IPB

Welcome Guest ( Log In | Register )

> The Case of the Flashget Trojan Download, Regardless of who was to blame, it happened.
LittleMonster
post 15.03.2008 18:03
Post #1


Member
**

Group: Members
Posts: 21
Joined: 13.03.2008
From: Lisbon




It would appear that Flashget's updates have been compromised and it has been downloading trojans to users' computers. Many Flashget users have been affected. What worries me is that I only picked it up after a virus scan. Perhaps naively, I would have expected KIS to spot this while it was happening and at least flag it up.

There was a most interesting article on this in Viruslist but the page is now empty. It described the vulnerability and suggested that it might have been the result of a hacker attack. This thinly veiled accusation I believe to be unfair. The trojan was firmly dropped into the Flashget folder, rather than squirreled away somewhere else, as though somebody was calling attention to the vulnerability rather than exploiting it.

Flashget was running on my PC when the Trojan was detected on disc but memory scans were clean. I take this to indicate that nothing was being sent elsewhere that I would object to. Please put me straight if I err. The now blanked article did carry the dates over which the events happened and it would be useful to see those again so I can assess what damage might have been done.

There has been discussion in Flashget's forum but no resolution. For this reason, I think it worth calling attention to for the sake of those who may still be unaware. The advice given was to uninstall the application until such time as a fix was released.

This may be paranoia but, in the event that the maliciousness was intended, will simply using control panel to remove the app work sufficiently to remove everything? Residues are often left behind as we all know.

Presumably, this can happen with any programme - even one we all trust. It would be useful to know how to use KIS to at least warn of anything like this in future. In the extreme case, an armed raid on any company's headquarters will compromise their servers!
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
Baz^^
post 15.03.2008 20:48
Post #2


Wrestling Champion
**************

Group: Moderators
Posts: 8251
Joined: 9.03.2007




The downloaded .exes would not be trusted....because they aren't flashget files smile.gif


--------------------
Kind Regards,

Baz (volunteer moderator/beta testing lead -- I don't work for Kaspersky ;)
)
Go to the top of the page
 
+Quote Post
LittleMonster
post 16.03.2008 04:01
Post #3


Member
**

Group: Members
Posts: 21
Joined: 13.03.2008
From: Lisbon




QUOTE(MAPKOBKA^^ @ 15.03.2008 17:48) *
The downloaded .exes would not be trusted....because they aren't flashget files smile.gif


Sorry to take so long replying.

Thanks for that reassurance. So all is now well and I just need to keep an eye on Flashget's website for when they fix the loophole and I can have a download manager again smile.gif

Thanks again, everyone beer.gif

Go to the top of the page
 
+Quote Post
Don Pelotas
post 16.03.2008 11:26
Post #4


Global Moderator
***************

Group: Global moderators

Posts: 25915
Joined: 7.04.2005




QUOTE(LittleMonster @ 16.03.2008 02:01) *
Sorry to take so long replying.

Thanks for that reassurance. So all is now well and I just need to keep an eye on Flashget's website for when they fix the loophole and I can have a download manager again smile.gif

Thanks again, everyone beer.gif

Or use another free one like LeechGet or others, but do you actually need one...?


--------------------
Go to the top of the page
 
+Quote Post
LittleMonster
post 16.03.2008 19:59
Post #5


Member
**

Group: Members
Posts: 21
Joined: 13.03.2008
From: Lisbon




QUOTE(Don Pelotas @ 16.03.2008 08:26) *
Or use another free one like LeechGet or others, but do you actually need one...?


I used to try to listen to BBC7 over the web but got fed up with the scrambling you get when traffic is heavy. Flashget would download almost perfect copies either overnight or in the early afternoon that I could listen to whenever. The BBC altered something last year that prevented this from working satisfactorily so, reluctantly, I have had to give up on that. I have used it once or twice since for html downloads but I suppose you are quite right and it isn't really necessary for that.

I'm having some fun and games now with internet access being repeatedly blocked. No reason is given in any popup and access returns (albeit briefly) after a reboot. I'll have a trawl around the forum, when I feel up to it, and see if that has happened to anyone else. It's not the first time access has been blocked like this but now it is being persistent about it!

I have, for example, had to reboot while composing this message!

sad.gif

Go to the top of the page
 
+Quote Post

Posts in this topic


Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 9.02.2010 16:50