<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Gumblar &#8211; virus Threat to the Internet &#8211; How to Remove</title> <atom:link href="http://www.webologist.co.uk/05/gumblar-virus-threat-to-the-internet-how-to-remove/feed" rel="self" type="application/rss+xml" /><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove</link> <description>Internet News Blog With A Little Search Optimisation</description> <lastBuildDate>Wed, 08 Feb 2012 22:33:54 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>By: Mel</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-23362</link> <dc:creator>Mel</dc:creator> <pubDate>Sat, 05 Jun 2010 12:26:22 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-23362</guid> <description>Thank you for the very thorough explanation. I have been googling this subject for about four hours, and yours is far and away the clearest for a simpleton like me to understand. AVG is blocking access to my own sites, and my webhost says Gumblar, so I am on the hunt for a solution. Thanks for the detail.</description> <content:encoded><![CDATA[<p>Thank you for the very thorough explanation. I have been googling this subject for about four hours, and yours is far and away the clearest for a simpleton like me to understand. AVG is blocking access to my own sites, and my webhost says Gumblar, so I am on the hunt for a solution. Thanks for the detail.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-21721</link> <dc:creator>Webologist</dc:creator> <pubDate>Wed, 31 Mar 2010 10:41:14 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-21721</guid> <description>What did you download? Maybe try to uninstall and delete that, then run av (avast is a good choice) and hope that clears it up.</description> <content:encoded><![CDATA[<p>What did you download? Maybe try to uninstall and delete that, then run av (avast is a good choice) and hope that clears it up.</p> ]]></content:encoded> </item> <item><title>By: Marie</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-21720</link> <dc:creator>Marie</dc:creator> <pubDate>Wed, 31 Mar 2010 10:30:44 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-21720</guid> <description>Hello there, I have a problem and I want to explain what is it.
I use Opera because Internet Explorer brought me a virus. I downloaded Google Chrome, and a few many hours ago, it said that I have a threat and that I&#039;m not connected to the Internet. The same happens when I open a program that I downloaded.
Sincerelly,
Marie</description> <content:encoded><![CDATA[<p>Hello there, I have a problem and I want to explain what is it.</p><p>I use Opera because Internet Explorer brought me a virus. I downloaded Google Chrome, and a few many hours ago, it said that I have a threat and that I&#8217;m not connected to the Internet. The same happens when I open a program that I downloaded.</p><p>Sincerelly,<br
/> Marie</p> ]]></content:encoded> </item> <item><title>By: Dan</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-16752</link> <dc:creator>Dan</dc:creator> <pubDate>Mon, 11 Jan 2010 13:42:21 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-16752</guid> <description>It is a shame that people still propagate the myth that other operating systems are immune to viruses.  As they become more popular they are being increasingly targeted and they have the same holes as any other OS I&#039;m afriad.  But this insistance that Macs are safe leaves people even more vulnerable to eg phishing scams etc as I find they are less aware.
People use Windows because consumer software and hardware is geared towards the MS world.  Life is too short for Linux.
Keep your OS up to date and be careful what sites you visit.</description> <content:encoded><![CDATA[<p>It is a shame that people still propagate the myth that other operating systems are immune to viruses.  As they become more popular they are being increasingly targeted and they have the same holes as any other OS I&#8217;m afriad.  But this insistance that Macs are safe leaves people even more vulnerable to eg phishing scams etc as I find they are less aware.</p><p>People use Windows because consumer software and hardware is geared towards the MS world.  Life is too short for Linux.</p><p>Keep your OS up to date and be careful what sites you visit.</p> ]]></content:encoded> </item> <item><title>By: Frank</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-14214</link> <dc:creator>Frank</dc:creator> <pubDate>Tue, 01 Dec 2009 15:19:41 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-14214</guid> <description>Use Google Webmaster Tools to keep an eye out for anything suspicious on your websites. Google alerts can also be set for the specific website. i.e. “site:yoursite.com viagra” will set an alert if your site is hacked by the usually jerks. Once corrected submit a sitemap to Google to re-index the pages.</description> <content:encoded><![CDATA[<p>Use Google Webmaster Tools to keep an eye out for anything suspicious on your websites. Google alerts can also be set for the specific website. i.e. “site:yoursite.com viagra” will set an alert if your site is hacked by the usually jerks. Once corrected submit a sitemap to Google to re-index the pages.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-12761</link> <dc:creator>Webologist</dc:creator> <pubDate>Wed, 04 Nov 2009 16:25:36 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-12761</guid> <description>Hi Mike, I am not familiar with Macs at all, and admit I have not been following this virus for some time now. There does appear to be a vulnerbility on Macs though:
&lt;blockquote&gt;&quot;So it appears Gumblar was downloaded on a Mac of ours. It doesn&#039;t appear to show any adverse affects. But when we started using that machine to access webservers, Gumblar got into these remote servers and infected multiple websites. Affected sites apparently crashed user&#039;s computers (only HP products for some reason) and they had to have them revived by service techs. Which I&#039;m paying for. I need to make a report about our situation. Any feedback on how this Gumblar can get from a Mac to a remote server yet not be evident on the host Mac?&quot; &lt;a href=&quot;http://news.cnet.com/8301-1009_3-10244529-83.html&quot; rel=&quot;nofollow&quot;&gt;http://news.cnet.com/8301-1009_3-10244529-83.html&lt;/a&gt;&lt;/blockquote&gt;
Not a solid source on information as it is just a forum post on Cnet.com. But there could well be a risk. Using Firefox and having all your software up to date is still the best security measure though - this applies to all operating systems not just Windows.
Plus the most important security measure - &lt;strong&gt;never allow software to store FTP logins and passwords&lt;/strong&gt; - not even text editors, but especially Dreamweaver etc. It is a lot safer to have the password on a bit of paper stuck on your wall than somewhere on your computer.</description> <content:encoded><![CDATA[<p>Hi Mike, I am not familiar with Macs at all, and admit I have not been following this virus for some time now. There does appear to be a vulnerbility on Macs though:</p><blockquote><p>&#8220;So it appears Gumblar was downloaded on a Mac of ours. It doesn&#8217;t appear to show any adverse affects. But when we started using that machine to access webservers, Gumblar got into these remote servers and infected multiple websites. Affected sites apparently crashed user&#8217;s computers (only HP products for some reason) and they had to have them revived by service techs. Which I&#8217;m paying for. I need to make a report about our situation. Any feedback on how this Gumblar can get from a Mac to a remote server yet not be evident on the host Mac?&#8221; <a
href="http://news.cnet.com/8301-1009_3-10244529-83.html" rel="nofollow">http://news.cnet.com/8301-1009_3-10244529-83.html</a></p></blockquote><p>Not a solid source on information as it is just a forum post on Cnet.com. But there could well be a risk. Using Firefox and having all your software up to date is still the best security measure though &#8211; this applies to all operating systems not just Windows.</p><p>Plus the most important security measure &#8211; <strong>never allow software to store FTP logins and passwords</strong> &#8211; not even text editors, but especially Dreamweaver etc. It is a lot safer to have the password on a bit of paper stuck on your wall than somewhere on your computer.</p> ]]></content:encoded> </item> <item><title>By: Mike</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-12760</link> <dc:creator>Mike</dc:creator> <pubDate>Wed, 04 Nov 2009 16:12:01 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-12760</guid> <description>Is Mac OSX vulnerable?</description> <content:encoded><![CDATA[<p>Is Mac OSX vulnerable?</p> ]]></content:encoded> </item> <item><title>By: Murphy %9</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-6839</link> <dc:creator>Murphy %9</dc:creator> <pubDate>Tue, 30 Jun 2009 16:52:12 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-6839</guid> <description>Super-Duper site! I am loving it!! Will come back again, Thanks.</description> <content:encoded><![CDATA[<p>Super-Duper site! I am loving it!! Will come back again, Thanks.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-6027</link> <dc:creator>Webologist</dc:creator> <pubDate>Thu, 28 May 2009 23:13:38 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-6027</guid> <description>OK, last night I installed Ubuntu onto my old XP machine, wiping the old XP installation. Took a while to install, as my disk is now 2 releases out of date, so upgraded to latest Ubuntu, 9.04 Jaunty Jackalope. Then installed VirtualBox OSE using the Synaptic Package Manager. Had to use command line once for &quot;sudo adduser me vboxusers&quot;. Then fired up VirtualBox, set up a new VM (virtual machine) and installed XP from disc. Now have a working XP within a Linux distro.
How bleedin&#039; secure is that eh?
So far only used IE, and it works a treat. Feel tempted to seek out dodgy sites to see what happens. Must be a list of sites with trojans/viruses on that I can test the system with.
The only reason I have XP running is for IE6 which seems to always screw up my CSS floats. And so many people still use IE6. When Google control all computers, and everyone uses Chrome, then life will be easier. Until then, VM&#039;s are the way to go.
