious software? None of my security software is showing anything so I've ordered a replacement Cisco router and will see if that helps the problem.
-
15. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Chubb dog Mar 25, 2014 7:03 PM (in response to Mike M)I have the same problem, tried uninstalling flash, any remnants afterwards, deleted personal settings in internet exploxer and reset, ran adware, malware and hitman. Nothing found. Virus is still there. Can change internet search option in control panel i.e. from google to bing and eventually shows up again. After two days of searching and trying different virus and malware removal programs I have backed up my data an am now trying an image restore from a different date. Anyone find another answer yet?
-
16. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Lars123 Mar 26, 2014 1:20 AM (in response to Chubb dog)yesterday i tried to remove it in save mode with malwarebytes, but that didn't work. Then i restored my data from a different date, that also didn't work. I have no idea how to remove it...
-
17. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 26, 2014 4:48 AM (in response to Lars123)Lars,
It appears that the redirect may be coming from malicious code that’s been put into the router. Are you by chance using a Linksys or DLink router?
I’m going to go over later this morning and remove our Linksys E2500 router from service and put one of our spare Cradlepoint routers (we use them in charter buses for WIFI access) as a temporary measure and see if this fixes the problem. I’ve done repeated scans of the computers that are popping up the bogus Adobe Flash message and am finding nothing so either the redirect is occurring in the router itself or this is new malware whose signature is not yet being recognized.
I’m feeling pretty strongly that the problem is malicious code in the router. In the meantime, we’re having all the passwords changed via phone to any online sites, accounts, etc.
I’ll let you know what happens with the temporary replacement router. The new Cisco I ordered should be here tomorrow.
Bill J.
-
18. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 26, 2014 11:26 AM (in response to whjco)Okay folks, here's the latest. Thanks to Mike M's post above I've been able to do some additional research and have come to the conclusion that our Linksys E2500 router has been hacked. I pulled it out of service and set up a router from a different manufacturer and we're now able to access the internet.
However, the redirects from the infected router had installed some additional settings in the browsers themselves, so I had to do a complete browser reset and that took care of the problem. To do this in Internet Explorer, I clicked on Internet Options/Advanced Tab and then click on the Reset link at the bottom and also reset all personal settings. In Google Chrome, I've had to go to Settings, click on Show Advanced Settings at the bottom, then click on Reset Browser Settings in the link at the very bottom.
So far, we've been back up and running without any problems.
-
19. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
trollwv Mar 26, 2014 2:38 PM (in response to whjco)Bill, one of my employee's downloaded this malware and we have a network, but only this one computer is affected. The computer's OS is Windows 7 w/IE 11 and the network is using Linksys E4200 router for intenet access. I have noticed that only .com's seem to be affected from the computers browser and that I can acess the internet through another programs or bring up a website with .net only once. None of our scans(4) picked it up either and we reran them through safe mode with no success. We even tried a web base scan with no luck picking it up. I did find something odd when I was able to acess a .net company in IE and tried to go another wesite the Adobe Flash Player malware reappeard and again asked to be downloaded. When I cancel that proces and went to the tools icon and went to security and Delete Browsing History and checked all boxes and ran it. Out of the 4 progams we've run Microsoft Security Essentials was the only program to picked up the malware and showed it as BackDoor:Win32\Simda.AT and when MSE removed it. We rebooted but it's still there. once its downloaded now the job of refinding and removing it, so if you or anyone else has something to remove it completly please let me know.
-
20. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 26, 2014 3:11 PM (in response to whjco)19.trollwv, the only way I could get rid of it was to go into the browser settings and do a complete reset on the browser. Remember, your Linksys router could have had malicious code installed in it that will just keep reloading it into your browser. I don't think that Linksys has a firmware update to fix this problem yet. I pulled our Linksys out of service and used a Cradlepoint router that we already had on hand for temporary internet access until our Cisco router arrives.
Another thing, if you have remote management turned on in your Linksys router, turn it off as port 8080 seems to be one of the ways that they're placing the malicious code in the router.
-
21. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
trollwv Mar 27, 2014 5:31 AM (in response to whjco)20.whjco, Thanks for the update. I don't have the remote management enabled on my router, and I tried the complete reset with the browser with no success. I will give the replacement router a try next and will give it a go once more.
-
22. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Jerrion Mar 27, 2014 7:50 AM (in response to trollwv)I have been having this same issue. It started a few days ago. I normally use a windows machine but have been using a mac (osx 10.9) for development lately. The mac is now having this issue. The PC is fine. The PC is on a hardwired network (not using a linksys) but the mac is on a wireless network that uses a linksys e3000. At first I thought it was a chrome only issue and resetting the browser cookies/settings would fix the issue. Today I went to load up a site in safari and it did the same redirect. I am stumped. I don't have admin rights so I cant check the router myself. Is there any way to test to see if the router is infected? Something I can take to our IT guy?
PS another guy in the office had the same issue and he was running fedora Linux. He got frustrated and switched to another machine (desktop) that is hardwired.
Thanks
-J
-
23. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
whjco Mar 27, 2014 7:58 AM (in response to whjco)You may want to contact support for the manufacturer of your router to see if there's any way to check for malicious code or the procedure to wipe and reload the router. In our infected Linksys E2500 router we had already installed the latest firmware version. I downloaded and reinstalled the latest firmware but it didn't seem to help.
-
24. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Jerrion Mar 27, 2014 8:04 AM (in response to whjco)Thanks for the reply. Just another note to further describe the problem. It seems to happen randomly once the browser info is cleared. It does not happen on the same website every time. The first time I noticed the issue was with bestbuy.com. After that it was google.com. Today its happening with reddit.com but not bestbuy/google. I have not been able to replicate it on a windows 8.1 surface tablet on chrome. If i clear the browser info the problem goes away again for a bit.
Thanks
-J
Message was edited by: Jerrion *spelling
-
25. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
tahoeje Mar 27, 2014 8:56 AM (in response to whjco)Resetting the E2500 to factory defaults corrected the problem, at least temporarily. Time will tell if the reset is a permanent fix.
I agree with the others who have posted on this thread. No malware of any kind is found on the machines that redirect to the SCAM Adobe flash error message screens. I have contacted CISCO and have filed a report on our finding through today and have asked they get involved to find the cause, source and cure for this issue. I would expect a new firmware release will be announced soon for the E2500 and any other CISCO router products that have been compromised. I would encourage all install the firmware when it becomes available.
-
26. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
trollwv Mar 27, 2014 9:57 AM (in response to whjco)whjco, Yes, its as you said. My Linksys/Cisco E4200 router was the problem. I didn't replace it, just Disabled the Remote Management Access & save and then under Security turned on Filter Anonymous Internet Requests and save. Then rebooted the router the issue stoped. Linksys called this The Moon malware it apparently bypasses authentication on the router by logging in without actually knowing the admin credentials. Once infected the router starts flooding the network with ports 80 and 8080 outbound traffic. A firmware update is said to becoming out soon. Thanks again for the insight.
-
27. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
peakbaggerdave Mar 28, 2014 8:07 AM (in response to trollwv)I did the same as trollwv yesterday for my E4200, and so far no re-appearance ... this might also explain my significant increase in bandwidth usage for the past several months; I thought it was just Netflix.
-
28. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
tahoeje Mar 28, 2014 8:16 AM (in response to peakbaggerdave)Current research suggests Linksys (Cisco) became aware of this threat a little over a year ago. Most people trying to discover the cause and cure would be searching for Adobe Flash issues, not searching for the "moon". We are currently exploring a secondary issue with the malware. We have 4 of the E2500 on the bench that were compromised, and none of them will take a firmware update. Failures consistantly occur at 18%. No comments back yet from Cisco.
-
29. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
merrifie Mar 28, 2014 10:54 AM (in response to whjco)In my experience, Malwarebytes reported finding Trojan.Happili within install_flashplayer_12_x32_64_msaa_aax_latest.exe. It seemed a bit suspicious from the get go (very un-Chrome like behavior to hijack the start page with an Adobe Flash Install page). This was a redirect of http://www.google.com but not https://www.google.com.
Changing my router settings to disable Remote Management solved the persistent redirct problem. My security settings already included Filter Anonymous Internet Requests.
Very glad to have found this page. Thankful for everyone's contribution.
-
30. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
scharique Apr 4, 2014 1:08 PM (in response to merrifie)I experienced the very same issue being discussed here last night via all browers. I have a Cisco/LinkSys E3000, there is quite a bit documented on this 'Moon' worm from SANS but very little from Cisco directly. Disabling remote management on the router has done the trick but i see that only as a temporary workaround to disable the hacking/ridirecting via the HNAP, the real fix would be firmware update and I can't find any reference on that from the horse's mouth.
-
31. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
k@fakefake Apr 15, 2014 1:40 AM (in response to scharique)Got this problem recently too.
Can anyone help solving this issue as it is very annoying that everytime I use Mac safari or Firefox, then it will redirect to the link and download automatically:
install_flashplayer_12_x32_64_msaa_aax_latest.exe
-
32. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Apr 15, 2014 1:44 AM (in response to k@fakefake)http://hackersnewsbulletin.com/2014/03/hackers-hacked-300000-wireless-routers-check-now.ht ml
It's a hardware problem. Adobe can't fix that.
-
33. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
k@fakefake Apr 15, 2014 1:51 AM (in response to Mike M)Thanks Mike M for the explaination in the webiste.
wondering is there anything we can do to get rid of the problem?
-
34. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M Apr 15, 2014 5:08 AM (in response to k@fakefake)If the router can be "flashed" (erased and rewritten) then have that done (your ISP may be able to do it). If not, it has to be replaced.
-
35. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Kevin2735 Apr 18, 2014 2:14 PM (in response to whjco)I have a Cisco E3000 Wireless N Router. I was having the issue accross OSX and Windows. This thread was a big help, but when I tried to get the latest firmware from Cisco I found the download link was no lnger present. I chatted with their support and obtained the following info if it helps anyone:
"Linksys is aware of the malware called “The Moon” that has affected select older Linksys E-Series routers and select older Wireless-N access points and routers. The exploit to bypass the admin authentication used by the worm only works when the Remote Management Access feature is enabled. Linksys ships these products with the Remote Management Access feature turned off by default."
" If you have not enabled the Remote Management Access feature of the router, you are not susceptible to this specific malware. If you have enabled the Remote Management Access feature, we can prevent further vulnerability to your network by disabling the Remote Management Access feature and rebooting your router to remove the installed malware. Linksys will be working on the affected products with a firmware fix that is planned to be posted on our website in the coming weeks."
"What we can do to fix this issue is to make sure that the router's security settings is enabled and the remote management is disabled."
"Ensure that the Filter Anonymous Internet Requests on the Security Page is enabled."
"The next step would disconnect us from the session. We need to reboot the router to clear the cache."
"According to the system, your product is already outside the complimentary assisted support period. I’d just like to inform you that we normally charge a fee for supporting this type of issue,
but since we’re seeing a potential hardware problem with the product, we’ll be extending complimentary support just this one time."
"We also need to upgrade the Firmware. However, the Firmware for this router is no longer available for download. Disabling the remote management on your router and securing it would help fix the issue."
I did find the latest firmware for the E3000 here: http://www.userdrivers.com/LAN-Network-Adapter/Linksys-E3000-Wireless-N-Router-Firmware-Up date-1-0-04-build-6/download/
-
36. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
tahoeje Apr 18, 2014 2:34 PM (in response to Kevin2735)Kevin,
Although Cisco will not admit it, there is an issue with this a two other of their devices. Thier blog that they sent you is a work around. If you need remote access, I would suggest acquiring another router. The Netgear N750 would be my suggestion. Solid engineering and support and under $100 if you shop around.
John
-
37. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
tankr32 May 3, 2014 10:08 PM (in response to whjco)Hey i am currently experiencing this problem at work. we have a Cisco router there.I made the mistake of getting my laptop (WIN 8.1) plugged into this network and then my laptop was experiencing the same thing. My questions are 1. is this transferable i.e. if i take my laptop home to a Netgear router will this infect my home network. 2. has there been a firmware update for this. 3. any more news on this?
-
38. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
Mike M May 4, 2014 12:51 AM (in response to tankr32)tankr32 wrote:
1. is this transferable i.e. if i take my laptop home to a Netgear router will this infect my home network.
Being as it's a router hack, it isn't even transferable TO the laptop. It's like a detour on a street. As long as you're on THAT street, it doesn't matter what car you drive, you'll still have to take that detour. but if you take a different street, you don't. It isn't in the car.
2. has there been a firmware update for this.
Not from Adobe, because Adobe doesn't make routers or firmware. Some routers (varies by make and model) can be "flashed" and reloaded like a cell phone.
3. any more news on this?
The link I posted is the latest I've read on it.
-
39. Re: Current Version of Adobe Flash Player is outdated! Is this a virus or malware?
crmont May 6, 2014 12:47 AM (in response to whjco)I figured out the problem. The router hack simply changes the DNS server to a DNS hosting service (severel.com). In my case a password hack could get downloaded. The malicious DNS server numbers in question for my issue were; 199.182.166.168 and 199.182.166.169 After you reset or flash your router firmware, make sure and install the correct DNS servers for your ISP.. Also make sure you disable "remote management". My router is a linksys E3000. Linksys has never updated the bios for this router.
A second option is to simply install the correct DNS server addresses for your ISP in the routers setup page.



