09-25-2011 07:35 AM
If I understood you right, this can be the sign of the new protection flaw(dead anti-rootkit) in NIS/NAV '12.Because it can't hook that function and therefore can't query the not fake information about those files.
Slightly not the same...
As written earlier:
All files taken to further analyse are gathered via typical Explorer.exe - may be real atapi.sys or svchost.exe was hiden from direct access and instead of them rootkit has given clean files to cover infection fact?
and (as written earlier also)
infected computer have no internet connection at all. on my works it is strongly restricted. I just copied (via typical Explorer) all the files (XP drivers folder) svchost.exe, soundman.exe (RealTek sound driver console) to my USB stick and bring this to home computer and start to analyse them... they are all Norton Trused.
offtopic: found that there are 2 types of Norton Trusted files:
1) fully trusted well-known files from well-known vendor
2) and only whitelisted files, for example: earlier having wrong false positive detection, analyzed and for now having not known malware activity (nearest example - LibreOffice files detection as malware by Norton, solved by Symantec several weeks ago, as they said).
They are all Norton Trusted with full three green bars in File Insight window. Now I know how to distinguish one Norton Trusted type from other.
09-25-2011
07:38 AM
- last edited on
09-25-2011
09:56 AM
by
shannons
Hitman Pro use another AV engines for detection, Can you show Hitman Pro results for these files?
Yes! I can do it again and again:
How many times to post this? May be one more time?
Suspicous.Curcus.2Fun!
Let's get started the topic again with the next message! Let's anybody post: What is your problem? Do you have any snapshots of that?
[edit: Please keep post content courteous per the Participation Guidelines and Terms of Service.]
09-25-2011 07:55 AM
Niko233 wrote:Hitman Pro use another AV engines for detection, Can you show Hitman Pro results for these files?
Yes! I can do it again and again:
You are very kindly ![]()
But can you try another AV vendors? For example, Kaspersky Virus removal tool and CureIt from DrWeb?
I'm interesting in the name of this rootkit
09-25-2011 08:53 AM - edited 09-25-2011 08:54 AM
You are very kindly ![]()
Bulbulator, but why to ask to post for prev. posted info?
I only can not undestand you and others who done that and you are not alone in this :)
will see, can not promise that. On that computer work another new man, who was taken to the work. Kaspersky Virus removal tool and CureIt from DrWeb are taking too long to scan and too many system resources - probably they can not be executed while computer as busy by him. Let I tell you RAM size: 512 MB. :))))) Processor is not very slow: Intel Pentium 4 3.06 GHz. OS: WinXP with unknown to me SP (2 or 3).
Anything else not so heavy tools and/or any methods?
09-25-2011 01:51 PM - edited 09-25-2011 01:57 PM
At this point you can try use of TDSSKiller which is good against unknown rootkits/bootkits as well as against Rootkit.Win32.TDSS. Also you could try GMER which is one of the best solutions against rootkits nowadays. Those tools are not use a lot of system resources and scan pretty quick.
http://support.kaspersky.com/faq/?qid=208283363 - TDSSKiller (latest version)
http://www.gmer.net/ - GMER site.
09-25-2011 02:09 PM - edited 09-25-2011 02:26 PM
Thanks, will try as well as Webroot ZeroAccess Remover 0.8.0.1. GMER is already used as you can see by snapshots (but that it can here? just).
Will see, may be this stuff can be detected with updated virus definitions... who knows ![]()
---
May be to add an additional offline scan mode into Norton Power Eraser for advanced users for example?
How to detect malware if right now there is no internet connection or it blocked/disabled by malware?
09-27-2011 10:58 AM - edited 09-27-2011 11:07 AM
Today I came to ofiice and saw that there is no Norton on the machine, and there is Kaspersky 6.0 (released in 2007 year as I know) on the machine. Norton was uninstalled from that machine, as expected :)) Norton have no good reputation in malware detection in our company. All machines have Kaspersky AV, only on my desktop I install Norton ;))). Probably only for some time.
