Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software
photo of Mary Landesman

Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software since 2000

More Infected Digital Picture Frames

Monday December 29, 2008

Gregg Keizer of ComputerWorld has reported a malware event eerily similar to last year's Best Buy snafu: More infected digital picture frames, this time from Samsung and distributed through Amazon. According to Keizer, "Samsung did not specify how the malware got on the CD, or how it escaped its quality control checks."

The malware is a variant of Sality, a file infecting virus that infected the Windows XP driver file somewhere within the Samsung networks, and which was then subsequently distributed on certain models of Samsung digital picture frames. Interestingly, the Samsung support notice (PDF) sent to affected customers says the issue can be resolved by uninstalling the old tainted driver and installing an updated version. Of course, nothing could be further from the truth. As a file infecting virus, Sality would quickly spread to other executable files on the system and it includes a downloader which installs additional malware via the Web. Sality also includes an autorun worm component, so the infection would quickly spread to USB thumb drives and other removable/discoverable drives. (See How to Disable Autorun to prevent autorun worms from spreading).

If you purchased a Samsung digital photo frame from Amazon.com prior to November 27th and you installed it on Windows XP (which was the infected driver file), your system would have been infected. You'll want to uninstall the digital frame driver, scan the system with up-to-date antivirus software and allow it to clean any Sality infected files and remove any other malware the scanner finds. Sality disables antivirus software on infected drives and it prevents access to certain security websites. You may need to use a clean computer to create a bootable antivirus rescue CD and use that to scan the infected computer(s). After which, you can proceed at your own risk and install a new driver from Samsung if you dare.

Comments

January 2, 2009 at 2:41 pm
(1) zak822 says:

It would be very useful if you could tell us a lot more about this sort of thing: “Sality also includes an autorun worm component, so the infection would quickly spread to USB thumb drives and other removable/discoverable drives.”

How do we protect jump drives, will having our security software set to scan on access prevent an infected jump drive from infecting the primary system are questions that I don’t have answers to! Help!

January 5, 2009 at 12:29 pm
(2) Mary Landesman says:

For questions on autorun, see: Autorun FAQs. For instructions on disabling autorun, see How to Disable Autorun

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Discuss

Community Forum

Explore Antivirus Software

About.com Special Features

Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.