davidn: (skull)
[personal profile] davidn
For a long time now, I'd thought that computer viruses were things only contracted by idiots and users of Internet Explorer (qualifications which it must be said often go hand in hand). But we had an infection of something at work last week that necessitated going out to buy a new hard drive, and my work laptop's just got something today as well. I'm not sure how it happened - as far as I can remember I wasn't doing anything with it that was more horrific than normal.

I got a trojan warning from Avast when things were going well on massive upgrade #3 of 4 in the middle of the day, and not too long after that, I noticed a process taking up far too much CPU time, and a pop-up advert appearing that was an Internet Explorer window trying to look like Firefox (the icon in the taskbar was wrong). Further, it seemed that some Google links were being redirected - I thought I'd just misclicked the first couple of times, but when I clicked on MalwareBytes and got a page about how to have a healthy pregnancy I was beginning to suspect that something was wrong.

Spybot caught it, it's called Virtumonde.prx and fiddles with your Internet traffic, so I've disconnected it from the network while it runs a giant scan to see if it's been successful in removing it after one reset. HijackThis couldn't seem to, though, so if that doesn't work I have Combofix and a big list of instructions to fall back on.

Date: 2010-02-09 12:46 am (UTC)
From: [identity profile] kytheraen.livejournal.com
I got an email from "Support Michael Raines" <parcel@dhl.com>

I know dhl.com is a real website but I'm pretty sure it's some kind of coverup... the attachment of delivery advice and shipment label to be taken to the depot for pickup is a .zip file. I've always been taught that .zips are the bog standard of virus carries.

Should I be opening this? Or if so... on a work computer instead? ;)

Date: 2010-02-09 12:50 am (UTC)
From: [identity profile] kytheraen.livejournal.com
Answered my own question: http://www.kenkai.com/seo-blog-article-207.htm

Date: 2010-02-09 10:41 am (UTC)
From: [identity profile] kytheraen.livejournal.com
What confused me was the email address it came from looks like a valid email. I was under the impression you could make anything look like a genuine email from X company, but you always failed at the email address. "DHLParcelTracker@hotmail.com" for example (or all the Neopets Team emails I get subjected to asking for my password and pin).

I just didn't think malicious emails could be sent from real companies.

Date: 2010-02-09 01:29 pm (UTC)
From: [identity profile] kytheraen.livejournal.com
758715082.06220334286440@mindblogger.com

Nice job Watson.

Expand Cut Tags

No cut tags

May 2020

S M T W T F S
     12
3456789
1011121314 15 16
171819 20 212223
24252627 28 2930
31      

Most Popular Tags

Style Credit

Page generated Jun. 24th, 2025 06:16 am
Powered by Dreamwidth Studios