Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts

18 May 2007

Malware

More work for support staff.

PCs infected with viruses and other malware continue to cause problems for the Division and the wider University. On more than one occasion over the last few months staff returning from China have returned with malware on the portable PCs they took with them, apparently transmitted through the use of thumb drives to transfer data from PC to PC.

The Fujacks/Looked.EK trojan has been particularly difficult to deal with. As soon as an infected computer is attached to the UC network, the malicious code is transferred to network drives, and unless it is eradicated will continue to reinfect the PC after it is cleaned, and possibly other PCs that connect to the same network drives. Any thumb drives infected with the trojan will spread it to other PCs the drive is connected to, which surprisingly has proved to be a particularly efficient vector to spread the code around.

University PCs should be set up to automatically install the latest malware “signatures” used by the campus anti-virus software eTrust whenever they become available. PCs that don’t conform to this practice should not be connected to the University network, nor should data be moved to a University computer without a virus check being done first.

We need to be more vigilant sharing data around, and when returning to the University campus it might be prudent to run a virus check on a PC before reconnecting it to the network.

20 February 2007

Malware infection

On a recent visit to China the PC laptop of a member of the Division’s staff became infected with a virulent form of malware: believed to be a trojan called FUJACKS.W32.

In an effort to repair the staff member’s PC, TSU staff involved attached an external hard drive to the infected computer. The hard drive became infected with the trojan, which was then unknowingly transmitted to the computer controlling the GlobeCaster vision switcher in the Television Control Room during an upgrade process. An external contractor’s PC may then have been infected with the trojan when it was connected to the GlobeCaster as a part of the upgrade process. The GlobeCaster is not connecter to the University network, particularly because the nature of the computer is such that the normal security patches shouldn’t be applied and therefore the computer is vulnerable to malware attack if it is connected to the Internet.

The staff member’s portable computer is now unusable and has had to be replaced. The GlobeCaster is currently not working, but a replacement for the controlling computer had been ordered anyway and will be installed, hopefully malware-free. We are awaiting confirmation that the trojan has not spread to other computers on the University network.

Staff should be reminded of the dangers of exposing their computers to malware attack. While measures are in place on the University network to reduce the risk (but not eliminate it entirely), attaching University computers to networks (wired or wireless) outside the campus, at home, during Conferences or at other institutions, comes with the possibility of greatly increased danger of the machine being compromised in some way. This incident is not unique: within the last month ICT Services has contacted the Division to report that a staff member’s computer that was attempting to connect securely (via VPN) to the University network from home was infected with malware. Access was denied until the computer concerned was cleaned up.

One suggestion is that people needing computers off-campus should use a Macintosh. While the Macintosh operating system is not immune to malware attack, it is more secure than Windows and there are no known malware exploits currently in circulation that would compromise a computer running Mac OS X. The Division should consider increasing the number of Macintosh portable computers available for short-term loan to accommodate this requirement.

22 February 2005

Virus activity

PCs on campus under attack yet again

Several new variants of the MyDoom worm infected campus PCs on Thursday 17 February 2005 and the following days. The emails containing the malicious code as an attachment were particularly sophisticated and managed to fool a number of people around the campus into opening the attachments, infecting their PC and spreading the infection.

It took a few hours for the anti virus vendor used by the campus to provide an updated signature file for the eTrust antivirus software used to protect PCs here, so campus PCs were vulnerable until eTrust could strip the malicious code from the offending emails. With the variations of the original worm coming out over successive days, new signature files were being issued daily by the vendors in an attempt to keep up.

Staff (and students) need to be more vigilant about emails and seek reassurance from colleagues or the helpdesk before opening attachments to ANY uninvited emails.

There was no impact on Macintosh users, except having to deal with the slowdown of the campus email servers under the burden of the worm, and receipt of many emails with the malicious code attached. The comedu helpdesk staff lost a day or two dealing with the impact of the attack at the helpdesk's busiest time of the year.