I will write a dedicate post for this at some point....</description> <content:encoded><![CDATA[<p>OK, last night I installed Ubuntu onto my old XP machine, wiping the old XP installation. Took a while to install, as my disk is now 2 releases out of date, so upgraded to latest Ubuntu, 9.04 Jaunty Jackalope. Then installed VirtualBox OSE using the Synaptic Package Manager. Had to use command line once for &#8220;sudo adduser me vboxusers&#8221;. Then fired up VirtualBox, set up a new VM (virtual machine) and installed XP from disc. Now have a working XP within a Linux distro.</p><p>How bleedin&#8217; secure is that eh?</p><p>So far only used IE, and it works a treat. Feel tempted to seek out dodgy sites to see what happens. Must be a list of sites with trojans/viruses on that I can test the system with.</p><p>The only reason I have XP running is for IE6 which seems to always screw up my CSS floats. And so many people still use IE6. When Google control all computers, and everyone uses Chrome, then life will be easier. Until then, VM&#8217;s are the way to go.</p><p>I will write a dedicate post for this at some point&#8230;.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5991</link> <dc:creator>Webologist</dc:creator> <pubDate>Wed, 27 May 2009 19:25:22 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5991</guid> <description>&lt;a href=&quot;http://www.unmaskparasites.com/&quot; rel=&quot;nofollow&quot;&gt;UnmaskParasites.com&lt;/a&gt; provide an online tool to check if your site (well, any site in fact) has Gumblar (and maybe another .js .php .html page infected virus. This is their response to the fact that thousands of web site owners are unaware that their sites are hacked and infected with parasites.</description> <content:encoded><![CDATA[<p><a
href="http://www.unmaskparasites.com/" rel="nofollow">UnmaskParasites.com</a> provide an online tool to check if your site (well, any site in fact) has Gumblar (and maybe another .js .php .html page infected virus. This is their response to the fact that thousands of web site owners are unaware that their sites are hacked and infected with parasites.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5990</link> <dc:creator>Webologist</dc:creator> <pubDate>Wed, 27 May 2009 19:18:45 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5990</guid> <description>More useful information on Gumblar:
&quot;In Gumblar, hackers only wanted to load the script on Windows machines with version of Windows prior Vista (NT 6). In Martuz, they added a new check and no longer load the external script in a Google Chrome browser. I guess hackers read multiple forums and noticed that many webmasters used Google Chrome to detect the malicious code (Chrome detects calls to blacklisted sites and warns users). Now, if a webmaster loads an infected web sites in Chrome, there will be no warning since the external code won’t load. And the webmaster may mistakenly think that the site is clean and no additional removal action is required.
Don’t count on Google Chrome (and Safari) warnings. As you can see, hackers can make their code unnoticeable. And they can use new domain names every day, so that even if Chrome detects calls to the new malicious sites, it won’t warn you since those site are not blacklisted yet.
Make sure to check the source code of web pages. Or check web pages with my Unmask Parasites - it detects suspicious scripts without executing them.&quot; Source: &lt;a href=&quot;http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/&quot; rel=&quot;nofollow&quot;&gt;Martuz .cn - New Incarnation of the Gumblar Exploit. So What’s New?&lt;/a&gt;</description> <content:encoded><![CDATA[<p>More useful information on Gumblar:</p><p>&#8220;In Gumblar, hackers only wanted to load the script on Windows machines with version of Windows prior Vista (NT 6). In Martuz, they added a new check and no longer load the external script in a Google Chrome browser. I guess hackers read multiple forums and noticed that many webmasters used Google Chrome to detect the malicious code (Chrome detects calls to blacklisted sites and warns users). Now, if a webmaster loads an infected web sites in Chrome, there will be no warning since the external code won’t load. And the webmaster may mistakenly think that the site is clean and no additional removal action is required.</p><p>Don’t count on Google Chrome (and Safari) warnings. As you can see, hackers can make their code unnoticeable. And they can use new domain names every day, so that even if Chrome detects calls to the new malicious sites, it won’t warn you since those site are not blacklisted yet.</p><p>Make sure to check the source code of web pages. Or check web pages with my Unmask Parasites &#8211; it detects suspicious scripts without executing them.&#8221; Source: <a
href="http://blog.unmaskparasites.com/2009/05/18/martuz-cn-is-a-new-incarnation-of-gumblar-exploit/" rel="nofollow">Martuz .cn &#8211; New Incarnation of the Gumblar Exploit. So What’s New?</a></p> ]]></content:encoded> </item> <item><title>By: dave</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5983</link> <dc:creator>dave</dc:creator> <pubDate>Wed, 27 May 2009 15:51:12 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5983</guid> <description>Useful article and some good advice there. Check out my blog post on &lt;a href=&quot;http://www.webpayments.ie/blog/Gumblar-What-is-it-How-to-I-remove-it-.html&quot; rel=&quot;nofollow&quot;&gt;Gumblar&lt;/a&gt;, the links section includes a link to a php script to help automate its removal from a php site. I will add a link to your article to the links section on my post.</description> <content:encoded><![CDATA[<p>Useful article and some good advice there. Check out my blog post on <a
href="http://www.webpayments.ie/blog/Gumblar-What-is-it-How-to-I-remove-it-.html" rel="nofollow">Gumblar</a>, the links section includes a link to a php script to help automate its removal from a php site. I will add a link to your article to the links section on my post.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5847</link> <dc:creator>Webologist</dc:creator> <pubDate>Sat, 23 May 2009 18:48:15 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5847</guid> <description>We should point out that this virus is now often referred to as martuz.cn although I think that this domain has also not been closed down. The virus is spreading, the creators are being hounded and closed, but at the moment there is still no end in site, due to the huge numbers of people with unsecured Windows computers.</description> <content:encoded><![CDATA[<p>We should point out that this virus is now often referred to as martuz.cn although I think that this domain has also not been closed down. The virus is spreading, the creators are being hounded and closed, but at the moment there is still no end in site, due to the huge numbers of people with unsecured Windows computers.</p> ]]></content:encoded> </item> <item><title>By: Webologist</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5814</link> <dc:creator>Webologist</dc:creator> <pubDate>Fri, 22 May 2009 20:50:55 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5814</guid> <description>You seem to know your stuff. This all makes sense. I think that we shall review some of these suggestions, especially remote backups and virtual machines.
