| View previous topic :: View next topic |
| Author |
Message |
wtfagain Guest
|
Posted: Fri Sep 14, 2007 5:41 pm Post subject: AHK Homepage distributes Psyme Trojan |
|
|
Could be a false positive, but reported by F-Secure AND Kaspersky antiviruses on different machines .
Name : Trojan-Downloader.JS.Psyme.le |
|
| Back to top |
|
 |
Harper
Joined: 19 Mar 2007 Posts: 14
|
Posted: Fri Sep 14, 2007 5:44 pm Post subject: |
|
|
i ever known this
ahk canīt be so good and not be evil^^ |
|
| Back to top |
|
 |
Guest
|
Posted: Fri Sep 14, 2007 7:28 pm Post subject: Re: AHK Homepage distributes Psyme Trojan |
|
|
| wtfagain wrote: | Could be a false positive, but reported by F-Secure AND Kaspersky antiviruses on different machines .
Name : Trojan-Downloader.JS.Psyme.le |
| http://www.liveslick.com/2007/09/top-10-freeware-software-nobody-knows.html wrote: |
Seems the Autohotkey Homepage is definitely infected with the trojan Trojan-Downloader.JS.Psyme.le, received the same error as in Kaspersky but with F-Secure...
DO NOT EVEN CLICK ON THE AUTOHOTKEY LINK |
Wow... if the second quote is you, way to jump the gun.  |
|
| Back to top |
|
 |
Phaze
Joined: 14 Sep 2007 Posts: 67 Location: Wichita, Kansas
|
Posted: Fri Sep 14, 2007 7:44 pm Post subject: |
|
|
Scanned with Avast, PC-cillin, and AVG. No problems here. I think you're programs are just over-protective, or misinterpreting something. It's safe. Stop posting these.  _________________
 |
|
| Back to top |
|
 |
Superfraggle
Joined: 02 Nov 2004 Posts: 962 Location: London, UK
|
Posted: Fri Sep 14, 2007 7:47 pm Post subject: |
|
|
It's a common problem, report it to your AV company as a false positive. _________________ Steve F AKA Superfraggle
http://r.yuwie.com/superfraggle |
|
| Back to top |
|
 |
daonlyfreez
Joined: 16 Mar 2005 Posts: 755 Location: Berlin
|
Posted: Fri Sep 14, 2007 8:00 pm Post subject: |
|
|
Jotti's malware scan
| Quote: | File: AutoHotkey104704_Install.exe
Status: OK(Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 9f51365cebfdfdb3646f73111ab38cc1
Packers detected: PE_PATCH.UPX, UPX
Bit9 reports: File not found
Scanner results
Scan taken on 14 Sep 2007 19:53:14 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing |
_________________ (sorry, homesite offline atm) |
|
| Back to top |
|
 |
sleepwell Guest
|
Posted: Fri Sep 14, 2007 8:04 pm Post subject: |
|
|
| yeah yeah old news, known problem, you should also uninstall your antivirus to avoid these annoying warnings... |
|
| Back to top |
|
 |
daonlyfreez
Joined: 16 Mar 2005 Posts: 755 Location: Berlin
|
Posted: Fri Sep 14, 2007 8:12 pm Post subject: |
|
|
Well, you shouldn't uninstall your AntiVirus (but I guess the previous poster was making an attempt at sarcasm), but you could inform your AntiVirus company of this warning as a probable "false positive". _________________ (sorry, homesite offline atm) |
|
| Back to top |
|
 |
ahklerner
Joined: 26 Jun 2006 Posts: 1249 Location: USA
|
Posted: Fri Sep 14, 2007 8:25 pm Post subject: |
|
|
| If you read it, it is saying that the trojan is in the JAVASCRIPT of the HOMEPAGE. I am pretty sure this is not about the installer having a virus.....at least this time. |
|
| Back to top |
|
 |
sleepwell Guest
|
Posted: Fri Sep 14, 2007 8:54 pm Post subject: |
|
|
Oh well i'll try to help a bit, why not?
Title : AHK Homepage distributes Psyme Trojan
This could indicate us the homepage is infected, not the install/software itself. Who knows? Maybe we should have a look at the sourcecode of the index.html. Or maybe not, i feel a little lazy tonight...
Name of the Trojan : Trojan-Downloader.JS.Psyme.le
JS, JS, JS... What does it stand for, JS... Man, am I tired...
Number of entries for psyme on the forums : 2, including the current topic
The second topic is also from today, huh?
Googling a bit for psyme : virulist.com & sophos.com, interesting stuff
Well I aint gonna do all work for u, see for urself
First shortcut/action in the template script: Open www.autohotkey.com
...In the default browser on Windows, heeheehee thats gettin funny...
Now im almost awake, should i stand up? Well, erff eh, no...
