Switchfast Blog: The Future of IT
Beware: Gumblar virus
Tuesday, June 02, 2009 by Michael Holley
News of the latest round of attacks from the Gumblar virus has
been erupting all over the internet, and experts are claiming that
the threat may be worse than the infamous Conficker.
Aside from stealing personal information, Gumblar is known to
intercept search queries from Internet Explorer through sites like
Google and replace legitimate results with predetermined links set
by attackers.
Experts are saying that Gumblar's scariest attribute how hard it
is to completely remove. According to ScanSafe, the most effective
remedy to this infection is simply a full reformat and
reinstallation. Fortunately, ScanSafe has provided a method of detecting a Gumblar infection.
Condensed steps below:
- Find sqlsodbc.chm in the Windows system
folder
- Obtain the SHA1 reading from the sqlsodbc.chm
file
- (CNET suggests using FileAlyzer to obtain the SHA1)
- Compare the SHA1 to the list of normal instances that ScanSafe
has identified in their blog
If your SHA1 doesn't match one of those listed by ScanSafe, you
could be infected with Gumblar and should contact your security
admin immediately.
If you need any help with any of this, let us know (TheFutureOfIT@switchfast.com).
Best,
Michael Holley
Switchfast Technologies
Chicago IT Support
& Consulting
Rochester
IT Support & Consulting
Leave comment: