Page 1 of 2 12 LastLast
Results 1 to 16 of 20

Thread: virus warning/anyone had this?

  1. #1
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,128
    Thanks
    605
    Thanked
    1,220 times in 1,121 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    virus warning/anyone had this?

    Battering my head against a virus here at work.

    It's being spread my memory sticks, via autorun.inf
    the memory stick infection is called ubs.exe (hidden, readonly, system file attributes) the icon is green cartoon fish

    when an infected stick is plugged into a pc it's generating 4 files, it takes the first 4 letters of the pc name to create a prefetch and exe (in c:\windows) and adds that to the startuplist.
    It also uses the first 6 letters of the pc name to create a 2nd prefetch and exe, this is the active running program that will infect any memory stick plugged in.

    So far it's been ease to manually stop and delete, ok there could be more of it hidden away, but stopping the (6 letter pc name) exe then maanually deleteing out the exe's and prefetches is stoping it running at startup and infecting clean memory sticks.

    However the big issue I've had is that Sophos (our anti-virus software) is not detecting it.
    So I've currently got no idea what it actually is.
    I've sent off a sample to Sophos and I'm going to try it out on a few other bits of anti-virus to see if it can go undetected by them.

    students and their infected usb sticks, dirty they just click on any link and open any email, no matter how many times we try to drum in into their thick skulls, they are still virus ridden breeding grounds.

    In 5 years time I pity the state computers and the net are going to be in if this is the state of future users.

  2. #2
    jim
    jim is offline
    HEXUS.clueless jim's Avatar
    Join Date
    Sep 2008
    Location
    Location: Location:
    Posts
    11,435
    Thanks
    612
    Thanked
    1,639 times in 1,304 posts
    • jim's system
      • Motherboard:
      • Asus Maximus IV Gene-Z
      • CPU:
      • i5 2500K @ 4.5GHz
      • Memory:
      • 8GB Corsair Vengeance LP
      • Storage:
      • 1TB Sandisk SSD
      • Graphics card(s):
      • ASUS GTX 970
      • PSU:
      • Corsair AX650
      • Case:
      • Silverstone Fortress FT03
      • Operating System:
      • 8.1 Pro
      • Monitor(s):
      • Dell S2716DG
      • Internet:
      • 10 Mbps ADSL

    Re: virus warning/anyone had this?

    I knew a girl at my old school - she asked if she could print something on my account, so I nodded, and she chucked her USB stick in. A Sophos warning comes up, and she says "Oh yeah, there's a virus on it. Just click OK".

    I could've swung for her, seriously. Apparently it had been there for months, but hey! Why bother clearing it off - doesn't affect the USB stick does it?

  3. #3
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: virus warning/anyone had this?

    it sounds like a new variant of conficker to me.
    □ΞVΞ□

  4. #4
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,128
    Thanks
    605
    Thanked
    1,220 times in 1,121 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    Re: virus warning/anyone had this?

    Yes, that's what I've been thinking, the fact sophos isn't picking it up is what's worrying me.

    Oh and the students cannot manually scan their memory sticks, we had to remove direct anti-virus access, because otherwise they just turned it off

  5. #5
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: virus warning/anyone had this?

    on a side note you can stop idiots turning sophos off by changing the settings at the management console on the server.
    □ΞVΞ□

  6. #6
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,027 times in 678 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS

    Re: virus warning/anyone had this?

    Quote Originally Posted by snootyjim View Post
    I knew a girl at my old school - she asked if she could print something on my account, so I nodded, and she chucked her USB stick in. A Sophos warning comes up, and she says "Oh yeah, there's a virus on it. Just click OK".

    I could've swung for her, seriously. Apparently it had been there for months, but hey! Why bother clearing it off - doesn't affect the USB stick does it?
    That's why the STD rate is so high in this country too. Don't ask me to quote what I overheard from sister-in-law's friend.

  7. #7
    Welcome to stampytown! Salazaar's Avatar
    Join Date
    Dec 2004
    Location
    Oxford-ish
    Posts
    4,459
    Thanks
    505
    Thanked
    353 times in 254 posts
    • Salazaar's system
      • Motherboard:
      • Asrock B450m Steel Legend
      • CPU:
      • Ryzen 5 3600
      • Graphics card(s):
      • 5700 XT

    Re: virus warning/anyone had this?

    Quote Originally Posted by directhex View Post
    Don't ask me to quote what I overheard from sister-in-law's friend.
    No, that's not right... Now you have to tell us!
    ____
    (='.'=)
    (")_(")

  8. #8
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,128
    Thanks
    605
    Thanked
    1,220 times in 1,121 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    Re: virus warning/anyone had this?

