A clever little malware...


Recommended Posts

I'm having difficulty with one of my client's machines. It seems to have been infected with some extremely vicious malware.

The malware itself is quite subtle. I seek to disable enough of the malware's functions so that my cleanup tools will work.

I don't even have a virus name to reference this by at the moment. Here's what it does:

1. It pops up web browser windows in whatever web browser happens to be open. This includes firefox portable, interestingly enough.

2. It hides the BHOs from HiJackThis. For this reason, I don't have a virus name, as I am unable to look up the .dlls responsible. Hell, if I could get a name for this malware, I could probably kill it.

3. It prevents any internet traffic to certain sites, including *.symantec.com. I didn't browse long, but one of the customer complaints is that "some web sites don't work," so there is probably a list of sites this malware is blacklisting.

4. It makes safe mode crash during boot so safe mode is currently unusable.

Tools at my disposal:

1. Symantec Antivirus Corporate and NOD32, installed on separate clean computers. I tried a Symantec scan and it came up a few files put in there by malware (tdssl.dll in specific) and those were cleaned, but it did not nuke the BHOs' .dll file apparently as HiJackThis is still crippled.

2. HiJackThis with enough knowledge to use it, provided the BHOs are accessible.

3. As mentioned above, I have access to two clean computers. Both of which have autorun turned off, and up-to-date scanners.

4. A flash drive with a write-protect switch.

5. Internet access through a heavily corporate firewall. Additional malware is unlikely to be downloaded when the machine is online.

6. Boot CDs including UBCD4Win and Parted Magic and Ubuntu.

Of course, I could always just nuke the thing, and I probably will anyways to be safe, but this is a first that I've come across something quite this interesting. I've never seen a malware hide the BHOs from HiJackThis before. This is not your typical AntiVirus2008/2009/VistaAntivirus infestation.

Link to comment
https://www.neowin.net/forum/topic/678346-a-clever-little-malware/
Share on other sites

I would also use this tool--- It may have blocked your ctl-alt-del task manager... but it probably didn't block this one.

http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx

Process Explorer...

Also I would boot with Ubuntu and mount the drive and check the Local locations--- Temp folders, User Start menu Startup Folder--- as well as manually remove the IE temp Cache. Also Check the USER Desktop to see if it has seeded itself as a Desktop Web Page. Also try running Stinger.exe..(not from Ubuntu) http://vil.nai.com/VIL/stinger/

That would be a good step, however this particular malware does not look like your usual vundo-variant that SmitFraudFix was designed to tackle. Vundo and its variants all seem to have some sort of fake AV or tuneup or registry cleaner UI that pops up and demands money, I don't see any of that with this particular malware... hence me describing it as "subtle."

Another issue is that when I do run SmitFraudFix, I like to do so from Safe Mode, which is currently inaccessible.

EDIT: I forgot to mention that I already cleared out the usual hiding places: The temp folders, and I also looked for suspicious looking folders or files in the program files folder too. Nada.

cmd line possible --sfc /scannow

Also check the hosts file--- It could be as simple as a redirect for all web traffic to their site.

You can use Ubuntu for that one...it opens just like a txt file.

That Hosts file could be the one blocking those websites.

Also try Spybot Search and Destroy.

http://www.safer-networking.org/index2.html

Also a quick edit-- of the hosts file (if you know the site it is taking them to) could block that site and give you the chance to minimize damage (or redownload) of the Software.

Edited by redvamp128

I've been cleaning out machines for 3 years, and in that time, Malwarebyte's Anti-Malware is by far the best software I have used. Disable all start up programs using MSCONFIG, install and run MBAM, remove threats. Boot to safe mode (if possible), update and run MBAM again (as a full scan, not partial), and remove any threats found. You are officially clean. Run AVG free scan to ensure safety. PM me with questions/results! Good luck!

Oh, thanks for replying, I had forgotten I had made this thread. The computer in question has been reformatted and reinstalled already. But this is after I did defeat the virus. Turns out that, according to NOD32, the malware was a virtumonde (Vundo) variant. However, I did find out that I could manually browse to the BHOs in the registry manually by using regedit and then look up their corresponding CLSID via simple search, this allowed me to track down the actual DLL file that was loading as a BHO that prevented HiJackThis from being able to see the BHOs.

NOD32 also was able to detect all the copies of the malware that squirreled themselves away inside the Windows folder. The system looked clean, however there was some funny page rendering problems left in IE which prompted me to wipe and reload the system.

Thanks for the hints everyone.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Snap Inc. launches new SPECS augmented reality glasses (for 'just' $2,195) by Aditya Tiwari Image: Snap Inc. Smartglasses powered by augmented reality are the latest fashion because the smartphone market is slowly reaching saturation. Snap Inc. announced its latest AR-powered smartglasses, called SPECS, that aim to strike a middle ground between underpowered AI glasses and heavy headsets you can't wear all the time. Available in two sizes, Snap SPECS are made from high-performance Swiss TR90 polymer and feature removable inserts to support prescription lenses. Its 47mm model weighs about 132g; the bigger 52mm model weighs 136g. Snap Inc has been spreading the word about the new glasses for a while now. Earlier this year, it even spun off its smart glasses team into a subsidiary called Specs Inc. Its proprietary LCOS (Liquid Crystal on Silicon) display delivers a 51-degree field of view and 16 million colors. Snap says the device gives the feel of a 24-inch desktop monitor when you're working, and of a 115-inch home cinema screen placed about 10 feet away when watching a movie. A pair of custom stereo speakers and 6x high-SNR MEMS microphones are built into the temples of the smartglasses to deliver open-ear audio while you cast a screen, stream content, open a whiteboard, or collaborate with others. Snap Inc. patted itself on the back, saying the smartglasses don't need tethering or a puck to connect to a computer. Under the hood, SPECS draw its power from two Snapdragon processors: one for computer vision and another for running Lenses. The device supports fast hand tracking, low latency, and responsive interactions that help digital content feel anchored in the real world, according to the company, which claims that SPECS can "deliver 7-millisecond motion-to-photon latency." The smartglasses offer up to four hours of battery life on a single charge while providing AI assistance, Bluetooth notifications, Lenses, audio/video playback, and more. The battery life could jump to 20 hours of mixed use when the charging case is included. Image: Snap Inc. You can view and interact with AR Lenses anchored directly to the physical world around you, and an on-board AI assistant uses the camera to see what's around to answer questions or provide real-time help with tasks. Snap Inc. noted that it filed more than 7,000 patents during the development of SPECS. It's trying to build the required digital ecosystem around the smartglasses, and said that developers have already published hundreds of Lenses for SPECS. Moreover, their electrochromic lenses use the same technology available in Boeing 787 Dreamliner windows, enabling them to shift from clear to tinted in just 10 seconds when you walk out of your house. Snap SPECS are now available for pre-order on the official website with a $2,195 price tag ($200 refundable deposit). The smartglasses are expected to ship in the US, UK, and France during the Fall this year.
    • Sound Booster 1.13 Build 575 by Razvan Serea Increase volume on your laptop. Boost the volume of even very quiet speakers. Raise volume above maximum. Letasoft Sound Booster can be used as an extra amplifier when the volume of the program you are listening to is too low for comfortable listening and you feel that your PC’s speakers can produce a louder sound. This can be the case when the audio or video has been recorded at the level below normal. Or, for example, when the other person’s microphone you are talking to on Skype, is not working properly. There can be a plenty of other reasons why the sound is being too quiet and there is not much you can do about it except buy external speakers. Sound of any application that is being played in the system can be amplified up to 500%. Letasoft Sound Booster can raise volume of programs like web browsers, on-line communication software (Teams, Discord, Zoom), any kind of media player or games. Simply put, volume of virtually any program that can play any sound in PC, can be boosted to a comfortable level with Letasoft Sound Booster. You can control current volume with the pop-up slider from the system tray. Alternatively, you can assign system-wide hot keys for increasing and decreasing, and use them when you need to adjust volume Letasoft Sound Booster constantly monitors current gain level and prevents samples from clipping, thus reducing all major sound distortions. Sound Booster 1.13 Build 575 changelog: usability improvements minor bug fixes Download: Letasoft Sound Booster 1.13.0.575 | 5.4 MB (14-Day Free Trial) View: Letasoft Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I own these and the normal QuietComfort ones from Bose. The QC are amazing and I want to love these, but for the life of me, I have a terrible time getting them attached to my ears.
  • Recent Achievements

    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      108
    4. 4
      Steven P.
      89
    5. 5
      ATLien_0
      67
  • Tell a friend

    Love Neowin? Tell a friend!