Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli
Got a lovely little one the other week.
It's dubbed the recycler virus.

It comes via remote media, usually memory sticks or hard drives.
The blighter sneaks in via auto-run, which I had turned off so it kicked in when I double clicked on my mate's drive.

It's dubbed thee for it placing RECYCLER into every drive along with an autorun.ini on every drive it finds.

On top of that it seems to enjoy making weird redirects in Firefox.
Links in google will open a new tab going to some odd search thing and any links to spybot return null.

There was some addon or something buried into Firefox, first time I've seen firefox actually inflicted by something.

Along with that there's the usual rootkit.

Thankfully it was easy to fix.
Had to boot into OSX and rip out anything and everything that appeared to be associated with it, along with shredding any left behind registry keys and re-installing virus scanners and spybot.

Malwarebytes picked it up, AVG and Spybot didn't.

Adbot
ADBOT LOVES YOU

BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli
If someone reworked that AIDS one it would cause more terror than conflicker.

BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli

Red_Fred posted:

So after reading about a guy making a virus kit on a USB stick I thought this would be a good idea. What are the best programs to have? What order should they be used?

I'll let others suggest scanning apps, but it will help if you put on USB immunizer so that you don't end up carrying back infections.
The program creates an locked autorun.ini that can't be overwritten by viruses.

http://labs.bitdefender.com/?page_id=108

What are people's opinions on Sophos Anti-Rootkit, how has it stacked up?

BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli
Is there any general way to safeguard against Cryptolocker. Does it just target My Documents or does it seek out every file on it's hitlist on the system?

BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli
My "work environment" is pretty much aimed at stopping a dreaded call from a family member when it hits. Does XP's GP have settings to stop executables running out of App Data?

Adbot
ADBOT LOVES YOU

BogDew
Jun 14, 2006

E:\FILES>quickfli clown.fli
Ahhh memories, I used to get monthly Sophos virus definition CDs back in the days when 56k ruled. They commonly became coasters.

Back then taking your computer away to get "fixed" for viruses meant some support bloke simply ran Sophos offline and calling it a day once it turned up clean.
You got back a machine that now was somewhat worse as all Sophos did was strip out any malicious code hiding in various .exes headers or flat out deleting various files Windows needed to use. Stuff would still remain in many dark corners or on other user profiles.

Gives you an idea how ineffective most scanners are - even if they do update hourly, they most likely just have found a few new variants of known signatures.

Leap 15 years ahead and you're in an age where Fortune 500 companies have to keep so far ahead of the game as people will simply leave a USB labeled "accounts" in the carpark waiting for a curious worker to pick it up and then try it at work or failing that give it a go at home.

OSI is on the ball when it comes to the cold war between viruses and a desktop scanner - they might sound all clever with fancy features and real-time detection, but it's been a long time since "FIRE EVERYTHING" did anything but keep a system floating long enough to evacuate data. And that's if you're lucky.

  • Locked thread