Jump to content

Recommended Posts

Posted

See attached screen shot, if I clear out the profiles it goes !!

Anyone else seen this ? [ it's NOT spyware or scareware as I have done a very deep scan and check ]

Capture.JPG

Posted
On investigation, this is more spyware by the looks of it, our firewall is certainly NOT doing what it's supposed to be doing.....I'm NOT happy. :mad:
Posted

It is spyware ('to pervent'?), and Malwarebytes Anti-Malware is the only thing I have found to clean it off reliably.

 

(It's Antivirus Pro 2010 btw, which of course is a complete hypocrisy.)

Posted

Hmmmmm, linked in with the other problem I had this morning.

All this getting though our firewall and AV - not good, NOT very good at all. Makes you wonder why we pay such vast sums of dosh for appliences that clearly are NOT doing the job at the moment.

Posted
Chances are that something infectious is in someone's profile, if it disappears when the profiles are cleared down.

 

Hit the nail on the head, I'm logging on as Admin, running a delprof, running a crap cleaner session, running the malware scan, making sure it gets rid of the nasties - re-booting and hey presto.

 

Pain the backside though as I would rather be testing my ESXi setup.....

Posted
Hmmmmm, linked in with the other problem I had this morning.

All this getting though our firewall and AV - not good, NOT very good at all. Makes you wonder why we pay such vast sums of dosh for appliences that clearly are NOT doing the job at the moment.

 

Don't think you can blame the firewall; I think you'd find it very difficult to get a firewall rule to block this kind of infection.

 

AV ought to pick it up but I've seen it get past Symantec (definitely up to date when it happened)

Posted

Sent off some samples and got this back: [ The world may now be a safer place.....for 2 mins ] ;)

 

Dear Matt,

 

The malware you have submitted are not yet included in our current patterns.

We are now in the process of adding it so it will be detected in our next pattern release.

 

Please expect another email from us as an update.

 

Please retain the subject heading of this email as it will serve as the case-ID reference for this case.

 

Best Regards,

_______________________________________

 

John Macariola

Antivirus Engineer

TREND MICRO EMEA

_______________________________________

 

"Matt wrote:

 

> Attached is a zip file of possible scare ware files that are not being

> detected - [ the Antivirus 2010 scam ]

>

> These files I have located from within the C:\windows\temp dir.

>

> The problem is only effecting locally stored profiles.

Posted

Personally I'd just reinstall. Why?

 

I don't believe that once a PC has been compromised that it can be trusted 100%.

 

It may be a bit cutthroat, but you can never be 100% sure it's clean afterwards from ANY infections.

(Even if you've cleaned off the most obvious ones, you have no idea what else is still hiding in there)

 

Just my 2p,

 

Chunks

Guest TheLibrarian
Posted
Personally I'd just reinstall. Why?

 

I don't believe that once a PC has been compromised that it can be trusted 100%.

 

It may be a bit cutthroat, but you can never be 100% sure it's clean afterwards from ANY infections.

(Even if you've cleaned off the most obvious ones, you have no idea what else is still hiding in there)

 

Just my 2p,

 

Chunks

 

Guess you aren't a DeepFreeze user then.

Posted

Deepfreeze? No.

Our LEA has it. We were purchased it. We don't use it - it can be compromised.

Nuke from above (it's the only way to be sure)

:)

 

I prefer to try to educate people to avoid getting the problems in the first place.

 

Chunks

 

PS: Have you considered running Astaro? (either a hardware box, or the VM?) Nice UTM provision.

Posted
Sent off some samples and got this back: [ The world may now be a safer place.....for 2 mins ] ;)

 

Dear Matt,

 

The malware you have submitted are not yet included in our current patterns.

We are now in the process of adding it so it will be detected in our next pattern release.

 

Please expect another email from us as an update.

 

Please retain the subject heading of this email as it will serve as the case-ID reference for this case.

 

Best Regards,

_______________________________________

 

John Macariola

Antivirus Engineer

TREND MICRO EMEA

_______________________________________

 

 

That's so worrying - it's been out for ages. Thought of changing your AV solution?

Posted
That's so worrying - it's been out for ages. Thought of changing your AV solution?

 

Nope, you have to remember that they change the checksums of files etc all the time. I send loads of dodgy looking stuff to them all the time, most of them fall under the same catagory.

Posted
Nope, you have to remember that they change the checksums of files etc all the time. I send loads of dodgy looking stuff to them all the time, most of them fall under the same catagory.

 

Yeah, I know what you mean, but they also have some kind of heuristics - and remember, it's not just you they're infecting - loads of people submit back to the AV companies.

 

Have you given the new MS solution a go? I have to admit, it's pretty hot on the prevention side of things.

 

Chunks

Posted
Yeah, I know what you mean, but they also have some kind of heuristics - and remember, it's not just you they're infecting - loads of people submit back to the AV companies.

 

Have you given the new MS solution a go? I have to admit, it's pretty hot on the prevention side of things.

 

Chunks

 

I turn the heuristics off, I've found it flags more false positives than actually getting the right ones. [ And that's on a number of products ]

Not looked at the MS side of things yet.

Posted

I guess you need to balance whether turning the heuristics off is worth the risk of putting you in the position now, or leaving them on and having to deal with false positives. Big decision.

(personally, I'd go for the safe approach of false positives. (plus, how "safe" are they?)

 

I'd rather be :drunken_smilie: than :doh: :sick:

 

Chunks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...