![]() |
Trojans using forbidden file names |
Post Reply
|
Page 12> |
| Author | ||
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Topic: Trojans using forbidden file namesPosted: 14 February 2008 at 7:57am |
|
|
Thank you D4v3 for sharing this info.
|
||
|
Ring0 - the source of inspiration
|
||
![]() |
||
D4v3
Newbie
Joined: 18 December 2007 Location: Mexico Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Posted: 14 February 2008 at 4:02am |
|
|
here is a VBS to remove this kind of pest, mainly found in USB pendrives =)
the description of the virus and the complete infection method (check system) spanish to english translation
Edited by D4v3 - 14 February 2008 at 11:43am |
||
![]() |
||
D4v3
Newbie
Joined: 18 December 2007 Location: Mexico Online Status: Offline Posts: 6 |
Post Options
Quote Reply
Posted: 13 February 2008 at 11:04pm |
|
autorun.small (exe and source code included) sended check your pms, hope it helps.
|
||
![]() |
||
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 13 February 2008 at 4:24pm |
|
|
Yes, it is Win9x era compatibility reasons.
|
||
|
Ring0 - the source of inspiration
|
||
![]() |
||
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 13 February 2008 at 4:07pm |
|
|
Nice 7.tmp moved to windir temp
|
||
![]() |
||
fcukdat
Senior Member
Joined: 02 September 2006 Location: United Kingdom Online Status: Offline Posts: 374 |
Post Options
Quote Reply
Posted: 13 February 2008 at 11:42am |
|
|
EP,
I have many working samples(droppers) that install Gromozon RK infection which incorperates the EFS service file.
Just to make sure i got gromozoned to the eyeballs again
Dropper>>>
Amongst other nasty Gromozon infection components drops this 'lil beauty
HJT Entry-
O23 - Service: LogPrf - Unknown owner - \\?\C:\Program Files\Windows NT\aux.exe (file missing)
Space inserted in file title when copied using IceSword inorder to facilitate uploading to VT service
Grmozon had landed and is about to get expunged
![]() Edited by fcukdat - 13 February 2008 at 12:14pm |
||
|
___________
Ade Gill Malwarebytes Researcher |
||
![]() |
||
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 13 February 2008 at 3:46am |
|
On my 64 bit Vista Ultimate I still able to crash/confuse Windows Shell by using long file names, forbidden names, etc. Nothing new in Shell directory listing / file access algorithms. More to say - NTFS hard link causes unnecessary shell warnings (e.g. try to open Documents and Settings folder on Vista with Explorer). Forbidden file names such as "lpt", "con", "com", folder names "..", "." is a 16 bit legacy and exist as I understand in compatibility reasons. Internally Windows is able to operate with such file system object through Native API routines and in some cases UNC. All trojans can work in the same manner as on Windows XP for example. And AFAIK XP SP3 doesn't contains these shell changes so necessary for security. |
||
|
Ring0 - the source of inspiration
|
||
![]() |
||
Elite
Senior Member
Joined: 15 April 2007 Location: United States Online Status: Offline Posts: 175 |
Post Options
Quote Reply
Posted: 13 February 2008 at 2:04am |
|
Probably same thing. |
||
|
4 > 1
|
||
![]() |
||
SystemPro
Senior Member
Joined: 26 April 2007 Location: Germany Online Status: Offline Posts: 504 |
Post Options
Quote Reply
Posted: 13 February 2008 at 1:48am |
|
|
||
![]() |
||
EP_X0FF
Senior Member
Joined: 08 March 2006 Location: Russian Federation Online Status: Offline Posts: 4753 |
Post Options
Quote Reply
Posted: 13 February 2008 at 1:38am |
|
|
@SystemPro
This is not a bug. This is limitations of Win32 API. I can tell, that such things will work even on Vista with SP1. @fcukdat Yes, Gromozon was one of the such trojans, if you have "alive" samples it will be very good if you can share them with me. @Elite And additionally SecuROM creates a registry key with embedded nulls under the HKCU\Software\SecuROM. Edited by EP_X0FF - 13 February 2008 at 1:40am |
||
|
Ring0 - the source of inspiration
|
||
![]() |
||
Post Reply
|
Page 12> |
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |