Help me get infected!

Discussion in 'Software' started by BlackZ2401, Jun 11, 2011.

  1. BlackZ2401

    BlackZ2401 Private E-2

    I work for a computer repair shop and I see virus/spyware infections all the time. What I'm trying to do it set up a OS in a virtual machine, and when we go to hire a new technician have them remove the infections on said machine and see how they go about it.

    Only problem is... I can't seem to get infected! I've tried the basics that I can think of... porn site, warez sites, clicking through stuff in my spam folder. I got nada (other then boring mywebsearch).

    Can someone either point me in the right direction or send me a link to something that will get me one (or 12) of those fake antivirus/trojans? That new one "Windows XP Recovery / Restore" would be amazing.

    Thanks guys for any help you can provide!
     
  2. thisisu

    thisisu Malware Consultant

    what i've tried before is going through my hosts file, after spybot search and destroy customizes it, and typing in the URLs into a virtualbox machine. Some of those sites were still alive and kicking, most weren't though. I didn't get any major infection though, but i also didn't go through every single host edit url either.

    I may try it again in a bit, i'm kind of in the same boat as you except i'm not an employer :(
     
    Last edited: Jun 11, 2011
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just a reminder to not post any links to malware sites. :major
     
  4. BlackZ2401

    BlackZ2401 Private E-2

    If someone DOES have a link, would it be OK to PM it to me? I can't believe how easily and often my customer get infected, yet while I'm TRYING to I can't. Kinda sad I think.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your ability to PM is restricted until you have 50 posts. So that avenue is out. However, here is some info on "How did I get Infected" which might help in your endeavor:

     
  6. thisisu

    thisisu Malware Consultant

    lol i think the same way :)
     
  7. thisisu

    thisisu Malware Consultant

    Tim, i've wondered, how come spywareblaster doesn't edit the hosts file, but spybot's immunization will? what techniques does spywareblaster use? where are these customizations being applied to, if not hosts. the SOFTWARE SECURITY files?
     
  8. BlackZ2401

    BlackZ2401 Private E-2

    Thanks for the tips, unfortunately I'm well aware what people do that get them infected.... I just need to figure out WHERE they are doing it. Alas I may just go dig through my spam folder and click away
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I really don't know what SpywareBlaster does to protect your system. I think it just loads definitions and stops any of those items from entering the system. But don't take that as gospel.

    Yes, spam is a good place to start. UTorrents are another good avenue.
     
  10. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    I PM'd a friend, he got a nasty IIS MBR frier and worse Apache killer. His site would have died. If he offers that then I'll send it to you if you wish. It all depends on the forum rules here which I won't break.;)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    PM me with it augie and I can pass it along. ;)
     
  12. BlackZ2401

    BlackZ2401 Private E-2

    Yes please!
     
  13. Rocktot

    Rocktot Private First Class

    Please keep us updated!:-D What is the minimum deecent memory for a Windows7 VB? Can you do them ok on 2 gigs?
     
  14. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    It will be slow but usable.

    As to the keygen, the admin wisely got rid of it.;) Why keep that on one's server eh?:-D Once burnt, then you'll never burn me again!roflmao
     
  15. thisisu

    thisisu Malware Consultant

    can you send it to me as well?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My only suggest is that if you are using WOT, start clicking on sites with a big RED button next to them. :-D:-D
     
  17. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Gawd, these 'infect me please' threads always give me migraines for some obscure reason.:confusedrolleyes:-D Go 'click happy too'.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After years now of doing Malware removal, I am still at a loss as to how these people get infected. Kid's where clicking on things, I was downloading a codec, I wasn't looking at porn, etc. It often seems to just be a luck of the draw by going to what seems to be safe web sites.
     
  19. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Agreed. My kids have sole use of our desktop and haven't gotten an infection yet. It's a miracle if you ask me. Granted, I have protection on it and they are on the limited user account, but it actually stuns me.

    I'd think there have to be sites out there that specialize in this type of thing to test systems.
     
  20. tgell

    tgell Major Geek Extraordinaire

    Spycar.org will test your antivirus or antisyware against a series of tests.

     
  21. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Yep. I do know there are sites that will do that. I think I worded my post wrong. I meant there have to be sites where you can find live infections to load onto your system.
     
  22. Caliban

    Caliban I don't need no steenkin' title!

    Greetings, BlackZ2401.

    One quick test for any potential technician would be to see if she/he can pass the "File .EXT" test: simply write a shutdown.exe batch file and rename the file to something else, such as .MP3 or .JPG. When the file is opened, the machine shuts down, simulating virus-like activity.
     
  23. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Nope, not gonna touch spycar, too involved.
     
  24. tgell

    tgell Major Geek Extraordinaire

    Hello,
    I received permission from an admin to post the following site. It lists many blocked malware domains.


    A word of WARNING

    You click this site at your own risk!!!

    It is being posted only for this the purposes of this thread and for the OP.

    Code:
    http://www.malwaredomains.com/
     
  25. theefool

    theefool Geekified

    also, change the host table. Have the host table point google.com, yahoo.com, msn.com, bing.com to a random site that you choose.

    Not getting their answers can be a laugh. heh.

    I know of a few other things that can mess with ppl.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I approved this post only for the reasons given. This is only for the purposes stated.

    Unless you want to become infected, do not click on any links in this site!! :major

    This is for testing purposes only!!
     
    Last edited: Jun 11, 2011
  27. mcsmc

    mcsmc MajorGeek

    When the malware removal forum explodes, we'll know why. :-D
     
  28. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    I don't think that will happen here any time soon.;) :-D
     
  29. thisisu

    thisisu Malware Consultant

    lol thanks :)
     
  30. mcsmc

    mcsmc MajorGeek

    Well... I could've chosen different words. I meant that when the malware forum's ACTIVITY explodes from its current flow rate, we'll know why.;)
     
  31. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    I hope I never see the Activity day.;) Soundsa likea pasta disha k?:cry:-D
     
  32. dlb

    dlb MajorGeek

    As a tech myself, I too have been looking for a known infectious site. Since I never found one, I ended up storing some known rogue EXE files on a flash drive. I booted to a PECD, located the rogue files, and copied 'em to a flash drive before deleting 'em from the hard drive. I now have a flash drive with about 50 different rogue/infectious EXE files. All I have to do is copy 'em to the SYSTEM32 folder, or the %username%\Local Settings\Application Data folder, or the %username%\AppData\Local (or Roaming) folder and then double click 'em to get them to fully install and hijack the PC.... yeah it sucks, but sometimes it MUST be done....
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I used to use a VM and oh I tried and tried to get the most exotic types of infections to study and see in action and ultimately remove. But all I ever got was MWS and vanilla typed adware.... tell you what though, I let my partner (at the time) use the machine a while and within 5 mins I kid you not it was loaded... I should send you his email address :-D :-D :-D But I won't.

    Ironic isn't it that we try and try and it just does not seem to happen. Google images (which Web of Trust integrates with) is a great way to find infections, sponsored links.. etc... no doubt hacker forums often link to bad files.

    I never get infected (I know that is tempting fate) yet some folks are formatting twice monthly... rolleyes I say it time and time again the best protection software is the user... if they are educated enough in computing basics. Lots of it is just common sense. ;)
     
  34. dlb

    dlb MajorGeek

    I just went to the site mentioned in post #24 above - EXCELLENT list of bad sites! I have bookmarked it and will be adding their lists to my hosts file.... kind of off topic, but does SpywareBlaster use these lists? I know SpywareBlaster does NOT use the hosts file, so I'm kind of wondering how SpywareBlaster goes about blocking sites.... but I guess that's for a new, different thread.
     
  35. thisisu

    thisisu Malware Consultant

    I think i've recalled seeing Spywareblaster using what appears to be a couple of the config files, like SOFTWARE SECURITY, but that's just an observation. i've checked their forums in the past and came up empty. would like to understand how that program works.
     
  36. sikvik

    sikvik Corporal Karma


    http://www.bleepingcomputer.com/forums/topic92857.html

    Cheers..
     
  37. Rocktot

    Rocktot Private First Class

    Isnt there a way to, look up 'how to write viruses', and you go into these sites and get infected? Or was it hacking sites? maybe google scriptkiddies?
     
  38. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    roflmao Good ideas man! This thread feels more and more like a link hunter looking for some fodder.;)
     
  39. mcsmc

    mcsmc MajorGeek

    Definitely look into getting Yahoo chat booter progz, hotmail hacking progz, etc.

    Also, find pr0n sites that want to install a special codec to view their naughty videos.
     
  40. dlb

    dlb MajorGeek

    A friend of mine got infected by downloading a "movie" from an very public torrent site (I think it was PirateBay). The movie was something that hadn't hit the theatre yet, but this download was supposed a BluRay rip of a brand new movie. Upon trying to play it, he got this message saying "click this link to install 'ultra-groovey media player' to watch this excellent rip from 'goofy-pirate-group'". So he clicked the link, and BAM!!! He immediately had 3 different "antivirus and system repair programs" reporting that he a bazillion infected files, registry problems, the hard drive had "critical errors", and all he had to do to fix everything was to submit a credit card number and accept the $69 fee and the PC would be "fixed". Luckily, he called me before "purchasing" the "software" and read to me exactly what was on-screen. I said "STOP!! DO NOT TYPE ANYTHING! DO NOT CLICK ANYTHING! TURN OFF THE PC!". 4 hours later, I had de-virused the PC..... uhhhh.... where was I going with this? Oh yeah- torrent sites can be a good source of rogue-ecs (like "codecs" but they're rogue) and malware in general...

    BE CAREFUL!!!
     
  41. augiedoggie

    augiedoggie The Canadian Loon - LocoAugie (R.I.P. 2012)

    Yup dlb, social engineering at it's best!:mad Shouldn't people be smarter than this?:confused Then again, people pay for roofing jobs that never happen. *sigh*
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds