ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Webroot - Malicious autorun scripts on USBs

    IT Discussion
    webroot avast security antivirus
    8
    17
    1.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Deleted74295D
      Deleted74295 Banned
      last edited by scottalanmiller

      0_1492681986125_screenshot.PNG

      This happened on my own laptop.

      Plugged in a customer pen drive to find all files/folders had been replaced by shortcuts which opened the original file or folder but also launched a script, this behaviour repeated itself on other USB sticks plugged in so something corrupted the autorun process.

      I also found this in the registry: HKEY_CURRENT_USER / Software / Microsoft / Windows / CurrentVersion / Run

      wscript.exe //D "C:\Users\BreffniPotter-DaraIT\AppData\Roaming\Microsoft Office\Microsoft Word.WsF"

      I'm using a policy which has all the features enabled and set to high.

      Opened a ticket with Webroot so will post back the reply.

      1 Reply Last reply Reply Quote 3
      • Deleted74295D
        Deleted74295 Banned
        last edited by

        Now reinstalling Windows....fun

        1 Reply Last reply Reply Quote 1
        • Deleted74295D
          Deleted74295 Banned
          last edited by

          Avast blocks the thing, just tested it.

          1 Reply Last reply Reply Quote 1
          • Reid CooperR
            Reid Cooper
            last edited by

            Sounds like a good candidate for our non-profit security test center!

            1 Reply Last reply Reply Quote 2
            • Mike DavisM
              Mike Davis
              last edited by

              So the malware was called by an autorun.inf, or you clicked on something on the pen drive?

              1 Reply Last reply Reply Quote 0
              • Deleted74295D
                Deleted74295 Banned
                last edited by

                Triggered before I touched any files.

                FYI Webroot replied to my ticket within 15 minutes requesting a time when one of their engineers could contact me. Fast reply.

                @Reid-Cooper said in Webroot - Malicious autorun scripts on USBs:

                Sounds like a good candidate for our non-profit security test center!

                No one would donate or fund it. Its not sexy enough to get donations.

                dafyreD C 2 Replies Last reply Reply Quote 0
                • dafyreD
                  dafyre @Deleted74295
                  last edited by

                  @Breffni-Potter said in Webroot - Malicious autorun scripts on USBs:

                  Triggered before I touched any files.

                  FYI Webroot replied to my ticket within 15 minutes requesting a time when one of their engineers could contact me. Fast reply.

                  @Reid-Cooper said in Webroot - Malicious autorun scripts on USBs:

                  Sounds like a good candidate for our non-profit security test center!

                  No one would donate or fund it. Its not sexy enough to get donations.

                  If I had the time to do it, I would definitely do it. Time is in short supply these days.

                  1 Reply Last reply Reply Quote 0
                  • C
                    Carnival Boy @Deleted74295
                    last edited by

                    @Breffni-Potter said in Webroot - Malicious autorun scripts on USBs:

                    Triggered before I touched any files.

                    Perhaps showing my ignorance here, but is autorun still a thing? I somehow thought it was disabled in Windows since about XP?

                    scottalanmillerS 1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @Carnival Boy
                      last edited by

                      @Carnival-Boy said in Webroot - Malicious autorun scripts on USBs:

                      @Breffni-Potter said in Webroot - Malicious autorun scripts on USBs:

                      Triggered before I touched any files.

                      Perhaps showing my ignorance here, but is autorun still a thing? I somehow thought it was disabled in Windows since about XP?

                      LOL, sadly, still a thing.

                      1 Reply Last reply Reply Quote 0
                      • Deleted74295D
                        Deleted74295 Banned
                        last edited by

                        @Carnival-Boy Nope. Still present in every version of Windows since XP. In 7 it asked what action you would like to take for removable media and a default was often, open file explorer.

                        In Windows 10, it is still alive and kicking but I thought I had it disabled.

                        1 Reply Last reply Reply Quote 0
                        • C
                          Carnival Boy
                          last edited by

                          Opening file explorer is ok though, isn't it? It's executing autorun.inf that's the problem.

                          1 Reply Last reply Reply Quote 0
                          • C
                            Carnival Boy
                            last edited by

                            From Wikipedia:
                            "Autorun.inf has been used to execute a malicious program automatically, without the user knowing. This functionality was removed in Windows 7 and a patch for Windows XP and Vista was released on August 25, 2009 and included in Microsoft Automatic Updates on February 8, 2011"

                            What am I missing here?

                            JaredBuschJ coliverC 2 Replies Last reply Reply Quote 0
                            • JaredBuschJ
                              JaredBusch @Carnival Boy
                              last edited by

                              @Carnival-Boy said in Webroot - Malicious autorun scripts on USBs:

                              From Wikipedia:
                              "Autorun.inf has been used to execute a malicious program automatically, without the user knowing. This functionality was removed in Windows 7 and a patch for Windows XP and Vista was released on August 25, 2009 and included in Microsoft Automatic Updates on February 8, 2011"

                              What am I missing here?

                              It is still there, but not by default anymore. Even Windows 10 lets you choose to allow autorun but on a per media basis.

                              1 Reply Last reply Reply Quote 0
                              • coliverC
                                coliver @Carnival Boy
                                last edited by

                                @Carnival-Boy said in Webroot - Malicious autorun scripts on USBs:

                                From Wikipedia:
                                "Autorun.inf has been used to execute a malicious program automatically, without the user knowing. This functionality was removed in Windows 7 and a patch for Windows XP and Vista was released on August 25, 2009 and included in Microsoft Automatic Updates on February 8, 2011"

                                What am I missing here?

                                This was the default functionality. Whenever you inserted a USB or CD it would search for the autorun.inf file and do whatever it said. Now it asks if you want to run it or do something else.

                                C 1 Reply Last reply Reply Quote 0
                                • C
                                  Carnival Boy @coliver
                                  last edited by

                                  @coliver said in Webroot - Malicious autorun scripts on USBs:

                                  Now it asks if you want to run it or do something else.

                                  Exactly. That's my point. It doesn't autorun, it asks you what you want to do.

                                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                                  • JaredBuschJ
                                    JaredBusch @Carnival Boy
                                    last edited by

                                    @Carnival-Boy said in Webroot - Malicious autorun scripts on USBs:

                                    @coliver said in Webroot - Malicious autorun scripts on USBs:

                                    Now it asks if you want to run it or do something else.

                                    Exactly. That's my point. It doesn't autorun, it asks you what you want to do.

                                    It does not automatically launch the autorun.inf, true. But to say the functionality is removed is incorrect. autorun.inf is still perfectly valid and lots of stupid people still click through.

                                    1 Reply Last reply Reply Quote 0
                                    • Reid CooperR
                                      Reid Cooper
                                      last edited by

                                      And a lot of people set it to "always do" something bad, then it doesn't ask again.

                                      1 Reply Last reply Reply Quote 0
                                      • 1 / 1
                                      • First post
                                        Last post