New Posts  All Forums:Forum Nav:

Possible trojan?

post #1 of 13
Thread Starter 
Hey guys,

I noticed recently that 2 of my USB keys were exhibiting some strange behavior. When I plug them into my laptop (running Fedora) I get a message that pops up telling me that there is a something that is trying to run itself and asks if I want to continue or to cancel. Naturally I select "No" because I have no idea what it is.

Upon investigating my USB keys I find that there have been 2 hidden files placed on each one:

On first USB key:

auto.inf
this file contained the following string:

Code:
;TjmBcAdwINUgNulktQuGCzksnwvXxiMrzcWYpelxhYoCrHUkxZbIPzWjjzuyBpXoxInGEpzsWdNMJsK
If was then followed with an additional file which was an executable called:
owlxck.exe


On the second USB key:

auto.inf
his file contained the following string:

Code:
;muindcBQHcOwb
It was then followed with an additional file which was an executable called:
ofalir.exe


Luckily I have only been plugging this USB into two machines. One being a VM of Windows 7 running on my laptop inside of Fedora 10. My anti-virus program on my Windows 7 machine has picked up an auto.inf file under the 'C:\\Windows\\system32'
which I had it delete.

I have been trying to find reference to these auto.inf's and the strings contained within them as well as the .exe's. However I haven't been able to turn up anything that indicates if they really are a threat or not. My instinct tells me that there is something fishy about them though.
I was wondering if anyone has seen this type of behavior before?
Any ideas on what I can do to squash the bug that I have that caused this problem?
Or am I just overreacting?

Thank you in advance


Cheers

Todd
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
post #2 of 13
Format the USB Drives
The Time Machine
(13 items)
 
  
CPUMotherboardGraphicsRAM
Kentsfiel Intel Core 2 Quad Q6700 3.6Ghz Evga nForce 790i SLI FTW Edition EVGA GTX 260 Core 216 Corsair DDR3 4096Mb @ 1600Mhz 
Hard DriveOptical DriveOSKeyboard
1 TB Western Digital LG SuperMulti Dvd Burner Windows 7 Ultimate 64Bit Razr Lycosa 
PowerCaseMouse
ANTEC True Power 750 Watt@80 Bronze Rating NZXT Guardian 921 Logitech M510 
  hide details  
Reply
The Time Machine
(13 items)
 
  
CPUMotherboardGraphicsRAM
Kentsfiel Intel Core 2 Quad Q6700 3.6Ghz Evga nForce 790i SLI FTW Edition EVGA GTX 260 Core 216 Corsair DDR3 4096Mb @ 1600Mhz 
Hard DriveOptical DriveOSKeyboard
1 TB Western Digital LG SuperMulti Dvd Burner Windows 7 Ultimate 64Bit Razr Lycosa 
PowerCaseMouse
ANTEC True Power 750 Watt@80 Bronze Rating NZXT Guardian 921 Logitech M510 
  hide details  
Reply
post #3 of 13
This happened a few days ago to my friend then I took his usb drive to school to turn in an essay and found out it was the Conficker virus and I infected some computers by accident
The Time Machine
(13 items)
 
  
CPUMotherboardGraphicsRAM
Kentsfiel Intel Core 2 Quad Q6700 3.6Ghz Evga nForce 790i SLI FTW Edition EVGA GTX 260 Core 216 Corsair DDR3 4096Mb @ 1600Mhz 
Hard DriveOptical DriveOSKeyboard
1 TB Western Digital LG SuperMulti Dvd Burner Windows 7 Ultimate 64Bit Razr Lycosa 
PowerCaseMouse
ANTEC True Power 750 Watt@80 Bronze Rating NZXT Guardian 921 Logitech M510 
  hide details  
Reply
The Time Machine
(13 items)
 
  
CPUMotherboardGraphicsRAM
Kentsfiel Intel Core 2 Quad Q6700 3.6Ghz Evga nForce 790i SLI FTW Edition EVGA GTX 260 Core 216 Corsair DDR3 4096Mb @ 1600Mhz 
Hard DriveOptical DriveOSKeyboard
1 TB Western Digital LG SuperMulti Dvd Burner Windows 7 Ultimate 64Bit Razr Lycosa 
PowerCaseMouse
ANTEC True Power 750 Watt@80 Bronze Rating NZXT Guardian 921 Logitech M510 
  hide details  
Reply
post #4 of 13
Thread Starter 
Quote:
Originally Posted by Gbomartin View Post
This happened a few days ago to my friend then I took his usb drive to school to turn in an essay and found out it was the Conficker virus and I infected some computers by accident
dammit it is the conficker virus? I had a funny feeling that is what it was. I wasn't 100% sure though because usually an anti-virus program will flag it as that. That is bogus!! It is such a pain in the ass to get rid of to!

I don't know where I would have picked it up though. I might have plugged it into a computer at school .

Will format though thank you for the advice.


Cheers
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
post #5 of 13
While I am not 100% sure that it is confickr, I had a similar issue with my USB, Hard Drives, and everything else. The process took about a day and I used several different programs to reconstruct everything that was tampered with.

In this case, I would just go and reformat. In the case about your school, if they use an imaging program, you have nothing to worry about. If they do not, you might want to tell a teacher if you could talk to your IT Consultant and inform them that you mey have accidently infected their machines with malware.
Dataslum
(23 items)
 
  
CPUMotherboardGraphicsGraphics
AMD Phenom II X6 1090T Crosshair IV Formula GTX 560 GTX 580 
RAMRAMRAMRAM
G. Skill F3-12800CL6D-4GBPI G. Skill F3-12800CL6D-4GBPI G. Skill F3-12800CL6D-4GBPI  G. Skill F3-12800CL6D-4GBPI 
Hard DriveHard DriveHard DriveOptical Drive
Seagate Hard Drive Seagate Hard Drive Crucial M4 SSD Sony Optiarc 
CoolingOSMonitorMonitor
Corsair H70 Windows 7 Professional x64 ASUS VH242H 23" Monitor ASUS VH242H 23" Monitor 
MonitorKeyboardPowerCase
Samsung SyncMaster 906BW 19" Monitor Logitech G15 Corsair 1K PSU Lian-Li 70A 
MouseMouse PadAudio
Logitech Performance MX Razer Vespula HT Omega Pro+ 
  hide details  
Reply
Dataslum
(23 items)
 
  
CPUMotherboardGraphicsGraphics
AMD Phenom II X6 1090T Crosshair IV Formula GTX 560 GTX 580 
RAMRAMRAMRAM
G. Skill F3-12800CL6D-4GBPI G. Skill F3-12800CL6D-4GBPI G. Skill F3-12800CL6D-4GBPI  G. Skill F3-12800CL6D-4GBPI 
Hard DriveHard DriveHard DriveOptical Drive
Seagate Hard Drive Seagate Hard Drive Crucial M4 SSD Sony Optiarc 
CoolingOSMonitorMonitor
Corsair H70 Windows 7 Professional x64 ASUS VH242H 23" Monitor ASUS VH242H 23" Monitor 
MonitorKeyboardPowerCase
Samsung SyncMaster 906BW 19" Monitor Logitech G15 Corsair 1K PSU Lian-Li 70A 
MouseMouse PadAudio
Logitech Performance MX Razer Vespula HT Omega Pro+ 
  hide details  
Reply
post #6 of 13
Reformat the USB drives I think.

You can also upload the files to http://www.virustotal.com/ to have them scanned by ~100 anti-viruses.
snowRAZR
(13 items)
 
  
CPUMotherboardGraphicsRAM
Q6600 Core 2 Quad 2.4 Ghz Gigabyte EP45-UD3P Sapphire ATI 4830 4 GB 
Hard DriveOSMonitorPower
320GB WD 7200 rpm Windows 7 Professional/Windows XP 64 bit Samsung 19" Widescreen LCD 550W Corsair CMPSU-550VX 
Case
XCLIO Windtunnel 
  hide details  
Reply
snowRAZR
(13 items)
 
  
CPUMotherboardGraphicsRAM
Q6600 Core 2 Quad 2.4 Ghz Gigabyte EP45-UD3P Sapphire ATI 4830 4 GB 
Hard DriveOSMonitorPower
320GB WD 7200 rpm Windows 7 Professional/Windows XP 64 bit Samsung 19" Widescreen LCD 550W Corsair CMPSU-550VX 
Case
XCLIO Windtunnel 
  hide details  
Reply
post #7 of 13
Thread Starter 
Quote:
Originally Posted by GH0 View Post
While I am not 100% sure that it is confickr, I had a similar issue with my USB, Hard Drives, and everything else. The process took about a day and I used several different programs to reconstruct everything that was tampered with.

In this case, I would just go and reformat. In the case about your school, if they use an imaging program, you have nothing to worry about. If they do not, you might want to tell a teacher if you could talk to your IT Consultant and inform them that you mey have accidently infected their machines with malware.
Thank you for the suggestion. I was at school today and it was actually confirmed that the schools network has been infected with the confickr virus....again. It has apparently been infected for the last few weeks. I guess I was unlucky and got hit with it.

Quote:
Originally Posted by TheGrayNobleman View Post
Reformat the USB drives I think.

You can also upload the files to http://www.virustotal.com/ to have them scanned by ~100 anti-viruses.

Thats pretty cool, I didn't know that existed. I will check it out thank!


Cheers
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
post #8 of 13
It sounds as if you might have gotten the virus. I know you figured that out already but I hope it is an easy fix.
MusicPC
(13 items)
 
Headphone rig
(2 items)
 
 
CPUMotherboardGraphicsRAM
Intel Core i7-920 2.66Ghz Quad Core Processor Asus P6T Deluxe Gaming Motherboard nVidia 9800GT 512MB GDDR3 Video Card 3GB DDR3-1333 Triple Channel Memory (3x1GB) 
Hard DriveOSPower
Western Digital 1TB SATA-II Hard Drive Vista Home Premium 64-bit 580 Watt Power Supply 
OtherOther
Burson HA-160Ds Hifiman HE-400 
  hide details  
Reply
MusicPC
(13 items)
 
Headphone rig
(2 items)
 
 
CPUMotherboardGraphicsRAM
Intel Core i7-920 2.66Ghz Quad Core Processor Asus P6T Deluxe Gaming Motherboard nVidia 9800GT 512MB GDDR3 Video Card 3GB DDR3-1333 Triple Channel Memory (3x1GB) 
Hard DriveOSPower
Western Digital 1TB SATA-II Hard Drive Vista Home Premium 64-bit 580 Watt Power Supply 
OtherOther
Burson HA-160Ds Hifiman HE-400 
  hide details  
Reply
post #9 of 13
with the stick drives being so handy plug em in and drop files or take files off its easy to not bother with a scan before doing anything with it i will check any stick before it touches my pc by scan or odd looking files.

ithe worst virus i had a few months ago infected every .exe in windows and on every reboot the count went up a total wipe then reformat was the only answer so you have to be careful just take a moment to check before you plug anything in.
    
CPUMotherboardGraphicsRAM
i7 930 Asus Rampage II Extreme  Sapphire Radeon HD7770 1gb 6gb ocz reaper 
Hard DriveOptical DriveOSMonitor
WD250gb-AAJS WD640gb-AAKS Sony optiarc ad5250 sata Windows 7 ultimate 64bit Lg Flatron E2260 22"hdmi 
KeyboardPowerCaseMouse
Logitech g15 Corsair AX750 Cooler Master HAF X Logitech m505 laser 
Mouse PadAudio
mouse pad ASUS Xonar Essence STX 
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
i7 930 Asus Rampage II Extreme  Sapphire Radeon HD7770 1gb 6gb ocz reaper 
Hard DriveOptical DriveOSMonitor
WD250gb-AAJS WD640gb-AAKS Sony optiarc ad5250 sata Windows 7 ultimate 64bit Lg Flatron E2260 22"hdmi 
KeyboardPowerCaseMouse
Logitech g15 Corsair AX750 Cooler Master HAF X Logitech m505 laser 
Mouse PadAudio
mouse pad ASUS Xonar Essence STX 
  hide details  
Reply
post #10 of 13
Thread Starter 
Quote:
Originally Posted by musicPC View Post
It sounds as if you might have gotten the virus. I know you figured that out already but I hope it is an easy fix.
Haha yeah I have thought of this indeed - and actually it did sort of turn out to be an easy fix!

Quote:
Originally Posted by maxextz View Post
with the stick drives being so handy plug em in and drop files or take files off its easy to not bother with a scan before doing anything with it i will check any stick before it touches my pc by scan or odd looking files.

ithe worst virus i had a few months ago infected every .exe in windows and on every reboot the count went up a total wipe then reformat was the only answer so you have to be careful just take a moment to check before you plug anything in.
Definitely you are right about this, it appears as though I did pick something nasty up - although i am still unsure of where I got it from or now it managed to jump to my virtual machine...


I figured out what it was though - at least I think. I was getting frustrated with my USB drives constantly getting those stupid auto.inf's and exe's so I decided to run a few scans of my virtual machine WITH my USB key's plugged in. I ran several conficker removal tools, however they did not find anything. I didn't stop there though. I decided that I would try Malwarebytes as this program has saved my life a few times in the past.

**NOTE**: my windows VM was also experiencing additional weird behavior - explorer.exe was no longer running at startup.

I ran malwarebytes against my VM. It took almost 2 hours to complete haha... but when it was finished it did indeed find the nasties that were causing my problem. It turned out to be a trogan buried deep within my system. It was actually impersonating the crss.exe executable in windows, however it was running under a slightly modified name to make it appear legit - sneaky bastard! After running malwarebytes and cleaning it out I haven't had anymore nasties on my USB keys... love you malwarebytes.


Cheers


p.s. thank you to everyone that responded... cheers
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
For Fun
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Core 2 Quad Q6600 Asus P5N-E SLI MSI GeForce GTX 460 Fermi Cyclone OC 768MB OCZ/Corsair 6144MB PC6400 DDR2 800MHz 
Hard DriveOptical DriveOSMonitor
2x500GB Western Digital RAID 0 NEC DVD-RW ND-3520A Windows 7 64-bit Samsung 2033sw 20' 
KeyboardPowerCaseMouse
Razer Arctosa Coolmax CX1-600B PCI Express 600W THERMALTAKE Wing RS 100 ATX Razer Diamondback 
Mouse Pad
steelseries 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security