September 19, 2004

A new record in Windows virii

For one of my clients.. (also on the Web according to an article today on CNN).
But I digress.

I removed some 438 "infections", mostly the Win32.Bagle virus from a client's Windows XP Home machine this morning. Simply stunning. Poor people had neither a firewall, nor virus protection. They had about fifteen different virii on the machine and it was barely functioning.

Thanks Microsoft for the business but it seems to be approaching criminal to put out an OS that is both vulnerable and lacking in the most basic protections.

Or perhaps I judge them harshly.

No, no, on reflection I don't. Hang them from the highest yardarm!

Posted by artandscience at September 19, 2004 02:19 PM
Comments

I can beat that.

600+ on a broadband connected machine...I literally yanked the cable connection from the wall. No good barracking the user as well because they didn't have a clue.

The firewall took massive sessions of hits over the next week or so as people came looking for the zombies (static IP) and I had to keep telling the user not to turn the firewall off - it would setle down once they realised the machine was 'dead' to them.

I'd argue that 99.8% of machines spewing out spam and DoS attacks are sitting in the family study of unsuspecting households.

But I'm almost an entirely converted Mac user now so I don't worry bout it :)

Posted by: Gary at September 20, 2004 02:32 PM

The list of virii included:

BagleAB
Rbot.XW
ForbotAM
Glieder (G, B, E, F)
BagleAJ
Rbot.AAV
BAT.FTPDownloader
Reg.SecDrop.D
HTML.MHTMLRedir.Exploit

Three hours of my time just got their machine running near capacity again.

Posted by: stefan at September 20, 2004 02:49 PM
Implementation of James Seng's security plugin: