Jlhoffman Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 28 November 2012

New Malware That Hides Your Data

Posted on 12:12 by Unknown
For the last day or so we've been fighting battles for multiple client locations that are infected with a malware that McAfee calls a variant of W32/autorun.worm.aaeb-h.  The malware seems to travel on portable flash drives as well as possibly coming in as an email attachment.  It changes the attributes of files and entire folders of data so that they seem to disappear and the replaces them with similarly named .EXE files.  When a user accesses an infected flash drive or an infected folder on a network share, other folders to which they are connected will disappear from view right before their eyes.  (Talk about freaking out users!)  It also appears to infect in such a way that other users that access an infected folder will see it propagate itself to even more folders.  You will have to use Command line DOS prompts to change the attributes of the now hidden files to restore them and then delete the replacement executables that all have identical creation dates and file sizes.

McAfee sent out their alarm fully 7 days after we first encountered it in the wild which underlines just how overwhelmed many A/V vendors are trying to keep up with the flood of new malware and their variants.  As recently as 2007, A/V companies reported a few thousand viruses and malwares per year.  Now we're seeing several thousand new items PER DAY!  This one is a new variant of a well-known malware but it's tweaked enough that it avoided the original counter-measures.

This guy is a real stinker to remove on even a mid-sized network because of it's use of autorun to spread itself around a network.  If you disable AUTORUN on your network via Group Policy you can slow down it's spread but get ready to spend some time going from PC to PC searching for the original infection point.  The McAfee countermeasure/removal tool is called Striker.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Ransomeware Now #1 MalwareThreat - Learn More Here
    I just read an outstanding white paper from a couple of researchers at Sophos Security outlining how Ransomware is passing up FakeAlert malw...
  • Computer Support Rates - When Cheap Really Isn't
    What's in a labor rate?  Why are some IT companies more expensive than others?  Our company is neither the most expensive in our market ...
  • Server Configuration - Heaven Save Us From Well-Meaning Amateurs!
    How do I tell the client what their old tech did to them?  They've got to spend a bunch of money to correct the mess he made and I'm...
  • When It's Time To Fire A Customer
    What?  Isn't that backwards?  Isn't it the customer that usually does the firing? Usually, as business people, we work so hard to fi...
  • Using Personal Computers In the Workplace
    At ACT, we support a great many organizations that allow employees to use their own computers at work.  Sadly, I've noticed that some of...
  • What to do with Windows XP
    Well, it had a good long run.  Windows XP is now 13 years old.  In less than 10 months Microsoft is pulling the plug on our old friend XP.  ...
  • Wireless Networking Is Due For A Big Jump In Performance
    Just when we were getting comfortable with the 802.11n wireless standard, here comes a newer and better wireless solution - 802.11ac.  It wi...
  • Documentation - The Key To Client Support Success
    Recently, we won the trust of a new client that was unhappy with the service provided by their previous IT company.  After the client notifi...
  • Going to the Cloud is easy, getting out is a lot tougher!
    Everyone is pushing you to take your business to the cloud, right?  It's easy, right?  The sales rep used all the right words in his pit...
  • Support for Windows XP and Office 2003 stops on April 8th.
    All Microsoft support for Windows XP and Office 2003 stops on April 8th. What are the risks to your business if you don't upgrade? Let...

Blog Archive

  • ►  2013 (39)
    • ►  November (3)
    • ►  October (4)
    • ►  September (2)
    • ►  August (4)
    • ►  July (3)
    • ►  June (9)
    • ►  May (3)
    • ►  April (3)
    • ►  March (6)
    • ►  January (2)
  • ▼  2012 (12)
    • ►  December (2)
    • ▼  November (8)
      • New Malware That Hides Your Data
      • What? Apple leads in vulnerabilities? AND What t...
      • Microsoft Windows 8 - Introducing Chaos In The Wor...
      • Addressing Data Ownership In The Cloud
      • Malware on Mobile devices like Smartphones and Tab...
      • Helping a Client With e-Discovery
      • Portable Device Security On Your Network
      • Conventions in the Cloud? Where will it all end?
    • ►  October (2)
Powered by Blogger.

About Me

Unknown
View my complete profile