Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Panty Saluter
Jan 17, 2004

Making learning fun!
I got a fun little trojan downloader from a hacked JPG a little while ago. Apparently that's the favored vector of WoW gold farmers. It was a slippery little bastard so I wound up reformatting (I was considering one since windows had gotten a little wonky anyway).

Wish I could remember the name. :o:

Adbot
ADBOT LOVES YOU

Panty Saluter
Jan 17, 2004

Making learning fun!

AceSnyp3r posted:

I have a question kind of related to this thread. Are there/have there been any known ways for a virus to spread via e-mail without the use of an attachment or embedded image/audio/video/java/etc.?

That's interesting, is there another new image vulnerability in Windows or something? I'm kind of interested in how exactly a hacked JPG like you're talking about works.

I poked around in Google for "jpg trojan" but a lot of the results looked sketchy so click at your own risk I guess :v:

thelightguy posted:

The last JPG arbitrary code execution vulnerability I've heard of was one that affected Windows 2000 and, I think, Windows XP RTM. I don't think there have been any since then but I may be wrong.

XP RTM? I was running XP SP3 at the time. Maybe Vista patched that up. I didn't even know I had the nasty little bugger until my girlfriend's WoW account was hacked.

Panty Saluter
Jan 17, 2004

Making learning fun!

Casao posted:

You might've been running SP3, but unless these Chinese gold farmers know of some jpg exploit that nobody else in the universe does, you didn't get it via a jpg, you got it from doing something else. Probably something stupid, too.

The only thing I can think of is there was a thread on a gold farmer in another forum with a hotlinked picture. I hadn't got any email attachments and certainly wouldn't have opened them. Who the hell knows, though...

Panty Saluter
Jan 17, 2004

Making learning fun!
Well, I was using Firefox....does this mean IE7 is actually safer? :v:

Also, I wasn't running real-time-AV at the time. Yeah, pretty dumb.

Panty Saluter
Jan 17, 2004

Making learning fun!

Capnbigboobies posted:

I think the computer I am working on today is the worst machine I have ever found. So far antivir has found, I poo poo you not, over 4000 viruses.

EDIT: Just for fun



So at what point do you call it a total loss and reformat? :v:

Panty Saluter
Jan 17, 2004

Making learning fun!
Format and reinstall. gently caress him if he can't be responsible.

Panty Saluter
Jan 17, 2004

Making learning fun!

BorderPatrol posted:

Here's a good one I ran across today? Which one is Norton Internet Security 2006 and which one is Spy Defender?


Click here for the full 2038x936 image.


Even the "Live Update" link is the same.

More importantly, which one causes more damage to your computer?

Panty Saluter
Jan 17, 2004

Making learning fun!

Midelne posted:

Morro has apparently done very well in initial tests on detection, disinfection, and avoidance of false-positives. Neat.

I have it running on my XP32 machine and so far so good. I can't speak for it's effectiveness since I do at least try to avoid getting nasty software, but can say with 100% certainty it doesn't have Avira Free's annoying nag popups. :v:

Panty Saluter
Jan 17, 2004

Making learning fun!
get microsoft security essentials











oh wait, you can't :pwn:

Panty Saluter
Jan 17, 2004

Making learning fun!

Misogynist posted:

Interesting article from Yahoo news about malware that turned a guy's computer into a child porn repository.

While it's always terrible when this stuff hits, I always kind of hope this stuff gets scary enough to knock some sense into the "I ran with antivirus for 20 years and I never had a virus!" people.

I feel for those people because, well, kiddie porn is one accusation that justcan't be approached rationally. An accusation is as damning as signed confession with dated photos. Even if you get acquitted 100% you'll never be treated the same way.

Panty Saluter
Jan 17, 2004

Making learning fun!

Capnbigboobies posted:

So the other day MSE popped up with a warning that one of my buddies on aim (which one I do not know) had some sort of exploited .jpeg.

I imagine this was a false positive. I wanted to run it through virus total, but I was too lazy and just let MSE delete it.

I had this problem the other day with a collection of PNG/GIF and PDF files. I doubt they had any problems but they weren't important enough to save.

Panty Saluter
Jan 17, 2004

Making learning fun!


So how ugly are these customers? Obviously MSE found and dealt with them but who knows how long they were sitting on my machine. Thanks Java! :argh:

What's the most likely vector? Do I need to start changing passwords?

Adbot
ADBOT LOVES YOU

Panty Saluter
Jan 17, 2004

Making learning fun!
He needs to change the password from a known clean computer first. Changing the password on the infected computer won't help anything.

  • Locked thread