Hello Guest, if you are reading this it means you have not registered yet. Please take a second, Click here to register, and in a few simple steps you will be able to enjoy our community and use our OpenViX support section.
Page 1 of 2 12 LastLast
Results 1 to 15 of 28

Thread: IMG001.exe file?Malware?

  1. #1

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts

    Exclamation IMG001.exe file?Malware?

    Hi found this file in my box IMG001.exe is it normal?If i google it about IMG001.exe say malware.

  2. #2
    abu baniaz's Avatar
    Title
    Moderator
    Join Date
    Sep 2010
    Location
    East London
    Posts
    23,360
    Thanks
    6,442
    Thanked 9,160 Times in 6,235 Posts
    It is not normal.

    At which location on receiver did you find it?

  3. #3

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts
    So you think will be virus?

    Found it here

    Untitled-1.jpg

  4. #4
    abu baniaz's Avatar
    Title
    Moderator
    Join Date
    Sep 2010
    Location
    East London
    Posts
    23,360
    Thanks
    6,442
    Thanked 9,160 Times in 6,235 Posts
    You also have an info.zip file.

    I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai. Shame you have not said what image you have. 4.2 what? So not sure if you have those fixes.

    Maybe an idea to flash latest image to your receiver. Set a password for your receiver as well. I'd check if there is an updated firmware for your router too.

  5. #5

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts
    Quote Originally Posted by abu baniaz View Post
    You also have an info.zip file.

    I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai. Shame you have not said what image you have. 4.2 what? So not sure if you have those fixes.

    Maybe an idea to flash latest image to your receiver. Set a password for your receiver as well. I'd check if there is an updated firmware for your router too.
    I'm glad what you mentioned mirai. I received few letters from VM what one off my devices infected i was scratching my head which one now i know .
    Regarding image i was OpenViX 4.2.011 flashed now to OpenViX 4.2.023.
    So i should be save now regarding mirai?

  6. #6
    Huevos's Avatar
    Title
    Administrator
    Join Date
    Jun 2010
    Location
    38.5N, 0.5W
    Posts
    13,629
    Thanks
    2,006
    Thanked 4,953 Times in 3,274 Posts
    No. Your router/firewall has a problem that needs fixing.
    Help keep OpenViX servers online.Please donate!

  7. #7

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts
    Quote Originally Posted by Huevos View Post
    No. Your router/firewall has a problem that needs fixing.
    Regarding router. I have Asus ac3200 on merlin firmware i doubt this is router fault.Firewall you mean Pc firewall?

    Sent from my LG-D855 using Tapatalk

  8. #8
    birdman's Avatar
    Title
    Moderator
    Join Date
    Sep 2014
    Location
    Hitchin, UK
    Posts
    7,790
    Thanks
    237
    Thanked 1,658 Times in 1,306 Posts
    Quote Originally Posted by deividuska View Post
    Regarding router. I have Asus ac3200 on merlin firmware i doubt this is router fault.Firewall you mean Pc firewall?
    No - he means your router configuration. It doesn't matter how good the software can be if you configure it incorrectly.
    For the file to have ended up on your system it must(?) have been accessible to the outside world in some way. Do you configure things so that the box is contactable from outside your home network (port forwarding, or DMZ set-up)?
    MiracleBox Prem Twin HD - 2@DVB-T2 + Xtrend et8000 - 5(incl. 2 different USBs)@DVB-T2[terrestrial - UK Freeview HD, Sandy Heath] - LAN/USB-stick/HDD

  9. #9
    Huevos's Avatar
    Title
    Administrator
    Join Date
    Jun 2010
    Location
    38.5N, 0.5W
    Posts
    13,629
    Thanks
    2,006
    Thanked 4,953 Times in 3,274 Posts
    Something has crossed from the public internet onto your private home network. You need to find out why. On the home network security is more relaxed. This means once one of the devices on the home network (satellite receiver) has been compromised it can be used to attack other devices (PC for example) on the same home network.

    Have you exposed the satellite receiver to the public internet on purpose? If so you need to understand the satellite receiver is not security hardened for use on the public internet.

    If it is not exposed to the public internet on purpose you need to look at what is wrong with your router security that has allowed this.
    Last edited by Huevos; 25-12-16 at 08:57.
    Help keep OpenViX servers online.Please donate!

  10. #10

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts
    Quote Originally Posted by birdman View Post
    No - he means your router configuration. It doesn't matter how good the software can be if you configure it incorrectly.
    For the file to have ended up on your system it must(?) have been accessible to the outside world in some way. Do you configure things so that the box is contactable from outside your home network (port forwarding, or DMZ set-up)?
    Hi it was only ports open for watching tv on phone outside home network. Nothing else.

