yes, I have seen a version of that. Are they still calling it, Antivirus
2009, is it? I also saw something that looked *just*  like Windows security
alerts. But since Windows security had been turned off either by the user or
by the software, this would not have been the case.

I am not sure whether it actuallly did download anything at that time as I
got the heck out and when I investigated found a  gajillion trojans on that
computer and later had to take dozens of variations of it off of half the
other computers there. So I think a trojan that was already on the computer
tried to get me to download an update.

When I tried to download Spybot. I actually went  a couple of screens in
before i realized hey wait, since when does Spybot charge..... and yeah, it
was hard to get out of there too. That was a pretty slick forgery though,
they had the logo, background and layout exactly right. It was also ending
task on a couple of the well-known antivirus softwares; the scans simply
never completed. I had to do registry hacks and try out some lesser-known
brands. That was how I found Avira. Good times ;)

This particular virus got installed when someone downloaded what was
supposed to be a video codec. I do feel the need to mention for the benefit
of any prospective employers that may google me that that person was not me
and that I had not been responsible for workstation security before this
infection was discovered. Nobody was -- they didn't figure it wa an issue
because they were behind two hardware firewalls. Which were both set to
permit port 80 from anywhere, of course.

nuff said.

Anyway, it's great to hear that they came, they scanned, they found nothing.
ANd now they know it's out there,, because odds are overwhelming that
someone in the organization did click that link close as you are to
Auburn...

On Wed, Sep 2, 2009 at 7:43 AM, Ian Skinner <[email protected]> wrote:

>
> Dana wrote:
> > by the way, Ian, I would be interested in hearing any followup you have
> on
> > this. Lest Erika think I think you're stupid, I'll just mention that I
> > dealt with one of the early versions of that trojans at a former job
> site,
> > and at the time serveral anti-virus softwares were not detecting it. Work
> > put me in charge of hunting it down and quite the education in social
> > engineering *that* was :)
> >
> > Anyway.. professional interest ;)
>
> So far nothing has been found.  Scans currently turn up nothing, and I
> can not detect that the computer is trying to do anything that I do not
> expect it to do.
>
> Luckily I actually run a nonstandard configuration on my windows
> machine.  I don't use the "My Documents" folder for much anything.  Thus
> when this 'virus site' implied it was scanning and detecting thousands
> of files with viruses in the "My Documents" folder, I was pretty
> confidant it was just an animation meant to fool people into accepting
> the tool being offered.
>
> What really got my goat was how well the site prevented a user from
> closing or navigating away from it.  But there was no obvious
> downloads.  And as I said nothing yet detected.  We also got our monthly
> patches last night so hopefully the system is as up to date as possible.
>
>
>
> 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~|
Want to reach the ColdFusion community with something they want? Let them know 
on the House of Fusion mailing lists
Archive: 
http://www.houseoffusion.com/groups/cf-community/message.cfm/messageid:303296
Subscription: http://www.houseoffusion.com/groups/cf-community/subscribe.cfm
Unsubscribe: http://www.houseoffusion.com/cf_lists/unsubscribe.cfm?user=89.70.5

Reply via email to