Untangling the mystery
http://www.meetsinglepeople.org/ (don’t go there!)
Portions Copyright (c) 1999,2003 Avenger by NhT
sysusb\usbdur.exe
(Perdón por hacer el post en inglés)
It’s been a hard morning.
Yesterday, I was at the Concibe doing a small workshop about IP telephony and XML web applications for WML enabled phones, it was a nice experience. However, because I was the one with the presentation on the laptop, and a couple files we needed to distribute, my computer had some unprotected SEx (Software Exchange), coming from an university network where you can find almost any imaginable virus, something had to bypass the antivirus and infect my machine, almost 4 hours for the antivirus (AVG) claimed that my laptop was virus free.
However, my machine kept poping out the site http://www.meetsinglepeople.org/ at random intervals, using my digital camera (which pretty much work like a usb drive) I noticed that a locked autoexec.inf (which I couldn’t delete or open) was being written every time I connected the camera (I formatted the memory every time I unplugged it) and a hidden recycle bin folder named sysusb, inside that folder, 2 files: a desktop.ini which tells windows that the sysusb folder is a recycle bin and a usbdur.exe which I presume is the virus.
However, usbdur.exe seems to use a trick in order to be executed: it relies on the user to clic in the “Open folder to view files using Windows Explorer” option in the autorun menu, once it is on the system, it copies itself to any removable media and network drives, creating the autorun.inf and desktop.ini files.
Using my trusty Hex Editor, I managed to find a string “Portions Copyright (c) 1999,2003 Avenger by NhT” which a quick google search revealed some additional information, as it seems to be from a Delphi unit and also seem to be included in some Russian backdoor malware, sadly I can´t read machine code.
AVG currently (as of Octuber 28, 2009) does not recognize the file as a virus, using the Jotti’s Malware Scan reveals that most antivirus don’t recognize it either. I already mailed the file to the AVG team and decided to write this in order to present a bit more information than what I found originally (most results are quation to public forums, where they only suggest installing and running antivirus/antimalware, yet nobody had claimed that it worked, and somebody already said that formatting the machine trice didn’t work at all).
I’ll try to keep working on this, it may be just annoying to have a site poping up, but I´m paranoid to think that there may be something else, like a keylogger or a trojan.
Moose out
Etiquetas: Malware, meetsinglepeople, NhT, sysusb, usbdur, Virus


