Thank goodness for OpenDNS. I have to admit I am more adept at managing Macintosh systems. I do managed an Active Directory based Windows setup. I have endpoint security with Sophos and have installed CryptoPrevent and GPO's to prevent Crypto Locker.
I have installed the Umbrella client on all my desktop and laptops under management both Mac's and Windows systems. I noticed a Windows 7 system trying to phone home to these web addresses: fapncam.com, frizzcams.com and update-silo.com. Googling these sites didn't show much but pointed me to a trojan called BetaBot as being the culprit. In particular it pointed to safpdndnn.exe being installed.
Neither Malware Bytes or Sophos detected it. I used SpyHunter to find it but I wouldn't recommend that program. It wants to mess with your systems DNS settings.
Here's how I removed it:
1. Use PartedMagic (or you could use any Linux Live Distro) and boot into it. (Try this article on how to do this if you need help.)
2. Navigate to C:\ProgramData\\m9dt73hfbjh\safpdndnn.exe and delete the file.
The kicker is after giving the user a new clean system the infection showed up again. I had never gotten to the bottom of what caused the original infection. My bad for sure. It turned out to be a resume downloaded from Craig's List. How fun.
Not to hate on Microsoft products but how frustrating. Yes, the end user shouldn't have downloaded .doc files from questionable sources. Macros should be locked down. For whatever feelings you have about Google Docs at least for the time being, they are not an infection vector.
Subscribe to:
Post Comments (Atom)
Update: distributing ERB Secure Browser on Mojave
Mojave introduces some security enhancements that mess up the distribution of the ERB secure browser (the "App"). First, than...
-
Distributing the ERB Secure Browser App for Macintosh using MUNKI. ERB provides a zipped file but trying to create a package of the file w...
-
Ah, digital signage. A vertical market if there ever was one. I have researched many systems and all have struck me as either ve...
-
Click here for a Chart Comparing Features and Ratings This review considers which iOS (iPhone, iPad) email clients are best for Gmail ...
No comments:
Post a Comment