PDA

View Full Version : Humongous virus



Valve Bounce
17th December 2008, 07:49
...........discovered that has found a weakness in Internet Explorer and that will steal your passwords and whatever you have stored in your PC. Microsoft is supposed to have a fix tomorrow. Does anyone have more info on this please? I use Mozilla Firefox instead now.

leopard
17th December 2008, 08:06
A friend warned me and whoever get used to using public pc like in the cafe, to be more careful about additional hardware attached to the keyboard and get connected to the pc, it can easily identify whatever typed by the user.

Haven't heard yet that virus Valve...

Valve Bounce
17th December 2008, 09:39
A friend warned me and whoever get used to using public pc like in the cafe, to be more careful about additional hardware attached to the keyboard and get connected to the pc, it can easily identify whatever typed by the user.

Haven't heard yet that virus Valve...

It's the zero day virus: http://blogs.zdnet.com/security/?p=2062

The fix is supposed to be out later today. Daniel: any comment PLEASE?

Dave B
17th December 2008, 10:30
As with most things, it still needs consent from the user to install. Sadly the weakest link in any computer security system is the idiot with the keyboard.

I'm using IE8 quite confidently.

Daniel
17th December 2008, 10:58
It's not a virus :p It's an exploit ;)

Supposed to be patched later today. If it were Apple they'd simply say it didn't exist. As usual don't go to dodgy websites and so on and so forth.

Andrewmcm
17th December 2008, 11:05
It's not a virus :p It's an exploit ;)

Supposed to be patched later today. If it were Apple they'd simply say it didn't exist. As usual don't go to dodgy websites and so on and so forth.

Always with the digs at a rival to deflect attention away from the issue at hand eh Daniel.

Dave's right though, it all boils down to the user. If they're daft enough to install things without understanding what they are then it's their fault. Of course it could be seen as a failing of the security architecture of Windows to allow software to be installed without requiring the root password, but that's another issue altogether.

Daniel
17th December 2008, 11:22
Always with the digs at a rival to deflect attention away from the issue at hand eh Daniel.

Dave's right though, it all boils down to the user. If they're daft enough to install things without understanding what they are then it's their fault. Of course it could be seen as a failing of the security architecture of Windows to allow software to be installed without requiring the root password, but that's another issue altogether.

Fair point but my point is also fair. Whenever there is something wrong with a Mac product it's always brushed under the carpet :)

Dave is right. It's down to the idiot who uses the computer. Me personally even with XP pre SP2 and using IE6 I only ever once managed to get a virus and that was me running an executable that someone sent me on MSN because they were infected. Purely my fault of course.

Daniel
17th December 2008, 12:35
As with most things, it still needs consent from the user to install. Sadly the weakest link in any computer security system is the idiot with the keyboard.

I'm using IE8 quite confidently.
For you Dave :D

http://www.dailymail.co.uk/news/article-1095266/Microsoft-rush-security-patch-Internet-Explorer-Chinese-fraudsters-use-flaw-hijack-computers.html

Love the picture of the guy with a Netscape box and an IE box. How bloody old is that? :confused:

Dave B
17th December 2008, 16:16
IE Plus (http://www.microsoft.com/presspass/press/1997/oct97/iepluspr.mspx), I'll have you know, which puts it at October 1997!

Hmm. Diana is killed, then barely two months later IE+ launches. I smell a conspiracy which the Mail has clearly missed. :erm:

Daniel
17th December 2008, 16:20
IE Plus (http://www.microsoft.com/presspass/press/1997/oct97/iepluspr.mspx), I'll have you know, which puts it at October 1997!

Hmm. Diana is killed, then barely two months later IE+ launches. I smell a conspiracy which the Mail has clearly missed. :erm:
So Bill Gates was driving the white Fiat Uno? :eek: Or perhaps Diana's car was running some sort of Beta version of 98 which is probably why it crashed :p

Roamy
17th December 2008, 23:20
I don't know why you microsh!t users are surprised at the lastest security leak. Microsh!t has been trying to secure this operating system for 30 plus years. Did you really think that this is the year?? They will get it secure the year Coultard wins the WDC.

Valve Bounce
18th December 2008, 02:12
OK, I tried to find the download for this virus and it was as difficult as looking for teeth from an irate rooster to exrtract. The Microsoft Update website will not direct you to this download; it will simply tell you there are no security upgrades for your computer.

To find this, I had to go to google and look for the download for Microsoft KB958644 download

For those who use Apple instead, well, what can I say? I've been using Microsoft for bloody years and that's what I had to do to get the hotfix.

I rebooted my PC afterwards just to make sure.

18th December 2008, 02:56
I just went to Microsoft website and chked my update history. KB958644 (Windows XP update) was updated on my computer in Oct. My latest auto update (today) was KB960714 and is an IE7 security update. Not sure if this is any help.

Valve Bounce
18th December 2008, 12:00
I just went to Microsoft website and chked my update history. KB958644 (Windows XP update) was updated on my computer in Oct. My latest auto update (today) was KB960714 and is an IE7 security update. Not sure if this is any help.

Yes!! it did help. And thanks!! It took me ages to find the download but it's done. :)

MrJan
18th December 2008, 12:19
I think that my computer did this update this morning, seems to always be doing something new, all I know is that it slows the bloody computer up when it's installing them :mark:

Valve Bounce
18th December 2008, 12:23
I think that my computer did this update this morning, seems to always be doing something new, all I know is that it slows the bloody computer up when it's installing them :mark:

That patch was very fast when I did it. I made sure I rebooted the computer afterwards.

MrJan
18th December 2008, 12:25
It's my crap computer more than anything else :) I also rebooted but only because it'll spend the rest of the day complaining if I don't :D

schmenke
18th December 2008, 18:38
I just went to Microsoft website and chked my update history. KB958644 (Windows XP update) was updated on my computer in Oct. My latest auto update (today) was KB960714 and is an IE7 security update. Not sure if this is any help.

So is this update for IE7 only? Am I o.k. if I'm running IE8? :s

Daniel
18th December 2008, 19:02
So is this update for IE7 only? Am I o.k. if I'm running IE8? :s
From what I've seen it's IE7 only yes :)

Valve Bounce
18th December 2008, 21:16
Should I download IE8 then?

Daniel
18th December 2008, 21:32
Should I download IE8 then?
IE8 is currently a Beta so I wouldn't reccomend most people use it.

schmenke
18th December 2008, 21:34
IE8 is currently a Beta ...

True, but i'ts been beta for a while now, and I've been using it for months with no problems or issues.

19th December 2008, 06:35
I think IE8 is only the Beta version at the moment so I'm not downloading it.

oops, didn't see the last two posts, ignore mine.

Dave B
19th December 2008, 08:59
RC1 of IE8 has been out for a few days, which indicates that it's nearing a full public release.

Jag_Warrior
20th December 2008, 03:33
I'm running XP and IE 6. When I downloaded service pack 3 last Sunday, that's when all the fun really started. But even one day prior to that update, my AVG virus protection stopped updating, though it will run. Ad-Aware also stopped updating.

The most interesting thing about whatever I've picked up is that I can't go to the following sites: avg.com, trendmicro.com, symantec.com, mcafee.com

Notice anything strange about that? ;)

Whenever I try to go to any of those sites I get this:
The page cannot be displayed


I can however go to the HSBC and Washington Mutual sites (I don't have acounts at either of those banks :D ). I've tried several times to use System Restore. I can select a restore point, but when I try to click the OK button to restore, nothing happens. It's as if the button is deactivated. I don't do the peer-to-peer file sharing. I don't download any and every file that I come across. I'm using the same security settings that I've used for the past 3 years or so.

A computer is nothing more than a tool I use for work and a device I use for entertainment (like a TV). I'm not an expert by any means. I have a certain amount of basic knowledge. So if anyone here has any ideas of what I might do (on my own), I'd dearly love to hear your suggestions. The IT guru at work has no idea what this might be. But whatever it is, it seems damn good. Beating this one with a hammer until it breaks into 1000 pieces has already crossed my mind. Something else, please. I'm running the Windows Live OneCare Safety scanner now. We'll see what it does (probably nothing or I'd have probably been blocked from going to the site).

