Reply
Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

If I understood you right, this can be the sign of the new protection flaw(dead anti-rootkit) in NIS/NAV '12.Because it can't hook that function and therefore can't query the not fake information about those files.

 

Slightly not the same...

As written earlier:

All files taken to further analyse are gathered via typical Explorer.exe - may be real atapi.sys or svchost.exe was hiden from direct access and instead of them rootkit has given clean files to cover infection fact?

and (as written earlier also)

infected computer have no internet connection at all. on my works it is strongly restricted. I just copied (via typical Explorer) all the files (XP drivers folder) svchost.exe, soundman.exe (RealTek sound driver console) to my USB stick and bring this to home computer and start to analyse them... they are all Norton Trused.

 

offtopic: found that there are 2 types of Norton Trusted files:

1) fully trusted well-known files from well-known vendor

2) and only whitelisted files, for example: earlier having wrong false positive detection, analyzed and for now having not known malware activity (nearest example - LibreOffice files detection as malware by Norton, solved by Symantec several weeks ago, as they said).

They are all Norton Trusted with full three green bars in File Insight window. Now I know how to distinguish one Norton Trusted type from other.

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

Hitman Pro use another AV engines for detection, Can you show Hitman Pro results for these files?

 

Yes! I can do it again and again:

 

 

 

 

 

 

 

How many times to post this? May be one more time?

Suspicous.Curcus.2Fun!

 

Let's get started the topic again with the next message! Let's anybody post: What is your problem? Do you have any snapshots of that?

 

 

[edit: Please keep post content courteous per the Participation Guidelines and Terms of Service.]

Regular Contributor
Bulbulator
Posts: 105
Registered: ‎09-08-2009

Re: 19.1.0.28: undetected rootkit sample suggestion offer


Niko233 wrote:

Hitman Pro use another AV engines for detection, Can you show Hitman Pro results for these files?

 

Yes! I can do it again and again:


You are very kindly :smileyhappy:

But can you try another AV vendors? For example, Kaspersky Virus removal tool and CureIt from DrWeb?

I'm interesting in the name of this rootkit

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

You are very kindly :smileyhappy:

 

Bulbulator, but why to ask to post for prev. posted info? :smileyhappy: :smileywink: I only can not undestand you and others who done that and you are not alone in this :)

 

will see, can not promise that. On that computer work another new man, who was taken to the work. Kaspersky Virus removal tool and CureIt from DrWeb are taking too long to scan and too many system resources - probably they can not be executed while computer as busy by him. Let I tell you RAM size: 512 MB. :))))) Processor is not very slow: Intel Pentium 4 3.06 GHz. OS: WinXP with unknown to me SP (2 or 3).

 

Anything else not so heavy tools and/or any methods? 

Nerimash
Posts: 220
Topics: 20
Kudos: 24
Solutions: 4
Registered: ‎02-25-2011

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

At this point you can try use of TDSSKiller which is good against unknown rootkits/bootkits as well as against Rootkit.Win32.TDSS. Also you could try GMER which is one of the best solutions against rootkits nowadays. Those tools are not use a lot of system resources and scan pretty quick.

 

http://support.kaspersky.com/faq/?qid=208283363 - TDSSKiller (latest version)

http://www.gmer.net/ - GMER site.

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

Thanks, will try as well as Webroot ZeroAccess Remover 0.8.0.1. GMER is already used as you can see by snapshots (but that it can here? just).

Will see, may be this stuff can be detected with updated virus definitions... who knows :smileywink:

 

---

May be to add an additional offline scan mode into Norton Power Eraser for advanced users for example?

How to detect malware if right now there is no internet connection or it blocked/disabled by malware?

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

Today I came to ofiice and saw that there is no Norton on the machine, and there is Kaspersky 6.0 (released in 2007 year as I know) on the machine. Norton was uninstalled from that machine, as expected :)) Norton have no good reputation in malware detection in our company. All machines have Kaspersky AV, only on my desktop I install Norton ;))). Probably only for some time.

 

I brought some files from infected computer on the work to the home computer, now copied with GMER and that we have:

 

u.PNG

 

 u.PNG

 

 u.PNG

 

 u.PNG

 

 TDSS tool

 

u.PNG

 

 

 

all 5 of 6 is Norton Trusted. VT:

 

http://www.virustotal.com/file-scan/report.html?id=35a9b96298a6814b1af90c3e46f1230e3d5a4c9939fc8add1...

 

http://www.virustotal.com/file-scan/report.html?id=b40e1f02d2467805b2962a797bc743924ddbce2c03339c480...

 

http://www.virustotal.com/file-scan/report.html?id=c2e885192672df6c99f4be3598f26a9a5479a040a7675c7b7...

 

http://www.virustotal.com/file-scan/report.html?id=2485243b79697df31db01e5415bed8eff00c23cfa666871f2...

 

http://www.virustotal.com/file-scan/report.html?id=1bcab42b1fe4ec996dcb48dcdb66e57a6d589a330e2cbefce...

 

and sptd.sys - not:

 

u.PNG

 

 VT on sptd.sys:

  http://www.virustotal.com/file-scan/report.html?id=af3df0def023adbc81d742424b57581d7680fa4fa64b761be...

 

 AntiZeroAccess:

 

01.png

 

 02.png

 

 03.png

 

 04.png

 

 Four red-lighted files kl*.sys are Kaspersly Labs files, all signed and all Norton Trusted (only 1 snap for example):

  u.PNG

 

 Webroot AntiZeroAccess 0.8 Log File

 

Execution time: 27/09/2011 - 18:50

Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2

18:50:55 - CheckSystem - Begin to check system...

18:50:55 - OpenRootDrive - Opening system root volume and physical drive....

18:50:55 - C Root Drive: Disk number: 0  Start sector: 0x0000003F   Partition Size: 0x01483B3C sectors.

18:50:55 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAccess.sys".

18:50:55 - InstallAndStartDriver - Main driver was installed and now is running.

18:50:55 - CheckSystem - Disk class driver state is OK.

18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5

18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5

18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5

18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5

18:50:57 - CheckFile - Unable to read "sptd.sys" file. CreateFile last eror: 0x00000020.

18:50:57 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed.

18:50:57 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted!

18:50:57 - Execution Ended!

 

:)))))) no info... what is that - fresh Norton 2012, very old Kaspersky, newest TDSS killer, AntiZeroAccess do not knows...

HitmanPro and GMER can not find any infections in file structure or there is something not so ordinary. As I said earlier - I need tactics to collect sample(s) - steps sequence - what to do, step by step...

Nerimash
Posts: 220
Topics: 20
Kudos: 24
Solutions: 4
Registered: ‎02-25-2011

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

TDSSKiller just showed a bunch of files without digital signature. If you are afraid about the PC security and still think they are malware/ or you are experiencing some strange behavior just quarantine those files via TDSSKiller and after that: compress C:\TDSSKiller_quarantine folder using WinRar / Winzip with password infected, and send this archive to newvirus@kaspersky.com. After 24 hours you will see the result of file analysis  by someone from Kaspersky VirLab Team.

 

sptd.sys just Daemon Tools Optical Disk virtualization service.

 

 

kl1.sys(Kaspersky Unified Driver), klif.sys(Klif mini-filter driver), klim5.sys(Kaspersky Intermediate Network driver), klfltdev.sys( KLFLTDEV Pnp device filter driver). If that machine doesn't have Kaspersky installed then just uninstall the product using http://support.kaspersky.com/faq/?qid=208279463 KB article.

Regular Contributor
Niko233
Posts: 765
Registered: ‎06-25-2010

Re: 19.1.0.28: undetected rootkit sample suggestion offer

[ Edited ]

TDSSKiller just showed a bunch of files without digital signature.

they are Norton Trusted except sptd.sys. also they was uploded to VT service, non of theme are malware.

 

sptd.sys just Daemon Tools Optical Disk virtualization service.

or Alcohol 120/50% program.

 

If that machine doesn't have Kaspersky installed

> quote:"Today I came to ofiice and saw that there is no Norton on the machine, and there is Kaspersky 6.0 (released in 2007 year as I know) on the machine."

It have KAV 6.0.

 

So, all was false positives of GMER and HitmanPro? Can Symantec help?

Nerimash
Posts: 220
Topics: 20
Kudos: 24
Solutions: 4
Registered: ‎02-25-2011

Re: 19.1.0.28: undetected rootkit sample suggestion offer

1. KAV 6.0 is the latest release for business customers(KAV 6.0 for Workstations MP4).

 

2. They're not false-positives. GMER and Hitman-Pro just noticed the unusual case: drivers in which digital signature can't be verified. In some cases it could be the indication of system infection(like file-infection by some file infector like Virut or Sality etc) but in your case these files seems to be non malicious, maybe they're installed from non-genuine Windows installation package.

 

3. If you have any further concerns of system infection, just post them on http://virusinfo.info in 'Help me' section.