Windows AutoRun malware spreading

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,490
Significant increase in infection is curious because Windows 7 and Windows 8 PCs will not launch autorun.inf files.

The significant increase in infection is curious because Windows 7 and Windows 8 PCs will not launch autorun.inf files, and Microsoft has released two patches for older systems. Therefore, security experts believe infections are happening through a combination of unpatched computers, shared folders and files and social media.

The latest malware disguises itself as files and folders in writeable network shares and removable devices, while hiding the originals. The application will also create .exe files named "porn" and "sexy" and a folder called "passwords," to entice people to click on them, Sophos said.

Source
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
Nope, I have mine that it will download the updates for me, but gives me the choice on whether to install them or not. Reason why is that in the past I had installed a update from Microsoft and it crashed my machine and had a lot of trouble finding out why. So I find it easier to just download them and I install them.
 

tipo

Level 8
Well-known
Jul 26, 2012
353
wuauclt service is disabled here. i`m on defensewall and antivirus. the vulnerabilities will always come and go but the defensewall protection is permanent. i don`t want to clutter my HDD with (sometimes) faulty updates. if an update is released then a vulnerability was discovered, meaning someone`s pc was infected. who knows maybe someday i will be the one infected waiting a miracle from M$ to release an update patch while my personal data was/is being stolen...this is my opinion about AV/IS too...i just use them as a second opinion.
 

Littlebits

Retired Staff
May 3, 2011
3,893
McLovin said:
Nope, I have mine that it will download the updates for me, but gives me the choice on whether to install them or not. Reason why is that in the past I had installed a update from Microsoft and it crashed my machine and had a lot of trouble finding out why. So I find it easier to just download them and I install them.

I use the same configuration, Automatically download the updates but let me choose when to install them. The main reason is security software are the major cause of failed updates, I like to disable all of my security products and then install the updates manually. In the past WinPatrol Plus with advanced registry monitor list has cause updates to fail. Most HIPS products and some AV's will also cause problems with system changes resulting in failed updates.

I can't believe some Windows systems are still get infected with the AutoRun feature. Vista and Windows 7 are patched by updates which disables autorun. I'm not completely sure but I believe a autorun patch for XP was also pushed out awhile back. The only thing that comes to mind is these systems that got infected were not keeping Windows updated.

Thanks.:D
 
D

Deleted member 178

Most infected systems are illegal Windows not updated by scared users that dont have the skills/knowledge to bypass WAT and are afraid of MS retaliation.
 

zorror

New Member
Verified
Nov 25, 2012
22
Automatic windows updates are a pain. I always manually check 4 updates.
Autoruns are no problem if you have a real antivirus (not MSE)
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
zorror said:
Autoruns are no problem if you have a real antivirus (not MSE)

There are sometimes where it can miss the AV totally. So here it's best not to rely on your AV.
 
P

Plexx

I got Automatic Updates disabled and instead I manually check every 2 weeks. Reason being I like to check exactly what has been released and give it sometime before installing it. Most of the time I recommend automatic for the new users while average download automatically but let user install.
 
P

Plexx

Umbra Corp. said:
Most infected systems are illegal Windows not updated by scared users that dont have the skills/knowledge to bypass WAT and are afraid of MS retaliation.

Even using the Windows Loaders for windows 7, I believe not everyone is detected by KB971033 patch to detect those keys doesnt fully work. I know for a fact that WL goes undetected.

Unable to test it since there are just so many but the most common one ins WL.


The problem is most users don't really update the system, including AVs.

Install and forget settings work best for them but when someone changes something, they will not know how to change back.


As for pirated versions of windows, until XP most system are either installed with the "crack" that will allow the automatic updates or majority is OEM keys.

Windows 7 builds is slightly a different story but "vanilla" builds users will just be staring at expired trial windows and upon googling, will stumble across guides to activate and those guides are a no brainer.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top