Valve Bounce
20th December 2008, 07:48
OK! I did try my AVG update - ran it and I got a message that it has been updated. I then ran Lavasoft's Adaware update and it did update.

So I don't know what is going wrong with Jag Warrior's PC.

I am toying with the idea of running IE8 and am just awaiting good news and approval from the guys here before I do.

I updated my Firefox and I've lost the auto spell check function. Anyone know how I can re-activate that? Thanks.

20th December 2008, 09:07
Jag Warrior. You can right click My Computer from your desktop and select Properties and then the System Restore tab to check whether Turn Off System Restore has been checked for some reason. I'm no expert, just gaining a little knowledge along the way.

Andrewmcm
20th December 2008, 10:40
I'm running XP and IE 6. When I downloaded service pack 3 last Sunday, that's when all the fun really started. But even one day prior to that update, my AVG virus protection stopped updating, though it will run. Ad-Aware also stopped updating.

The most interesting thing about whatever I've picked up is that I can't go to the following sites: avg.com, trendmicro.com, symantec.com, mcafee.com

Notice anything strange about that? ;)

Whenever I try to go to any of those sites I get this:
The page cannot be displayed


I can however go to the HSBC and Washington Mutual sites (I don't have acounts at either of those banks :D ). I've tried several times to use System Restore. I can select a restore point, but when I try to click the OK button to restore, nothing happens. It's as if the button is deactivated. I don't do the peer-to-peer file sharing. I don't download any and every file that I come across. I'm using the same security settings that I've used for the past 3 years or so.

A computer is nothing more than a tool I use for work and a device I use for entertainment (like a TV). I'm not an expert by any means. I have a certain amount of basic knowledge. So if anyone here has any ideas of what I might do (on my own), I'd dearly love to hear your suggestions. The IT guru at work has no idea what this might be. But whatever it is, it seems damn good. Beating this one with a hammer until it breaks into 1000 pieces has already crossed my mind. Something else, please. I'm running the Windows Live OneCare Safety scanner now. We'll see what it does (probably nothing or I'd have probably been blocked from going to the site).




My aunt has a similar thing on her PC. I tried to fix it using anti-spyware and suchlike but it wouldn't let me install the programs or visit their websites.

Backup your documents, reformat and re-install XP I'm afraid. Then immediately set-up your firewall and anti-virus.

Daniel
20th December 2008, 13:27
I'm running XP and IE 6. When I downloaded service pack 3 last Sunday, that's when all the fun really started. But even one day prior to that update, my AVG virus protection stopped updating, though it will run. Ad-Aware also stopped updating.

The most interesting thing about whatever I've picked up is that I can't go to the following sites: avg.com, trendmicro.com, symantec.com, mcafee.com

Notice anything strange about that? ;)

Whenever I try to go to any of those sites I get this:
The page cannot be displayed


I can however go to the HSBC and Washington Mutual sites (I don't have acounts at either of those banks :D ). I've tried several times to use System Restore. I can select a restore point, but when I try to click the OK button to restore, nothing happens. It's as if the button is deactivated. I don't do the peer-to-peer file sharing. I don't download any and every file that I come across. I'm using the same security settings that I've used for the past 3 years or so.

A computer is nothing more than a tool I use for work and a device I use for entertainment (like a TV). I'm not an expert by any means. I have a certain amount of basic knowledge. So if anyone here has any ideas of what I might do (on my own), I'd dearly love to hear your suggestions. The IT guru at work has no idea what this might be. But whatever it is, it seems damn good. Beating this one with a hammer until it breaks into 1000 pieces has already crossed my mind. Something else, please. I'm running the Windows Live OneCare Safety scanner now. We'll see what it does (probably nothing or I'd have probably been blocked from going to the site).



A bit of googling brings up this.

http://help.lockergnome.com/security/access-anti-virus-websites-ftopict11459.html

Jag_Warrior
20th December 2008, 15:35
Thanks for the replies everyone.

Daniel, it looks like that's what I have. The ComboFix application appears to be (at least one of) the program(s) that I need. My problem, I've yet to find a site that I can get to that will allow me to download the application.

Every site that offers a link to ComboFix gives me
res://shdoclc.dll/pagerror.gifThe page cannot be displayed

The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings.

Whoever wrote this viral application, I have much respect for. I admire intelligence and logic, even when it beats me. This person has thought of just about everything: he seems to have blocked ALL exits. After shaking his hand, I would cut his b#lls off with a dull knife. But I'd still shake his hand.

So... any ideas on how I can get to a site that will allow me to download ComboFix? And let's say I have someone else download it for me, am I going to be able to install it, or will Mr. Master Virus thwart me? Dumping my files onto the standalone and wiping this thing down with a fresh install is beginning to look like a (not very desireable) option.

Double damn!!!!!!!!!!! :mad:

Daniel
20th December 2008, 15:37
Thanks for the replies everyone.

Daniel, it looks like that's what I have. The ComboFix application appears to be (at least one of) the program(s) that I need. My problem, I've yet to find a site that I can get to that will allow me to download the application.

Every site that offers a link to ComboFix gives me
res://shdoclc.dll/pagerror.gifThe page cannot be displayed

The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings.

Whoever wrote this viral application, I have much respect for. I admire intelligence and logic, even when it beats me. This person has thought of just about everything: he seems to have blocked ALL exits. After shaking his hand, I would cut his b#lls off with a dull knife. But I'd still shake his hand.

So... any ideas on how I can get to a site that will allow me to download ComboFix? And let's say I have someone else download it for me, am I going to be able to install it, or will Mr. Master Virus thwart me? Dumping my files onto the standalone and wiping this thing down with a fresh install is beginning to look like a (not very desireable) option.

Double damn!!!!!!!!!!! :mad:

The silver lining is that your PC will run much faster!

Jag_Warrior
20th December 2008, 15:50
OK. I guess I'll start looking for that Windows XP CD in the next few minutes. :(

If you guys don't hear from me for awhile (this may not go well), have a Merry Christmas. :)

Jag_Warrior
24th December 2008, 18:07
7 hours of looking for and reloading software. :mad:

Andrewmcm
24th December 2008, 19:02
Welcome back!

Valve Bounce
28th December 2008, 04:01
7 hours of looking for and reloading software. :mad:

I'm thinking of doing the same - but first, I have to save all my pics. It will probably mean two days of work altogether. :(

Jag_Warrior
28th December 2008, 15:32
I'm thinking of doing the same - but first, I have to save all my pics. It will probably mean two days of work altogether. :(

It really is worth it. I grabbed a 250GB standalone pocket drive from Walmart and just dumped whole folders onto it. I used this drive instead of my regular standalone, just in case I had an infected file hiding some place.

The big thing was lining up all the software that I'd need to do the reinstall. But my WinSux box now runs better than when new (looks like a few drivers were left out when the factory loaded them).

If you have anything like what I had, it's not worth the time and aggravation to try to fix it (IMO) - IF you can save all of your files and applications before dumping.

Good luck.

Jag_Warrior
16th January 2009, 20:31
Save yourselves! Save yourselves!

http://arstechnica.com/news.ars/post/20090116-conficker-worm-spikes-infects-1-1-million-pcs-in-24-hours.html

Valve Bounce
16th January 2009, 23:01
It really is worth it.
Good luck.

Well, I did it. I reformatted the HD and then re-installed Windows XP. I did have some problems because I didn't realise that I had to install the drivers for the Ethernet, and sound driver manually from the FELL resources disc. I also found out that DELL has sold off their free support to GIZMO and I had to pay if I wanted tech support. I then ran my Cyberscrub (7 passes) and erased a helluva lot of crap that was still on my HD. The PC runs OK now - I must have had some conflicting programs before the re-installation.