lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <BAY19-DAV10034B5749FF0FE3BCF10ED9A70@phx.gbl>
Date: Tue Sep  6 03:14:32 2005
From: se_cur_ity at hotmail.com (Morning Wood)
Subject: Shell32.dll.124.config

sounds like an ADS ( alternate data stream )
http://www.sysinternals.com/Utilities/Streams.html

I wrote this awhile back as notes on a project...

this is a simple example...
Create an executable ADS:
-------------------------
c:\>type c:\fullpath\exename.exe > somefile.ext:exename.exe
( or somefile.exe:someothername.exe )

Execute an ADS:
---------------
c:\>start c:\pathto\somefile.ext
( starts the example above running exename.exe
behind the visible somefile.ext )
c:\>type c:\start.bat > c:\windows\explorer.exe:start.bat
( this creates a file named start.bat that executes
explorer.exe )
c:\>start ( will now execute the full path to c:\to\somefile.ext )

hope this helps.


----- Original Message ----- 
From: "y0himba" <y0himba@...hnolounge.org>
To: <full-disclosure@...ts.grok.org.uk>
Sent: Monday, September 05, 2005 4:33 PM
Subject: [Full-disclosure] Shell32.dll.124.config


> Hi,
> Yes I am a "noob".  I have a question though.  Google searches and a
> few other things can tell me nothing about "shell32.dll.124.config".  I am
> on WindowsXP SP2, and keep seeing this file show up in antivirus scans,
but
> cannot find it anywhere on the system!  I think it is dynamically created
by
> something, but after sitting and watching Filemon 7.02 for 20 minutes or
so,
> I give up.  Has anyone heard of this file?  Antivir, Bitdefender, AVG and
> Clam all show it on the system, have scanned it, but have found nothing.
I
> have never seen this file before...
>
> Thanks in advance for your help!
>
> -----BEGIN GEEK CODE BLOCK-----
> Version: 3.1
> GCM/GIT/GO d- s: a C++++$ UL++++ P++++ L++++ E++++ W++++ N+++++ o++++ K++
w
> O- M- V-- PS+ PE Y++ PGP++ t+ 5-- X+++++ R* tv++ b+++++ DI++ D++++
> G++ e h---- r+++ y++++
> ------END GEEK CODE BLOCK------
> Get Your Geek Code:  http://www.geekcode.com
>
> -- 
> No virus found in this outgoing message.
> Checked by AVG Anti-Virus.
> Version: 7.0.344 / Virus Database: 267.10.18/90 - Release Date: 9/5/2005
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