Search blog.co.uk

Posts archive for: October, 2006
  • USBDumper - analysis

    Test platform MS Win2k.
    The executable is distributed with source code. I did not re-compile but gave the source a very cursory glance over. Nothing immeditately jumped out at me but remember, I am not a hugely experienced programmer.
    InCtrl5 listed no registry entries changed and no files added. The USBDumper executable is clearly visible in Task Manager.
    The process has not shown any signs thus far of attempting to access any network facilities.
    It does what it claims. In the directory from which it was executed, it creates a folder of todays date and copies the information from the USB memory device into it. If the folder exists the files from the key are copied into it.
    It does not always work. My Dell 16MB key - it always copies the data off. My 1GB key - no joy. Both are FAT formatted, I will need to find my NTFS formatted key before I can test.

    Requires a little more investigation.

  • Not happy with McAfee

    OK, McAfee has been detecting the 'psexec.exe' tool from Sysinternals (http://www.sysinternals.com) as 'Unwanted Programs' and as default, automatically deleting it. Since I am using a corporate license at work, I do not have a support contract number easily available to me so I emailed 'Customer Service' to explain that they were detecting (now) Microsoft software as malware. Apparently it is a job for technical support and they were unable, or more likely unwilling, to pass the information on.
    So, that will be the last time I contact McAfee directly and they will be removed from my malicious code submission list. I don't suppose they are bothered.

  • USBDumper

    Not the easiest bit of software to find, I got it here: http://www.secuobs.com/USBDumper.rar

    I have not subjected it to my usual testing as my sandbox is not available to me right now, I'll get it tested hopefully by tomorrow. Until then, treat as highly suspicious!

Footer:

The content of this website belongs to a private person, blog.co.uk is not responsible for the content of this website.