T
tburtenshaw
Hey, has anyone had problems with AVG not detecting the RJUMP virus (i
keep getting one called adober.exe).
I'm in thailand (mae sot) at the moment, and it is incredibly prevalent
here. I have seen in at nearly every internet cafe I have been to.
It's a virus transmitted via USB drives and card readers, thanks to
Windows' habit of running any autorun.inf file on any item of new
media.
It's obviously quite simple to do. When someone puts an infected
pendrive into a USB port, Windows finds the autorun.inf file, and runs
adober.exe. This program copies itself to the C:\WINDOWS directory (or
whatever), and alters the registry so it is run when windows starts.
The program remains resident in memory, and hijacks the usual "new
drive found" stuff, and as soon as a new USB drive is inserted, it
copies an executable, a DLL and the autorun.inf file. The new drive is
now ready to infect the next computer in the next thai internet cafe.
Most have AVG installed, but this did nothing. Another antivirus
program at one place did detect the virus, and even cleaned it from my
USB drive.
I now lock my SD cards before connecting them, and quickly check for
adober.exe in the running processes.
I haven't seen much about this anywhere else, I was wondering if others
have seen something like this. And also, WHY DOES WINDOWS RUN SOMETHING
WITHOUT ASKING!!! :-D
Thanks,
Tristan
keep getting one called adober.exe).
I'm in thailand (mae sot) at the moment, and it is incredibly prevalent
here. I have seen in at nearly every internet cafe I have been to.
It's a virus transmitted via USB drives and card readers, thanks to
Windows' habit of running any autorun.inf file on any item of new
media.
It's obviously quite simple to do. When someone puts an infected
pendrive into a USB port, Windows finds the autorun.inf file, and runs
adober.exe. This program copies itself to the C:\WINDOWS directory (or
whatever), and alters the registry so it is run when windows starts.
The program remains resident in memory, and hijacks the usual "new
drive found" stuff, and as soon as a new USB drive is inserted, it
copies an executable, a DLL and the autorun.inf file. The new drive is
now ready to infect the next computer in the next thai internet cafe.
Most have AVG installed, but this did nothing. Another antivirus
program at one place did detect the virus, and even cleaned it from my
USB drive.
I now lock my SD cards before connecting them, and quickly check for
adober.exe in the running processes.
I haven't seen much about this anywhere else, I was wondering if others
have seen something like this. And also, WHY DOES WINDOWS RUN SOMETHING
WITHOUT ASKING!!! :-D
Thanks,
Tristan