Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

BHO scanning tool and New Scam Targets Bank Customers

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
Walt Starr Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jun-29-04 04:31 PM
Original message
BHO scanning tool and New Scam Targets Bank Customers
Handler's Diary June 29th 2004
Updated June 29th 2004 18:17 UTC
BHO scanning tool and New Scam Targets Bank Customers
------------------------------------------
Browser Helper Objects (BHO) scanning tool
------------------------------------------

BHODemon is a free tool that will list all Browser Helper Objects that are installed on a Windows system by scanning the registry and give you the ability to disable them. This will also list "good" BHOs as well, but nevertheless is a useful tool in detecting and disabling malicious software.

It is available at: http://www.definitivesolutions.com/bhodemon.htm

-------------------------------
New scam targets bank customers
-------------------------------

On June 24th, a visitor to the SANS Internet Storm Center reported that his company was "...in the middle of a very disturbing ... issue regarding the adware/spyware/IE exploit genre..." He requested help analyzing an "encrypted or compressed" file that had been downloaded to a machine at their site. Tom Liston, one of our volunteer handlers, spent the weekend analyzing this issue. His findings are summarized here.

The victim of the attack found that a file called "img1big.gif" had been loaded onto their machine. Because of the account restrictions on the person running the machine, it had failed to install properly, which was why it had come to their attention. It is this file that they forwarded to the SANS Internet Storm Center for analysis.

The file is not a graphic file at all. It is actually a 27648 byte Win32 executable that has been compressed using the Open Source executable compressor UPX. This file decompresses to an 81920 byte file which contains two Win32 executables bound together. The first portion of the file (and what actually runs if the file extension is changed and the program is launched) is a "file dropper" Trojan, designed to install any executable concatenated to its body. The second half of the file consists of a Win32 DLL that is installed by the file dropper under WindowsXP as a randomly named .dll file under C:\WINDOWS\System32\. This DLL is installed as a "Browser Helper Object" (BHO) under Internet Explorer

http://isc.incidents.org/diary.php?date=2004-06-29

I recommend using Opera, Mozilla, or Firefox browsers for online transactions as this exploit affects IE.
Printer Friendly | Permalink |  | Top
mbperrin Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jun-29-04 04:48 PM
Response to Original message
1. Thanks for the tip! I just downloaded
Firefox; is it possible that it loads faster or is it just me?
Printer Friendly | Permalink |  | Top
 
hightime Donating Member (395 posts) Send PM | Profile | Ignore Tue Jun-29-04 05:43 PM
Response to Reply #1
2. It was very slow to load for me at work, much faster at home.
Printer Friendly | Permalink |  | Top
 
AnnInLa Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Jun-29-04 05:50 PM
Response to Original message
3. Scanning tool
Thanks for the scanning tool...had a horrendous episode with unwanted BHOs recently, glad now to have the tool.
Printer Friendly | Permalink |  | Top
 
mrsteve Donating Member (713 posts) Send PM | Profile | Ignore Tue Jun-29-04 07:18 PM
Response to Original message
4. Use Ad-aware also...
It checks for both malicious and non-malicious spyware, and gives you the option to delete if you wish (including cookies).

Been using it at work for years - keeps a lot of pesky IE add-ins away.

Although Opera, Mozilla, or Firefox are usually better browser choices, they won't let us use anything other than IE at the office.

Lavasoft Sweden website for Ad-aware
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Dec 26th 2024, 10:19 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC