PDA

View Full Version : Beware


Pigeon Poop
02-18-2008, 07:43 PM
Well, it didn't take long.

China has put out another one, this one looks fairly insidious. If you have purchased, or received a digital photo frame recently, there is a possibility that it may contain code that allows hackers to obtain your account information.

Computer Associates discovered it and call it Mocmex. Here is the story (http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/02/15/BU47V0VOH.DTL)from the SF Chronicle.

The Mocmex was first identified as a Trojan horse that collected online games passwords, further studies has revealed its ability to get around more than hundred antivirus vendors and Windows security layers. The malware infected PC only ( Windows!, what else?), and known to download files and hid them randomly with hard to trace patterns, it would then propagated to another PC or other portable storage device as a shelter as soon as it’s plugged into one. CA says Mocmex’s strength is more than just a simple game-password collector, it has the potential for a much bigger attack with its nature to collect personal and private data.

It appears that once a machine gets infected, it begins to propagate thru the autorun feature in your USB ports. Meaning, that once the infected digital frame is plugged into your computer, any other USB device, such as a Flash drive or and iPod, helps transmit this bug.

As far as I can tell, there isn't a fix just yet. The best fix so far is to have your system scanned from a Linux machine or a Mac. Or, just scan the flash drive. This is assuming, of course, that all definitions have been updated.

The bottom line is this: if you have plugged in a Digital Photo frame recently, be very aware. I'll post more when I find more info on this.

MadMardegan
02-18-2008, 08:59 PM
Wow, sounds fairly serious.

N V
02-18-2008, 09:16 PM
that sounds very serious indeed =/

Pigeon Poop
02-18-2008, 11:55 PM
Yeah, it's serious, alright. It seems there is no fix available yet other than not pluging in any Digital Picture Frame device into your USB ports.

This in from Console News Blog (http://wow.consolenewsblog.com/), a WoW blog site.

Mocmex has been reported to be hard - if not impossible - to flush out of your PC system. If you think your PC has been infected with the Mocmex worm, contact SANS at info@sans.org (http://www.sans.org/2008menaces/?utm_source=web-sans&utm_medium=text-ad&utm_content=text-link_2008menaces_homepage&utm_campaign=Top_10__Cyber_Security_Menaces_-_2008&ref=22218) and contact the retailer where you bought the device.

If you get the bug, you will know it when you loose your account. One real good fix is to back up your system and re-load Windows. I know, makes you wish you had a Mac. Just be careful. If you don't have any Digital Picture Frames, them you are safe, but, be aware of any USB devices from other users being placed in your system.

Wal-Mart, Target, Best Buy and Sams Club are aware of this bug and most have pulled the product from their shelves already. There are still products out there, however. At this point, it is in your best interest to not use these products.

If and when a fix comes along, I'll be sure to post a link. If anyone does loose an account, let us know. In the mean time, be very careful with what you plug into your Ports.

Skullcaptain
02-19-2008, 12:28 AM
Thanks for sharing this news with us. Appreciated!

:)