Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 25th, 2008, 09:19 AM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default WTF??

I got infected last night via an USB drive. I inserted it, copied a .doc and a .xls to my computer and removed it. I didn't opened the files. I have Autorun disabled. Next thing I know, my laptop is slow, as in SLOW. So I downloaded CureIt and it found the following:

c:\windows\system32\amvo.exe
c:\windows\system32\amvo0.dll
c:\nlblkhq.com
d:\nlblkhq.com
z:\nlblkhq.com

All identified as Win32.besso by CureIt.

BTW, my friend, who owned the usb drive, was also infected, but the file was named help.exe, also win32.besso.

after deleting the files, I wasn't able anymore to open any of the disks, when double-clicking or when trying to explore, it launched the list for choosing a program to open. So, time to go back in time with System Restore and it was solved. One last check with CureIt, one check with AVP tool and one check with SAS. All clean. Time for me to go to sleep.

But my question is: how could this happen if I didn't executed anything and Autorun is disabled? Maybe there was another culprit I'm not aware of or can't remember? I blame the usb drive because both me and my friend where infected, I didn't installed or downloaded anything yesterday and I do all my browsing sandboxed.
Would an app like AntiExecutable have helped in this case?
Is it possible to open USB-drives sandboxed? Are there any problem if I do so?


PS: NOD32 has let me down a bit to often lately...maybe time to move on...
__________________
I SandboxIE

Last edited by HURST : March 25th, 2008 at 01:59 PM.
  #2  
Old March 25th, 2008, 01:15 PM
Cerxes's Avatar
Cerxes Cerxes is offline
Frequent Poster
 
Join Date: Sep 2005
Location: Northern Europe
Posts: 581
Default Re: WTF??

Do you have your hidden files and folders displayed? Choose to show them otherwise.

Regarding this trojan you could have stop it from doing its thing by:

1. Using a HIPS that monitors the processes in your system.

2. Running in a restricted account and thereby have write/change permissions disabled for root, windows, programfiles and HKLM.

It was presumably loaded into the explorer.exe process.

/C.

Last edited by Cerxes : March 25th, 2008 at 01:32 PM.
  #3  
Old March 25th, 2008, 02:03 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: WTF??

Quote:
1. Using a HIPS that monitors the processes in your system.

Yeah, probably a HIPS is the best way, but I don't feel I'm ready to safely use a HIPS. I know that eventually I'm going to click the wrong option and/or I'm going to get bored of the pop-ups... Almost 6 months now and still can't decide myself on trying a HIPS.
__________________
I SandboxIE
  #4  
Old March 25th, 2008, 02:41 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: WTF??

Quote:
Originally Posted by HURST
how could this happen if I didn't executed anything and Autorun is disabled?

See here for a possible explanation:
Code:
[autorun] open=kwjkpww.exe shell\open=Open shell\open\Command=kwjkpww.exe shell\open\Default=1 shell\explore=Explore shell\explore\Command=kwjkpww.exe
Quote:
Holding down the Shift Key will prevent the execution of the first line of the file, but the shell commands will be written to the Registry effectively overriding the 'Open' and 'Explore' actions on the right-click context menu, and the double-clicking of the drive icon to open the drive to view the contents. Any of those actions will launch the executable.
Using TweakUI the right way
Quote:
Originally Posted by HURST
Would an app like AntiExecutable have helped in this case?
Sure. Or a HIPS. Or a behav. blocker. Or LUA + SRP.
Quote:
Originally Posted by HURST
Is it possible to open USB-drives sandboxed? Are there any problem if I do so?
I don't know about Sandboxie, but in GeSWall you can make custom rules to treat removable drives as always untrusted.
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #5  
Old March 25th, 2008, 05:04 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: WTF??

Thanks lucas..that was an interesting read...
After this, I'm trying ThreatFire... let's see how it goes....
__________________
I SandboxIE
  #6  
Old March 25th, 2008, 09:26 PM
farmerlee's Avatar
farmerlee farmerlee is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,581
Default Re: WTF??

Anti-executable may have helped. I've noticed that if i insert a flashdrive containing exe files and go to view the contents i get pop ups from AE telling me those exe's have been blocked.
__________________
Pryon G930V2
Windows 7 Home Premium 64 bit
Norton 360 v6
Sandboxie
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:24 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums