Saturday, April 24, 2010

sitrep_20100424 gestapiware


GESTAPIWARE


malware,
spyware and the latest is gestapiware.


From
tampering puter

the picture above is a photo of my desktop showing the windows
eplorer tree of my camera card reader with the removable disk N being the camera card carrying slot.
the foleder Dcim and the subfolders inside Dcim are the normal ones created by the camera software of my cannon a400.
The folder cold and the autorun file are abnormal and I feel are the handiworks of the ( indian + gestapo = ) gestapi.

From
tamperingputer

The folder cold on opening shows a recycle bin sort of thing which according to the auTORUN file carries the executable file sysdiag64.exe.

From
tampering puter

what you see above is the details of the autorun file.

I have a couple of usbsticks from sandisk and they provide a driver for using it on the win 98 os that is available on their website. I have downloaded it and have been using the usb stick on the win 98 as well.

yes over and above my win Xp system I have a second desktop running win 98. The fact is that the win 98 system that I had initially is the older version and not win98 se and so has many disadvantages - upgrading to win XP was a must.

I made myself an additional desktop with the left overs after upgrading to winXP and I have my old win 98 os on it - if I sell the old hardware what I would get is peanuts and so rather than sell it I thought I may keep it.


I used to use the sandisk usb stick to transfer data from the 98 to the xp system easily. But then the win 98 was fiddled with and it stopped recognizing the usb stick in spite of installing the driver.

Recently I found out that the usb was again being recognized by the 98 ( I wonder whether it has got anything to do with my shifting to this house in chemp. ) and it was then that I found out this cold – hott business and the file sysdiag64.exe auto run file ( I have not been able to detect this file on the puter but only have seen the inf
file.)

now a days, i lock the camera card before i connect it to the xp system and then there is lot of confusion going on with the system coming up with a message that "Sysdiag64.exe" cannot be executed!

the folder and autorun file mentioned above is seen even on my ipod when I connect it to the usbport of the win98 to recharge the battery.

It is not visible when the usb device is connected to the win xp system – though it is very much present on the device and is doing the damage that it is intended to do – probably this malware is written for win XP. win 98 is not as gestapi-savy as win XP.

& & &

LINKS

online diary

viceman verses