Author Topic: Nasty Malware Going Around  (Read 9096 times)

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Nasty Malware Going Around
« on: September 09, 2009, 10:57:37 PM »
There is a nasty new rogueware out in the wild called AntiSpy Protector 2009.  There are also variants called PC_AntiSpyware2010 and Advanced Antivirus.  It is also known by the anti-malware companies by one of its common filenames, Braviax.exe.  Braviax has been out for a year or so, but this newest variant started appearing sometime last month.

Most rogues can usually be dealt with, but this one drops two extremely difficult to dig out rootkits on your system that kill almost all anti-malware processes and programs.  It will not allow any of the well known anti-malware programs to run after they have been installed.  It stops most file, service, or hidden process scans.  It prevents the use of almost all good anti-rootkit scanners.   It changes permissions on important system files, and generally causes havoc with your system.
If it pops up on your screen, just pull the plug on your PC.  Unlike most other rogues, this one has been known to self-install without any user intervention at all.  Granted, pulling the plug on your Windows machine can sometimes cause problems, but the misery caused by this bug is far worse.  It's much easier to deal with the aftereffects of an unexpected power down than it is to root out this malware.

I've dug out a lot of malware in my time, but this one is by far the worst I have ever encountered.  It took me four days of research to find a the tools and a process to dig this one out.  If you run across it, shoot me a message and I will pass on what I have learned.

Be careful out there.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

RaspberrySurprise

  • friend
  • Senior Member
  • ***
  • Posts: 2,020
  • Yub yub Commander
Re: Nasty Malware Going Around
« Reply #1 on: September 09, 2009, 11:10:59 PM »
This is why good backups are essential, because sometimes is far far easier to kill it with fire and just repartition, reformat, and reinstall.
Look, tiny text!

Standing Wolf

  • friend
  • Senior Member
  • ***
  • Posts: 2,978
Re: Nasty Malware Going Around
« Reply #2 on: September 09, 2009, 11:43:27 PM »
The gods be thanked the government is waging war against the people who write that stuff!
No tyrant should ever be allowed to die of natural causes.

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,593
Re: Nasty Malware Going Around
« Reply #3 on: September 09, 2009, 11:46:48 PM »
The gods be thanked the government is waging war against the people who write that stuff!

I'll sleep better tonight knowing that.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Re: Nasty Malware Going Around
« Reply #4 on: September 09, 2009, 11:54:51 PM »
This is why good backups are essential, because sometimes is far far easier to kill it with fire and just repartition, reformat, and reinstall.

Agreed, RaspberrySurprise.  I image every machine I have to a Windows Home Server box, so no problems there.
This one that I finally killed is on a customer's box.  No backups at all.  Of course we are going to have that discussion.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

Harold Tuttle

  • Professor Chromedome
  • friend
  • Senior Member
  • ***
  • Posts: 8,069
Re: Nasty Malware Going Around
« Reply #5 on: September 10, 2009, 12:59:53 AM »
I had some fun with "total Security" on my kids PC
once it was running it disabled IE, the task manager, symantic and spybot

i finally was able to taskmanager it off as it was starting, from a reboot, then use symantic to kill it off

"The true mad scientist does not make public appearances! He does not wear the "Hello, my name is.." badge!
He strikes from below like a viper or on high like a penny dropped from the tallest building around!
He only has one purpose--Do bad things to good people! Mit science! What good is science if no one gets hurt?!"

grislyatoms

  • friends
  • Senior Member
  • ***
  • Posts: 3,740
Re: Nasty Malware Going Around
« Reply #6 on: September 12, 2009, 08:19:43 PM »
I ran into this a couple of weeks ago. 4-5 machines. Would not allow any antivirus ware to even launch.

Had to nuke the drives and re-image. I concur, it's pretty nasty.
"A son of the sea, am I" Gordon Lightfoot

Silver Bullet

  • friend
  • Senior Member
  • ***
  • Posts: 1,859
Re: Nasty Malware Going Around
« Reply #7 on: September 12, 2009, 11:49:49 PM »
This is why good backups are essential, because sometimes is far far easier to kill it with fire and just repartition, reformat, and reinstall.

That, or use a Macintosh.

What the heck is malware, anyway ? 

Perd Hapley

  • Superstar of the Internet
  • friend
  • Senior Member
  • ***
  • Posts: 61,411
  • My prepositions are on/in
Re: Nasty Malware Going Around
« Reply #8 on: September 13, 2009, 12:01:36 AM »
It's something grown-up computers get.   :laugh:
"Doggies are angel babies!" -- my wife

Jim147

  • friends
  • Senior Member
  • ***
  • Posts: 7,593
Re: Nasty Malware Going Around
« Reply #9 on: September 13, 2009, 12:43:27 AM »

Quote
What the heck is malware, anyway ?
 

That would be the clothes mal wares. You know Firefly. I guess some people just don't like his taste in shirts if they have to call them nasty.

jim
Sometimes we carry more weight then we owe.
And sometimes goes on and on and on.

BAH-WEEP-GRAAAGHNAH WHEEP NI-NI BONG

MikeB

  • friend
  • Senior Member
  • ***
  • Posts: 924
Re: Nasty Malware Going Around
« Reply #10 on: September 13, 2009, 05:03:30 AM »
Combofix or Malwarebytes should work on these. If they don't, use Bitdefender rescue CD, run that, then run Combofix or Malwarebytes. The rescue cd will load a version of Knoppix and then run the antivirus against the hard disk, this prevents the rootkit from loading so it can be removed. I've used this method on this virus/malware. No need to nuke the drive.

For real bad infections I usually run all three. Combofix sometimes needs to be run twice to complete cleanup. If you can't load internet sites after cleanup you may need to reset the TCP/IP stack. Some of these infections inject a process into the stack, once it's removed by the anti-malware software internet won't work without resetting the stack.

Combofix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Malwarebytes
http://www.malwarebytes.org/

Bitdefender Linuxdefender rescue CD
http://download.bitdefender.com/rescue_cd/

How to reset TCP/IP stack
http://windowsxp.mvps.org/winsock.htm

lee n. field

  • friend
  • Senior Member
  • ***
  • Posts: 13,577
  • tinpot megalomaniac, Paulbot, hardware goon
Re: Nasty Malware Going Around
« Reply #11 on: September 13, 2009, 09:04:48 AM »
Quote
Combofix or Malwarebytes should work on these.

Assuming the malware will let them run.  A lot of them block processes now, which means they are basically impossible for Joe Enduser to deal with.

These day I usually end up pulling the drive, scanning on a clean computer with a good AV, and, Malwarebytes or Superantispyware.  Then and only then, put it back in the computer and scan with native apps.  Each pass finds new crap.

Oh, yeah.  Current home user grade Mcafee and Norton are worthless.
In thy presence is fulness of joy.
At thy right hand pleasures for evermore.

MechAg94

  • friend
  • Senior Member
  • ***
  • Posts: 33,745
Re: Nasty Malware Going Around
« Reply #12 on: September 13, 2009, 09:24:18 AM »
I think I had some version of this a few months ago.  None of the anti-virus or anti-malware programs would work on it.  They either would not install or would not update.  All the web sites for those programs were blocked. 

I ended up getting a SATA/USB adapter, pulled out the hard drive, and scanned it with my laptop with Norton and then with Malwarebytes.  Norton actually caught and cleaned most of it.  Malwarebytes found one more item.  When I put the hard drive back in, I was able to get my anti-virus updated along with a couple other programs.  No problems since then. 
“It is much more important to kill bad bills than to pass good ones.”  ― Calvin Coolidge

Monkeyleg

  • friend
  • Senior Member
  • ***
  • Posts: 14,589
  • Tattaglia is a pimp.
    • http://www.gunshopfinder.com
Re: Nasty Malware Going Around
« Reply #13 on: September 13, 2009, 09:30:30 AM »
I'm not sure if what I have is the same as what you folks are talking about. Yesterday a program installed itself, and keeps giving me a constant warning that my computer is affected. If I click on the icon, I get a promotion for Antivirus Pro 2010. It won't go away, and it wasn't there before.

It lets me run my programs, but it's still a pain in the neck.

I still haven't upgraded my OS, so maybe this is the time to do so.

Perd Hapley

  • Superstar of the Internet
  • friend
  • Senior Member
  • ***
  • Posts: 61,411
  • My prepositions are on/in
Re: Nasty Malware Going Around
« Reply #14 on: September 13, 2009, 10:59:01 AM »
Upgraded your OS from what?  If you haven't already done so, back up all of your important data, while you still can. 
"Doggies are angel babies!" -- my wife

Monkeyleg

  • friend
  • Senior Member
  • ***
  • Posts: 14,589
  • Tattaglia is a pimp.
    • http://www.gunshopfinder.com
Re: Nasty Malware Going Around
« Reply #15 on: September 13, 2009, 01:41:12 PM »
My old laptop runs Windows 2000. I only need it for one very simple purpose, so I haven't bothered to change operating systems. Somewhere around here I have Windows XP.

Silver Bullet

  • friend
  • Senior Member
  • ***
  • Posts: 1,859
Re: Nasty Malware Going Around
« Reply #16 on: September 13, 2009, 02:41:17 PM »
It's something grown-up computers get.   :laugh:


  =D

Guess I'll keep using my iBrat.   =)

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Re: Nasty Malware Going Around
« Reply #17 on: September 13, 2009, 06:16:16 PM »
I'm not sure if what I have is the same as what you folks are talking about. Yesterday a program installed itself, and keeps giving me a constant warning that my computer is affected. If I click on the icon, I get a promotion for Antivirus Pro 2010. It won't go away, and it wasn't there before.

It lets me run my programs, but it's still a pain in the neck.