    Quote Originally Posted by Jay View Post
    on a side note you can stop idiots turning sophos off by changing the settings at the management console on the server.
    Yep that's what we've done unfortunately due to our setup this means it also blocks basic users from running manual scans, so it just sits in the background quarantining anything it spots.
    The issue here is sophos is not spotting it in the first place, even manual scans is not finding it.

  9. #9
    jim
    jim is offline
    HEXUS.clueless jim's Avatar
    Join Date
    Sep 2008
    Location
    Location: Location:
    Posts
    11,435
    Thanks
    612
    Thanked
    1,639 times in 1,304 posts
    • jim's system
      • Motherboard:
      • Asus Maximus IV Gene-Z
      • CPU:
      • i5 2500K @ 4.5GHz
      • Memory:
      • 8GB Corsair Vengeance LP
      • Storage:
      • 1TB Sandisk SSD
      • Graphics card(s):
      • ASUS GTX 970
      • PSU:
      • Corsair AX650
      • Case:
      • Silverstone Fortress FT03
      • Operating System:
      • 8.1 Pro
      • Monitor(s):
      • Dell S2716DG
      • Internet:
      • 10 Mbps ADSL

    Re: virus warning/anyone had this?

    Quote Originally Posted by directhex View Post
    That's why the STD rate is so high in this country too. Don't ask me to quote what I overheard from sister-in-law's friend.
    Directhex, could you paraphrase what you overheard from your sister-in-law's friend?


  10. #10
    HEXUS.timelord. Zak33's Avatar
    Join Date
    Jul 2003
    Location
    I'm a Jessie
    Posts
    35,157
    Thanks
    3,105
    Thanked
    3,138 times in 1,916 posts
    • Zak33's system
      • Storage:
      • Kingston HyperX SSD, Hitachi 1Tb
      • Graphics card(s):
      • Nvidia 1050
      • PSU:
      • Coolermaster 800w
      • Case:
      • Silverstone Fortress FT01
      • Operating System:
      • Win10
      • Internet:
      • Zen FTC uber speedy

    Re: virus warning/anyone had this?

    can you upload it to this to check what it is?

    http://www.virustotal.com/ seems to know loads of stuff that PC pre loads don't

    Quote Originally Posted by Advice Trinity by Knoxville
    "The second you aren't paying attention to the tool you're using, it will take your fingers from you. It does not know sympathy." |
    "If you don't gaffer it, it will gaffer you" | "Belt and braces"

  11. #11
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: virus warning/anyone had this?

    I think its the Kavo virus
    □ΞVΞ□

  12. #12
    PHP Geek Flash477's Avatar
    Join Date
    Dec 2008
    Location
    Devon
    Posts
    822
    Thanks
    51
    Thanked
    72 times in 65 posts

    Re: virus warning/anyone had this?

    Have you sent a sample of the virus to Sophos?

  13. #13
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: virus warning/anyone had this?

    Quote Originally Posted by Pob255 View Post
    I've sent off a sample to Sophos and I'm going to try it out on a few other bits of anti-virus to see if it can go undetected by them.
    I think he has...
    □ΞVΞ□

  14. #14
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    653 times in 482 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: virus warning/anyone had this?

    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  15. #15
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,128
    Thanks
    605
    Thanked
    1,220 times in 1,121 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    Re: virus warning/anyone had this?

    Quote Originally Posted by Jay View Post
    I think he has...
    I tried but it got bounced by our e-mail filter

    What more it gets worse, after some digging around in the management console, I think I found the reason sophos was not spotting it.
    The reason comes from HIPS scanning, we had HIPS turned off because it was constantly clashing with our internet filtering+user monitoring+logon scripts+remote control+network installation of software. (pretty much every part of bing on a network sophos thinks is some form of hijack or virus)

    Guess what this virus uses to spread?

    So I've turned HIPS scanning back on, went through adding all the known network things to the exceptions list, no doubt we'll get loads of calls on manday from people who cannot log on.
    And to install any new software is going to be a total for us.

    Well there goes all my Friday, there's time I want to the servers, just to force the issue and get it redone from scratch rather than trying to nurse it along.

  16. #16
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: virus warning/anyone had this?

    I know how you feel mate, I have a datacenter I feel like that about
    □ΞVΞ□

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Netskyb virus...
    By streetster in forum General Discussion
    Replies: 18
    Last Post: 10-03-2004, 04:00 PM
  2. Advice needed Re: Virus plz :)
    By Lujan in forum Software
    Replies: 2
    Last Post: 02-03-2004, 02:44 PM
  3. The AOL virus :D
    By Alex in forum General Discussion
    Replies: 2
    Last Post: 07-02-2004, 04:10 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •