WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionConficker's autorun and social engineering EmptyConficker's autorun and social engineering

more_horiz
We wrote several diaries about Conficker (or Downadup, depending on the AV tool you are using). F-Secure posted some interesting information about the number of infections which is almost certainly in millions (and who knows how many machines will stay infected as the owners will not even notice anything).

One of the reasons for infecting so many machines is that Conficker uses multiple infection vectors:

1. It exploits the MS08-067 vulnerability,
2. It brute forces Administrator passwords on local networks and spreads through ADMIN$ shares and finally
3. It infects removable devices and network shares by creating a special autorun.inf file and dropping its own DLL on the device.

F-Secure also blogged about the autorun.inf file where they noticed that it contained a lot of garbage (about 60 kb of random binary data). This fooled some AV programs so they didn't scan the device properly (otherwise, they would have picked up the referenced DLL also stored on the device).

F-Secure also blogged about the autorun.inf file where they noticed that it contained a lot of garbage (about 60 kb of random binary data). This fooled some AV programs so they didn't scan the device properly (otherwise, they would have picked up the referenced DLL also stored on the device).

After removing garbage, one can see a nice autorun.inf file containing all important keywords. This grabbed my attention:

[Autorun]

Action=Open folder to view files
Icon=%systemroot%\system32\shell32.dll,4
Shellexecute=.\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn

Full article:
http://isc.sans.org/diary.html?storyid=5695

Atleast we now have some idea of where the dropper/infecter hides.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Conficker's autorun and social engineering DXwU4
Conficker's autorun and social engineering VvYDg

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Social engineering? This hacker really knows what he's doing man.

............................................................................................

Please be a GeekPolice fan on Facebook!

Conficker's autorun and social engineering Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Is it possible to detect it with HJT?

............................................................................................

Conficker's autorun and social engineering Segmen10

FunSubstance is the place to go for daily entertainment.

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Not as far as we know, but as I said, it's located in the system hidden recycle bin folder on external drives.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Conficker's autorun and social engineering DXwU4
Conficker's autorun and social engineering VvYDg

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Abit more news.
Conficker calls home to download updates for itself, meaning it will only get worse and there isn't much point fighting it.

The infected machines will also be compromised and use in mass DDoS attacks.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Conficker's autorun and social engineering DXwU4
Conficker's autorun and social engineering VvYDg

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
All this happens because of lazy users who can't be bothered to update Windows. This security patch was issued by Microsoft in October 2008.

............................................................................................

Please be a GeekPolice fan on Facebook!

Conficker's autorun and social engineering Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Found this surfing around today, maybe conficker.
Conficker's autorun and social engineering F_virusm_32367d2618

Haven't seen that SSCVIIHOST.exe before, but I suspect that's what that autorun.inf file is loading.

Virus couldn't be deleted, kept regenerating, suspect machine is infected with it too.
Formatting the stick didn't work, deleting the partition didn't neither.
Stick maybe trashed now. Indifferent or Blank

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Conficker's autorun and social engineering DXwU4
Conficker's autorun and social engineering VvYDg

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
Formatting didn't work probably because the malware stored itself in the PC and it could copy itself over and over again.... Let me think

............................................................................................

Please be a GeekPolice fan on Facebook!

Conficker's autorun and social engineering Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionConficker's autorun and social engineering EmptyRe: Conficker's autorun and social engineering

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum