Chicago IT Support and Consulting

Switchfast Blog: The Future of IT

Beware: Gumblar virus

Tuesday, June 02, 2009 by Michael Holley

News of the latest round of attacks from the Gumblar virus has been erupting all over the internet, and experts are claiming that the threat may be worse than the infamous Conficker. Aside from stealing personal information, Gumblar is known to intercept search queries from Internet Explorer through sites like Google and replace legitimate results with predetermined links set by attackers.

Experts are saying that Gumblar's scariest attribute how hard it is to completely remove. According to ScanSafe, the most effective remedy to this infection is simply a full reformat and reinstallation. Fortunately, ScanSafe has provided a method of detecting a Gumblar infection. Condensed steps below:

  • Find sqlsodbc.chm in the Windows system folder
  • Obtain the SHA1 reading from the sqlsodbc.chm file
  • (CNET suggests using FileAlyzer to obtain the SHA1)
  • Compare the SHA1 to the list of normal instances that ScanSafe has identified in their blog

If your SHA1 doesn't match one of those listed by ScanSafe, you could be infected with Gumblar and should contact your security admin immediately.

If you need any help with any of this, let us know (TheFutureOfIT@switchfast.com).

Best,

Michael Holley

Switchfast Technologies
Chicago IT Support & Consulting
Rochester IT Support & Consulting

Related posts

0 comment(s) for “Beware: Gumblar virus”

    Leave comment:

    Name:  
    Email:  
    Website:
    Comment:  




    Archives