mattx Posted October 20, 2009 Posted October 20, 2009 See attached screen shot, if I clear out the profiles it goes !! Anyone else seen this ? [ it's NOT spyware or scareware as I have done a very deep scan and check ]
mattx Posted October 20, 2009 Author Posted October 20, 2009 On investigation, this is more spyware by the looks of it, our firewall is certainly NOT doing what it's supposed to be doing.....I'm NOT happy.
powdarrmonkey Posted October 20, 2009 Posted October 20, 2009 It is spyware ('to pervent'?), and Malwarebytes Anti-Malware is the only thing I have found to clean it off reliably. (It's Antivirus Pro 2010 btw, which of course is a complete hypocrisy.)
mattx Posted October 20, 2009 Author Posted October 20, 2009 Hmmmmm, linked in with the other problem I had this morning. All this getting though our firewall and AV - not good, NOT very good at all. Makes you wonder why we pay such vast sums of dosh for appliences that clearly are NOT doing the job at the moment.
powdarrmonkey Posted October 20, 2009 Posted October 20, 2009 To be fair, AVP2010's stock infection technique is drive-by-downloads, so you probably need to blame your content filter more than your firewall.
jedmondson Posted October 20, 2009 Posted October 20, 2009 Malwarebytes Anti-Malware gets rid of this one quite nicley if you boot into safe mode first.
elsiegee40 Posted October 20, 2009 Posted October 20, 2009 Chances are that something infectious is in someone's profile, if it disappears when the profiles are cleared down.
mattx Posted October 20, 2009 Author Posted October 20, 2009 Chances are that something infectious is in someone's profile, if it disappears when the profiles are cleared down. Hit the nail on the head, I'm logging on as Admin, running a delprof, running a crap cleaner session, running the malware scan, making sure it gets rid of the nasties - re-booting and hey presto. Pain the backside though as I would rather be testing my ESXi setup.....
srochford Posted October 20, 2009 Posted October 20, 2009 Hmmmmm, linked in with the other problem I had this morning. All this getting though our firewall and AV - not good, NOT very good at all. Makes you wonder why we pay such vast sums of dosh for appliences that clearly are NOT doing the job at the moment. Don't think you can blame the firewall; I think you'd find it very difficult to get a firewall rule to block this kind of infection. AV ought to pick it up but I've seen it get past Symantec (definitely up to date when it happened)
mattx Posted October 21, 2009 Author Posted October 21, 2009 Heads up on this. Found my computer zero and for anyone getting similar problems: TROJ_BREDOLAB.EF: TROJ_BREDOLAB.EF - Description and solution TROJ_INJECT.ANU: TROJ_INJECT.ANU - Description and solution
mattx Posted October 21, 2009 Author Posted October 21, 2009 Sent off some samples and got this back: [ The world may now be a safer place.....for 2 mins ] Dear Matt, The malware you have submitted are not yet included in our current patterns. We are now in the process of adding it so it will be detected in our next pattern release. Please expect another email from us as an update. Please retain the subject heading of this email as it will serve as the case-ID reference for this case. Best Regards, _______________________________________ John Macariola Antivirus Engineer TREND MICRO EMEA _______________________________________ "Matt wrote: > Attached is a zip file of possible scare ware files that are not being > detected - [ the Antivirus 2010 scam ] > > These files I have located from within the C:\windows\temp dir. > > The problem is only effecting locally stored profiles.
dirtydog Posted October 21, 2009 Posted October 21, 2009 weve had loads of these the past 2 weeks coming via email, malwarebytes does the trick.
Chunky Posted October 21, 2009 Posted October 21, 2009 Personally I'd just reinstall. Why? I don't believe that once a PC has been compromised that it can be trusted 100%. It may be a bit cutthroat, but you can never be 100% sure it's clean afterwards from ANY infections. (Even if you've cleaned off the most obvious ones, you have no idea what else is still hiding in there) Just my 2p, Chunks
Guest TheLibrarian Posted October 21, 2009 Posted October 21, 2009 Personally I'd just reinstall. Why? I don't believe that once a PC has been compromised that it can be trusted 100%. It may be a bit cutthroat, but you can never be 100% sure it's clean afterwards from ANY infections. (Even if you've cleaned off the most obvious ones, you have no idea what else is still hiding in there) Just my 2p, Chunks Guess you aren't a DeepFreeze user then.
mattx Posted October 21, 2009 Author Posted October 21, 2009 Guess you aren't a DeepFreeze user then. LOL
Chunky Posted October 21, 2009 Posted October 21, 2009 Deepfreeze? No. Our LEA has it. We were purchased it. We don't use it - it can be compromised. Nuke from above (it's the only way to be sure) I prefer to try to educate people to avoid getting the problems in the first place. Chunks PS: Have you considered running Astaro? (either a hardware box, or the VM?) Nice UTM provision.
Chunky Posted October 21, 2009 Posted October 21, 2009 Sent off some samples and got this back: [ The world may now be a safer place.....for 2 mins ] Dear Matt, The malware you have submitted are not yet included in our current patterns. We are now in the process of adding it so it will be detected in our next pattern release. Please expect another email from us as an update. Please retain the subject heading of this email as it will serve as the case-ID reference for this case. Best Regards, _______________________________________ John Macariola Antivirus Engineer TREND MICRO EMEA _______________________________________ That's so worrying - it's been out for ages. Thought of changing your AV solution?
mattx Posted October 21, 2009 Author Posted October 21, 2009 That's so worrying - it's been out for ages. Thought of changing your AV solution? Nope, you have to remember that they change the checksums of files etc all the time. I send loads of dodgy looking stuff to them all the time, most of them fall under the same catagory.
Chunky Posted October 21, 2009 Posted October 21, 2009 Nope, you have to remember that they change the checksums of files etc all the time. I send loads of dodgy looking stuff to them all the time, most of them fall under the same catagory. Yeah, I know what you mean, but they also have some kind of heuristics - and remember, it's not just you they're infecting - loads of people submit back to the AV companies. Have you given the new MS solution a go? I have to admit, it's pretty hot on the prevention side of things. Chunks
mattx Posted October 21, 2009 Author Posted October 21, 2009 Yeah, I know what you mean, but they also have some kind of heuristics - and remember, it's not just you they're infecting - loads of people submit back to the AV companies. Have you given the new MS solution a go? I have to admit, it's pretty hot on the prevention side of things. Chunks I turn the heuristics off, I've found it flags more false positives than actually getting the right ones. [ And that's on a number of products ] Not looked at the MS side of things yet.
Chunky Posted October 21, 2009 Posted October 21, 2009 I guess you need to balance whether turning the heuristics off is worth the risk of putting you in the position now, or leaving them on and having to deal with false positives. Big decision. (personally, I'd go for the safe approach of false positives. (plus, how "safe" are they?) I'd rather be than Chunks
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now