I still haven't upgraded my OS, so maybe this is the time to do so.

Sorry Dick, but you have the bug I was referring to.  One of its names is Antivirus Pro 2010.
The rootkit pair that does most of the nastiness will not let any of the usual disinfection tools run.  That includes ComboFix (not a tool for the faint of heart, btw) and Malwarebytes.
Pulling the drive and scanning it on another computer will not kill the rootkits.  They are still present and active when the drive is placed back in the original computer and booted.
The rootkit files themselves are not visible to Windows or in a DOS box.  Attempting to change their attributes does nothing to make them visible in most instances, although some have reported success with that. 
Some rootkit scanners like rootkitrepeal will show them, but cannot kill them.  The filenames are win32k.sys:1 and win32k.sys:2, if I remember correctly.  Not to be confused with the normal win32k.sys file that is part of Windows.  I need to go back to my notes to remember for sure.
You need to take care of it.  One of its reported actions is a keylogger that captures passwords and such.
Unfortunately, I think this bug is going to bring a lot of business my way.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

Gewehr98

  • friend
  • Senior Member
  • ***
  • Posts: 11,010
  • Yee-haa!
    • Neural Misfires (Blog)
Re: Nasty Malware Going Around
« Reply #18 on: September 13, 2009, 07:11:04 PM »
Dust off and nuke it from orbit.
"Bother", said Pooh, as he chambered another round...

http://neuralmisfires.blogspot.com

"Never squat with your spurs on!"

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Re: Nasty Malware Going Around
« Reply #19 on: September 13, 2009, 07:32:22 PM »
Dust off and nuke it from orbit.

While the infection can be cured, it does take a fair amount of work.  It may be simpler to do just what GW suggests if all backups are up to date.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

Silver Bullet

  • friend
  • Senior Member
  • ***
  • Posts: 1,859
Re: Nasty Malware Going Around
« Reply #20 on: September 13, 2009, 07:32:55 PM »
 

That would be the clothes mal wares. You know Firefly. I guess some people just don't like his taste in shirts if they have to call them nasty.

jim

That would be, "What the heck does malware, anyway ?"

 :police:

BryanP

  • friendly hermit
  • friend
  • Senior Member
  • ***
  • Posts: 2,808
Re: Nasty Malware Going Around
« Reply #21 on: September 13, 2009, 07:41:43 PM »

Bitdefender Linuxdefender rescue CD
http://download.bitdefender.com/rescue_cd/


I've found this one to be extremely useful.  It boots a Knoppix environment and if it can detect an internet connection it will download the most recent patterns for BitDefender before it starts scanning your machine.
"Inaccurately attributed quotes are the bane of the internet" - Abraham Lincoln

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Re: Nasty Malware Going Around
« Reply #22 on: September 13, 2009, 07:46:04 PM »
I've found this one to be extremely useful.  It boots a Knoppix environment and if it can detect an internet connection it will download the most recent patterns for BitDefender before it starts scanning your machine.

I use BitDefender on most of my machines, but I have not heard of their rescue CD.  I'll have to give it a try.
Thanks for the info, BryanP.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.

MikeB

  • friend
  • Senior Member
  • ***
  • Posts: 924
Re: Nasty Malware Going Around
« Reply #23 on: September 13, 2009, 08:42:43 PM »
Assuming the malware will let them run.  A lot of them block processes now, which means they are basically impossible for Joe Enduser to deal with.

These day I usually end up pulling the drive, scanning on a clean computer with a good AV, and, Malwarebytes or Superantispyware.  Then and only then, put it back in the computer and scan with native apps.  Each pass finds new crap.

Hence the reason for the whole paragraph I had written.

Quote
Combofix or Malwarebytes should work on these. If they don't, use Bitdefender rescue CD, run that, then run Combofix or Malwarebytes. The rescue cd will load a version of Knoppix and then run the antivirus against the hard disk, this prevents the rootkit from loading so it can be removed. I've used this method on this virus/malware. No need to nuke the drive.

Especially the bold part, which apparently skipped when writing your response.

Booting off a linux live cd and running the scan is the same as running the scan on another computer. As well if someone found the virus a few days ago, there is a decent chance combofix or malwarebytes has a new definition file.

RocketMan

  • Mad Rocket Scientist
  • friend
  • Senior Member
  • ***
  • Posts: 13,622
  • Semper Fidelis
Re: Nasty Malware Going Around
« Reply #24 on: September 13, 2009, 08:49:56 PM »
Mike, your statement presumes that the BitDefender rescue CD is even keyed to find and delete those particular rootkit files.  It may not be.
If there really was intelligent life on other planets, we'd be sending them foreign aid.

Conservatives see George Orwell's "1984" as a cautionary tale.  Progressives view it as a "how to" manual.

My wife often says to me, "You are evil and must be destroyed." She may be right.

Liberals believe one should never let reason, logic and facts get in the way of a good emotional argument.