Published on Maximum PC (http://www.maximumpc.com)


Digital Picture Frames - Now with Free Malware!
Created 02/16/2008 - 8:37pm

Maximum IT
    • Cisco Cranks Out iPhone Security App for IT Managers
    • Verizon Puts Together Telehealth Collaboration Services
    • Ciena Coughs Up $530 Million in Cash for a Slice of Nortel Networks

    Sponsored
SEE MORE MAXIMUM IT
News
  • BenQ and Fujitsu to Jump on E-Book Bandwagon
  • At Least Five Countries Arming Themselves for Cyberwar
  • eBay Giving Out Coupons and Other Compensation after Website Crash
  • Beautiful Curved Monitor Now Available for Sale to Tycoons, Fatcats
  • Another Day, Another Promising New Battery Technology
SEE MORE NEWS
News

Digital Picture Frames - Now with Free Malware!

Posted 02/16/08 at 10:37:17 PM  by Mark Soper

comment Commentsprint Printemail EmailDeliciousDiggStumbleUponRedditFacebookSlashdot

Digital picture frames showed up everywhere this past holiday season - and unfortunately, some of them, it turns out, also include a Trojan Horse payload as a 'free' bonus.

From One to Many...Vendors

The first reports in late January fingered some examples of the Insignia NS-DPF-10A 10.4-inch digital picture frames sold by Best Buy. However, the San Francisco Chronicle is now reporting that digital picture frames sold by several other vendors may also contain computer viruses, including products sold by Sam's Club, Target, and Costco. The digital picture frames involved contain flash memory to store images loaded from a PC.

A Multi-Pronged Malware Attack

Initially, it was believed that the malware on infected digital picture frames was relatively easy to deal with. One of the infections is W32.Rajump, which also infected some Apple video iPods back in October 2006. It spreads itself to removable drives and can attack Windows 9x through XP. Three other trojans are also older infections easily detectable by current antivirus programs. However, the biggest payload is a new Trojan Horse known to CA (formerly Computer Associates) as Mocmex, and identified as W32.Autorun.worm.e by McAfee.

Introducing Mocmex

Whether you call it Mocmex or W32.Autorun.worm.e, it's bad news. It performs the following actions:

  • - Kills various processes
  • - Downloads malware from two remote websites
  • - Deletes registry keys
  • - Adds registry keys to run malware
  • - Disables most major antivirus software products
  • - Disables Windows security and firewall features
  • - Captures passwords for online games (and could easily be tweaked to capture other types of information as well)

If that last behavior reminds you of a previous storage-based malware outbreak, you're right. We brought you reports of Maxtor external hard disks infected with malware from China back in November, and antivirus researchers, according to the Chronicle, have traced back this latest infection to a China-based group as well.

Stopping Mocmex

Mocmex can be detected by updated CA and McAfee antivirus programs (and possibly others), but because it uses Autorun.inf to spread (and can reenable Autorun, even if you have disabled this feature), waiting until you have connected the picture frame to a Windows-based PC may be too late - your system's already infected! So, how can you detect Mocmex or other nasties stored in a removable storage device? Deborah Hale at the SANS Institute (www.sans.org), a leading information security training and research firm, suggests scanning media from a computer running Linux or MacOS.

Here's a better idea, especially for us Windows diehards: create a BartPE CD (as suggested by our own Logan Decker), include your preferred antivirus tool (you'll find a list of antivirus plugins here), and use it to boot your PC and scan digital picture frames or other removable-media drives for viruses and malware.

COMMENTS:2
TAGS: malware, china, Trojan Horse, picture frame, viruses, target, best buy
COMMENTS
  • Login or register to post comments
  • Technology News

  • Computer Cooling Fans

  • Computer Cases

  • PC Game Controllers

  • PC Games

  • Computer Hardware

  • Headphones

  • MP3 Players

  • Stream Video

  • Computer Mouse

  • Monitors

  • Motherboards

  • NAS Storage

  • Networking

  • Laptop Computers

  • DVD Burner

  • Digital Cameras

  • Portable Storage

  • Computer Accessories

  • Smartphone

  • Antivirus Software

  • Sound Cards

  • Speakers

  • Computer Systems

  • Thumb Drives

  • Video Cameras

  • Video Card Reviews

  • Water Cooling

  • Gadgets

  • Keyboards
  • Contact Us
  • Advertising
  • Privacy Policy
  • Terms & Conditions
  • RSS Feeds
  • TechBlips
  • PCHardwareBlips
  • Site Map
  • Customer Service
Future © 2009 Future US, Inc. All Rights Reserved.

Source URL: http://www.maximumpc.com/article/digital_picture_frames_now_with_free_malware

Links:
[1] http://www.maximumpc.com/user/marcus_soperus
[2] http://www.insignia-products.com/news.aspx?showarticle=13
[3] http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/02/15/BU47V0VOH.DTL
[4] http://www.channelregister.co.uk/2008/01/11/malware_digital_devices
[5] http://www.symantec.com/security_response/writeup.jsp?docid=2006-062310-0921-99
[6] http://vil.nai.com/vil/content/v_142518.htm
[7] http://www.maximumpc.com/article/big_maxtor_disks_making_big_security_headaches
[8] http://www.maximumpc.com/article/How-To--Make-a-Bootable-CD-ROM
[9] http://www.bootcd.us/BartPE_Plugins_Category/antivirus/
[10] http://www.maximumpc.com/article/smart_new_malware_targets_e_banking_are_you_ready