I brought some files from infected computer on the work to the home computer, now copied with GMER and that we have:
TDSS tool
all 5 of 6 is Norton Trusted. VT:
and sptd.sys - not:
VT on sptd.sys:
AntiZeroAccess:
Four red-lighted files kl*.sys are Kaspersly Labs files, all signed and all Norton Trusted (only 1 snap for example):
Webroot AntiZeroAccess 0.8 Log File
Execution time: 27/09/2011 - 18:50
Host operation System: Windows Xp X86 version 5.1.2600 Service Pack 2
18:50:55 - CheckSystem - Begin to check system...
18:50:55 - OpenRootDrive - Opening system root volume and physical drive....
18:50:55 - C Root Drive: Disk number: 0 Start sector: 0x0000003F Partition Size: 0x01483B3C sectors.
18:50:55 - PrevX Main driver extracted in "C:\WINDOWS\system32\drivers\ZeroAccess.sys".
18:50:55 - InstallAndStartDriver - Main driver was installed and now is running.
18:50:55 - CheckSystem - Disk class driver state is OK.
18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5
18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5
18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5
18:50:56 - CheckFile - Unable to send FSCTL_GET_RETRIEVAL_POINTERS to file object. DeviceIoControl last error: 5
18:50:57 - CheckFile - Unable to read "sptd.sys" file. CreateFile last eror: 0x00000020.
18:50:57 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed.
18:50:57 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted!
18:50:57 - Execution Ended!
:)))))) no info... what is that - fresh Norton 2012, very old Kaspersky, newest TDSS killer, AntiZeroAccess do not knows...
HitmanPro and GMER can not find any infections in file structure or there is something not so ordinary. As I said earlier - I need tactics to collect sample(s) - steps sequence - what to do, step by step...
09-27-2011 03:19 PM - edited 09-27-2011 03:25 PM
TDSSKiller just showed a bunch of files without digital signature. If you are afraid about the PC security and still think they are malware/ or you are experiencing some strange behavior just quarantine those files via TDSSKiller and after that: compress C:\TDSSKiller_quarantine folder using WinRar / Winzip with password infected, and send this archive to newvirus@kaspersky.com. After 24 hours you will see the result of file analysis by someone from Kaspersky VirLab Team.
sptd.sys just Daemon Tools Optical Disk virtualization service.
kl1.sys(Kaspersky Unified Driver), klif.sys(Klif mini-filter driver), klim5.sys(Kaspersky Intermediate Network driver), klfltdev.sys( KLFLTDEV Pnp device filter driver). If that machine doesn't have Kaspersky installed then just uninstall the product using http://support.kaspersky.com/faq/?qid=208279463 KB article.
09-27-2011 03:45 PM - edited 09-27-2011 03:46 PM
TDSSKiller just showed a bunch of files without digital signature.
they are Norton Trusted except sptd.sys. also they was uploded to VT service, non of theme are malware.
sptd.sys just Daemon Tools Optical Disk virtualization service.
or Alcohol 120/50% program.
If that machine doesn't have Kaspersky installed
> quote:"Today I came to ofiice and saw that there is no Norton on the machine, and there is Kaspersky 6.0 (released in 2007 year as I know) on the machine."
It have KAV 6.0.
So, all was false positives of GMER and HitmanPro? Can Symantec help?
09-28-2011 01:00 AM
1. KAV 6.0 is the latest release for business customers(KAV 6.0 for Workstations MP4).
2. They're not false-positives. GMER and Hitman-Pro just noticed the unusual case: drivers in which digital signature can't be verified. In some cases it could be the indication of system infection(like file-infection by some file infector like Virut or Sality etc) but in your case these files seems to be non malicious, maybe they're installed from non-genuine Windows installation package.
3. If you have any further concerns of system infection, just post them on http://virusinfo.info in 'Help me' section.
