Posting mode: Reply
[Return]
Name
E-mail
Subject
Comment
Verification
Get a new challenge Get an audio challengeGet a visual challenge Help
File
Password(Password used for file deletion)
  • Supported file types are: GIF, JPG, PNG
  • Maximum file size allowed is 3072 KB.
  • Images greater than 250x250 pixels will be thumbnailed.
  • Read the rules and FAQ before posting.
  • このサイトについて - 翻訳


  • File : 1304298080.png-(120 KB, 1360x725, ohshit.png)
    120 KB Anonymous 05/01/11(Sun)21:01 No.17267424  
    oh shit, they are getting smarter! I clicked a random google image and it shrunk the size of my firefox browser and this popped up.
    >> Anonymous 05/01/11(Sun)21:02 No.17267447
    Injection into sites with determination of whether it's in a frameset (user on google images) or outside of one (google image bot browsing for images).

    Very common. Google images is somewhat perilous these days as a resutl.
    >> Anonymous 05/01/11(Sun)21:04 No.17267464
    >he allows javascript to resize his windows
    >> Anonymous 05/01/11(Sun)21:04 No.17267474
    If you've already visited the page and have downloaded the file, can you give me a copy of the infected exe?
    >> Anonymous 05/01/11(Sun)21:04 No.17267477
    >isn't running NoScript
    welp
    >> Anonymous 05/01/11(Sun)21:06 No.17267497
    >.cz.cc
    Seems legit, Microsoft does a lot of outsoucing these days
    >> Anonymous 05/01/11(Sun)21:06 No.17267502
    >he has java installed
    >2011
    >> Anonymous 05/01/11(Sun)21:06 No.17267515
         File1304298414.png-(198 KB, 1280x800, Screenshot-2.png)
    198 KB
    feels good to be part of the linux master race
    >> Anonymous 05/01/11(Sun)21:07 No.17267519
    >>17267502
    How do you know for a fact that he has Java installed? I see no indication of it from the OP image.
    >> Anonymous 05/01/11(Sun)21:07 No.17267530
    >>17267515
    Can you upload a copy of BestAntivirus2011.Exe to mediafire for me to fuck around with?
    >> Anonymous 05/01/11(Sun)21:08 No.17267536
    >>17267515
    That page is awesome. The source is actually pretty funny if you like that sort of thing.
    >> Anonymous 05/01/11(Sun)21:08 No.17267539
    a metric fuckload of image results lead to some fake security scan site

    the one that tries to keep you from leaving with a dialog box. i hate that shit so much. i want to block alert scripts entirely.
    >> Anonymous 05/01/11(Sun)21:08 No.17267540
    >>17267519
    Did you somehow miss the large white rectangle that is trying to scare OP into clicking OK?
    >> Anonymous 05/01/11(Sun)21:08 No.17267545
    >>17267530
    Never mind, downloaded in a VM. Virustotlan now.
    >> Anonymous 05/01/11(Sun)21:09 No.17267549
    >>17267530
    just download it from the website but dont execute it.
    >> Anonymous 05/01/11(Sun)21:09 No.17267556
    I got one of those today in a Google image search as well
    >> Anonymous 05/01/11(Sun)21:09 No.17267563
    >>17267549
    In some cases, these sites use Java/Flash/Adobe Reader/Windows vulnerabilities to elevate + autoexecute automatically.

    Fully up to date, but could have a zero day.
    >> Anonymous 05/01/11(Sun)21:10 No.17267565
    >/fa/
    How the fuck did you fags miss this? Obvious fucking hipster Firefox user, Go back to >>>/fa/.
    >> Anonymous 05/01/11(Sun)21:10 No.17267575
    Detection is pretty bad, I'm submitting to microsoft and avira.
    >> Anonymous 05/01/11(Sun)21:12 No.17267601
    >>17267565
    They have a pretty nice guide on what clothes to wear if you don't want to look like a child.
    >> Anonymous 05/01/11(Sun)21:12 No.17267603
    >>17267545
    Post link/hash when done.
    >> Anonymous 05/01/11(Sun)21:13 No.17267611
    >>17267603
    http://www.virustotal.com/file-scan/report.html?id=2652630b329aa4231baa72368645cea1dfc07e162a6752a4d
    dad62efb68410af-1304298547

    8/42. Microsoft is testing the file now.
    >> Anonymous 05/01/11(Sun)21:13 No.17267613
    >intro to algebra
    >spark notes
    >/fa/
    confirmed for 8th grade faggot
    >> Anonymous 05/01/11(Sun)21:13 No.17267617
    >>17267613
    algorithms dumbshit
    >> Anonymous 05/01/11(Sun)21:15 No.17267636
         File1304298936.png-(154 KB, 967x819, Untitled.png)
    154 KB
    >> Anonymous 05/01/11(Sun)21:15 No.17267638
    >>17267611
    How about the box? What does the program do? Any data going in/out? Thread has me interested. I fucking hate this shit but can't resist knowing how others get away with this.
    >> Anonymous 05/01/11(Sun)21:17 No.17267671
    Avira took the file in, but they're pretty slow.

    File if anybody wants it:
    http://www.mediafire.com/?n4itugart8yp4c7

    ZIP Password is "infected". This is a torjan. DOn't download unless you know what the fuck you're doing.

    >>17267638
    Ah, well, I used the VM as a potential sacrifice in case there was an exploit. I could burn the box, I suppose... let me shutdown and make a copy of the VM before proceeding.
    >> Anonymous 05/01/11(Sun)21:21 No.17267719
    >>17267671
    I'm pretty sure that true /g/entoomen know what they're doing.

    And people who don't... they deserve it.
    >> Anonymous 05/01/11(Sun)21:22 No.17267742
    copying my vm, here's the CWSandbox report in the meantime (may take a couple minutes to process):
    http://www.sunbeltsecurity.com/cwsandboxreport.aspx?id=12077122&cs=48CBBC0AEBF39180762A1FB43CB6D
    81E

    Anubis report incoming:
    http://anubis.iseclab.org/?action=result&task_id=11f8a84d15a1d0dc411969ac15c958bf1&call=firs
    t
    >> Anonymous 05/01/11(Sun)21:23 No.17267759
         File1304299419.jpg-(128 KB, 1800x1272, how.jpg)
    128 KB
    >>17267515

    At least they put some effort into it, right?
    >> Anonymous 05/01/11(Sun)21:24 No.17267778
    >>17267742
    Sigh. CWSandbox reports make it look likely that there's VM detection in place.
    >> Anonymous 05/01/11(Sun)21:25 No.17267797
    >>17267671
    I don't have a box on hand to destroy and no Windows install discs around atm, Otherwise I would do it myself.

    >>17267742
    Neat.
    >> Anonymous 05/01/11(Sun)21:28 No.17267836
         File1304299681.png-(32 KB, 416x261, fun.png)
    32 KB
    >>17267797
    I hear ya. Say, any suggestions on how to filter down wireshark to only show activity from a particular EXE (virtual box)?

    >>17267759
    True.
    >> Anonymous 05/01/11(Sun)21:30 No.17267888
    >>17267836
    Never mind. I think I can watch the virtual net adapter instead.
    >> Anonymous 05/01/11(Sun)21:31 No.17267914
    Anubis barked on the VM detection as well. I wonder if this'll react to virtualbox.
    >> Anonymous 05/01/11(Sun)21:34 No.17267968
    >>17267540
    are you aware that java and javascript are two different and unrelated languages?
    >> Anonymous 05/01/11(Sun)21:35 No.17267979
    >>17267540
    You're a fucking idiot.
    >> Anonymous 05/01/11(Sun)21:37 No.17268025
    Backed up the VDI, awaiting VirutalBox to finish updating.

    Precaution - sometimes VMs have holes.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:39 No.17268053
         File1304300368.png-(198 KB, 1366x768, Windows XP Professional-2011-0(...).png)
    198 KB
    My fresh XP install has so many viruses, i must buy xp total security 2011!
    >> Anonymous 05/01/11(Sun)21:39 No.17268056
    >>17268025
    I learned this the hard way from Microsoft's virtual machine. The older 2005 version anyway, Long ago. I switched to VirtualBox and never had any problems but the simplicity and accessibility is kinda gone.
    >> Anonymous 05/01/11(Sun)21:40 No.17268069
    >>17268053
    lol'd.
    >> Anonymous 05/01/11(Sun)21:41 No.17268085
         File1304300493.png-(1.12 MB, 1040x848, meh2.png)
    1.12 MB
    >>17268056
    Yeah. VM's booted, I'm updating the additions to the guest.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:41 No.17268094
         File1304300518.png-(89 KB, 1366x768, Windows XP Professional-2011-0(...).png)
    89 KB
    This is its efforts to stop me opening add/remove programs :/
    >> Anonymous 05/01/11(Sun)21:43 No.17268120
         File1304300596.png-(440 KB, 1040x850, rebootan.png)
    440 KB
    >>17268085
    Rebooting, then...adventure awaits!
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:44 No.17268140
         File1304300661.png-(87 KB, 640x480, Windows XP Professional-2011-0(...).png)
    87 KB
    Even opens in safe mode, crafty.
    >> Anonymous 05/01/11(Sun)21:45 No.17268170
         File1304300748.png-(914 KB, 816x681, alrighty.png)
    914 KB
    >>17268120
    No antivirus in the VM. Go naked or install something? We know MSE and Avira won't catch it, but will the virus stop them from running?

    Thoughts?
    >> Anonymous 05/01/11(Sun)21:47 No.17268198
    this virus doesn't run on windows 7?
    >> Anonymous 05/01/11(Sun)21:48 No.17268212
    >>17268170
    Avast / Super Antispyware. See what that in a combination picks up with their on-demand scans.

    Otherwise, I'd say go naked.
    >> Anonymous 05/01/11(Sun)21:48 No.17268213
    >>17268198
    I'm going to try in a minute. I wanted thoughts on whether or not I should install an antivirus first and, if so, what does /g/ want.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:48 No.17268220
         File1304300905.png-(79 KB, 640x480, Windows XP Professional-2011-0(...).png)
    79 KB
    Lets see if MBAM will pick it up.
    >> Anonymous 05/01/11(Sun)21:49 No.17268234
    >>17268212
    Avast misses the EXE (before install, at least), SAS catches it.

    Guess I'll go naked.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:49 No.17268247
         File1304300999.png-(82 KB, 640x480, Windows XP Professional-2011-0(...).png)
    82 KB
    after only one minute it caught an exe, lets see if its gone...
    >> Anonymous 05/01/11(Sun)21:50 No.17268251
    >>17268234
    Fuck, looks like Wireshark won't pick up the VM traffic properly. Guess I'll have to skip the network analysis.
    >> Anonymous 05/01/11(Sun)21:50 No.17268258
    >>17268234
    Oh, Oops. I forgot about that earlier VirusTotal scan.
    >> Anonymous 05/01/11(Sun)21:51 No.17268264
    >>17268251
    Time to get infected.
    >> Anonymous 05/01/11(Sun)21:51 No.17268285
         File1304301118.png-(652 KB, 816x681, wat.png)
    652 KB
    >>17268264
    wat
    >> Anonymous 05/01/11(Sun)21:52 No.17268296
         File1304301160.png-(211 KB, 816x681, winregister.png)
    211 KB
    >>17268285
    It registers with windows as an antivirus. interesting.

    Still haven't seen the virus.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:52 No.17268302
         File1304301179.png-(129 KB, 1366x768, Windows XP Professional-2011-0(...).png)
    129 KB
    >>17268247
    Nope, 9 more, even though the "antivirus" wont open.
    >> Anonymous 05/01/11(Sun)21:53 No.17268312
         File1304301210.png-(313 KB, 816x681, nowait.png)
    313 KB
    >>17268296
    Didn't have to wait long though.
    >> Anonymous 05/01/11(Sun)21:54 No.17268327
         File1304301280.png-(106 KB, 816x681, durp.png)
    106 KB
    >>17268312
    /g/ was visible briefly, but then, this shit came up. Hitting the view anyway button has it come back up a moment later.
    >> Anonymous 05/01/11(Sun)21:55 No.17268335
    >>17268312
    What do I have to do to get infected? Is just visiting the site enough?
    >> Anonymous 05/01/11(Sun)21:56 No.17268345
    >>17268327
    Interesting, Too bad you didn't upgrade to IE9 to see if it affects that as well.

    >>17268335
    There's a MediaFire link a few posts above.
    >> Anonymous 05/01/11(Sun)21:56 No.17268354
         File1304301387.png-(85 KB, 816x681, netstat.png)
    85 KB
    Netstat found nothing out of norm. My guess is a rootkit.

    >>17268327
    Not for this particular site, but yes, on many sites exploits are used to automatically install this shit.
    >> Anonymous 05/01/11(Sun)21:57 No.17268374
    >>17268345
    I know I am not planning on installing it. I was just curious.
    >> Anonymous 05/01/11(Sun)21:57 No.17268378
    >>17267424
    does this click on random image also happen
    on Bing?
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)21:57 No.17268383
         File1304301475.png-(123 KB, 1366x768, Windows XP Professional-2011-0(...).png)
    123 KB
    And there we go, a couple of MBAM runs and its all cleaned out.
    >> Anonymous 05/01/11(Sun)21:57 No.17268384
    >>17268354
    Most definitely around warez sites and the likes. Not hard to come by if you do google searches a typical person that didn't know anything would click on.
    >> Anonymous 05/01/11(Sun)21:58 No.17268395
         File1304301512.png-(167 KB, 800x600, reallynow.png)
    167 KB
    Cropping the VM window from now on.

    >>17268354
    It enforces IE being disabled with a fucking addon???
    >> Anonymous 05/01/11(Sun)21:59 No.17268411
    I remember this shit. Got payed 60$ to pull it off of a laptop the other day. The fact that it got into Safe Mode was a piss off to be honest.
    >> Anonymous 05/01/11(Sun)21:59 No.17268423
         File1304301598.png-(238 KB, 800x600, hnngh.png)
    238 KB
    >>17268395
    This must not be a very aggressive variant.
    >> Pawl !SwCnVqbk.E 05/01/11(Sun)22:01 No.17268440
         File1304301667.png-(46 KB, 1366x768, Windows XP Professional-2011-0(...).png)
    46 KB
    Anyway, thats it gone for XP.

    U jelly?
    >> Anonymous 05/01/11(Sun)22:01 No.17268454
         File1304301701.png-(113 KB, 816x681, startscan.png)
    113 KB
    >>17268423
    Starting the scan.

    Also, LOL at the warning in the bottom.
    >> Anonymous 05/01/11(Sun)22:02 No.17268476
         File1304301747.png-(78 KB, 800x600, foudnit.png)
    78 KB
    >>17268454
    Under a minute to find it.
    >> Anonymous 05/01/11(Sun)22:03 No.17268487
    >>17268423
    Forgot about Super Antispyware having a portable program, Wanted to test it out as I honestly have yet to try it in ages but got this:

    >SUPERAntiSpyware.com - Site Momentarily Unavailable
    >We are currently experiencing a high server load with our site. Our system administrators are working to resolve this issue and the site should be back up in a few moments. We apologize for the inconvenience.
    >> Anonymous 05/01/11(Sun)22:03 No.17268503
         File1304301826.png-(149 KB, 800x600, options.png)
    149 KB
    >>17268476
    The options tick on other tabs, but immediately change back to what they were if you leave the tab.
    >> Anonymous 05/01/11(Sun)22:05 No.17268528
    >>17268503
    So /g/, I'm at a crossing here.

    A) Boot from an ISO and see if any rescue CDs find this.

    B) Allow SUPERAntispyware to try to remove it.
    >> Anonymous 05/01/11(Sun)22:06 No.17268558
    >>17268503
    In a nutshell, Options are just there for looks and nothing else.

    >>17268528
    I would format and persist any friend that got caught with it to format. Otherwise, Use a rescue disc as safety to backup and do basics in safe mode with portable scanners / hijackthis / mbam / the likes.
    >> Anonymous 05/01/11(Sun)22:06 No.17268570
    interesting thread thanks
    goodnight
    >> !.FURRYW1y. 05/01/11(Sun)22:07 No.17268576
    >>17268528
    The obvious answer, A.

    But go with B.
    >> Anonymous 05/01/11(Sun)22:08 No.17268599
    >>17268576
    I'll try B, then reinstall the virus and try A.

    What rescue CDs do you guys like (And want me to try?)
    >> Anonymous 05/01/11(Sun)22:08 No.17268601
    Poster of >>17268558, Misread a few things and then read >>17268576. I would use the rescue CD's to attempt and _find_ this first. Otherwise, Boot safe mode and do everything else for checks.
    >> Anonymous 05/01/11(Sun)22:10 No.17268635
         File1304302201.png-(220 KB, 1189x668, elp-elp.png)
    220 KB
    I'm bein opressed!
    >> Anonymous 05/01/11(Sun)22:10 No.17268655
         File1304302259.jpg-(164 KB, 1575x955, idiot.jpg)
    164 KB
    Apparently you are not getting smarter though.

    Using Firefox and not using noscript is just full retard.
    >> Anonymous 05/01/11(Sun)22:14 No.17268729
    adblock plus prevented me from getting any malicious exe when I visited the site.
    >> Anonymous 05/01/11(Sun)22:15 No.17268768
    >>17268635
    Can you show what happens if you try to register? Are you sent to some shady russian site or something?
    >> Anonymous 05/01/11(Sun)22:15 No.17268769
    >>17268729
    This site didn't do a drive-by. You had to manually download it.

    Therefore, any statements made about the efficacy of adblock plus on that site would be automatically invalid.
    >> Anonymous 05/01/11(Sun)22:16 No.17268791
    oh boy!
    a malware inspection thread!
    hey, where do you guys get windows installs to make vm's with?
    >> Anonymous 05/01/11(Sun)22:17 No.17268798
         File1304302631.png-(176 KB, 800x600, yerp.png)
    176 KB
    >>17268768
    IE opens in a window with no address bar. View source gets you http://zuzusutity.com/buy.html.
    >> Anonymous 05/01/11(Sun)22:17 No.17268803
    >>17268791
    Any basic Windows install will do.
    >> Anonymous 05/01/11(Sun)22:17 No.17268808
    >>17268791
    I used a loader on a MSDN download.
    >> Anonymous 05/01/11(Sun)22:18 No.17268827
    >>17268768
    I've had a few customers that have actually registered for this and payed the $50 or whatever for it to go away.

    They give you a serial key that doesn't even fit in the boxes where you register within the program.
    >> Anonymous 05/01/11(Sun)22:19 No.17268830
    >>17268803
    so you don't authenticate it?
    or you use a loader...
    >> Anonymous 05/01/11(Sun)22:19 No.17268834
         File1304302767.png-(169 KB, 991x680, Screen shot 2011-04-26 at 1.47(...).png)
    169 KB
    Fuck, does anyone know some good virus scanners for os x?
    >> Anonymous 05/01/11(Sun)22:20 No.17268847
    >>17268827
    I would pay for this if I wanted to deal with the time/risk of a chargeback, because they'd get hit with a chargeback free from the merchant bank. Don't have time to deal with that shit, really.
    >> Anonymous 05/01/11(Sun)22:20 No.17268853
    >>17268830
    Why would I need to make it genuine (If that's what you're trying to say)? There's no reason to if you're going to scrap it later. Otherwise, Just use a loader I guess.
    >> Anonymous 05/01/11(Sun)22:21 No.17268865
    >>17268635
    nmap -Pn 24.165.231.237

    Starting Nmap 5.21 ( http://nmap.org ) at 2011-05-01 22:17 EDT
    Nmap scan report for mta-24-165-231-237.satx.rr.com (24.165.231.237)
    Host is up (0.0047s latency).
    Not shown: 999 closed ports
    PORT STATE SERVICE
    714/tcp filtered unknown

    Nmap done: 1 IP address (1 host up) scanned in 165.06 seconds

    begin the attack on mta-24-165-231-237.satx.rr.com:714
    >> Anonymous 05/01/11(Sun)22:21 No.17268871
    >>17268830
    On 7, you have a 30 day grace period that you can reset 3 times with slmgr.vbs -rearm.

    But if you're smart, you make a snapshot after updating/setting up but before you rearm and keep reusing it forever.
    >> Anonymous 05/01/11(Sun)22:22 No.17268904
         File1304302979.png-(85 KB, 800x600, sum.png)
    85 KB
    OP Here. Killed it from Task manager. I think Superantispyware will succeed. Quite tame variant.
    >> Anonymous 05/01/11(Sun)22:23 No.17268916
    >>17268865
    That's not nice, considering the warning was almost surely fake.
    >> Anonymous 05/01/11(Sun)22:23 No.17268917
    >>17268798
    Thanks! Are you going to try to clean the install or you will just nuke it?
    >> Anonymous 05/01/11(Sun)22:24 No.17268924
    >>17268917
    I'll nuke it for future usage, but I'm trying Superantispyware. Then reinstalling and trying a boot CD.

    /g/ still hasn't picked a rescue CD to try.
    >> Anonymous 05/01/11(Sun)22:24 No.17268925
    >mfw this is actually a genuine antivirus trying to help people out

    that would be a great trojan/virus
    >> Anonymous 05/01/11(Sun)22:24 No.17268927
    >>17268871
    ah ha...
    thats what i though...
    so what do you guys do?
    do you actually do any reverse engineering, or are you just watching what it does?

    i really like the idea of reverse engineering
    >> Anonymous 05/01/11(Sun)22:25 No.17268950
    >>17268798

    This looks legit

    >>"I found Win 7 Anti-Virus 2011 4 years ago."
    >>2011
    >>4 years ago
    >> Anonymous 05/01/11(Sun)22:25 No.17268953
         File1304303151.png-(913 KB, 816x681, clean.png)
    913 KB
    She's clean.

    If anyone wants me to reinstall and try a boot CD, I'm open to suggestions.
    >> Anonymous 05/01/11(Sun)22:25 No.17268954
    >>17268924
    Can't say I'm experienced on what Rescue CD's are worth using nowadays, as I only use the ones that boot Linux so I'm able to backup files.
    >> Anonymous 05/01/11(Sun)22:26 No.17268965
         File1304303199.png-(96 KB, 480x320, 1303850644613.png)
    96 KB
    really?

    got this on my iphone this morning.
    >> Anonymous 05/01/11(Sun)22:27 No.17268982
         File1304303261.png-(71 KB, 800x600, feck.png)
    71 KB
    >>17268953
    It broke EXE file associations in Windows. LONG TROLL.
    >> Anonymous 05/01/11(Sun)22:28 No.17268995
    >>17268954
    hirens boot cd is really nice
    >> Anonymous 05/01/11(Sun)22:29 No.17269026
    >>17268995
    Does he actually still bundle a scanning antivirus in the part of the CD that runs live?
    >> Anonymous 05/01/11(Sun)22:32 No.17269084
    >>17268995
    >>17269026
    Checked it out, And actually does. Not OP, But I can't find download link anywhere on this page. Where the hell is it?

    >http://www.hiren.info/pages/bootcd
    >> Anonymous 05/01/11(Sun)22:32 No.17269085
    OP here. Stub downloaded files out of IPs registered in Chicago and New Jersey.
    >> Anonymous 05/01/11(Sun)22:33 No.17269114
    >>17269026
    >>17269084
    http://www.hirensbootcd.org/
    >> Anonymous  !YIFFSvTMcg 05/01/11(Sun)22:34 No.17269117
         File1304303651.png-(284 KB, 320x480, IMG_0422.png)
    284 KB
    >>17268965
    >MFW someone posted a screenshot I posted before
    >> Anonymous 05/01/11(Sun)22:35 No.17269134
    >>17269085
    Err, not OP. Fuck. Forgot I didn't make a separate thread for this shit.

    Downloading Kaspersky for first attempt.

    IPs it connected to (* means previous octets the same as last one)
    76.73.85.187
    *.*.*.188
    *.*.*.190
    67.196.15.116
    *.*.*.109
    *.*.*.108
    *.113
    *.112
    *.115
    *.114
    *.117
    *104
    *106
    76.73.85.186
    67.196.15.141
    *.105
    *.140
    *.107
    >> Anonymous 05/01/11(Sun)22:35 No.17269141
    >>17269114
    D'oh... Fuck me. I found it as soon as you posted it. Thanks for that.
    >> Anonymous 05/01/11(Sun)22:40 No.17269195
         File1304304002.png-(317 KB, 1040x849, guess.png)
    317 KB
    Anybody want to speculate on potential detection?
    >> Anonymous 05/01/11(Sun)22:41 No.17269212
    >>17268808
    all the windows 7 downloads are unavailable
    >> Anonymous 05/01/11(Sun)22:42 No.17269230
    >>17269195
    I'd say it will get detected but won't be removed completely or successfully. Calling it.
    >> Anonymous 05/01/11(Sun)22:42 No.17269241
    ThreatExpert report:
    http://www.threatexpert.com/report.aspx?md5=09c50e2821be0806bc09cbf928bc9aee

    It downloaded from one of the IPs I mentioned earlier.
    >> Anonymous 05/01/11(Sun)22:45 No.17269286
    Flew right over Kaspersky's head. What now.
    >> Anonymous 05/01/11(Sun)22:46 No.17269294
    >>17269286
    Shit, Move on to the next AV then.
    >> Anonymous 05/01/11(Sun)22:48 No.17269323
    >>17269294
    I'm getting a copy of BitDefender's ISO.
    >> Anonymous 05/01/11(Sun)22:50 No.17269350
    >>17269323
    Also, Give that boot CD a try here >>17269114.
    >> Anonymous 05/01/11(Sun)22:51 No.17269361
         File1304304661.png-(25 KB, 435x359, shitinternet.png)
    25 KB
    >>17269323
    Shit internet here. Next ISO in a couple minutes.
    >> Anonymous 05/01/11(Sun)22:51 No.17269371
    >>17269350
    I'll grab Hiren's, but I think he removed both the pirated Mcafee and F-prot (no longer updated) boot CD images.
    >> Anonymous 05/01/11(Sun)22:52 No.17269384
    >>17269212
    this
    should i just torrent sp1?
    >> Anonymous 05/01/11(Sun)22:52 No.17269393
    >>17269371
    Eh, What're you gonna do when receive lawsuit threats. Just gotta make it yourself instead of trying to help others. Regardless, The features it still has makes it much useful to this day.
    >> Anonymous 05/01/11(Sun)22:53 No.17269404
    This thread is awesome thanks /g/.

    Has anyone looked at this shit with wireshark/Olly/IDA yet?

    Is this packed with anything?
    >> Anonymous 05/01/11(Sun)22:54 No.17269422
    >>17269384
    Just grab this, modify the ei.cfg if you want an edition other than Pro:
    32 bit:
    http://msft-dnl.digitalrivercontent.net/msvista/pub/X15-65804/X15-65804.iso

    64-bit:
    http://msft-dnl.digitalrivercontent.net/msvista/pub/X15-65805/X15-65805.iso

    (ignore the msvista directory names; google the part numbers)
    >> Anonymous 05/01/11(Sun)22:56 No.17269452
         File1304305019.png-(207 KB, 816x681, bitdef.png)
    207 KB
    Anyone wish to speculate?
    >> Anonymous 05/01/11(Sun)22:57 No.17269458
    >>17269452
    No dice.
    >> Anonymous 05/01/11(Sun)23:00 No.17269496
    >>17269458
    Something I also find amusing, A person would take this long to completely scan their entire system instead of taking the time to backup their most important essentials and doing an easy format. Starting fresh is always a great thing no matter what. I can only assume the greatest arguments would be old settings they once had.
    >> Anonymous 05/01/11(Sun)23:01 No.17269520
    >>17269496
    it does take a while to back up
    im usually lazy when it comes to backup and reinstall, been putting it off for almost 3 weeks while slowly as fuck backing stuff up
    >> Anonymous 05/01/11(Sun)23:02 No.17269522
         File1304305324.png-(275 KB, 816x681, stillgo.png)
    275 KB
    >>17269496
    Tons of people don't backup.

    Still going...
    >> Anonymous 05/01/11(Sun)23:02 No.17269533
         File1304305356.png-(273 KB, 816x681, OHSHIT.png)
    273 KB
    Well, well. What have we here.
    >> Anonymous 05/01/11(Sun)23:04 No.17269549
    >>17269520
    Lazyness isn't an excuse though if you know your system is compromised.

    >>17269522
    I don't backup at all on a daily basis. In fact, rarely once every 3 months or so. Even then, I don't do it regardless. But I'm referring to saving what's left on your system before severe damage is done and moving on to reinstall the OS.
    >> Anonymous 05/01/11(Sun)23:04 No.17269555
         File1304305468.png-(69 KB, 800x600, logview.png)
    69 KB
    >>17269533
    (still scanning)
    >> Anonymous 05/01/11(Sun)23:05 No.17269569
    >>17269555
    Oh shit, I had doubts. BitDefender is actually coming through with the business.
    >> Anonymous 05/01/11(Sun)23:07 No.17269582
         File1304305620.png-(18 KB, 452x708, who.png)
    18 KB
    >>17268798
    http://newlydomains.com/domain-2011-04-28-com-334.html
    Registered 3 days ago, and looking there, seems like a bunch of other malware-hosting domains too.

    <--- and here's the whois info. The idiot didn't even protect the info.
    >> Anonymous 05/01/11(Sun)23:07 No.17269591
    >>17269582
    Tom Schwartz in Sulzberg? Probably fake.
    >> Anonymous 05/01/11(Sun)23:07 No.17269596
    This thread is making me want to reinstall Virtualbox, install XP Home (WITHOUT ANY SERVICE PACKS :o) and see how infected I can get.
    >> Anonymous 05/01/11(Sun)23:09 No.17269607
    >>17269596
    Windows 7 can be harder, but in regular use, fairly quick, probably within a day on googl eimages.
    >> Anonymous 05/01/11(Sun)23:19 No.17269659
         File1304306346.png-(169 KB, 816x681, bam-a-lam.png)
    169 KB
    He's dead, jim.
    >> Anonymous 05/01/11(Sun)23:21 No.17269669
    >The Microsoft Malware Protection Center (MMPC) strives to keep you informed about the status of your submission.

    >This email communicates what we currently know about the file(s) you submitted.

    >If you were to scan the files you submitted using one of Microsoft's Antimalware products such as Microsoft Forefront Client Security or Microsoft Security Essentials, you would see relevant detection information similar to what is displayed below.
    =======================================>======
    >BestAntivirus2011.exe [Changes to detection currently undergoing testing]
    >> Anonymous 05/01/11(Sun)23:22 No.17269676
    Overall, an EXTREMELY tame variant. Requires a manual install, easily removed. Can even kill it with task manager.

    Anybody got another sample?
    >> Anonymous 05/01/11(Sun)23:24 No.17269684
    >>17269676
    Odd that it wasn't very persistent. Unfortunately 4chan is going dead slow over the Bin Laden news. There's a website dedicated to archiving various malware sparked on a daily basis. I don't have it bookmarked but perhaps someone else may know of it? Could keep this thread open for hours longer, For enjoyment purposes anyway.
    >> Anonymous 05/01/11(Sun)23:25 No.17269692
    >>17269684
    youd think that with so many people using google images, the thing would be more malicious
    >> Anonymous 05/01/11(Sun)23:26 No.17269702
    >>17269692
    (VM Guy here)
    My twin brother (not a techie) had outdated java + didn't do windows update this month (he did after disinfection), he got a highly aggressive variant that automatically installed through Google images.
    >> Anonymous 05/01/11(Sun)23:29 No.17269730
    look for flash.go.plugin.exe
    >> Anonymous 05/01/11(Sun)23:31 No.17269743
    I could play the RS.4chan.org game and download...

    DDoS application.exe

    Sound good?
    >> Anonymous 05/01/11(Sun)23:31 No.17269747
    >>17269702
    So, I've stuck through this thread since the beginning and through your VM experiments. I have to ask as I may be sitting under a rock this entire time or just ballsy enough to go through the images, What the hell is wrong with Google Images? How does this happen exactly? I know how people get malware sites on top searches but images I'm unaware of. I've seen fake sites but nothing happens and usually get a white page (Because I block by host), How does this affect Google Images?



    [Return]
    Delete Post [File Only]
    Password
    Style [Yotsuba | Yotsuba B | Futaba | Burichan]