Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

It's the frakkin' Black Plague!

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 06-Sep-2008, 03:21 PM
neutralhills's Avatar
neutralhills neutralhills is offline
Valued Member
Posts: 336
Points: 1814 neutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 points
Power: 23
None
Join Date: 23 Feb 2008
Location: Kirriemuir AB Canada
Age: 40
Certifications: Lots.
WIP: Upgrading MS certs
Wink It's the frakkin' Black Plague!

I had 39 systems come into my shop for disinfection this week. They all had the latest rogue AV applications making the rounds:

Win XP Antivirus 2008/2009 Pro
MS Antivirus
Anti-spyware 2008
...etc.

Up until now I could just pretty much throw COMBOFIX onto the systems and let it work its magic. Except over the past week the new variants all include a bastard of a rootkit component that can side-step COMBOFIX. I've had to resort to using UNHACKME 4.8 to knock out the rootkit component, follow it up with COMBOFIX, and then clean after those with MALWAREBYTES ANTIMALWARE and AVAST just to make sure I got everything. The bloom is off the rose for me with AVG 8.0. I'm extremely unhappy with the amount of crap that slips past the latest version.

Most of this rogue malware @#$% seems to be slipping in through either IE or poisoned Flash ads in the case of the Firefox users. XP and Vista are equally vulnerable. I've been sending the machines back out with Firefox 3 with the No-Script addon loaded to try and keep them from coming back into the shop again soon.

Anyone else seeing the same thing?

 
Reply With Quote
  #2  
Old 06-Sep-2008, 03:27 PM
zimbo's Avatar
zimbo zimbo is offline
Resident Greek Mafia Boss
Posts: 5,351
Points: 1419 zimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 pointszimbo has over 1000 points
Power: 74
None
Join Date: 10 Jul 2005
Location: London & Cyprus
Age: 23
Certifications: MCDST & MCSA
WIP: B.Sc Computer Networks
mate personally im a NOD32 (dont quite like the new v3 - 2.7 was the best) and spyware doctor with xoftspy worse case throw in Hijackthis too!!



Goals for 2009:
Graduate!!
CCENT
M.Sc - Computer Forensics
 
Reply With Quote
  #3  
Old 06-Sep-2008, 04:09 PM
zebulebu's Avatar
zebulebu zebulebu is offline
Premium Member
Posts: 2,144
Points: 6367 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 89
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 35
Certifications: A few
WIP: NCDA, VCP
Quote:
Originally Posted by neutralhills View Post
I had 39 systems come into my shop for disinfection this week. They all had the latest rogue AV applications making the rounds:

Win XP Antivirus 2008/2009 Pro
MS Antivirus
Anti-spyware 2008
...etc.

Up until now I could just pretty much throw COMBOFIX onto the systems and let it work its magic. Except over the past week the new variants all include a bastard of a rootkit component that can side-step COMBOFIX. I've had to resort to using UNHACKME 4.8 to knock out the rootkit component, follow it up with COMBOFIX, and then clean after those with MALWAREBYTES ANTIMALWARE and AVAST just to make sure I got everything. The bloom is off the rose for me with AVG 8.0. I'm extremely unhappy with the amount of crap that slips past the latest version.

Most of this rogue malware @#$% seems to be slipping in through either IE or poisoned Flash ads in the case of the Firefox users. XP and Vista are equally vulnerable. I've been sending the machines back out with Firefox 3 with the No-Script addon loaded to try and keep them from coming back into the shop again soon.

Anyone else seeing the same thing?
Yep. Its definitely infected banner ads - brought to you by the good folks at AdTraff exploiting the stupidity and lax security protocols at Doubleclick. Been going on for well over a year now, but I've definitely noticed a larger number of infections in the past month. I've had eleven private jobs since the beginning of July - nine of which were malware infections without obvious vectors (P2P, warez etc). All of them were running pre-SP2 XP so vulnerable to shedloads of crap anyway, but more than half had some form of free AV (Avast, AVG) installed.

I even had it at work a couple of weeks back - a user told me she 'had a virus' - it was a scam for WinAntiVirus that had slipped under McAfee's anti-spyware desktop client radar and got past our Finjan defences as well. Its starting to get nasty again - after about two years of relative quiet where they seemed to be focussing on Storm and its variants as drop vectors, they seem to have cottoned on big time to the DART malicious ad redirect route and its variants.





I claim this mouth in the name os In-Ci-Sor!
I think not...
Bicuspid! We meet again!
 
Reply With Quote
  #4  
Old 06-Sep-2008, 06:44 PM
VantageIsle's Avatar
VantageIsle VantageIsle is offline
Valued Member
Posts: 299
Points: 308 VantageIsle has over 250 pointsVantageIsle has over 250 pointsVantageIsle has over 250 pointsVantageIsle has over 250 points
Power: 9
None
Join Date: 19 May 2007
Location: Sussex
Certifications: A+ ITIL V3 70-620
WIP: 70 290, 70 291, MCSA
Yep, likewise.
Over the past three weeks I have delt with over 5 virus infections. All had slipped by Norton wich we have the misfortune to use at work. The worst one I have seen appeared last week, it was a hijack of IE that kept on prompting for some spyware removal add-in to be installed, blocked access to task manager and add and remove programs (yes, even from the command line) managed to remove it in safe mode only for it to respawn on normal startup. Thats a reinstall then. Over viruses I manged to remove, but rebuilt the machines as a precaution.

On a side note, I have been using AVG free for over a year now, I'm thinking of investing in an antivirus program for home use as I hear AVG is not as effective as it once was.


"I will not be pushed, filed, stamped, indexed, briefed, debriefed or numbered. My life is my own." - No. 6
 
Reply With Quote
  #5  
Old 06-Sep-2008, 08:49 PM
dales's Avatar
dales dales is offline
its all smoke and mirrors
Posts: 808
Points: 624 dales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 pointsdales has over 500 points
Power: 19
None
Join Date: 12 Sep 2006
Certifications: A+ MCDST MCP 270,290 ITIL F
WIP: 291 MCSA,maybe CCA?
On a similar note someone gave me their home laptop to have a look at, its the first virus I've ever seen that im actually really impressed with. They had the advanced antivirus 2008 version of spyware/virus, and I must admit that it looks really good. In that I mean the way it does actually look like a fairly genuine bit of antivirus software. Got to hand it to those particular set of virus writers its a genius idea, even if they are scum of the earth!


Regards
Dale A+ MCDST MCP, ITIL V3 Foundation, MBCS
www.dales-diary.blogspot.com
My linkedin Profile


Somewhere there's danger, somewhere there's injustice...and somewhere else the tea is getting cold.
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Black screens for pirate copies of Windows wagnerk News 23 01-Sep-2008 03:30 AM
Black Hat Speakers expose Virtualization, OS Security Gaps wagnerk News 0 08-Aug-2008 09:45 AM
hard drive has blue text not black... fatp Hardware & Upgrading 5 04-Aug-2008 04:32 PM


All times are GMT +1. The time now is 07:49 AM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages