Home Malware Programs Browser Hijackers ‘M66.dnsqa.me’ Pop-Ups

‘M66.dnsqa.me’ Pop-Ups

Posted: February 2, 2016

M66.dnsqa.me is a website that may use exploits to force you to download threatening software that may disguise itself as a document or another, non-hostile file. Like other sub-domains of this website, M66.dnsqa.me may initiate its downloads automatically and use a browser-hijacking campaign that may force your Web browser to load its Web address. After loading M66.dnsqa.me, shut down your computer, reboot it with Safe Mode, and run anti-malware scans to remove all relevant threats until you have verification of completely disinfecting your PC.

M66.dnsqa.me: Take a Number for Trojans

M66.dnsqa.me is the latest iteration in a series of websites conducting threat campaigns, alongside clones such as M53.dnsqa.me and M51.dnsqa.me. These websites have no visible content, but, once loaded, may use scripts to trigger an attack. The nature of the exploits in use still is a subject of investigation, although similar threats tend to utilize Java, JavaScript, Flash, or built-in vulnerabilities that are most prolific in out-of-date browsers.

Some cases are verifiable of M66.dnsqa.me downloads requiring consent, although malware experts can't provide confirmation of that being the case with all of M66.dnsqa.me's attacks. Whether consent is needed or not, the file downloaded from M66.dnsqa.me (or its fellow domains) is threatening and compromises the security of your computer. Popular payloads from such attacks may include backdoor Trojans granting third parties remote access to your PC, spyware programs that collect account login information, or Trojan downloaders configurable for installing other threats.

M66.dnsqa.me's current payloads use files without any extension types, thereby preventing the user from identifying them as programs.

Scratching One Bad Domain Off the List

M66.dnsqa.me hijackings currently are most strongly tied to the Chrome and Firefox Web browsers, although attacks of a similar nature are a common risk to any browser. PC users who are seeing redirects to M66.dnsqa.me or pop-ups for it should reboot their computers. Selecting Safe Mode (the means of accessing which varies with your OS edition) will let you launch your operating system with a bare minimum of programs, after which your anti-malware software should have a chance to scan your computer. Disabling 'Advanced' browser features, like scripts, also offers a limited degree of protection from typical attacks.

Since M66.dnsqa.me is only one of a rotation of numerous, malign sites, similar precautions should be taken against all other sub-domains of Dnsqa.me. Recent M66.dnsqa.me hijackings also have been tied to at least one other threat: the DNS Unlocker adware, for Chrome. Malware experts remind all PC users to monitor their software downloads for potential bundles carrying browser hijackers, adware, and other browser-changing threats, all of which are detectable with the right security solutions. However, not all of these attacks have been tied to adware installations, and, as noted earlier, other browsers still may come under attack.

Loading...