Log in

View Full Version : Beware of nka.exe when browsing...



N1LAF
05-14-2011, 10:09 PM
I was hit by a malicious page that even AVG missed. Symptoms: Firefox quit abruptly, a Windows Security dialog box popped up with a list of infected files (fake), Windows firewall disabled, and Malwarebytes would not run. AVG did run, and did pick up this file, that was just added according to file detail view:
C:\documents and settings\{your login name}\local settings\application data\nka.exe

If you see this, delete it right away. Turn off your router.

As soon as nka.exe was deleted, I was able to run Malwarebytes, and access Windows Firewall panel.

I ran superantispyware first, turned on router, updated database, and it did find a registry threat, but the nka.exe was already deleted. Turned router off.

I then ran Firefox. Do this with the router off. What happens when Firefox crashes, it will try to reload the previous tabs that was open at crash, and doing so may reinvent the malware load. Cleared all tabs, close Firefox.

Then I turned router on, ran Malwarebytes, updated database, rebooted computer, turned router off, and scanned with Malwarebytes. Malwarebytes found stuff missed by Superantispyware. Deleted suspect items (7 total).

Reboot computer, ran Malwarebytes again, clean bill of health. Checked Windows Firewall settings, turned on router, and ran AVG antivirus. Update database, now scanning - zero hits so far.

-----

I should know better, when doing general searches, do them in a VMware window. I have VMware on all my computers, with Firefox loaded in all.

Superantispyware has a blurb on the nka.exe file, there are three other filenames other than nka.exe that are one in the same, this threat was reported on Mar 24, 2011, so it is relatively new.

Hope this helps others....

W2NAP
05-15-2011, 12:18 AM
my debian laughs at .exe

PA5COR
05-15-2011, 02:46 AM
Thanks for the heads up Paul, appreciated, looks nasty...

N1LAF
05-15-2011, 06:09 AM
I forgot to say, if you see something that looks like a Windows Security dialog box that you never have seen before, close it, do not use the buttons on it. Clicking any of the buttons would most likely infest your computer. It is why the malware has to disable the Windows Firewall, to allow download of the rest of the crap. This is why as soon as you see your browser crash and/or see this security box, IMMEDIATELY turn off your router/network. A quick disconnect of network cable is just as effective.

After three consecutive clean runs of AVG, malwarebytes, and Superantispyware, I am starting to feel clean again...

N8YX
05-15-2011, 07:50 AM
Make sure you have "System Restore" turned off, or a 'questionable' file which has registered itself as a Windows component will be placed back onto the system at the next reboot...

N8YX
05-15-2011, 07:51 AM
my debian laughs at .exe
My virtualized Knoppix and OWASP CD boot images laugh at everything.

ad4mg
05-15-2011, 07:51 AM
Make sure you have "System Restore" turned off, or a 'questionable' file which has registered itself as a Windows component will be placed back onto the system at the next reboot...
Gold Star post. Very few consider this!

KC2UGV
05-15-2011, 07:53 AM
I tried to run nka.exe, but I got the following:

libdll.so.3 died from an unexpected error: No 'iexplore.exe' found.

N8YX
05-15-2011, 08:24 AM
I tried to run nka.exe, but I got the following:

libdll.so.3 died from an unexpected error: No 'iexplore.exe' found.
Wine not configured properly? :snicker: :rofl:

KC2UGV
05-15-2011, 09:10 AM
Wine not configured properly? :snicker: :rofl:

Yeah, I think so. Just don't use it all that often :lol:

NQ6U
05-15-2011, 12:34 PM
my debian laughs at .exe

My Mac says "This is a Windows program and can't be run on this computer." Really. Apple added that dialog a few OS iterations ago.