    Sent from my LG-D855 using Tapatalk

  11. #11

    Title
    Forum Supporter
    Donated Member
    Join Date
    Dec 2014
    Location
    Bradford
    Posts
    126
    Thanks
    23
    Thanked 10 Times in 8 Posts
    Quote Originally Posted by Huevos View Post
    Something has crossed from the public internet onto your private home network. You need to find out why. On the home network security is more relaxed. This means once one of the devices on the home network (satellite receiver) has been compromised it can be used to attack other devices (PC for example) on the same home network.

    Have you exposed the satellite receiver to the public internet on purpose? If so you need to understand the satellite receiver is not security hardened for use on the public internet.

    If it is not exposed to the public internet on purpose you need to look at what is wrong with your router security that has allowed this.
    Only thing I done regarding satellite box just opened ports to watch tv on phone outside home network. So it is only thing i can think off.

    Sent from my LG-D855 using Tapatalk

  12. #12
    ccs's Avatar
    Title
    ViX Beta Tester
    Join Date
    Sep 2014
    Posts
    5,836
    Thanks
    554
    Thanked 1,277 Times in 1,089 Posts
    ... that's all it needs for them to get in.

  13. #13
    SpaceRat's Avatar
    Title
    Senior Member
    Join Date
    Apr 2015
    Posts
    206
    Thanks
    25
    Thanked 79 Times in 52 Posts
    Quote Originally Posted by abu baniaz View Post
    I'm glad Spacerat and Jibyel have blocked off the vulnerabilities to Mirai.
    Actually hardening against Mirai has to be credited to betacentauri (Although it was me who asked him to implement this change).

    Forcibly closing OWIF was actually pro-active:
    OWIF got a package manager at the same time, which WOULD have introduced a new attack vector (Not sure if the backup/restore capability of its Bouquet-Editor already was vulnerable to put arbitrary code).

    Mirai however attacks open Telnet ports, which the busybox patch by betacentauri forcibly closes by not accepting ANY connections that do not come from private address space or same subnet (= local network or VPNs) anymore.

    Actually that patch respectively the busybox upgrade it causes is the reason why 022 and 023 require a reflash for some users:
    I fixed opkg on 18th of September to be able to perform busybox upgrades again (They stopped working in oe-a 3.0, when switching from opkg 0.2.x to 0.3.x).
    The opkg fix couldn't be rolled out in online updates however, as self-updating opkg was another thing broken since oe-a 3.0.

    That's why boxes that had been flashed with images created after 18th of September survive the busybox upgrade and older flashes don't.

    Gesendet von meinem Siemens C25 mit Tapatalk
    Receiver/TV:
    • Vu+ Duo² 4*S2+2*C / 1.8TB HDD / OpenATV 6.1@Samsung 50" Plasma
    • AX Quadbox 2400 / 2*S2/2*C / 930GB HDD / OpenATV 6.1@Samsung 32" LCD
    • Vu+ Solo² / 465GB HDD / OpenATV 6.1
    • Vu+ Solo² / 230GB HDD / OpenATV 6.1
    • DVBSky S2-Twin-Tuner PCIe@Samsung SyncMaster T240HD (PC)
    Pay TV: Redlight Mega, Brazzers TV Europe, XXL, HD-, Sky
    Internet: Unitymedia 1play 100 / Cisco EPC3212 + Linksys WRT1900ACS + Fritz!Box 7390 / IPv4 (UM) + IPv6 (HE)

  14. The Following 3 Users Say Thank You to SpaceRat For This Useful Post:

    abu baniaz (18-11-17),Clabs (25-12-16),twol (25-12-16)

  15. #14

    Title
    Forum Supporter
    Donated Member
    Join Date
    Jun 2015
    Posts
    338
    Thanks
    64
    Thanked 65 Times in 56 Posts
    If anybody wants to test the security of their router can I suggest they go to the Shields Up website run by Gibson Research Corporation and run the port tests.

  16. The Following User Says Thank You to spanner123 For This Useful Post:

    deividuska (25-12-16)

  17. #15
    Larry-G's Avatar
    Title
    V.I.P
    Donated Member
    Join Date
    May 2010
    Posts
    32,542
    Thanks
    7,824
    Thanked 22,935 Times in 12,378 Posts
    Quote Originally Posted by deividuska View Post
    Only thing I done regarding satellite box just opened ports to watch tv on phone outside home network. So it is only thing i can think off.

    Sent from my LG-D855 using Tapatalk
    Thats exactly what they are looking for. There are a army of script kiddies and even automated scripts trawling the internet for open E2 boxes to take advantage of, in most cases they just steal your channels to host on a dodgy pay TV server but as you just discovered it can be a little more dangerous now to leave your receiver wide open for any one to walk into at will.
    My posts contain my own personal thoughts and opinions, they do not represent those of any organisation or group but my own.

    If you don't like what I post, Don't read it.

    SIMPLES.

  18. The Following User Says Thank You to Larry-G For This Useful Post:

    deividuska (26-12-16)

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
This website uses cookies
We use cookies to store session information to facilitate remembering your login information, to allow you to save website preferences, to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners.