Full Disclosure mailing list archives

Autorun Flashdrive Worm


From: Charles Timko <charles.timko () hotmail com>
Date: Sat, 19 Feb 2011 10:49:27 -0500

While I was at the SuperComputing Conference I went ahead and plugged in a
flashdrive that belonged to a friend of mine.  After Windows 7 loaded the
driver for the device, I was prompted by AVG Free's Resident Shield.  It had
stopped the worm from running, which I am thankful for.  I told my friend he
had a worm on his flash drive and didn't believe me.  He took his drive back
and scanned it with ClamAV and sure enough, there was a worm on the drive.
It was at that point we have been trying to locate it on disk, and I was
unable to access the folder from the Command-line with the complete path.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: