Page 2 of 6 FirstFirst 123456 LastLast
Results 11 to 20 of 52

Thread: New phishing technic?

  1. #11
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Quote Originally Posted by Olezhik View Post
    Есть ешо два варинат если надо ещё могу придумать ;).

    1) с помошу [Java Script] вовремя загрузки странитси извеминть то что написано в аддресс бар ну не пересилать на другои аддресс.

    2) Во время загрузки странитси симетировать нажатие кнопки [F11] а саму странису нарисовать в рамке [IE]
    1) And what virus would do that?

    2)No, it's not the case (tested)
    I'll adapt...
    Question authority

  2. #12
    Forum Regular In2HiDef's Avatar
    Join Date
    Dec 2007
    Location
    The Buckeye State
    Posts
    37,506

    Default Re: New phishing technic?

    Посмотреть список плагинов ИЕ. Не затесался ли там кто интересный.

  3. #13
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Quote Originally Posted by In2HiDef View Post
    Посмотреть список плагинов ИЕ. Не затесался ли там кто интересный.
    I turned off all of them. Still the same thing. And it does that even in Safe Mode with Networking.
    I'll adapt...
    Question authority

  4. #14
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Also, the proxy on the server shows that the computer tries to connect to different websites like xyrbvfsdf.com and similar
    Изображения Изображения
    I'll adapt...
    Question authority

  5. #15
    Forum Regular In2HiDef's Avatar
    Join Date
    Dec 2007
    Location
    The Buckeye State
    Posts
    37,506

    Default Re: New phishing technic?

    Quote Originally Posted by Bibob3d View Post
    I turned off all of them. Still the same thing. And it does that even in Safe Mode with Networking.
    Это специфически ИЕ8 заражение. Скорее всего на бинарном уровне, через плагины, через режистри, вызывается какая–то ДЛЛ или екзекютабл. Возможно даже есть сервис, который это дело поддерживает. Советую инспектировать список системных сервисов (через Административ Тулз), смотреть на дескрипшн и искать странный текст.
    Искать на Гугле, найти инструкцию по уничтожению, раздавить гадину.

  6. #16
    Forum Regular In2HiDef's Avatar
    Join Date
    Dec 2007
    Location
    The Buckeye State
    Posts
    37,506

    Default Re: New phishing technic?

    Quote Originally Posted by Bibob3d View Post
    I turned off all of them.
    oh, yea? Check again, these suckers can be resilient

  7. #17
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Quote Originally Posted by In2HiDef View Post
    oh, yea? Check again, these suckers can be resilient
    Checked and rechecked
    I'll adapt...
    Question authority

  8. #18
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Quote Originally Posted by In2HiDef View Post
    Это специфически ИЕ8 заражение. Скорее всего на бинарном уровне, через плагины, через режистри, вызывается какая–то ДЛЛ или екзекютабл. Возможно даже есть сервис, который это дело поддерживает. Советую инспектировать список системных сервисов (через Административ Тулз), смотреть на дескрипшн и искать странный текст.
    Искать на Гугле, найти инструкцию по уничтожению, раздавить гадину.
    That computer had IE6. We put IE7 - didn't fix it

    And we don't know what to look for. The closest thing I found was Vundo - it does disable Spybot and it does create those two files I mentioned. But Norton's scanner didn't find anything
    I'll adapt...
    Question authority

  9. #19
    Forum Regular In2HiDef's Avatar
    Join Date
    Dec 2007
    Location
    The Buckeye State
    Posts
    37,506

    Default Re: New phishing technic?

    Quote Originally Posted by Bibob3d View Post
    That computer had IE6. We put IE7 - didn't fix it

    And we don't know what to look for. The closest thing I found was Vundo - it does disable Spybot and it does create those two files I mentioned. But Norton's scanner didn't find anything
    Er, I meant IE7, sorry.
    I had dealt with similar infection once, scanners didn't detect it, and I could only clean it by hand, following instructions I found on Google. Took 2 days. The virus installed a search plugin for IE6, faked a legitimate service, and recreated itself every time I cleaned IE plugins.

    Good luck!

  10. #20
    АнунафигВеликий Bibob3d's Avatar
    Join Date
    Jan 2005
    Location
    Los Angeles County, CA, USA
    Пол
    Мужской
    Posts
    9,156

    Default Re: New phishing technic?

    Quote Originally Posted by In2HiDef View Post
    Er, I meant IE7, sorry.
    I had dealt with similar infection once, scanners didn't detect it, and I could only clean it by hand, following instructions I found on Google. Took 2 days. The virus installed a search plugin for IE6, faked a legitimate service, and recreated itself every time I cleaned IE plugins.

    Good luck!
    What virus was that?
    I'll adapt...
    Question authority

Page 2 of 6 FirstFirst 123456 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Russian America Top. Рейтинг ресурсов Русской Америки. Terms of Service | Privacy Policy Рейтинг@Mail.ru