As they said, old known problem... shouldnt give a ****... zzzzzzzzzz |
|
| Back to top |
|
 |
sleepwell
Joined: 14 Sep 2007 Posts: 2
|
Posted: Fri Sep 14, 2007 9:23 pm Post subject: |
|
|
Edit : use Firefox with Noscript to call up the homepage, im tellin u guys
Actually nobody with JS activated should access it, I mean I think so... |
|
| Back to top |
|
 |
Chris Site Admin
Joined: 02 Mar 2004 Posts: 10474
|
Posted: Fri Sep 14, 2007 9:38 pm Post subject: |
|
|
Thanks for the report; this has been fixed.
Now to search the log files to try to figure out how it got on there. Update: I've found the security hole and plugged it.
To anyone affected by this, I apologize for the problem. |
|
| Back to top |
|
 |
sleepwell
Joined: 14 Sep 2007 Posts: 2
|
Posted: Sat Sep 15, 2007 8:51 am Post subject: |
|
|
Now that was an interesting topic : everybody except for the Site Admin Chris and ahklerner misunderstood/downplayed the threat.
From Guest "way to jump the gun", over Phaze "It's safe. Stop posting these", Superfraggle "It's a common problem" to daonlyfreez oh so useful logs and "probable false positive", a nice journey through the "nothing to see here" country.
This was a trojan you installed on your machine without ur knowledge by just surfing on the homepage or testing the template script. Does it ring now?
Thanks to Chris for removing the security hole (pretty ugly JS script in the HTML code) quickly.
Now to the Lessons/Thoughts/Suppositions/Trivia:
-people having the ability to read/understand what they read are a minority
-Windows users are not security-oriented, even if they have the correct tools they cant make a use of it (message AV -> false positive...), this seems to be clearly history-related (duh, another warning...)
-people have indeed the ability to read and are security-oriented, but they write trojans, so it could be better for them to downplay the threat in the forums of the target
-IE with JS activated by default (it is, or not? dunno) is still the most popular browser.
-AHK is a win-app aimed in my opinion at office/corporate users who do not have the choice to use another OS than Windows and another browser than IE at work and still want to be/get more productive.
-theres been a bit of publicity around AHK in the last days/weeks, i think i saw what on reddit, liveslick and lifehacker with DIRECT LINKS to the homepage
To sum it up:
It would be nice to know for how long the JS script has been waiting for hits on the page, and also to know the average hit-count/day of the homepage. This could help figure the extend of the attack and incite people to take measure on monday morning before all the $ start flowing in the wrong directions.
In the end :
-do not use IE
-do not use JS
-do not use Windows
Good luck |
|
| Back to top |
|
 |
Chris Site Admin
Joined: 02 Mar 2004 Posts: 10474
|
Posted: Sat Sep 15, 2007 11:42 am Post subject: |
|
|
| sleepwell wrote: | | It would be nice to know for how long the JS script has been waiting for hits on the page, and also to know the average hit-count/day of the homepage. This could help figure the extend of the attack and incite people to take measure on monday morning before all the $ start flowing in the wrong directions. | The site was affected for about 15 hours on Sep 14 2007 starting at 2 AM local (EST). Since the main index.html page is viewed about 4000 times per day, I wish I'd noticed it sooner.
| sleepwell wrote: | | Now that was an interesting topic : everybody except for the Site Admin Chris and ahklerner misunderstood/downplayed the threat. | To keep this in perspective, there have probably been over a dozen false postives reported on the forum in the past year. This made it easy to misinterpret the original report.
| sleepwell wrote: | | This was a trojan you installed on your machine without ur knowledge by just surfing on the homepage or testing the template script. | The only affected pages were the index.html files, not the entire site. The forum and wiki were never affected.
| sleepwell wrote: | | Thanks to Chris for removing the security hole (pretty ugly JS script in the HTML code) quickly. | If anyone knows more about the malicious JavaScript (e.g. what to look for and how to remove it if you find it), please post here because it might help anyone who was affected.
Thanks.
Edit: I've found out the following info about the malware that was distributed:
Means to detect it: If the following command displays any files, you're probably infected:
dir /a %WinDir%\system32\wsnpoem
Means by which it auto-starts: A hidden file "ntos.exe" in the following registry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
Means to remove it (modifying the regkey above probably won't be enough):
Use the Windows recovery console ( http://support.microsoft.com/kb/314058 ) to do the following:
del %WinDir%\System32\ntos.exe (if it can't be deleted, it might be necessary first to do: attrib -h -s -r ntos.exe ... if that fails, you can try: del /f ntos.exe)
Delete all the files in %WinDir%\system32\wsnpoem
Last edited by Chris on Thu Sep 27, 2007 9:25 pm; edited 1 time in total |
|
| Back to top |
|
 |
Guest
|
Posted: Sat Sep 15, 2007 2:43 pm Post subject: |
|
|
Very irresponsible of you to allow such a thing to happen.
I love autohotkey, but.. really. |
|
| Back to top |
|
 |
|