Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

17.3.08

Windows Task Manager Not Working / Accessible- EXPLOIT

After seeing post after post on various security / computer forums where people are stating their task manager No Longer works, I decide to look around. I first suspected a virus disabling the Task manager to hide it's process from the user. Little did I know, it would be verified. So if you have this problem, it isn't your only problem. You more than likely have a Virus or some type of Malware.
This is Not a fix, It is a possible Reason.

Windows XP SP2 Taskmgr bug


http://core-security.net/archive/2008/march/index.php#14032008

Back in 2006 Izee of the EOF virus writing team discovered a possibility to crash the Windows Taskmanager. It was easily done by setting a REG_BINARY value in the Registry of Windows to 0x00. The key is the following:

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager:Preferences

If you set it to 0x00, 0x00, 0x00... the Taskmanager will crash on the next startup. I (skyout) have therefore coded an exploit and used it back in 2006 in one of my first viruses as a very basic technique to hide my process to the user. Then we waited for a long time without using this bug anymore. With the release of Windows Vista we tested it again and it was fixed. In 2008 now, exactly in February, I got in contact with Microsoft Germany and informed them about the bug. They told me, that they will work on it, but for weeks not even an email came back. Now it is time for making this public! Now this bug is open for every person and everyone can use it and put pressure on Microsoft to fix it.

Here you can find the exploit: [taskmgr_dos.c.txt]


16.1.08

Malware Quietly Reaching 'Epidemic' Levels

New reports say malware increased by a factor of five to 10 in 2007


JANUARY 16, 2008 | 5:40 PM
By Tim Wilson
Site Editor, Dark Reading

Everybody knew it was bad, but few knew it was this bad.

In separate studies released yesterday, two research firms now say that malware increased between 500 percent and 1,000 percent in 2007, and it shows no signs of slowing down.

"The number of new strains of malware that appeared in 2007 increased tenfold with respect to the previous year," said PandaLabs, Panda Security's research arm, in a report issued yesterday. "Over the last year, PandaLabs has received an average of more than 3,000 new strains of malware every day. This represents a malware epidemic which -- although silent, with little media coverage and no widespread alerts -- is nevertheless dangerous."

The results indicate that signature-based defenses for malware are no longer effective, the research firm said. Some 72 percent of networks with more than 100 workstations -- and 23 percent of home users -- are currently infected with malware, despite having operative antivirus or other signature-based tools in place, PandaLabs said.

Experts at AV-Test, an independent testing organization, also reported skyrocketing incidence of malware yesterday. After a detailed count, the organization said it identified nearly 5.5 million different malware files in 2007 -- more than five times as many as in 2006.

AV-Test counted the number of files with different MD5 hashes, sometimes called "fingerprints." This includes malware which is packed using a different run-time packer or is differently encrypted, the testing organization said.

In 2007, AV-Test found almost 5.5 million such files, up from about 973,000 in 2006 and 333,000 in 2005, the report said. And the trend is accelerating: The group already has identified more than 118,000 different malware files in the first two weeks of January.

The results drove AV-Test to concur with PandaLabs's assessment. "The figures clearly demonstrate that the signature-based approach of current anti-virus software is no longer appropriate," the report said.

3.1.08

Digital photo frame contains Virus/Malware part2

In a previous post HERE
we learned of people either buying or receiving NEW hardware loaded with a virus or malware. While the reports speculate that this is not widespread, or in the wild, this can not by any means be the end of this. Since most,'not unlike myself' do not suspect a NEW device to contain a virus, we don't even think of looking/scanning for it on said device. This being the case, I am sure there are many others out there in the world that have become infected in this manner and don't even realize it.

In my previous post on this subject I said:
"Well the who seems fairly easy. Correct me if I'm wrong. The who is China. I say this due to the fact most of these types of electronics and damn near everything else comes from them. Under the Direction of whom is all together another Question."
This appears to have been somewhat CONFIRMED in this latest post from SANS Internet Storm Center where a reader reports, "Google-ing the name of the virus executable turns up three Chinese-language links."

What makes this all the worse is that some have an autorun.exe file. For those that don't know/understand what this is I'll try and simply explain. You know when you put a music CD or a movie DVD in and it starts Automatically, that's what autorun does. If this is the case, there is NO WAY to SCAN the device to detect the infection before it runs.

As I stated before this is BIG, and NO telling how many devices are infected without people realizing it.
_______________________________

http://isc.sans.org/diary.html?storyid=3807

Digital Hitchhikers Part Two
Published: 2008-01-04,
Last Updated: 2008-01-04 02:51:08 UTC
by Marcus Sachs (Version: 1)

Several days ago David Goldsmith posted a diary concerning a digital photo frame that came with a value added feature. Since then, two more readers have sent us notes concerning malware on digital photo frames that were purchased or received as Christmas presents last week. We've been in contact with the security team of the retail store chain where they were purchased as well as the product vendor and both swear that no malware is on the units they are selling.

So, dear readers, here is your first project for the New Year. If you either purchased or were given a digital photo frame, GPS unit for your car, external hard drive, or any other device that connects to your computer via a USB cable and
appears to your operating system as one or more mounted drives, please let us know via our contact form if you experienced any suspicious behavior that smells like malware.

To give you an idea of what we are talking about, here are edited excerpts from the three notes we have received so far:

First notification.

Behavior after attaching the USB digital photo frame to the PC:

1. MSCONFIG would not run - it would briefly open and then terminate

2. Blue screen when starting in safe mode

3. Many antivirus websites would result in browser terminating

4. Various popups for random name.exe "not valid image messages"

Using the CA AV2008 product, a new aggressive virus named Win/32Mocmex.AM was found on the photo frame (filename: kwjkpww.exe ). No detailed info on it is listed yet in their database. (More information was later available at http://www.prevx.com/filenames/394470622808329496-0/KAWDHZY.DLL.html.)

Second notification.

The attached file is from a digital picture frame. This file was originally named "autorun.inf", was marked as a hidden, system file, and was located along-side the sample pictures shipped with the picture frame. The program file launched by this autorun was deleted, but is a variant of the trojan Win32/Agent virus. This file was also marked as hidden.

It did appear all seals were intact and the product was carefully wrapped when it was unpacked. However, I can't say for sure that this frame was not a victim of a prior connection.

The virus scanner I'm using tagged the virus .exe file "cfhskjn.exe" as shown in this log entry:

Threat Name:Trojan:Win32/Agent

Detection Date and Time:1/1/2008 4:23 PM

File Name:G:\kwjkpww.exe

Threat Severity:Severe

Threat Category:Trojan

Threat found by On Demand Scan:(ANTIVIRUS_ONDEMAND)

Threat Status:Removed

so I'm thinking it was not the autorun.inf worm or "silly worm" as described in this link. Although I've not dug into this particular .exe code that was found on this frame, the classification as a Win32/Agent threat tells me it is not of a worm (self-propagating) type and behaves more as a Trojan threat.

Google-ing the name of the virus executable turns up three Chinese-language links. Using the Google-translate function, you get this web page from the first link:

http://tinyurl.com/28w8vc

which tells me this virus has been in circulation since at least Oct 30 of 2007.

Third notification.

I too connected a digital picture frame to my computer and received the nastiest virus that I've ever encounterd in my 20 plus year I/T career. The product vendor tells me it's not true however I know exactly what, how and when. The virus absolutely came from the frame. Is there any way to cooberate this?

This virus was indeed on the frame. It propagates to any connected device by copying a script, a com file and an autorun file. It hides all systems files and itself while completely eliminating the user admin ability to show hidden files. It creates processes that negate any attempt to go to anti virus and anti spam web sites. It prevents the remote installation of any anti virus components. I was able to remove it by using the attrib command to unhide then delete the files, then run Symantec anti virus. I also manually deleted the files from my USB drive and and flash drive that I used to back up my data. I then had to long format and rebuild my computer because I had no trust that it was safe.

I was using my computer the morning that it crashed without any troubles at all. I web mailed, VPN connected to my business network which is FDA regulatory compliant and very secure. When I completed my work I then connected the picture frame and my system immediately went crazy. After this happened I ceased to use my system and went to a second computer here I your publication that re-enforced my immediate conclusion.

By the way, I also received a digital photo frame for Christmas but have not had any problems with it other than the resolution totally sucks. But that's a subject of another diary some day. The GPS unit I bought in November mounts as a drive letter in Windows but it too had no malware on it. We are pretty certain that this is not a wide-spread problem but we need to know if others have experienced anything like this. Please use our contact form to report any observed malware-like behavior in any of these external devices you recently purchased or received as gifts. Please be sure to include information about the model name, where you bought it, and if you've been in contact with the store or product vendor. We'll provide a summary in a few days with details on what was reported.

Many thanks to readers Edd, Larry, and Rick for bringing this issue to our attention.

Marcus H. Sachs
Director, SANS Internet Storm Center

25.12.07

New Hardware contains Virus/Malware

This is another report of buying NEW Hardware with Virus/Malware pre-installed on it.
So lets see now......We have HD's with them, We have USB sticks with them, and now the Digital Picture Frame.[Which I still think are cool.] I'm sure there are many other devices out in the Wild we don't know about. I mean if some of these things happened on your Box, would you suspect the New Hardware of installing or having installed it??
My Question is: Who is doing this, and why.
Well the who seems fairly easy. Correct me if I'm wrong. The who is China. I say this due to the fact most of these types of electronics and damn near everything else comes from them. Under the Direction of whom is all together another Question.
Is this another way to prepare for the coming 'CYBER WARS'?
Infect and control as much as possible before your adversary has a chance.
Sounds about right in War strategy.
------------------------------------

Digital Hitchhikers

Published: 2007-12-25,
Last Updated: 2007-12-25 23:24:44 UTC
by David Goldsmith (Version: 1)
http://isc.sans.org/diary.html?storyid=3787

We received a report this afternoon from someone who had recently received a digital picture frame. Unfortunately, it had a extra component with it. The built-in storage came with what appears to be some malware already loaded on it -- a file called 'cfhskjn.exe' was on it when unpacked.

Some of the behavior seen when the digital picture frame was connected to the computer was:

* MSCONFIG would not run - it would briefly open and then terminate
* The system would blue screen when starting in safe mode
* Going to various anti-virus websites would result in the web browser terminating
* Various popups for random name.exe "with 'not valid image' messages

This specific product was an "ADS Digital Photo Frame - 8" (sold by Sam's Club - see http://www.samsclub.com/shopping/navigate.do?dest=5&item=368725) but this type of infection can, and has affected other portable devices with internal storage.

Kaspersky has a blog entry 'Adventures at altitude' (see http://www.viruslist.com/en/weblog?discuss=208187471&return=1) about one of their employees who bought a Kingston CF memory card that came with a virus on it.

Whether its a picture frame, a digital camera or any USB, CF, SD, etc memory card, the portable nature of these devices dredges up of memories of all the floppy boot viruses we used to have to deal with. [ What's a 'floppy disk' you ask? ;-) ]

Care should be taken when attaching storage devices to your computer to ensure you scan them for possible malware and handle them in as secure a fashion as is possible.

David Goldsmith (dgoldsmith -at- sans.org)