***VIRUS WARNING***Large-Scale Attack Hits Thousands of Web Sites NAME: Download.Ject/Scob

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Amused

Elite Member
Apr 14, 2001
57,455
19,923
146
Originally posted by: Strang
Originally posted by: Stark
has anyone seen this one yet? just wondering how cautious i need to be.

I'm curious too -- I hadn't heard anything about it until seeing this post, but it'd be nice to know what to look for if/when it hits my company's network.

I'd like to know what it's called, and what are the warning signs or how to know you're infected.

And why isn't this stickied yet???
 

Ilmater

Diamond Member
Jun 13, 2002
7,516
1
0
Originally posted by: PanzerIV
I wish we could chop off the fingers of these losers who keep releasing this stuff. I am sick to death of it. Of course there are a lot of very successful companies whose very livlihood depends on this sh!t to continue indefinitely.
Where do you think they come from?
 

Amused

Elite Member
Apr 14, 2001
57,455
19,923
146
Originally posted by: Lazee
this is only for IE users. look on the top of nynewsday.com

And the vast majority of people use IE. So this is very important.
 

Zee

Diamond Member
Nov 27, 1999
5,171
3
76
Originally posted by: Amused
Originally posted by: Lazee
this is only for IE users. look on the top of nynewsday.com

And the vast majority of people use IE. So this is very important.

True... but then a better post to sticky would be "Will everyone stop using IE and use Firefox until further notice"

:D
 

skyking

Lifer
Nov 21, 2001
22,809
5,974
146
I got hit with it, and NAV found it in a systemwide scan. It comes in and infects temporary internet files, posing as gifs and jpegs.
Norton does not catch it on the way in. It identifies it as "trojan horse", a very generic reference at best.
I t has infected many mainstream sites, as far as I could tell by looking at the titles of the images.
 

NogginBoink

Diamond Member
Feb 17, 2002
5,322
0
0
There are two things you can do:

If you run an IIS 5.0 server, make sure you have MS04-011 installed. (And that you've rebooted since you installed it.) Make sure the 'enable document footer' isn't unexpectedly checked on any of your websites.

If you run IE, you can tighten the security in the local computer zone.
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
The only problem with tightening security, Noggin, is that you have to disable JavaScript to plug the hole. These forums, in turn, are a casualty of disabling JavaScript.:(