YeOldeStonecat
Well-Known Member
- Reaction score
- 6,940
- Location
- Englewood Florida
Phone ringing off the hook....all 3 of us out onsite cleaning up rigs hit with hard drive alerts and security fortress 2012. Big outbreak today.
Phone ringing off the hook....all 3 of us out onsite cleaning up rigs hit with hard drive alerts and security fortress 2012. Big outbreak today.
I noticed when I installed Flash the other day on a computer that it asked if you would like Flash to update itself automatically which is the default. It's about time they did this. I don't install Java on computers anymore unless the customer is specifically using it.Hello,
All the ones I've seen lately have outdated Flash and/or Java.
Hello,
All the ones I've seen lately have outdated Flash and/or Java.
Can't seem to convince people to keep them updated.
On several, the update notifications were showing as needing updated, but customer didn't run.
They said they were "afraid to", with all the bogus "updates" out there.
Been instructing them on using Filehippo Update Checker to look for legit updates and how to download and install.
Wish I had your troubles. I have seen virtually no viral infections for probably 3+ months.
Oh yeah..she's been rooty scanned. TDSS gets blocked..GMER finished and came up clean. Ran out of time...will continue Monday with MBR checks...which is what I'm starting to thing it is. Manually checked everything HJT would...quite clean. TCP/winsock rebuild. Scanned with SAS, MWB, Panda AV, even brought out old Spybot. Will have to continue with MRT (Microsoft tool) on Monday, and yank drive and slave to another machine and scan. TCP clean, no proxy in browser connection settings, browser set to default, even installed and tested Chrome and she still gets redirected.
Wish I had your troubles. I have seen virtually no viral infections for probably 3+ months.
I've yet to see a redirect combofix didn't kill.
Yeah, Pihar.B is becoming increasingly common these days. I kill it offline with TDSSKiller.I've been seeing alot more lately when in the same situation its a rootkit hidden in an small partition tacked on to the end of the drive that is set to hidden and boot last one was only 1 meg large. Used partition magic to delete grow the main drive over the now unused space and set the boot flag on the right partition. After this all the tools that wouldn't run work just fine. Hope this might help.
Tis my rule of thumb also...but one of the rigs I worked on today HAD all updated...Adobe 10, Flash 11, Java 6.31, IE 8.0.
This new variant here is leaving a redirector behind that we've not yet been able to clean off. Within several minutes your browser starts going to affiliate sites instead of what you hoped for. "letmehelpu" is one of them.