Full Disclosure mailing list archives

RE: Shell32.dll.124.config


From: "y0himba" <y0himba () technolounge org>
Date: Mon, 5 Sep 2005 22:22:15 -0400

 Thanks for the information.  I have sent an email to Mark to see if he can
verify this or assist me in any way.  This is helpful.

-----Original Message-----
From: Morning Wood [mailto:se_cur_ity () hotmail com] 
Sent: Monday, September 05, 2005 10:15 PM
To: y0himba; full-disclosure () lists grok org uk
Subject: Re: [Full-disclosure] Shell32.dll.124.config

sounds like an ADS ( alternate data stream )
http://www.sysinternals.com/Utilities/Streams.html

I wrote this awhile back as notes on a project...

this is a simple example...
Create an executable ADS:
-------------------------
c:\>type c:\fullpath\exename.exe > somefile.ext:exename.exe ( or
somefile.exe:someothername.exe )

Execute an ADS:
---------------
c:\>start c:\pathto\somefile.ext
( starts the example above running exename.exe behind the visible
somefile.ext ) c:\>type c:\start.bat > c:\windows\explorer.exe:start.bat (
this creates a file named start.bat that executes explorer.exe ) c:\>start (
will now execute the full path to c:\to\somefile.ext )

hope this helps.


----- Original Message -----
From: "y0himba" <y0himba () technolounge org>
To: <full-disclosure () lists grok org uk>
Sent: Monday, September 05, 2005 4:33 PM
Subject: [Full-disclosure] Shell32.dll.124.config


Hi,
Yes I am a "noob".  I have a question though.  Google searches and a
few other things can tell me nothing about "shell32.dll.124.config".  I am
on WindowsXP SP2, and keep seeing this file show up in antivirus scans,
but
cannot find it anywhere on the system!  I think it is dynamically created
by
something, but after sitting and watching Filemon 7.02 for 20 minutes or
so,
I give up.  Has anyone heard of this file?  Antivir, Bitdefender, AVG and
Clam all show it on the system, have scanned it, but have found nothing.
I
have never seen this file before...

Thanks in advance for your help!

-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCM/GIT/GO d- s: a C++++$ UL++++ P++++ L++++ E++++ W++++ N+++++ o++++ K++
w
O- M- V-- PS+ PE Y++ PGP++ t+ 5-- X+++++ R* tv++ b+++++ DI++ D++++
G++ e h---- r+++ y++++
------END GEEK CODE BLOCK------
Get Your Geek Code:  http://www.geekcode.com

-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.344 / Virus Database: 267.10.18/90 - Release Date: 9/5/2005


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


-- 
No virus found in this incoming message.
Checked by AVG Anti-Virus.
Version: 7.0.344 / Virus Database: 267.10.18/90 - Release Date: 9/5/2005
 

-- 
No virus found in this outgoing message.
Checked by AVG Anti-Virus.
Version: 7.0.344 / Virus Database: 267.10.18/90 - Release Date: 9/5/2005
 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: