SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 08-14-12, 03:28 AM   #1
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default indication for a trojan infection

Was surfing yesterday in search of pics of the Russian and Chinese stealth fighters. Found the known old pics only, investiogated some sites nevertheless. Then left the house for some time. After coming back home and booting ther system, I was greeted by an error message that some sys32/rundll32.exe worked incorrect and that an entry FQ10 was missing.

Googling told me that this was an indication for a trojan infection. Further scanning showed that it was the jackpot: Spyware.Zeus and Trojan.Ransom.Gen. The latter is said that you can handle it if you discover it soon and get rid of it before it starts to really spread around. But Zeus is something different, andf they say even the latest definitions for malware and virus scanner detect it only with a probability of 23%.

Avira Security Suite rang no alarm. An active scan via Malware's Anti-Malware (free) found it. It even made short process with both. However - this must not mean that the thing is really gone, eh?

After that, I scanned again, full scans with Avira Security Suite, Malware's Anti-Malware, SuperAntiSpyware and Emsisoft Anti-Malware Squared. All with no results anymore. But I do not trust it, this Zeus is probably the most dangerous and well-supported criminal trojan currently plagueing the web. I hope those criminals behind it, and others like them, race against a tree with their cars or fall off a bridge.

System reinstallation is in order sooner or later, preferrably before I do my next financial transactions via my system. Great. Right what I was craving for. It'S not so much the installation - but the finetuning of options and individual preferrances.

I hope Zeus punishes them with well-aimed lightning bolts.

Does anyone know how to prepare better against threats like Zeus which you can catch up by simple surf-bys? Detection probabilities of even the latest scanner updates of around 23% are not encouraging, are they.
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Old 08-14-12, 03:38 AM   #2
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default

As a warning to all others: if you ever meet Zeus, take it serious and realise that you just have been found by major trouble. I found this excellent German article published by an analyst from Kaspersky which describes it. It is so hard to detect becasue the gangsters behind it spread it in a myriads of versions - and make sure that they release only a small number of modifications into the wild at the same time - but in very short intervals. The record has been over 5000 mutations within just one month. The total number of altered versions of Zeus ranks amongst the hundreds of thousands. In 2009, over 3.6 million systems in the US alone were found to be infected, and formed one of the biggest botnets ever revealed.

http://www.viruslist.com/de/analysis?pubid=200883691

I am not aware that the article is around in English, too. If you stumble over it, link it.
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Old 08-14-12, 05:29 AM   #3
Dowly
Lucky Jack
 
Join Date: Apr 2005
Location: Finland
Posts: 25,005
Downloads: 32
Uploads: 0


Default

Quote:
Originally Posted by Skybird View Post
Does anyone know how to prepare better against threats like Zeus which you can catch up by simple surf-bys? Detection probabilities of even the latest scanner updates of around 23% are not encouraging, are they.
You could try Avast!

I've used it for years and it is every bit as good as people say it is.
Dowly is offline   Reply With Quote
Old 08-14-12, 05:33 AM   #4
HunterICX
Rear Admiral
 
Join Date: May 2006
Location: Malaga, España
Posts: 10,750
Downloads: 8
Uploads: 0


Default

Avast and use a noscript plug-in for your browser *if it supports one*
blocks all the nasty ambush ads that contain trojans and other malware.

HunterICX
__________________
HunterICX is offline   Reply With Quote
Old 08-14-12, 06:20 AM   #5
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default

I am pretty sure that I fell victim to a drive-by infection, since I was searching pics of those airplanes. Zeus is known to be extremely stealthy and extremely adaptable, and that is why even the latest up-to-date scanners and definitions have only a 1:2 - 1:3 chance of detecting the latest incarnations. Since some time it also has been known to have been encrypted even better, so that it can deceive security scanners even better.

So, Avast or Avira, Bit Defender or Kaspersky - you better do not feel safe against this beast. It completely escaped Avira Security 2012's radar - and that is a solid security suite as well.

Do a search for Zeus ion the Web to get some info. DO NOT TRUST YOUR SCANNERS TO PROTECT YOU IF YOU MEET IT. CHANCES ARE THEY WILL NOT. 70% of all PCs infested in 2009 or 2010 that were examined by a security company, were protected by up-to-date Firewalls and Virus-Scanners with updated definitions.

Will go to town now, and then this late afternoon start the dance.
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Old 08-15-12, 02:12 AM   #6
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

Panda Cloud free antivirus is okay well i used it for a while but what got to me is its so silent that i use to wonder is it actually doing anything. No updates of the definitions are required because its running in the cloud. For a free antivirus reviews ive read have stood by it, but for me it was so damn silent where the paranoia got the better of me so i went back to a paid antivirus.
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 08-15-12, 07:47 AM   #7
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default

Only payware Firewall and AntiVirus suites for me. Nobody can convince me that what they do for a fee is done for same effectiveness but for free by "free versions". Additionally using free malware scanners is recommended. I use Malwarebyte'S program, and SuperAntiMalware. Emsisoft's program also often gets recommended over here.

This year, the internet suites of Bit Defender and Kaspersky, F-Secure and G-Data score highest for recognition rates and cleaning, according to testzs in German computer magazines. Panda Cloud was rated okay for recognition, but moderate in cleaning, another Panda version there is which is even weak in recognition. Avast is found to be moderate only in recognition, and weak in cleaning, it is the one suite that has massively lost in this year's incarnation, they say by their results (it was one of the top contenders in past years). My Avira scores good in recognition and cleaning, but moderate only regarding performance (it takes long time to scan the HD).

Well, that says the test by German market leading computer magazine Chip. I sticked with Avira only for reasons of comfort, I already had the abo last year. If I would install brandnew a suite, i would go with BitDefender this year. In the tests it was the only one scoring top in all three categories recognition rate, cleaning, and performance.

Regarding my Zeus problem, none of these suites gives you really safe security. If you got a Zeus clone, and it is not a years-old incarnation (and how would you tell, there are several hundred thousands), there is a good chance that it is still there after the scanner says he "cleaned" it, so REINSTALL. It was not Avira finding it, it was Malwarebyte's Anti-Malware and SuperAntiMalware, btw (both can be had for free in their active scan versions). I would recommend to run active scans with both once a week.
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Old 08-15-12, 08:03 AM   #8
Dowly
Lucky Jack
 
Join Date: Apr 2005
Location: Finland
Posts: 25,005
Downloads: 32
Uploads: 0


Default

Hard to believe Avast! scored so poorly. Like I've said, I've used the (free ed.)
Avast! for years. I do a complete boot scan 1-2 a month and a more thorough
scan with Avast! and various anti-malware apps every 3 months or so. I haven't had
a single virus or malware in probably 2 years. Avast! always picks up bad websites
as I try to connect to them and automatically cuts the connection.

As for payware AV, my only experience is with F-Secure and I hated it. It was
slow and it leaked like hell. And just the other day, Crécy had problems starting
the Combat Mission: Commonwealth Forces add-on. Turns out his (payware)Norton
was for some reason blocking the executable.
Dowly is offline   Reply With Quote
Old 08-15-12, 08:50 AM   #9
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

I use to use Avast years ago and back then it was a very good free antivirus i dont know about now but i would presume it could only get better. The only thing that annoyed me was whenever a virus was found or an update was completed it scream out on the speakers about it. Not good when browsing then all a sudden YOUR ANTIVIRUS HAS BEEN UPDATED!
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 08-15-12, 08:54 AM   #10
kranz
The Old Man
 
Join Date: Aug 2007
Location: Poland
Posts: 1,430
Downloads: 5
Uploads: 0
Default

Quote:
Originally Posted by Skybird View Post
Only payware Firewall and AntiVirus suites for me. Nobody can convince me that what they do for a fee is done for same effectiveness but for free by "free versions".
that's the second time I have to agree with him.
I've been using Norton for sth like 6 years now and I've never had any problems.
I tried to use some free stuff for around a week a few years ago and after a few clicks my win XP tried to "save my marriage". After this prompt I immediately installed Norton back.
kranz is offline   Reply With Quote
Old 08-15-12, 08:58 AM   #11
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

^Yeah ive gone back to Norton 360 premium edition. Works well and seems like its doing something, plus its smooth when gaming it has a silent mode option when gaming but i don't need to turn it on.
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 08-15-12, 08:58 AM   #12
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default

Quote:
Originally Posted by Dowly View Post
Hard to believe Avast! scored so poorly. Like I've said, I've used the (free ed.)
Avast! for years. I do a complete boot scan 1-2 a month and a more thorough
scan with Avast! and various anti-malware apps every 3 months or so. I haven't had
a single virus or malware in probably 2 years. Avast! always picks up bad websites
as I try to connect to them and automatically cuts the connection.

As for payware AV, my only experience is with F-Secure and I hated it. It was
slow and it leaked like hell. And just the other day, Crécy had problems starting
the Combat Mission: Commonwealth Forces add-on. Turns out his (payware)Norton
was for some reason blocking the executable.

Avast was a top contender until last year, but if you check over several years, you see that most internet suites go up and down and up and down in cycles which can have several year's lifespan.

From: Chip Magazine. Paste and copy did not work. Go here, and scroll down to the table. http://www.chip.de/artikel/Sicherhei..._55120663.html
the columns are entitled "Malware-Protection / Malware-Removing / Performance / Total "
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Old 08-15-12, 08:58 AM   #13
CaptainHaplo
Silent Hunter
 
CaptainHaplo's Avatar
 
Join Date: Apr 2007
Posts: 4,404
Downloads: 29
Uploads: 0
Default

I am sorry, but for those of us in the security world, this entire discussion is a lesson in irony.

Data security doesn't start at your PC - it starts with the user.

While I know Skybird posted this to help others, I am going to point out a couple of mental choices that show why he is now in this situation - hopefully to help folks avoid bad decisions.

First - let us review one very important fact. If you never want to "get hacked" or "infected" from the web is to stay off of it entirely. So the moment you choose to get on the interwebz, your choosing to expose yourself. Antivirus/anti-spyware software are risk mitigation, not a guarantee.

Now - Skybird wanted to do some research. Nothing wrong with that - but he states that some sites he chose to "investigate". Simple things like - if its an unknown site with a .ru or .cn domain, you have to be cognizent that your exposing yourself to an even higher risk. Tread carefully - ask yourself if your willing to take the risk to investigate.

Next, the idea of "drive by" infection. Infections don't just "happen" - they require either human interaction (via a click to open or save a picture) or they are injected using scripts. If you choose to open an infected file and your "real time protection" doesn't catch the threat, your had. But what about scripts - the dreaded "drive by, I didn't click anything" infection?

TURN OFF SCRIPTING or set it to prompt you for permission before running. ActiveX especially for IE (since most exploits target the largest market share) is the biggest culprit. So many people don't do this - and then get hit with a drive by that used scripting to infect them.

One tool most end users don't know about (or choose not to use) is sandboxing. Its creating a memory space that can run an application (including web browsers) without allowing direct hard drive access. So if you do get an infection - and it doesn't get caught - when the sandbox is "flushed" - the virus goes away. It never gets out of the "box" of memory devoted to the application. Again - not a perfect technology (and you need decent amounts of RAM to be able to dedicate some to the sandbox) but it can often save you heartache. Its likely that a sandbox would have saved Skybird the frustration he now has. A company I worked for at one time took this to the extreme - the entire OS and all applications ran in a sandbox - so if anything ever happened you rebooted and your machine came up clean. That takes it too far for most users, but it does point to our next tip....

Expect an infection. What does this mean? Simply put, infections are a pill because they take time to get rid of, and if you don't do a full rebuild you will always wonder "did I get it all?". Build your machine with the OS and truly critical apps. Update it. Tweak it. Then make an image of it. That way, if you are infected your looking at a quick reimage with a few additional apps/games to install instead of a multi-hour build. Plan for failure and your recovery will be much quicker.

On that point - ideally you want to avoid failure. Or at least - avoid it on your prize PC. Don't be a dummy, use a dummy instead! If you want to be on the interwebz, consider using an old, crappy piece of junk to do your web surfing on. Don't expose your expensive rig to the uglies IF you have an old clunker to ride the information superhighway in. A PC with top specs isn't going to outperform a clunker on the web in most cases - because the limiting factor is the speed of your internet connection - not the pc. Sure your browser may start slower, but after that its going to be all about the data flow..... So if you have a clunker, use it. And don't worry gents, all those hot girls on the interwebz can't see your driving the pinto when you meet then online!

Of course - if your gaming online - using the clunker isn't an option. So use the gaming rig - but be disciplined. Don't go to links you don't know, don't open attachments or emails from people you are not sure of, etc.

Your brain is the first line of defence. Make good choices.

Oh - and for those that want them - there are some good, free tools out there for imaging and sandboxing.....
__________________
Good Hunting!

Captain Haplo
CaptainHaplo is offline   Reply With Quote
Old 08-15-12, 09:18 AM   #14
kiwi_2005
Eternal Patrol
 
Join Date: May 2004
Location: Aeoteroa
Posts: 7,382
Downloads: 223
Uploads: 1
Default

I made up my own security suite once and had this setup running for a while

Malwarebytes

Panda Cloud

McAfee SiteAdvisor
will give you update on sites you are entering

Microsoft Security Essentials

CCleaner,

Zonealarm firewall

Common sense

All the above is free, you now have yur own cowboy Security Suite.
__________________
RIP kiwi_2005



Those who can't laugh at themselves leave the job to others.



kiwi_2005 is offline   Reply With Quote
Old 08-15-12, 09:20 AM   #15
Skybird
Soaring
 
Skybird's Avatar
 
Join Date: Sep 2001
Location: the mental asylum named Germany
Posts: 40,514
Downloads: 9
Uploads: 0


Default

I know that all, Haplo, and I agree.

I am quite aware of security holes like scriptings, Java, and that you should not trust to click everything, everywhere. And like I repeatedly said: even modern security software does not detect especially this damn Zeus thing reliably - as a matter of fact latest Zeus incrantions defeat dsecurity software most oif thte time. My browser is pretty much closed up, almost on maximum settings, but tzhere is always the chance of human error: that I oversee to update Adobe Flash in time, or during some ordering process I needed to unlock cookies or some scriptiung setting , and afterwards forgot to close the door again.

The damn thing with drive-by attacks is that yiou must not do anything anym,ore to exceute malware. Simply ladning on the site already triggers the activation, you must not open a mail or click on a link on that site. It is like walking in town. You muts not ask people to cpough at you. If there is a sick person breathing once or twice in your neck and you are unlucky, you got infected. You can avoid that only by staying at home, and not going out.

I do like this on the web most of the time. But some risks simply mjust be taken, and maybe this time I have leaned myself out of the window in just the wrong place. Click one pic of a Chinese fighter on Google Picture Search - and voila. I played, I took a risk, and this time I got burned. It's been the first timne since many years, and I am lucky enough to have realised it within hours of daytime and minutes of computer operation time.

The one tnhbing I wanted to get over in my opening posting is that there are threads out there, like Zeus, where you cannot trust in your security software to protect you. Zeus beats it in 3 out of 4 events.

You swim at the beach, its holiday. When you do not meet Mr. Shark in the water, everything's fine and holiday continues. When you meet him, you are srewed. That'S how it is.

Much worse it becomes when you do not realsie that you have been compromised and that you have been assimilated by a zombienet. And I think that is the case with most people who caught an infection. They even do not realise it. I have, immediately, and reinstalled and changed my important passwords, for banking and buying tansactions, not for harmless forums. Time-consuming, but no financial damage done (so far). In the end, it just confirms me in my usual paranoia (shopping accounts, social networks, Google, and the like).
__________________
If you feel nuts, consult an expert.
Skybird is online   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 06:54 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.