January 20, 2009
12:17 am

The Downadup worm utilizes autorun.inf files to spread via removable devices such as USB drives. The autorun.inf uses some tricks, such as variable size, to help avoid detection. Bojan Zdrnja at SANS Internet Storm Center recently posted some additional analysis. Downadup attempts a social engineering trick in Windows Vista.

Downadup's autorun.inf file uses an action keyword and icon extracted from shell32.dll to produce the following. The category is "Install or run program" but the text and icon are for "Open folder to view files". The first option will run Downadup, not good. The second "general" option is the choice that will safely open the USB drive. It happens on Windows 7 also, F-Secure Weblog.

Loading

Contextual Related Posts:

1 Response | RSS comments on this post | Leave a comment»

  1. 1
    Extremesecurity says#1 | January 23rd, 2009 at 2:41 am

    Did Downadup/conficker attack your network? I've created a batch file for system administrators to clean/patch/cure infected systems in their networks.

    check it out here:

    http://extremesecurity.blogspo.....ro-my.html

No Pingback yet

PingBack URI

Leave a Response

Comment Preview
« Apple’s China website selling refurbished productsFix Windows 7 Sidebar with UAC Off issue »
Feed Icon

Subscribe via RSS or email: