AutoHotkey Homepage AutoHotkey Community
Let's help each other out
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

AHK Homepage distributes Psyme Trojan
Goto page 1, 2  Next
 
Post new topic   Reply to topic    AutoHotkey Community Forum Index -> Ask for Help
View previous topic :: View next topic  
Author Message
wtfagain
Guest





PostPosted: Fri Sep 14, 2007 5:41 pm    Post subject: AHK Homepage distributes Psyme Trojan Reply with quote

Could be a false positive, but reported by F-Secure AND Kaspersky antiviruses on different machines .
Name : Trojan-Downloader.JS.Psyme.le
Back to top
Harper



Joined: 19 Mar 2007
Posts: 14

PostPosted: Fri Sep 14, 2007 5:44 pm    Post subject: Reply with quote

i ever known this
ahk canīt be so good and not be evil^^
Back to top
View user's profile Send private message
Guest






PostPosted: Fri Sep 14, 2007 7:28 pm    Post subject: Re: AHK Homepage distributes Psyme Trojan Reply with quote

wtfagain wrote:
Could be a false positive, but reported by F-Secure AND Kaspersky antiviruses on different machines .
Name : Trojan-Downloader.JS.Psyme.le


http://www.liveslick.com/2007/09/top-10-freeware-software-nobody-knows.html wrote:


Seems the Autohotkey Homepage is definitely infected with the trojan Trojan-Downloader.JS.Psyme.le, received the same error as in Kaspersky but with F-Secure...

DO NOT EVEN CLICK ON THE AUTOHOTKEY LINK


Wow... if the second quote is you, way to jump the gun. Rolling Eyes
Back to top
Phaze



Joined: 14 Sep 2007
Posts: 67
Location: Wichita, Kansas

PostPosted: Fri Sep 14, 2007 7:44 pm    Post subject: Reply with quote

Scanned with Avast, PC-cillin, and AVG. No problems here. I think you're programs are just over-protective, or misinterpreting something. It's safe. Stop posting these. Smile
_________________
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Superfraggle



Joined: 02 Nov 2004
Posts: 962
Location: London, UK

PostPosted: Fri Sep 14, 2007 7:47 pm    Post subject: Reply with quote

It's a common problem, report it to your AV company as a false positive.
_________________
Steve F AKA Superfraggle

http://r.yuwie.com/superfraggle
Back to top
View user's profile Send private message MSN Messenger
daonlyfreez



Joined: 16 Mar 2005
Posts: 755
Location: Berlin

PostPosted: Fri Sep 14, 2007 8:00 pm    Post subject: Reply with quote

Jotti's malware scan

Quote:
File: AutoHotkey104704_Install.exe
Status: OK(Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 9f51365cebfdfdb3646f73111ab38cc1
Packers detected: PE_PATCH.UPX, UPX
Bit9 reports: File not found

Scanner results

Scan taken on 14 Sep 2007 19:53:14 (GMT)

A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

_________________
(sorry, homesite offline atm)
Back to top
View user's profile Send private message
sleepwell
Guest





PostPosted: Fri Sep 14, 2007 8:04 pm    Post subject: Reply with quote

yeah yeah old news, known problem, you should also uninstall your antivirus to avoid these annoying warnings...
Back to top
daonlyfreez



Joined: 16 Mar 2005
Posts: 755
Location: Berlin

PostPosted: Fri Sep 14, 2007 8:12 pm    Post subject: Reply with quote

Well, you shouldn't uninstall your AntiVirus (but I guess the previous poster was making an attempt at sarcasm), but you could inform your AntiVirus company of this warning as a probable "false positive".
_________________
(sorry, homesite offline atm)
Back to top
View user's profile Send private message
ahklerner



Joined: 26 Jun 2006
Posts: 1249
Location: USA

PostPosted: Fri Sep 14, 2007 8:25 pm    Post subject: Reply with quote

If you read it, it is saying that the trojan is in the JAVASCRIPT of the HOMEPAGE. I am pretty sure this is not about the installer having a virus.....at least this time.
Back to top
View user's profile Send private message
sleepwell
Guest





PostPosted: Fri Sep 14, 2007 8:54 pm    Post subject: Reply with quote

Oh well i'll try to help a bit, why not?

Title : AHK Homepage distributes Psyme Trojan
This could indicate us the homepage is infected, not the install/software itself. Who knows? Maybe we should have a look at the sourcecode of the index.html. Or maybe not, i feel a little lazy tonight...

Name of the Trojan : Trojan-Downloader.JS.Psyme.le
JS, JS, JS... What does it stand for, JS... Man, am I tired...

Number of entries for psyme on the forums : 2, including the current topic
The second topic is also from today, huh?

Googling a bit for psyme : virulist.com & sophos.com, interesting stuff
Well I aint gonna do all work for u, see for urself

First shortcut/action in the template script: Open www.autohotkey.com
...In the default browser on Windows, heeheehee thats gettin funny...

Now im almost awake, should i stand up? Well, erff eh, no...
As they said, old known problem... shouldnt give a ****... zzzzzzzzzz
Back to top
sleepwell



Joined: 14 Sep 2007
Posts: 2

PostPosted: Fri Sep 14, 2007 9:23 pm    Post subject: Reply with quote

Edit : use Firefox with Noscript to call up the homepage, im tellin u guys
Actually nobody with JS activated should access it, I mean I think so...
Back to top
View user's profile Send private message
Chris
Site Admin


Joined: 02 Mar 2004
Posts: 10474

PostPosted: Fri Sep 14, 2007 9:38 pm    Post subject: Reply with quote

Thanks for the report; this has been fixed.

Now to search the log files to try to figure out how it got on there. Update: I've found the security hole and plugged it.

To anyone affected by this, I apologize for the problem.
Back to top
View user's profile Send private message Send e-mail
sleepwell



Joined: 14 Sep 2007
Posts: 2

PostPosted: Sat Sep 15, 2007 8:51 am    Post subject: Reply with quote

Now that was an interesting topic : everybody except for the Site Admin Chris and ahklerner misunderstood/downplayed the threat.
From Guest "way to jump the gun", over Phaze "It's safe. Stop posting these", Superfraggle "It's a common problem" to daonlyfreez oh so useful logs and "probable false positive", a nice journey through the "nothing to see here" country.
This was a trojan you installed on your machine without ur knowledge by just surfing on the homepage or testing the template script. Does it ring now?
Thanks to Chris for removing the security hole (pretty ugly JS script in the HTML code) quickly.

Now to the Lessons/Thoughts/Suppositions/Trivia:

-people having the ability to read/understand what they read are a minority
-Windows users are not security-oriented, even if they have the correct tools they cant make a use of it (message AV -> false positive...), this seems to be clearly history-related (duh, another warning...)
-people have indeed the ability to read and are security-oriented, but they write trojans, so it could be better for them to downplay the threat in the forums of the target
-IE with JS activated by default (it is, or not? dunno) is still the most popular browser.
-AHK is a win-app aimed in my opinion at office/corporate users who do not have the choice to use another OS than Windows and another browser than IE at work and still want to be/get more productive.
-theres been a bit of publicity around AHK in the last days/weeks, i think i saw what on reddit, liveslick and lifehacker with DIRECT LINKS to the homepage

To sum it up:
It would be nice to know for how long the JS script has been waiting for hits on the page, and also to know the average hit-count/day of the homepage. This could help figure the extend of the attack and incite people to take measure on monday morning before all the $ start flowing in the wrong directions.
In the end :
-do not use IE
-do not use JS
-do not use Windows
Good luck
Back to top
View user's profile Send private message
Chris
Site Admin


Joined: 02 Mar 2004
Posts: 10474

PostPosted: Sat Sep 15, 2007 11:42 am    Post subject: Reply with quote

sleepwell wrote:
It would be nice to know for how long the JS script has been waiting for hits on the page, and also to know the average hit-count/day of the homepage. This could help figure the extend of the attack and incite people to take measure on monday morning before all the $ start flowing in the wrong directions.
The site was affected for about 15 hours on Sep 14 2007 starting at 2 AM local (EST). Since the main index.html page is viewed about 4000 times per day, I wish I'd noticed it sooner.

sleepwell wrote:
Now that was an interesting topic : everybody except for the Site Admin Chris and ahklerner misunderstood/downplayed the threat.
To keep this in perspective, there have probably been over a dozen false postives reported on the forum in the past year. This made it easy to misinterpret the original report.

sleepwell wrote:
This was a trojan you installed on your machine without ur knowledge by just surfing on the homepage or testing the template script.
The only affected pages were the index.html files, not the entire site. The forum and wiki were never affected.

sleepwell wrote:
Thanks to Chris for removing the security hole (pretty ugly JS script in the HTML code) quickly.
If anyone knows more about the malicious JavaScript (e.g. what to look for and how to remove it if you find it), please post here because it might help anyone who was affected.

Thanks.

Edit: I've found out the following info about the malware that was distributed:

Means to detect it: If the following command displays any files, you're probably infected:
dir /a %WinDir%\system32\wsnpoem
Means by which it auto-starts: A hidden file "ntos.exe" in the following registry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
Means to remove it (modifying the regkey above probably won't be enough):
Use the Windows recovery console ( http://support.microsoft.com/kb/314058 ) to do the following:
del %WinDir%\System32\ntos.exe (if it can't be deleted, it might be necessary first to do: attrib -h -s -r ntos.exe ... if that fails, you can try: del /f ntos.exe)
Delete all the files in %WinDir%\system32\wsnpoem


Last edited by Chris on Thu Sep 27, 2007 9:25 pm; edited 1 time in total
Back to top
View user's profile Send private message Send e-mail
Guest






PostPosted: Sat Sep 15, 2007 2:43 pm    Post subject: Reply with quote

Very irresponsible of you to allow such a thing to happen.
I love autohotkey, but.. really.
Back to top
Display posts from previous:   
Post new topic   Reply to topic    AutoHotkey Community Forum Index -> Ask for Help All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum


Powered by phpBB © 2001, 2005 phpBB Group