January 16, 2010

Major virus spyware activity Gumblar Vundo overlay.xul

Filed under: News — admin @ 6:27 pm

Jan this year was fun, a variant of Vundo and Gumblar came roaring back.  It infected my desktop and 70 of my websites before I know it was even here.  It happened on Jan 14th to me, but looks like it was unleashed around December 2009 January 2010.   It redirected google results to ad pages but not all of the time if I backed out and clicked again it would let me through.  From what I can tell this is the largest attack in a while and a major security breach, stealing passwords and usernames from all kind of programs, ftp seems like its preferred data so it can spread itself and take over your websites.

Here is a link to the tool I used to remove the rogue code from over 7000 files it infected of mine in 1 day.   http://justcoded.com/article/gumblar-family-virus-removal-tool/

I believe mine came in with a variant of the Vundo trojan and installed a variant of the gumblar spyware.

http://en.wikipedia.org/wiki/Gumblar<

http://en.wikipedia.org/wiki/Vundo<

It seems to be Asia and now migrating to the U.S.

;Gumblar botnet builder resurfaces with a vengeance<

http://www.mxlogic.com/securitynews/viruses-worms/gumblar-botnet-builder-resurfaces-with-a-vengeance335.cfm

Thursday, January 7, 2010

Though security researchers had believed it to be more or less dormant, the Gumblar malware came storming back into prominence at the turn of the decade, performing what Softpedia calls a “mass injection attack” on computers and websites around the world.

Sunday, Jan. 10, 2010

Police begin Gumblar virus probe
http://search.japantimes.co.jp/cgi-bin/nn20100110a7.html

Kyodo News

Tokyo police have begun investigating suspected cases of unauthorized Internet access after a number of companies reported that their Web sites had been altered, apparently by the Gumblar computer virus and its variants, Metropolitan Police Department officials said.

The department’s high-tech crime investigators believe IDs and passwords were used to access the sites in many of the cases that have been reported since mid-December. Viewers of these altered sites were redirected to other Web sites containing malicious software.

Hackers Compromise Fox Sports Website
http://www.spamfighter.com/News-13713-Hackers-Compromise-Fox-Sports-Website.htm

According to a warning released by security researchers, the Fox Sports website, an integral part of the Fox Broadcasting Company, has gone under the control of unknown hackers. The hackers injected malware inside the ‘custom error’ section of the site. Two different malicious codes have been found, each as a result of a different infection.

and the best article I found so far is from Scansafe -

To load the malware from the backdoored websites, tens of thousands of other compromised websites have had malicious iframes embedded. Alarmingly, Web surfers who visit one of these conduit sites will be exposed to a collection of exploits designed to silently install the Gumblar malware.  On Windows systems, the installed malware loads when sound-enabled sites or devices are accessed.  It also injects itself into the Internet Explorer process and intercepts all Web traffic to and from the computer.  Any captured FTP credentials are sent to the attacker thus furthering the growth of the Gumblar website botnet.

 

Party Crashers

Filed under: Uncategorized — admin @ 2:40 pm

Everyone knows there has been some party crashing happening lately, but now it is striking closer at home. Nobody seems responsible or can figure out how they got it but the pictures from the events tell the story.

January 8, 2010

New toy

Filed under: Local Events — admin @ 1:02 am

Should be fun

toy.jpg

and always a classic window sticker….

2a.jpg

December 7, 2009

What are my old neighbors up to?

Filed under: Local Events — admin @ 9:31 pm

This is kind of funny, kind of sad.  Some local yocal neighbors down on KI Sawyer were busted trying to extort money from John Stamos!  FBI showed up instead and arrested them.

http://www.thesmokinggun.com/archive/years/2009/1207091mrx1.html

Scott Edward Sippola and Allison Lenore Coss have been named in a federal investigation involving a television and Broadway actor.
Monday, December 07, 2009 at 4:39 p.m.

MARQUETTE COUNTY — A Marquette man and woman are the target of a criminal complaint for internet extortion.

Scott Edward Sippola and Allison Lenore Coss have been named in a federal investigation involving a television and Broadway actor.

The name of the celebrity is not in the federal court documents.

He’s referred to as Mr. X.

Sippola and Coss are both charged with intent to extort money from a person, transmitted in interstate commerce, a communication containing a threat to injure the reputation of another person.

The complaint states that on or about November 28 of this year, Mr. X contacted the FBI office in Nashville saying he was the subject of a scheme to extort money from him.

In the complaint, it says Mr. X was vacationing in Florida in 2004 and met Allison Coss and a friend he knew as ‘Qynn’.

Mr. X attended a party with them, and photographs were taken during the party.

Through a series of emails with a ‘Brian L”, the complaint says a threat was made to sell the pictures to the media if Mr. X did not buy them for $680,000.

Last Wednesday, the FBI set up a meeting with ‘Brian L’ at Sawyer International Airport in the area of Boreal Aviation to exchange the money.

Coss and Sippola were in a pick-up truck in the area of the meeting.

They were both arrested.

They have a preliminary hearing in Federal District Court set for December 17 in Marquette.

December 6, 2009

Snow Shoveled

Filed under: Snowmobiling — admin @ 3:30 am

The never ending battle of the snow plow berm vs my shovel.  If you drive over the berm or it warms up and freezes again it wins…

snow.jpg

December 5, 2009

Christmas must be around the corner…

Filed under: Work — admin @ 12:21 am

04122009209.jpg

Next Page »