A clever little malware...


Recommended Posts

I'm having difficulty with one of my client's machines. It seems to have been infected with some extremely vicious malware.

The malware itself is quite subtle. I seek to disable enough of the malware's functions so that my cleanup tools will work.

I don't even have a virus name to reference this by at the moment. Here's what it does:

1. It pops up web browser windows in whatever web browser happens to be open. This includes firefox portable, interestingly enough.

2. It hides the BHOs from HiJackThis. For this reason, I don't have a virus name, as I am unable to look up the .dlls responsible. Hell, if I could get a name for this malware, I could probably kill it.

3. It prevents any internet traffic to certain sites, including *.symantec.com. I didn't browse long, but one of the customer complaints is that "some web sites don't work," so there is probably a list of sites this malware is blacklisting.

4. It makes safe mode crash during boot so safe mode is currently unusable.

Tools at my disposal:

1. Symantec Antivirus Corporate and NOD32, installed on separate clean computers. I tried a Symantec scan and it came up a few files put in there by malware (tdssl.dll in specific) and those were cleaned, but it did not nuke the BHOs' .dll file apparently as HiJackThis is still crippled.

2. HiJackThis with enough knowledge to use it, provided the BHOs are accessible.

3. As mentioned above, I have access to two clean computers. Both of which have autorun turned off, and up-to-date scanners.

4. A flash drive with a write-protect switch.

5. Internet access through a heavily corporate firewall. Additional malware is unlikely to be downloaded when the machine is online.

6. Boot CDs including UBCD4Win and Parted Magic and Ubuntu.

Of course, I could always just nuke the thing, and I probably will anyways to be safe, but this is a first that I've come across something quite this interesting. I've never seen a malware hide the BHOs from HiJackThis before. This is not your typical AntiVirus2008/2009/VistaAntivirus infestation.

Link to comment
https://www.neowin.net/forum/topic/678346-a-clever-little-malware/
Share on other sites

I would also use this tool--- It may have blocked your ctl-alt-del task manager... but it probably didn't block this one.

http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx

Process Explorer...

Also I would boot with Ubuntu and mount the drive and check the Local locations--- Temp folders, User Start menu Startup Folder--- as well as manually remove the IE temp Cache. Also Check the USER Desktop to see if it has seeded itself as a Desktop Web Page. Also try running Stinger.exe..(not from Ubuntu) http://vil.nai.com/VIL/stinger/

That would be a good step, however this particular malware does not look like your usual vundo-variant that SmitFraudFix was designed to tackle. Vundo and its variants all seem to have some sort of fake AV or tuneup or registry cleaner UI that pops up and demands money, I don't see any of that with this particular malware... hence me describing it as "subtle."

Another issue is that when I do run SmitFraudFix, I like to do so from Safe Mode, which is currently inaccessible.

EDIT: I forgot to mention that I already cleared out the usual hiding places: The temp folders, and I also looked for suspicious looking folders or files in the program files folder too. Nada.

cmd line possible --sfc /scannow

Also check the hosts file--- It could be as simple as a redirect for all web traffic to their site.

You can use Ubuntu for that one...it opens just like a txt file.

That Hosts file could be the one blocking those websites.

Also try Spybot Search and Destroy.

http://www.safer-networking.org/index2.html

Also a quick edit-- of the hosts file (if you know the site it is taking them to) could block that site and give you the chance to minimize damage (or redownload) of the Software.

Edited by redvamp128

I've been cleaning out machines for 3 years, and in that time, Malwarebyte's Anti-Malware is by far the best software I have used. Disable all start up programs using MSCONFIG, install and run MBAM, remove threats. Boot to safe mode (if possible), update and run MBAM again (as a full scan, not partial), and remove any threats found. You are officially clean. Run AVG free scan to ensure safety. PM me with questions/results! Good luck!

Oh, thanks for replying, I had forgotten I had made this thread. The computer in question has been reformatted and reinstalled already. But this is after I did defeat the virus. Turns out that, according to NOD32, the malware was a virtumonde (Vundo) variant. However, I did find out that I could manually browse to the BHOs in the registry manually by using regedit and then look up their corresponding CLSID via simple search, this allowed me to track down the actual DLL file that was loading as a BHO that prevented HiJackThis from being able to see the BHOs.

NOD32 also was able to detect all the copies of the malware that squirreled themselves away inside the Windows folder. The system looked clean, however there was some funny page rendering problems left in IE which prompted me to wipe and reload the system.

Thanks for the hints everyone.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Same Internet Archive seemed to grab the new version https://web.archive.org/web/20...d/Setup_MakeMKV_v1.18.4.exe Here's the link to an additional file it periodically downloads https://web.archive.org/web/20260213092148/https://www.makemkv.com/sdf.bin I think update's keys, etc. To manually trigger this update, put the sdf.bin file in the root of where the program is installed. When you launch the program it will pick up the file and import it. Typically put it here: C:\Program Files (x86)\MakeMKV\sdf.bin
    • Windows 11 KB5094126, KB5093998 bugging out Office apps but it may not be Microsoft's fault by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. Although the tech giant did not acknowledge any major problems, some users online reported various issues ranging from OneDrive and Dropbox access problems, BitLocker recovery lockouts, to blue screens and BSODs. You can read about them in this dedicated piece. While there is still no confirmation about those problems from Microsoft the company has admitted to another bug which we did not report on. The tech giant has confirmed it has received reports of an issue in which certain third-party applications may be unable to launch Microsoft Office apps or open Office documents after installing the Patch Tuesday. This affects both Windows 11 as well as Windows 10. The company says the problem impacts a subset of applications that rely on OLE (Object Linking and Embedding) automation to communicate with Microsoft Office programs. According to Microsoft, affected scenarios involve third-party software attempting to open Office applications or documents from within their own interface. In such cases, the Office program may fail to launch altogether, or the requested document may not open. Oddly there may not be any error message, which probably makes the issue difficult to diagnose. The bug affects several Office products, including Word, Excel, PowerPoint, Access, and other apps in the Microsoft Office suite when they are launched through the affected software. These include tax and accounting software such as CCH Engagement and Workpaper Manager, dental practice management solutions like Dentrix and Softdent, as well as the popular research and reference management tool Zotero. Microsoft adds that other applications using similar Office integration methods could also experience the same problematic behavior. To understand the issue it is important to look at OLE, the Microsoft technology involved. OLE allows different applications to work together and share data, while its Automation feature lets one program control another. Thus this enables third-party software to launch Microsoft Office apps, open documents, and perform tasks automatically without requiring users to switch between programs. Because many accounting, healthcare, research, and business applications rely on OLE automation to interact with Word, Excel, PowerPoint, and other Office apps, any disruption can break those workflows. As a result, affected software may be unable to open Office documents or launch Office applications even though the programs themselves continue to work normally. At the moment the company has not provided a permanent fix though it has confirmed that engineers are actively working on a resolution, which will be delivered through a future Windows update. As such additional details will be shared once more information becomes available. In the meantime, Microsoft recommends a simple workaround for affected users whic is to open the Office application or document directly rather than launching it through the third-party program. For enterprise customers and organizations managing larger deployments, Microsoft says an additional mitigation is available. Admins experiencing the problem on their managed devices are advised to contact Microsoft Support for business to obtain and apply the workaround.
    • It saddens me when cars are such dull colours now. Mine is bright metallic blue and I absolutely adore it for standing out in contrast to that depressing backdrop of traffic.
    • Sparkle 2.20.0 by Razvan Serea Sparkle is a free, open-source Windows optimization tool designed to make your PC faster, cleaner, and more private. With Sparkle, you can easily debloat Windows by removing unnecessary apps and services, disable Microsoft tracking to enhance privacy, and apply performance tweaks to boost speed. Its cleaner removes junk and temporary files, while every change is safe and fully reversible. Sparkle also features a modern, user-friendly interface with automatic updates, making system maintenance simple. Explore over 39 tweaks, from disabling telemetry and hibernation to optimizing network and game settings, all aimed at customizing and enhancing your Windows experience. Sparkle supports Windows 10 and 11. Sparkle 2.20.0 changelog: Debloat Tweak has animated border New homepage loading UI New Tweak Modal (Markdown Supported) Refactored GPU Detection Added Tests with vitest Added foobar2000 to apps Added Localsend to apps Updated Modal Styles Added styles for disabled inputs Added Animated Border to debloat-windows tweak Bumped dependencies Refactor System info logic for speed Tweak info modals now support Markdown Added Clear System info cache to settings Redesigned Home Page Loading UI Changed Some Icons around the app Download: Sparkle 2.20.0 | Portable | ~100.0 MB (Open Source) Links: Sparkle Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • lol it was a typo, fixed! haha imagine an actual 4TB Gen4 NVMe for $40 in 2026
  • Recent Achievements

    • Reacting Well
      Dys Topia earned a badge
      Reacting Well
    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      106
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      68
  • Tell a friend

    Love Neowin? Tell a friend!