Page 1 of 2 12 LastLast
Results 1 to 16 of 21

Thread: Just got Infected

  1. #1
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Just got Infected

    With this Trojan.

    https://www.theregister.co.uk/2017/0...ner_downloads/

    Avast didn't pick it up at all, but Malwarebytes did.
    What's the current thinking on free AV ? Do I have to bite the bullet and pay ?

    If so, recommendations gratefully received.
    Society's to blame,
    Or possibly Atari.

  2. #2
    Studmuffin Flibb's Avatar
    Join Date
    Jul 2003
    Location
    Kent
    Posts
    4,904
    Thanks
    31
    Thanked
    324 times in 277 posts
    • Flibb's system
      • Motherboard:
      • Gigabyte GA-970A-UD3
      • CPU:
      • AMD FX-6300
      • Memory:
      • 16GB Crucial Ballistix DDR3 PC3-12800
      • Storage:
      • Samsung SSD 840 EVO 250G
      • Graphics card(s):
      • 3GB MSI Radeon HD 7950 Twin Frozr
      • PSU:
      • FSP
      • Operating System:
      • Win7 64bit
      • Monitor(s):
      • Deffl TFT thing

    Re: Just got Infected

    Some bank accounts offer free AV, think Barclays give free McAfee

    Sent from my SM-G950F using Tapatalk

  3. #3
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Just got Infected

    Good call. I'll check.
    (Lloyds btw)

    EDIT: Apparently not.
    Society's to blame,
    Or possibly Atari.

  4. #4
    Senior Member
    Join Date
    Jan 2009
    Posts
    281
    Thanks
    15
    Thanked
    15 times in 11 posts

    Re: Just got Infected

    This may not be too helpful (sorry) but many of the big AV names give very sizeable discounts over the Black Friday / Monday period coming up soon. But, lasts a year, do same again the next year.

    In the meantime there there a many good free alternatives. If you google Free AV reviews there will be a lot of information on the best ones.

  5. Received thanks from:

    Phage (19-09-2017)

  6. #5
    Senior Member
    Join Date
    Aug 2013
    Location
    North Wales
    Posts
    1,849
    Thanks
    165
    Thanked
    271 times in 202 posts
    • virtuo's system
      • Motherboard:
      • Gigabyte Aorus Master X570
      • CPU:
      • Ryzen 9 5950x
      • Memory:
      • 64Gb G.Skill TridentZ Neo 3600 CL16
      • Storage:
      • Sabrent 2TB PCIE4 NVME + NAS upon NAS upon NAS
      • Graphics card(s):
      • RTX 3090 FE
      • PSU:
      • Corsair HX850 80+ Platinum
      • Case:
      • Fractal Meshify 2 Grey
      • Operating System:
      • RedStar 3, Ubuntu, Win 10
      • Monitor(s):
      • Samsung CRG90 5140x1440 120hz
      • Internet:
      • PlusNet's best, but still poor, attempt

    Re: Just got Infected

    Can we ask what you were doing when you picked it up? I find the free AVs are good enough, especially combined with some common sense/best practice when browsing/downloading.

  7. #6
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Just got Infected

    It's in the article I linked to above. Essentially a software provider (now owned by Avast !) was compromised and it's servers dished out infected updates.
    Quite similar to the Ukrainian attack recently.
    Society's to blame,
    Or possibly Atari.

  8. #7
    Super Moderator Jonj1611's Avatar
    Join Date
    Jun 2008
    Posts
    5,722
    Thanks
    1,763
    Thanked
    996 times in 763 posts

    Re: Just got Infected

    Barclays give Kaspersky

    Have Kaspersky running on the kids pc's and Norton on mine(laugh if you will)
    Jon

  9. #8
    root Member DanceswithUnix's Avatar
    Join Date
    Jan 2006
    Location
    In the middle of a core dump
    Posts
    12,986
    Thanks
    781
    Thanked
    1,588 times in 1,343 posts
    • DanceswithUnix's system
      • Motherboard:
      • Asus X470-PRO
      • CPU:
      • 5900X
      • Memory:
      • 32GB 3200MHz ECC
      • Storage:
      • 2TB Linux, 2TB Games (Win 10)
      • Graphics card(s):
      • Asus Strix RX Vega 56
      • PSU:
      • 650W Corsair TX
      • Case:
      • Antec 300
      • Operating System:
      • Fedora 39 + Win 10 Pro 64 (yuk)
      • Monitor(s):
      • Benq XL2730Z 1440p + Iiyama 27" 1440p
      • Internet:
      • Zen 900Mb/900Mb (CityFibre FttP)

    Re: Just got Infected

    Quote Originally Posted by Phage View Post
    If so, recommendations gratefully received.
    I think it is just a mess, to the point that some are saying you can be better off without it: https://arstechnica.co.uk/informatio...ivirus-is-bad/

    Until they messed up recently, I was tending towards "just use what Microsoft ships, at least it integrates properly".

    So bad luck this time, better luck next time, but AV seems to be a bit of a dice roll.

    Or you can switch to Linux, forget about AV and have a whole bunch of different problems

    My Windows boxes use Avast but I don't install any of the addons, so *hopefully* I got away with it this time.

  10. #9
    Registered User
    Join Date
    Sep 2017
    Posts
    1
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: Just got Infected

    My advice would be get yourself Norton, I can't recommend many others as many others* install their own Certificate Authority which breaks various protections server admins add to their server (HPKP), and if you remember this is basically what the Lenovo Superfish was, so they could inject ads into encrypted sites.
    I also use the Premium version of Malwarebytes as it has Anti-Exploit (Like EMET) as a second layer of protection.

    *Kaspersky, BitDefender, AVG, Avast (from memory)

    Kind regards

    Lloyd

    (No I don't work for Norton lol)

  11. #10
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,143
    Thanks
    608
    Thanked
    1,226 times in 1,123 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    Re: Just got Infected

    I gave the free thing my bank keeps bugging me to use every time I log in (ibm trusteer rapport) . . . it increased the load time of every web page by 2-5 seconds.

    It could well of been conflicting with something else, I'd not be surprised, but that makes it worse and it didn't stay on my pc for long.

    when you say Avast didn't spot it, was that after a manual scan of your system, or just the active, running in the background

  12. #11
    Senior Member Smudger's Avatar
    Join Date
    Oct 2005
    Location
    St Albans
    Posts
    3,866
    Thanks
    674
    Thanked
    619 times in 451 posts
    • Smudger's system
      • Motherboard:
      • Gbyte GA-970A-UD3P
      • CPU:
      • AMD FX8320 Black Edition
      • Memory:
      • 16GB 2x8G CML16GX3M2A1600C10
      • Storage:
      • 1x240Gb Corsair M500, 2TB TOSHIBA DT01ACA200
      • Graphics card(s):
      • XFX Radeon HD4890 1GB
      • PSU:
      • Corsair HX520
      • Case:
      • Akasa Zen
      • Operating System:
      • Windows 10 Home
      • Monitor(s):
      • Dell 24"
      • Internet:
      • Virgin 200Mbit

    Re: Just got Infected

    I knew there was a reason I was ignoring the CCleaner update notifications... Looks like I might have dodged a bullet here, but I'll have to check when I get home. It comes to something when an AV company is delivering trojans to you...

  13. Received thanks from:

    Phage (19-09-2017)

  14. #12
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Just got Infected

    Quote Originally Posted by Pob255 View Post
    I gave the free thing my bank keeps bugging me to use every time I log in (ibm trusteer rapport) . . . it increased the load time of every web page by 2-5 seconds.

    It could well of been conflicting with something else, I'd not be surprised, but that makes it worse and it didn't stay on my pc for long.

    when you say Avast didn't spot it, was that after a manual scan of your system, or just the active, running in the background
    Neither I'm afraid. Not when running in the background, nor when I did a manual scan yesterday
    Last edited by Phage; 19-09-2017 at 02:01 PM.
    Society's to blame,
    Or possibly Atari.

  15. #13
    Senior Member Pob255's Avatar
    Join Date
    Apr 2007
    Location
    The land of Brum
    Posts
    10,143
    Thanks
    608
    Thanked
    1,226 times in 1,123 posts
    • Pob255's system
      • Motherboard:
      • Asus M5A99X EVO
      • CPU:
      • FX8350 & CM Hyper 212+
      • Memory:
      • 4 x 2gb Corsair Vengence 1600mhz cas9
      • Storage:
      • 512gb samsung SSD +1tb Samsung HDD
      • Graphics card(s):
      • EGVA GTX970
      • PSU:
      • Seasonic GX 650W
      • Case:
      • HAF 912+
      • Operating System:
      • W7 Pro
      • Monitor(s):
      • iiyama XB3270QS-B1 32" IPS 1440p

    Re: Just got Infected

    Quote Originally Posted by Phage View Post
    Neither I'm afraid. Not when running in the background, or when I did a manual scan yesterday
    not great
    Still that's why I keep malwarebytes around the free manual scan only version.

    Although on a side note I updated malwarebytes recently and it automatically upgraded to a free trial of the paid for active version, it's easy to downgrade back, something too keep an eye out for.
    multiple active AV is a fast recipe to cripple the performance of any machine.

  16. #14
    Senior Member
    Join Date
    Dec 2013
    Location
    Cymru
    Posts
    309
    Thanks
    152
    Thanked
    47 times in 45 posts
    • satrow's system
      • Motherboard:
      • ASRock Z77E-ITX
      • CPU:
      • Ivy Xeon 1230 v2/Be Quiet Shadow Rock Topflow
      • Memory:
      • GSkill 2x8GB DDR3 2400Mhz
      • Storage:
      • 3x 256GB SSDs, 2x 1TB 2.5" HDDs.
      • Graphics card(s):
      • Asus blower GTX 1060 6GB
      • PSU:
      • Seasonic 360W Gold
      • Case:
      • BitFenix Prodigy/2x 120mm fans
      • Operating System:
      • W7x64 Pro
      • Monitor(s):
      • Dual (/triple) Dell U2412M 1900x1200
      • Internet:
      • TalkTalk FTTC ~14Mbps

    Re: Just got Infected

    Trusteer's Rapport can be a nightmare, esp. where any non-mainstream software/drivers are involved. Might be okay on managed corporate machines but I don't recommend it for home use.

    My understanding is that the Ccleaner infection only affected a proportion of x86 installs; only the Cloud version was auto-infected and only if the update check was connected to one compromised Piriform server. The manual update infections also required a download from the same infected server, though some 3rd party software hosting sites also had/have the infected version. x64 Windows installs were not infected.

    Nothing detected this infection for weeks; though a good firewall/HIPS should have prevented the connection being made to the C&C server. Free/paid AV/security is still a lottery, nothing will detect all Zero days and overall detection rates will vary according to how good the detection engine is and how good the latest definitions are. You can build a free security 'suite' that's as good as, maybe better than, a paid suite - but it takes a lot of time and experience to research the options and regular free time to ensure each piece of the jigsaw is updated at least once per day.

    For the companies that are now claiming their 'advanced heuristics' are the best thing since sliced bread - remember that heuristics = guesswork and watch out for unrelated false positives, esp. where non-mainstream software is flagged up.

  17. #15
    Pork & Beans Powerup Phage's Avatar
    Join Date
    May 2009
    Location
    Kent
    Posts
    6,260
    Thanks
    1,618
    Thanked
    608 times in 518 posts
    • Phage's system
      • Motherboard:
      • Asus Crosshair VIII
      • CPU:
      • 3800x
      • Memory:
      • 16Gb @ 3600Mhz
      • Storage:
      • Samsung 960 512Gb + 2Tb Samsung 860
      • Graphics card(s):
      • EVGA 1080ti
      • PSU:
      • BeQuiet 850w
      • Case:
      • Fractal Define 7
      • Operating System:
      • W10 64
      • Monitor(s):
      • Iiyama GB3461WQSU-B1

    Re: Just got Infected

    Ahem - This is a x64 machine
    Society's to blame,
    Or possibly Atari.

  18. #16
    Senior Member
    Join Date
    Dec 2013
    Location
    Cymru
    Posts
    309
    Thanks
    152
    Thanked
    47 times in 45 posts
    • satrow's system
      • Motherboard:
      • ASRock Z77E-ITX
      • CPU:
      • Ivy Xeon 1230 v2/Be Quiet Shadow Rock Topflow
      • Memory:
      • GSkill 2x8GB DDR3 2400Mhz
      • Storage:
      • 3x 256GB SSDs, 2x 1TB 2.5" HDDs.
      • Graphics card(s):
      • Asus blower GTX 1060 6GB
      • PSU:
      • Seasonic 360W Gold
      • Case:
      • BitFenix Prodigy/2x 120mm fans
      • Operating System:
      • W7x64 Pro
      • Monitor(s):
      • Dual (/triple) Dell U2412M 1900x1200
      • Internet:
      • TalkTalk FTTC ~14Mbps

    Re: Just got Infected

    Quote Originally Posted by Phage View Post
    Ahem - This is a x64 machine
    So the detection was of the installer, not the infection?

    Do you have an HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\Agomo key?

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •