Jump to content


Just dodged a driveby rootkit, I think


22 replies to this topic

#1 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 10 January 2009 - 07:42 PM

Had Powershadow running, Returnil probably would have worked also.
Used eDintori.net, Irish search engine to look for Piriform forums.

One of the links (about hanged people, dont go) went to a site which locked me up. All I did was open it. It tried to install a rootkit, I think. Edit: would welcome any comments from members more knowledgeable about what happened.

Not entirely sure of the following order, but IE was locked up, thats for sure.

Got warning 1. Clicked cancel.
Window wouldn't get out of the way...always on top. Windows key+d will clear the screen.
Got the install prompt.
Clicked cancel on the install prompt. It cancelled.
Clicked cancel on the download prompt. The prompt just repeated itself. 5 times
Clicked the x to close the next install prompt. The prompt just repeated itself. 5 times
Clicked on another tab in IE. Wouldn't change tabs. Got the bloop sound.
Clicked on the x to close IE. Nope.
Clicked on the system tray to close IE. Nope.
Disabled 'net connection from systray.

ctl+alt+delete brought up task manager.
Used tskmgr to shut down IE. worked.

Scans of C:\Documents and Settings\Compaq_Owner\Local Settings before reboot
Avast = nothing
SuperAnti = nothing
mbam = nothing
A2 = Rootkit.win32.TDSS!K in c:\...Local Settings\temporary internet files\ContentIE5\O9H2O13\[1].EXE.
Apparently this is a fairly new malaware. ?

Scans after reboot: Apparently nothing installed.

Don't Know what would have happened if I hadn't had PS running. Wish it was still free, but Returnil has the same capabilities, I guess. I notified eDintori.

Posted Image

Posted Image

Posted Image

Edit: Well, OK, guess I'll quit using xs.to for image hosting. Lotsa junk comes with those thumbnail links. <_<
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#2 OFFLINE   YoKenny

    Super Power User

  • Members
  • PipPipPipPipPip
  • 2,874 posts
  • Gender:Male
  • Location:Oshawa, Ont. Canada
  • Interests:Helping people get rid of malware on their systems then showing them how not to get re-infected again

Posted 10 January 2009 - 09:05 PM

This is a symptom of the infamous antivirus2009 gang that are currently rampant on the Internet

See Newest Rogue Threats:
http://www.malwareby...hp?showforum=30

Malwarebytes MBAM is on top of them.
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
IE7Pro user

#3 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 10 January 2009 - 09:30 PM

Thanks for the info, YoKenny. MBAM is a great app. :D
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#4 ONLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 10 January 2009 - 11:03 PM

You should block that URL you went to in everything you have including IE, HOSTS and even input it into Avast's Web Shield as a blocked site.

We have listed sites on here before to let others know to block them, if you do list it just put it inside of a code box that way the URL won't be active:
Posted Image

It would look like this for example:
www.bad-site-address.com

Complexity of incoherent design.

#5 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 10 January 2009 - 11:48 PM

Just to give an idea of what the AV/AS authors (good guys) have to try and stay on top of.

Below is a pic of a few Antivirus 2009 installers I've picked up in the last month or so.

On the day they are released most AV/AS won't pick them up as they have been morphed (changed) ever so slightly so as to avoid detection until the AV/AS apps have their databases updated in order to detect these new rogue installers.

I think over at MBAM's forum we've found 6-8 new installers since Friday, and that's only for Antivirus 2009 with a lot of other rogue apps doing exactly the same thing.

The installer I uploaded to Virus Total wasn't being flagged on the day I found it.

Quote

File InstallAVg_77019105.exe received on 01.09.2009 10:51:02 (CET)
Current status: finished
Result: 0/38 (0.00%)
Virus Total

And on re-uploading just now a few AV's are starting to detect it.

Quote

File InstallAVg_77019105.exe received on 01.11.2009 00:40:38 (CET)
Current status: finished
Result: 6/34 (17.65%)
Virus Total

Posted Image

#6 OFFLINE   YoKenny

    Super Power User

  • Members
  • PipPipPipPipPip
  • 2,874 posts
  • Gender:Male
  • Location:Oshawa, Ont. Canada
  • Interests:Helping people get rid of malware on their systems then showing them how not to get re-infected again

Posted 11 January 2009 - 12:34 AM

View PostAndavari, on Jan 10 2009, 06:03 PM, said:

You should block that URL you went to in everything you have including IE, HOSTS and even input it into Avast's Web Shield as a blocked site.

By the way hpHosts and MVPS HOSTS files have been recently updated.

I'm finally getting around to Ripping my old CDs to my recently rebuilt XP Pro system.
The Best of the Moody Blues, Magic Bus and Who's Next The Who, The best of Eric Clapton and The Seeger Sessions Bruce Springsteen
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
IE7Pro user

#7 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 11 January 2009 - 03:59 PM

OK, thanks, Andavari, I will post the site below. I didn't before for fear someone would go to it.
Humpty, the anti-malaware business must be like fighting a swarm of bees. Are those all variations of a single install.exe?

The site:
http://new4scan.com/22/?uid=117

It was (and is right now) the only anomalous finding when searching for "Piriform". The site is listed as "the Hanging Tree...etc", and appears to go to dealfa . com but it is an obfuscated url. It is listed below:

http://ie.edintorni.net/search/redirector.asp?t=&u=http%3A//wzey1.ask.com/r%3Ft%3Dp%26d%3Dsyneu%26s%3Dedn%26c%3Dbh%26l%3Ddir%26o%3D0%26sv%3D0a5c4318%26ip%3D415004db%26id%3D4F3614A90464748B0D62A6C4A7E71196%26q%3Dpiriform+forums%26p%3D1%26qs%3D121%26ac%3D7%26g%3D7edbaRxFOjIJSA%26en%3Dte%26io%3D5%26b%3Dalg%26tp%3Dd%26ec%3D10%26pt%3DThe+Hanging+Tree%253A+Execution+and+the+English+Hanged+People.%26ex%3D%26url%3D%26u%3Dhttp%3A//dealfa.com/wp-content/uploads/2007/04/oudelcn-2381.html


Now lookit, guys, I don't hang around (no pun intended) morbid sites. It was anomalous, I'm tellin ya... :unsure:
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#8 OFFLINE   davey

    Keep it simple !

  • Members
  • PipPipPipPipPip
  • 2,235 posts
  • Gender:Male
  • Location:Maryland U.S.A.

Posted 11 January 2009 - 04:47 PM

View Postlogin123, on Jan 11 2009, 10:59 AM, said:

Now lookit, guys, I don't hang around (no pun intended) morbid sites. It was anomalous, I'm tellin ya... :unsure:
OK !!! We will grant you the anomaly. :unsure:
We can overlook the short-term memory or long-term memory loss. :blink:
But the lack of being granted a Favorites entry or a Bookmark? :angry:
:( forum.piriform.com :( members :(
You better dig up a good "guilty smiley" or this one. :ph34r:
You have "cut us to the quick". :( davey
P.S. After further contemplation, all is forgiven. :lol:
After all, you did discover a new "meany" out there. Trying to entrap others searching for "piriform forums".
These guys are truly "deceivers".
THANKS FOR THE WARNING !!!

#9 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 11 January 2009 - 04:50 PM

Site seems down atm?

Quote

Firefox can't find the server at www.new4scan.com.
Yep, most if not all of those installers belong to the rogue Antivirus 2009.

A couple may be for Antivirus 360 which is a clone of AV 2009.

Funny thing is I changed the url to:

Quote

www.new5scan.com

and picked up an installer for Internet Antivirus Pro which is another rogue app which must be quite a new one as not too many are flagging it including MBAM.

Quote

File install.exe received on 01.11.2009 17:44:44 (CET)
Current status: finished
Result: 8/38 (21.05%)
Virus Total

#10 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 11 January 2009 - 05:05 PM

Just to follow up, the installer I downloaded for Internet Antivirus Pro was a morphed version from the other five samples I have.

You can see in the pic below they are the same size but packed at a different size.

Posted Image

Edit:
Changed the url again to:

Quote

www.new6scan.com
and picked up another installer for Internet Antivirus Pro which is different again.

Ya gotta pity those poor Antimalware good guys trying to keep up with these rogues, huh. :blink:

#11 OFFLINE   slowday444

    Power Member

  • Members
  • PipPipPipPip
  • 807 posts

Posted 11 January 2009 - 11:29 PM

View PostHumpty, on Jan 11 2009, 01:05 PM, said:

Just to follow up, the installer I downloaded for Internet Antivirus Pro was a morphed version from the other five samples I have.

You can see in the pic below they are the same size but packed at a different size.

Posted Image

Edit:
Changed the url again to:

and picked up another installer for Internet Antivirus Pro which is different again.

Ya gotta pity those poor Antimalware good guys trying to keep up with these rogues, huh. :blink:
I feel even more sorry for people who are trying to find utilities to protect or keep their systems running and get duped by this garbage. Fortunately, most of us here have our defenses and utilities set up.
Despite a hardware firewall, OA Free, NOD32, ThreatFire, Windows Defender, Sandboxie, some on demand scanners, and AyRecovery, I've come to the conclusion that one of the great defenses and first line of defense (besides common sense) is WOT or similar, and to never, never, ever open anything that isn't green in search results.

#12 OFFLINE   YoKenny

    Super Power User

  • Members
  • PipPipPipPipPip
  • 2,874 posts
  • Gender:Male
  • Location:Oshawa, Ont. Canada
  • Interests:Helping people get rid of malware on their systems then showing them how not to get re-infected again

Posted 11 January 2009 - 11:39 PM

View PostHumpty, on Jan 11 2009, 12:05 PM, said:

Ya gotta pity those poor Antimalware good guys trying to keep up with these rogues, huh. :blink:

There are quite few complaints on avast! and McAfee forums about those infections and they are slowly starting to detect and remove them plus I notice avast! preventing access to their download sites.
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
IE7Pro user

#13 OFFLINE   Tunerz

    Advanced Member

  • Members
  • PipPipPip
  • 490 posts
  • Gender:Male
  • Location:Philippines
  • Interests:No idea

Posted 12 January 2009 - 12:41 PM

Also, take note that the malware authors are aware of a person clicking the red X button to close the window. So far, it is preferred to end the task of the browser rather than simply clicking the X button, which will execute the malware rather than closing the browser.

#14 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 12 January 2009 - 01:47 PM

Thanks, Davey, for letting me off the hook. :P Be comforted, I have Piri on speed dial. The eDintori foray was an experiment to see how different search engines find the same entry.

Tunerz, you are quite right, and maybe a lot of people don't know that. If I hadn't had a virtualization app running, I would have just shut down IE. Might have been too late anyway.

edit: The malicious site is still there. Going to go there 3 times: once w/ PS running, once with Returnil running, and once with Sandboxie running, see what happens. :o Back soon, I hope. Don't try this at home.
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#15 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 12 January 2009 - 04:40 PM

Site is still there, looks and behaves differently. Several clicks required to get to the install prompt. No warning from avast nor from A2 this time, even upon installation. ?
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#16 OFFLINE   DennisD

    Just another volunteer

  • Moderators
  • 7,931 posts
  • Gender:Male
  • Location:England: NE Coast

Posted 12 January 2009 - 05:36 PM

View Postlogin123, on Jan 10 2009, 07:42 PM, said:

Disabled 'net connection from systray.

ctl+alt+delete brought up task manager.
Used tskmgr to shut down IE. worked.

You got there in the end login.

For anyone who hasn't had the misfortune to be hit with this crazy situation of warnings popping up all over the screen, with what appears to be the good guys scanning your system with the offer of immediate help, there's one very important rule to follow. As mentioned by Tunerz above.

Do not click on anything:

The "cancel" buttons, and the red x "close window" buttons are usually spring loaded with links to other nasty stuff, or may even trigger the actual download of a virus.

Although not easy to do, stay calm and do two things in whichever order you find easiest.

Launch Task Manager with Ctrl+Alt+Del, scroll to your browser, highlight it, and select "End Task".

Disconnect your connection by whichever way you find easiest. Right click or double click your Internet icon in the system tray, and select "disconnect".

Or maybe via the "Start" button:

Posted Image

Lets hope you never have to do this, but make sure you know how to.

#17 ONLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 12 January 2009 - 07:14 PM

Thanks for listing the sites. They're now blocked on my end.
Complexity of incoherent design.

#18 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 12 January 2009 - 11:18 PM

Firefox with noscript stops those rogue sites cold.

Or if browsing sandboxed with scripts allowed globally you can right click Sandboxie's taskbar icon and terminate programs or delete contents will have the same effect.

#19 OFFLINE   login123

    blanko

  • Members
  • PipPipPipPip
  • 1,778 posts
  • Gender:Not Telling

Posted 13 January 2009 - 03:44 AM

View PostAndavari, on Jan 12 2009, 02:14 PM, said:

Thanks for listing the sites. They're now blocked on my end.

You're welcome, Andavari. The last trip gave 2 more:

http://new5scan.com/21/?uid=167\?uid=167
and when you close that, to
http://www.online-safe-way.com/

And a new installer file, called installer_00526.exe

Still no warnings are triggered from avast or A2, even though it installed.

Gonna sign out now. Would be glad to help or report more about it if need be.
The SLIM version is always released a bit after any new version; when it is it will be HERE :-)

#20 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 13 January 2009 - 04:06 AM

new5scan.com/21/?uid=167\?uid=167 seems dead atm.

Went to hxxp://www.online-safe-way.com/ and picked up an "installer_00001.exe" which installs Antivirus Plus which is another rogue.

Not too many are flagging the above installer so it must be a fairly new one and which I've uploaded to Malwarebytes.

Quote

File installer_00001.exe received on 01.13.2009 04:54:11 (CET)
Current status: finished
Result: 4/38 (10.53%)
Virus Total

Posted Image