Author Topic: Tchibo sells negative scanner with a virus surprise (Win32/Conficker.B)  (Read 168 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15515
  • ┌∩┐(◕_◕)┌∩┐
heise Security - 3 Jan 2013

Over the Christmas period, German coffee roaster turned retailer Tchibo has been selling a virus-laden 35mm negative scannerGerman language link in its stores and online shop. The device, which is produced by electronics accessory manufacturer Hama, was sold for €60 (approximately £48). In an email to customers who purchased the scanner on their online store and an announcement on their web site, the company confirmed the problem.

Talking to The H's associates at heise Security, Hama corroborated Tchibo's report of the incident. The affected device was exclusively sold through Tchibo and was infected with the Win32/Conficker.B virus which rose to notoriety four years ago when it caused infections around the globe. Nowadays, any current anti-virus scanner should be able to detect this strain of malware with ease.

On the affected devices, Conficker is apparently present in the DCIM.exe and autorun.inf files. The autorun file itself cannot cause much trouble these days, as Microsoft modified the behaviour of Windows in this regard as a reaction to the original Conficker outbreak. However, if the .exe file is executed, the malware can still be spread on unprotected systems. Tchibo is offering affected customers refunds for the devices but also says that they can be safely used after the virus has been removed with a modern anti-virus application.

http://www.h-online.com/security/news/item/Tchibo-sells-negative-scanner-with-a-virus-surprise-1776642.html
PCLinuxOS 32bit KDE 4.10.4; kernel-3.4.11-pclos1.bfs & 64bit 3.4.38bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 11071
  • MLUs Forever!
Re: Tchibo sells negative scanner with a virus surprise (Win32/Conficker.B)
« Reply #1 on: January 06, 2013, 05:31:25 AM »
Quote
Tchibo has been selling a virus-laden 35mm negative scanner

Really?

The virus is in the scanner?

I do not believe it.

I believe the virus is in the software supplied on disc to operate the scanner  .....  the executable  dcim.exe  in particular (not the first case of this executable being infected)


Would it not be just as easy to report the situation truthfully ?


MLUs rule the roost!

Linux XPS 3.4.48-pclos1.bfs  64 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT