Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » USB Viruses take off
Search Topic:
Uniqs:
542
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
(topic move) cvv2 1$ per one visa master US 1$ per one »
« [419] The FBI are 419ing me!  
AuthorAll Replies

moike

join:2007-03-31
Atlanta, GA

USB Viruses take off

I'm surprised that USB viruses haven't spread faster than they have to date.

»garwarner.blogspot.com/2008/08/l···ool.html

...
While many viruses spread via email or by visiting infected webpages, this network spreads by network connections and via "USB Thumb Drives".

When a USB drive is inserted into a computer, the computer scans the drive for an "AutoRun.inf" file. If the AutoRun.inf file is present, the computer does whatever it is told to do.

If a stranger (or a student, in this case) gives you a USB thumb drive and you stick it into the computer, the default setting on any Windows computer is to execute that AutoRun sequence.

The way this family of viruses, which we call "USB Jumpers", works is that they modify the AutoRun.inf file to execute a copy of the virus, which is often present on the thumbdrive as a "hidden file" called "Setup.exe".

...
Of particular interest is the auto-run .PIF virus:

if the drive contains a ".pif" extension, there is further danger. Browsing a folder containing a ".pif" from Active Desktop (the default in Windows XP) is enough to invoke the virus.
Vista adds a notification to the user before blindly running whatever is on a USB drive. XP is more challenging. Disable AutoRun. You'll put up with endless nagging from iTunes about the disabled AutoRun state, but it beats getting a virus. Don't just trust the directions to disable Autorun ... test it. I use this harmless but startling file here ... named autorun.inf on the root directory of a USB drive:

[AutoRun]
Open= cmd.exe /k color 4e && echo Gotcha!
shell\Open\command= cmd.exe /k for /l %%a in (1,1,9) do start cmd.exe /k color %%ae ^&^& p rompt Gotcha!


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
·AT&T Midwest

Take a look at this thread:
»Disabling 'Autorun' on USB and beyond. Need help.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1


fireflier
Coffee. . .Need Coffee
Premium
join:2001-05-25
Limbo

edit:
September 1st, @03:26PM

reply to moike
.


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
·AT&T U-Verse
·RoadRunner Cable
·AT&T Yahoo

reply to moike
In one case, "take off" is literal: that being the password
stealing worm that infected laptops aboard the International
Space Station. It first got onto an astronaut's USB memory
stick.
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)

dentman42

join:2001-10-02
Columbus, OH
·AT&T Midwest

reply to moike
said by moike See Profile :

Vista adds a notification to the user before blindly running whatever is on a USB drive. XP is more challenging. Disable AutoRun. You'll put up with endless nagging from iTunes about the disabled AutoRun state, but it beats getting a virus.
Good reason to not use iTunes. One of my first actions on a new install is to disable autorun. (Right up there with changing default folder view to details, showing hidden files, not hiding extensions for known file types, not hiding system files, and showing the contents of system folders.)
-
Forums » Up and Running » Security » Spam, Scam and Phishbusters(topic move) cvv2 1$ per one visa master US 1$ per one »
« [419] The FBI are 419ing me!  


Thursday, 20-Nov 18:08:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [198] Obama FCC Selection Team Won't Make AT&T Happy
· [101] DSL's Not Dead Yet
· [77] Zone Alarm Pro Free Just For Today
· [75] Harvard Law Professor Sues RIAA
· [67] New Xbox 360 'Experience' Goes Live
· [57] CRTC Rules Against Indie ISPs In Throttling Dispute
· [51] Cable Grabbing 71% Of New Broadband Customers
· [48] Comcast DOCSIS 3.0 Hits Pacific Northwest In December
· [44] Comcast Offers 'Bare Bones' 768kbps VoIP Double Play
· [43] Comcast Buys San Fran Muni-Network
Most people now reading
· CRTC ruling coming Thursday Nov 20 [TekSavvy]
· Rocky - time to offer VPN service to all your customers [TekSavvy]
· How would you take this? [General Questions]
· Dumping Bell Home Phone Because Of CRTC ruling [TekSavvy]
· Xbox 360 NXE is available! [Console/Handheld games]
· Official news from TekSavvy regarding the CRTC descision [TekSavvy]
· Discussion on CRTC Non-Ruling thus far... [TekSavvy]
· [WotLK] LK download/install [World of Warcraft]
· We're not endorsing internet throttling: CRTC [TekSavvy]
· [OOL] OOL upgrade to Docsis 3.0 ? Y my internet so fast ? [OptimumOnline]