Superb quality and spec AB-Com PULSe 4K SE. Crazy offer! Only £129! FREE UK DELIVERY! 4K UHD, Enigma 2, Multiboot 4 images & more!...
Superb quality and spec AB-Com PULSe 4K Rev II Twin Satellite tuner only £179! FREE UK DELIVERY! 4K UHD, Enigma 2, SATA HDD facility, Multiboot 4 images & more!...

[VU+ Duo2] IMG001.exe file?Malware?

deividuska

Forum Supporter
Donated Member
Joined
Dec 27, 2014
Messages
126
Reaction score
0
Points
0
Age
48
Location
Bradford
Hi found this file in my box IMG001.exe is it normal?If i google it about IMG001.exe say malware.
 
It is not normal.

At which location on receiver did you find it?
 
Last edited:
You also have an info.zip file.

I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai. Shame you have not said what image you have. 4.2 what? So not sure if you have those fixes.

Maybe an idea to flash latest image to your receiver. Set a password for your receiver as well. I'd check if there is an updated firmware for your router too.
 
Last edited:
You also have an info.zip file.

I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai. Shame you have not said what image you have. 4.2 what? So not sure if you have those fixes.

Maybe an idea to flash latest image to your receiver. Set a password for your receiver as well. I'd check if there is an updated firmware for your router too.

I'm glad what you mentioned mirai. I received few letters from VM what one off my devices infected i was scratching my head which one :mad: now i know :mad:.
Regarding image i was OpenViX 4.2.011 flashed now to OpenViX 4.2.023.
So i should be save now regarding mirai?
 
No. Your router/firewall has a problem that needs fixing.
 
No. Your router/firewall has a problem that needs fixing.
Regarding router. I have Asus ac3200 on merlin firmware i doubt this is router fault.Firewall you mean Pc firewall?

Sent from my LG-D855 using Tapatalk
 
Regarding router. I have Asus ac3200 on merlin firmware i doubt this is router fault.Firewall you mean Pc firewall?
No - he means your router configuration. It doesn't matter how good the software can be if you configure it incorrectly.
For the file to have ended up on your system it must(?) have been accessible to the outside world in some way. Do you configure things so that the box is contactable from outside your home network (port forwarding, or DMZ set-up)?
 
Something has crossed from the public internet onto your private home network. You need to find out why. On the home network security is more relaxed. This means once one of the devices on the home network (satellite receiver) has been compromised it can be used to attack other devices (PC for example) on the same home network.

Have you exposed the satellite receiver to the public internet on purpose? If so you need to understand the satellite receiver is not security hardened for use on the public internet.

If it is not exposed to the public internet on purpose you need to look at what is wrong with your router security that has allowed this.
 
Last edited:
No - he means your router configuration. It doesn't matter how good the software can be if you configure it incorrectly.
For the file to have ended up on your system it must(?) have been accessible to the outside world in some way. Do you configure things so that the box is contactable from outside your home network (port forwarding, or DMZ set-up)?
Hi it was only ports open for watching tv on phone outside home network. Nothing else.

Sent from my LG-D855 using Tapatalk
 
Something has crossed from the public internet onto your private home network. You need to find out why. On the home network security is more relaxed. This means once one of the devices on the home network (satellite receiver) has been compromised it can be used to attack other devices (PC for example) on the same home network.

Have you exposed the satellite receiver to the public internet on purpose? If so you need to understand the satellite receiver is not security hardened for use on the public internet.

If it is not exposed to the public internet on purpose you need to look at what is wrong with your router security that has allowed this.
Only thing I done regarding satellite box just opened ports to watch tv on phone outside home network. So it is only thing i can think off.

Sent from my LG-D855 using Tapatalk
 
... that's all it needs for them to get in.
 
I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai.
Actually hardening against Mirai has to be credited to betacentauri (Although it was me who asked him to implement this change).

Forcibly closing OWIF was actually pro-active:
OWIF got a package manager at the same time, which WOULD have introduced a new attack vector (Not sure if the backup/restore capability of its Bouquet-Editor already was vulnerable to put arbitrary code).

Mirai however attacks open Telnet ports, which the busybox patch by betacentauri forcibly closes by not accepting ANY connections that do not come from private address space or same subnet (= local network or VPNs) anymore.

Actually that patch respectively the busybox upgrade it causes is the reason why 022 and 023 require a reflash for some users:
I fixed opkg on 18th of September to be able to perform busybox upgrades again (They stopped working in oe-a 3.0, when switching from opkg 0.2.x to 0.3.x).
The opkg fix couldn't be rolled out in online updates however, as self-updating opkg was another thing broken since oe-a 3.0.

That's why boxes that had been flashed with images created after 18th of September survive the busybox upgrade and older flashes don't.

Gesendet von meinem Siemens C25 mit Tapatalk
 
If anybody wants to test the security of their router can I suggest they go to the Shields Up website run by Gibson Research Corporation and run the port tests.
 
Only thing I done regarding satellite box just opened ports to watch tv on phone outside home network. So it is only thing i can think off.

Sent from my LG-D855 using Tapatalk

Thats exactly what they are looking for. There are a army of script kiddies and even automated scripts trawling the internet for open E2 boxes to take advantage of, in most cases they just steal your channels to host on a dodgy pay TV server but as you just discovered it can be a little more dangerous now to leave your receiver wide open for any one to walk into at will.
 
Is there any way to delete these files, all at one time (some script perhaps)
Actually these files are supposed to be runing and infecting PC's since they are *.exe files, but they always end up in my Gigabox Quad Plus with openvix, in all the versions that I flashed with the virus/trojan ends up entering and is placed in all the folders of the system openvix.
In fact these files are placed in so many folders of the system that I always end up preferring to reinstall a new image in the system (this is also one of the reasons I know now it is a vulnerability of openvix image) in other images I was not infected, example with openMips, only with openvix this happens.
So if someone has a script for linux that can search in multiple folders and delete files at our choice would be very useful :confused:
 
I suggest you should read this thread from start to finish to establish how these files are getting into your local lan, block the loophole, and then reflash the Gigabox.
 
I think I got a better solution... a fast one at least !

find / \( -name "*.exe" -o -name "*.zip" \) -type f -delete

this does the trick ;)
 
Last edited:
It's a crappy solution.
You are messing with the symptoms rather than fixing the problem.

It's a PEBKAC type of problem.
 
In fact these files are placed in so many folders of the system that I always end up preferring to reinstall a new image in the system (this is also one of the reasons I know now it is a vulnerability of openvix image) in other images I was not infected, example with openMips, only with openvix this happens.
That's sounds as though you are mounting your Vix box's file-system on your PC and a virus there is just copying file into all directories it can find (?).
The problem wodul then be on your PC, and until you fix that (your PC) there's no point doing anything anywhere else.
 

OpenViX Feeds Status

Back
Top