Readers may want an explanation on running VM in Linux/Ubuntu .... if you could give us some pointers, that would be greatly appreciated.</description> <content:encoded><![CDATA[<p>You seem to know your stuff. This all makes sense. I think that we shall review some of these suggestions, especially remote backups and virtual machines.</p><p>Readers may want an explanation on running VM in Linux/Ubuntu &#8230;. if you could give us some pointers, that would be greatly appreciated.</p> ]]></content:encoded> </item> <item><title>By: Server Security Analyst for a .com</title><link>http://www.webologist.co.uk/blog/gumblar-virus-threat-to-the-internet-how-to-remove#comment-5813</link> <dc:creator>Server Security Analyst for a .com</dc:creator> <pubDate>Fri, 22 May 2009 20:30:33 +0000</pubDate> <guid
isPermaLink="false">http://www.webologist.co.uk/2009/05/gumblar-virus-threat-to-the-internet-how-to-remove.html#comment-5813</guid> <description>This attack, like any virus attack, works because people adopt unsafe practices such as using the same PC for web development / business as home use, storing passwords without any thought of who may gain access to them, running old AV software, out of date OS installations, no firewalls, old browser software etc. etc.
Some suggestions to avoid getting infected with a trojan of any kind (not just gumblar):
&lt;strong&gt;1. Use a proper OS rather than Windows - OSX, Linux (Ubuntu is v. windows friendly)
2. Manage websites through a dedicated VM (and, have a dedicated VM for ebanking)
3. Turn on auto-update on all software
4. Subscribe to email updates for software to ensure you have the latest patch installed
5. Turn on auto-updates for Windows
6. Make regular remote backups&lt;/strong&gt;
Any one of the first three would have prevented a user being infected, the fourth would have made recovering from the attack trivial. Most PC users fail to take responsibility for their own machines, and end up spending far more time trying to eradicate viruses, trojans, spyware etc. than they would ever have to spend on actually making the PC secure in the first place.
Saying that, I still wonder why so many people continue to use Windows. Apart from some good games, you can do everything on Linux for free. And it is safer. For those that really want to continue to use a Windows operating system, as long as any Windows machines are running in a VM within Ubuntu, you can keep them pretty safe, even if they are not up to date with the latest security patches.</description> <content:encoded><![CDATA[<p>This attack, like any virus attack, works because people adopt unsafe practices such as using the same PC for web development / business as home use, storing passwords without any thought of who may gain access to them, running old AV software, out of date OS installations, no firewalls, old browser software etc. etc.</p><p>Some suggestions to avoid getting infected with a trojan of any kind (not just gumblar):</p><p><strong>1. Use a proper OS rather than Windows &#8211; OSX, Linux (Ubuntu is v. windows friendly)<br
/> 2. Manage websites through a dedicated VM (and, have a dedicated VM for ebanking)<br
/> 3. Turn on auto-update on all software<br
/> 4. Subscribe to email updates for software to ensure you have the latest patch installed<br
/> 5. Turn on auto-updates for Windows<br
/> 6. Make regular remote backups</strong></p><p>Any one of the first three would have prevented a user being infected, the fourth would have made recovering from the attack trivial. Most PC users fail to take responsibility for their own machines, and end up spending far more time trying to eradicate viruses, trojans, spyware etc. than they would ever have to spend on actually making the PC secure in the first place.</p><p>Saying that, I still wonder why so many people continue to use Windows. Apart from some good games, you can do everything on Linux for free. And it is safer. For those that really want to continue to use a Windows operating system, as long as any Windows machines are running in a VM within Ubuntu, you can keep them pretty safe, even if they are not up to date with the latest security patches.</p> ]]></content:encoded> </item> </channel> </rss>
