General Chat

Top tip - using the Genes Reunited community

Welcome to the Genes Reunited community boards!

  • The Genes Reunited community is made up of millions of people with similar interests. Discover your family history and make life long friends along the way.
  • You will find a close knit but welcoming group of keen genealogists all prepared to offer advice and help to new members.
  • And it's not all serious business. The boards are often a place to relax and be entertained by all kinds of subjects.
  • The Genes community will go out of their way to help you, so don’t be shy about asking for help.

Quick Search

Single word search

Icons

  • New posts
  • No new posts
  • Thread closed
  • Stickied, new posts
  • Stickied, no new posts

New Computer Threat virus

ProfilePosted byOptionsPost Date

Staffs Col

Staffs Col Report 15 May 2009 10:48

The following is from Yahoo news this morning:

A complex new malware attack is setting infection records and raising serious alarms in the security community.


Known unofficially as 'Gumblar' for one of the attack domains, the malware uses prolific attack methods and carries a dangerous payload.

Researchers say that the attack spreads by compromising web sites and injecting malicious JavaScript code into certain components of the site. A victim runs the risk of the JavaScript attack simply by visiting the infected pages.

Once a site is compromised, the malware alters access credentials and folder permissions to allow an attacker a 'back door' for entry to the site even when the user has changed passwords. The malicious code is also altered in slight ways, preventing administrators from automatically searching out and deleting the scripts.

Because the infection is so hard to get rid of, researchers say that Gumblar has enjoyed far more success than previous malware attacks.

First detected in late March, researchers thought that the attacks had been halted by mid-April when Google delisted the offending sites.

However, a new variant of the attack arose early this month and has been spreading rapidly. Security firm ScanSafe estimates that Gumblar attacks have jumped some 188 per cent over the past week alone, and Sophos credits Gumblar with up to 42 per cent of all malware infections in the past seven days.

"The gross infection rate is exceptional, especially this late in the game," said Mary Landesman, senior security researcher at ScanSafe. "Basically, it has been enjoying a free reign."

The payload is also believed to be highly dangerous. Landesman said that the malware intercepts web traffic such as Google search requests, and redirects it to fraudulent results. This allows the attackers to collect referral fees, and places the user at risk of further infection.

The malware also contains botnet controllers and is programmed to collect all FTP permissions on the infected systems, allowing Gumblar to infect any sites which the user administrates, further fostering the spread to new domains.

****MO***Rocking***Granny****

****MO***Rocking***Granny**** Report 15 May 2009 13:30

Many thanks for this info

ShimmsRedRoseAndMistletoe

ShimmsRedRoseAndMistletoe Report 15 May 2009 15:07

Hi Col

Thank you.

I use Norton, will that be able to protect me please?

xxx Shimms xxx

Meriwether

Meriwether Report 15 May 2009 16:10

This is worrying. My virus protection is updated daily, and my firewall is often telling me that it is blocking my computer from being scanned.

I know my Anti-Virus company is amongst the best, but whatever they do, there is always some so-called genius computer expert putting him/herself to ill use - often for money, sometimes for the hell of it - who will do their best to override all defense efforts.

ShimmsRedRoseAndMistletoe

ShimmsRedRoseAndMistletoe Report 15 May 2009 17:10

Oh MGHS ►►►

Thank you, it sounds very worrying. I do comprehensive scans on a regular basis, Norton does its own yet I like to be 'on top' if that makes sense. My web addys are protected too, will phish anything they don't recognise.

Trojan ... sounds very nasty indeed. :((

xxx

Doesn't it just Meri. I turned Windows Firewall off, have Norton protecting me. xxx

Sue in Somerset

Sue in Somerset Report 15 May 2009 19:46

This may help people.

http://www.pcworld.com/article/164899/new_wave_of_gumblar_hacked_sites_installs_googletargeting_malware.html

It sounds as if you will be best protected if you keep updated.

Sue