Club PA 2.0 has arrived! If you'd like to access some extra PA content and help support the forums, check it out at patreon.com/ClubPA
The image size limit has been raised to 1mb! Anything larger than that should be linked to. This is a HARD limit, please do not abuse it.
Our new Indie Games subforum is now open for business in G&T. Go and check it out, you might land a code for a free game. If you're developing an indie game and want to post about it, follow these directions. If you don't, he'll break your legs! Hahaha! Seriously though.
Our rules have been updated and given their own forum. Go and look at them! They are nice, and there may be new ones that you didn't know about! Hooray for rules! Hooray for The System! Hooray for Conforming!

Portable malware + ipod

Samir Duran DuranSamir Duran Duran Registered User regular
So it seems I've got a sweet new portable app on my ipod nano: badware portable.

Basically it seems to be operating from a subfolder of a hidden read-only system folder called RECYCLER, and edits my autorun.inf to do... something. Here is the text as of now:

[autorun]
open=RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
shell\open\default=1

I assume the above is meant to launch ise32.exe when autorun runs, yes?

Anyway it also creates files with similar names that look like windows apps:

badware.jpg

And of course, everything associated with it is system hidden read-only and the files are recreated the moment they are deleted.

Now I would think portable walware would be a lot easier to combat but I'm just lost here, for starters I need to know how to delete that folder and if doing so would uproot this thing as I think it might.

Does anyone have some familiarity with this or do i need to provide more info?

Ani121OD.pngSpr_3e_121.gifAni121OD.png
Samir Duran Duran on

Posts

  • thegloamingthegloaming Registered User regular
    edited January 2009
    Your music's on your computer, right? A full reformat (of the iPod) will probably get rid of your problem.

    thegloaming on
  • ben0207ben0207 Registered User regular
    edited January 2009
    Best way to be rid of it would be to first make sure your PC is clean, then to restore the iPod in iTunes, as that includes a format. Or to be sure, format it yourself as a drive then get iTunes to repair it.

    ben0207 on
  • Samir Duran DuranSamir Duran Duran Registered User regular
    edited January 2009
    I'm considering doing that but I thought I'd see about killing the thing first since it doesnt have a registry to help defend itself with.

    Samir Duran Duran on
    Ani121OD.pngSpr_3e_121.gifAni121OD.png
  • wunderbarwunderbar What Have I Done? Registered User regular
    edited January 2009
    just format it. it'll be easier, and quicker.

    wunderbar on
    XBL: thewunderbar PSN: thewunderbar NNID: thewunderbar Steam: wunderbar87 Twitter: wunderbar
Sign In or Register to comment.