localzuk Posted March 3, 2011 Posted March 3, 2011 If people used Firefox with Adblock then that will stop Virii and fake virii coming though compromised ads in the future. But would also affect the sites they visit, as their ad revenue would fall and therefore could end up damaging the site.
SYNACK Posted March 3, 2011 Posted March 3, 2011 But would also affect the sites they visit, as their ad revenue would fall and therefore could end up damaging the site. Perhaps they should be damaged, maybe that way more care would be put into stopping this rubbish by ad providers with dropping client numbers.
difinity Posted March 3, 2011 Posted March 3, 2011 But would also affect the sites they visit, as their ad revenue would fall and therefore could end up damaging the site. I put the security and usability of my machines above the website revenue. It's not the first time stuff has been pushed through compromised ads.
localzuk Posted March 3, 2011 Posted March 3, 2011 Perhaps they should be damaged, maybe that way more care would be put into stopping this rubbish by ad providers with dropping client numbers. The problem is, it is legitimate ad providers who are serving up these adverts. It isn't the site's fault, it isn't the ad network's fault - its the advertiser for putting this stuff up. Put it this way, Edugeek uses adverts for revenue, how would you feel if everyone blocked Edugeek adverts? I put the security and usability of my machines above the website revenue. It's not the first time stuff has been pushed through compromised ads. Until the sites you use disappear of course.
somabc Posted March 3, 2011 Posted March 3, 2011 I disagree if an Ad Network is serving Malware it is definitely their fault. We could introduce a £10,000 fine for every instance to force them to be more thorough. In the same way a Transport Company is fined if they have an illegal immigrant stowed aboard their truck.
JoeBloggs Posted March 3, 2011 Posted March 3, 2011 The problem is, it is legitimate ad providers who are serving up these adverts. It isn't the site's fault, it isn't the ad network's fault - its the advertiser for putting this stuff up. Put it this way, Edugeek uses adverts for revenue, how would you feel if everyone blocked Edugeek adverts? Edugeek & any other site for that matter need to do as much as possible to protect its members, this includes who it picks for generating revenue.
localzuk Posted March 3, 2011 Posted March 3, 2011 Edugeek & any other site for that matter need to do as much as possible to protect its members, this includes who it picks for generating revenue. Of course they do, but a knee-jerk reaction of 'block all adverts using adblock' is a bad idea IMO.
morganw Posted March 3, 2011 Posted March 3, 2011 Do you need admin rights for it to install itself or because it's in the users profile will it install regardless?
difinity Posted March 3, 2011 Posted March 3, 2011 Of course they do, but a knee-jerk reaction of 'block all adverts using adblock' is a bad idea IMO. Not a knee-jerk reaction. I like a clean unclutterd webpage without annoying ads, the fact it blocks another attack vector is a bonus.
Arthur Posted March 3, 2011 Posted March 3, 2011 Do you have any of the malicious jar files, I would be interested to see exactly what they do? You might be able to find it on here... http://www.malwaredomainlist.com/mdl.php
CHR1S Posted March 3, 2011 Posted March 3, 2011 Ours were dropped via TDL4 rootkit, which bypasses pretty much everything - see here - http://www.edugeek.net/forums/security/71669-tdl4-rootkit.html
somabc Posted March 3, 2011 Posted March 3, 2011 Ours were dropped via TDL4 rootkit, which bypasses pretty much everything - see here - http://www.edugeek.net/forums/security/71669-tdl4-rootkit.html Interesting because I have not found any evidence of that Rootkit on any of ours.
CHR1S Posted March 3, 2011 Posted March 3, 2011 (edited) They were definitely the same viruses, one had 14 others as well as the fake AV type one but were at different stages of infection. One was reported immediately and the other had several days of runtime on a home network. Edit - and one was definitely infected prior to the 27th as reported by the BBC Edited March 3, 2011 by CHR1S
somabc Posted March 3, 2011 Posted March 3, 2011 I think the problem is there are multiple attack vectors going on whether Java, PDF, TDDS, Zeus etc.
CHR1S Posted March 3, 2011 Posted March 3, 2011 I think the problem is there are multiple attack vectors going on whether Java, PDF, TDDS, Zeus etc. Agreed!
segalp Posted March 3, 2011 Posted March 3, 2011 We've had two instances of 'Internet Defender' today - pain to remove but MalwareBytes seems to do the trick
CAM Posted March 4, 2011 Posted March 4, 2011 The blocking of Internet Ads was discussed at the conference. On one hand it can have a damaging effect on the site if school tech staff all block ads, EduGeek would get no money as all the ads would be blocked. On the other hand, the consumer gains benefit from blocking ads by closing another attack vector and removing distractions on the page (let's be honest, what is one good reason from the consumer perspective to show adverts? Some TV ad-breaks already take the mick with their frequency and length). Ultimately, it's down to a website to ensure it's ads are not compromised, don't get in the way and are of good enough design to not distract the user whilst being visible. hence why pop-ups fell out of favour for legitimate adverts. Likewise any site that has ads which make sudden unwanted noises get's swiftly vacated. The serving of malware also hurts a site in Google rankings and can lead to blacklisting so it is certainly in the site administrator's interest to secure their ad distribution.
synaesthesia Posted March 4, 2011 Posted March 4, 2011 I thought about using AdBlock or similar yesterday but realised management of it would be an absolute pain. Frankly, websites revenue streams come second to user and network security. It shouldn't happen in the first place of course, but writing it off because of the fear of blocking a few penny-hits of a banner ad is just daft. Maybe a little fine tuning - i.e. not hitting static ads but blocking java and flashed based ones.
Tunster Posted March 4, 2011 Posted March 4, 2011 We've had at least 7 infections (personal computers and 2 on-site computers) in the last week. All have come through a Java exploit (.jar files stored in the temp files) and deployed the System Tool 2011 fake agent. A full scan using Malwarebytes has cleared them all (except for one which had it's boot-up corrupted). All have mentioned Hotmail. I know several sites are affected by this, but we've taken action by blocking Hotmail as it's heavily used and don't want any more infections until things calm down. Even though this ad servers have been reported to be cleared, it's still happening.
Fraser-09 Posted March 4, 2011 Posted March 4, 2011 Yep, see this popping up all over the place. Currently cleaning my 4th and 5th infected laptop this week with Malwarebytes as I write this
tech_guy Posted March 4, 2011 Author Posted March 4, 2011 I've done 9 machines this week ( we had two at work and I've done 7 at home - laptops of friends and family ). PITA.
DrCheese Posted March 4, 2011 Posted March 4, 2011 My Dad had this, probably from an out of date version of Java as everything else was fine. Had a member of SMT in a panic on the first Monday back with this on his home computer, didn't mind removing it for him (takes all of 5 seconds...) As for school so far we're ok *touch wood* I've always blocked ads at the proxy level for our users, this being a contributing reason for that.
synaesthesia Posted March 4, 2011 Posted March 4, 2011 The code would appear to inject a "dropper" trojan : not dangerous itself but rather like Conficker was rumoured to be, just a gateway for other nasties to enter the system. Hence why there appears to be many different types of the same infection, once the dropper is there more nasties can work their way in such as the aforementioned rootkits. Had one yesterday that stopped anything remotely useful being run. My old man's work PC actually rebooted into a "fake safe mode" after it looked like a proper MBR based infection found it's way in off the back of this dropper. Needless to say I didn't waste time in suggesting the use of a liveCD to backup then kill off the HDD!
GREED Posted March 5, 2011 Posted March 5, 2011 This is the symptoms I had, programmes being intercepted before being able to run. From a novice in the world of viruses etc, I must say I was somewhat impressed by what this was doing, not taking away the anger and frustration it causes. I guess probably quite easy to do, but I did tip the hat to the creators!!!
TechSupp Posted March 5, 2011 Posted March 5, 2011 Had my first of the new varient yesterday, teachers laptop and then had an LSA say she had it on her PC at home so just printed off the instructions on the Malwarebytes site for getting rid of it and let her have them. Can see these not being the first I will have to deal with! Had a similar one a couple of months ago but this seems to have hit big time in comparisson.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now