Browser Hijacking - Why Can't Norton fix these?

UncleWillie:

 

If you do have a Gen 3 rootkit, and you continue to fool with it, you may actually manage to remove the infected file.  If that happens, you will no longer be able to access your computer. 

 

In your IE go to tools> Internet Options>History>delete

 

In FF go to tools>clear recent history>all

 

For prefetch go to My Computer>C:>Windows>prefetch.  These files let your computer find things faster, but it won't hurt anything to get rid of them.  They will rebuild.  Leave the boot folder be.

 

For temp files Go to My Computer>C;>Windows>Temp Delete what you can.  Not all of them will delete probably.

 

Doing that won't hurt anything.

 

I don't think it shows on GMER but if you want to try it:  Scan only!

 

http://www.gmer.net/

After it is downloaded to your desktop, right click on the icon, run as admin.  Uncheck all but services, history and files.  It may cause a blue screen.  If so, try again in safe mode.  You will need to save the log to Notepad.

Message Edited by delphinium on 12-08-2009 08:37 PM

"I don't think it shows on GMER but if you want to try it:"

 

It depends on the Gen 3 in question.

 

I actually enjoyed infecting my PC with a Gen 3, testing to see which scanner found the one I had ( if any) then I removed it.

 

 

Quads 

Getting ready to run GMER.  When it starts up, it lists a ble c:\WINDOWS\system32\drivers\atapi.sys      suspiscious modification

 

Now I will scan...

Delphinium, I don't see "history" as an option in GMER.  It has System, Sections, IAT/EAT, Devices, Modules, Processes, Threads, Libraries, Services, Registry and Files. 

 

Willie

UncleWillie wrote:

Delphinium, I don't see "history" as an option in GMER.  It has System, Sections, IAT/EAT, Devices, Modules, Processes, Threads, Libraries, Services, Registry and Files. 

 

Willie

I think she was referring to "registry".

OK, thanks.  I will run the GMER scan thsis evening as my wife has the laptop.

 

BTW, I noticed on another PC that I got a ton of Windows XP security updates today.

 

Willie

Good morning Uncle Willie.  I'm glad to see you are still with us.  I would ask you to do one little thing.  When you have the laptop back, go into the computer pane>settings> scroll down to Exclusions >configure and add atapi.sys to both the scan exclusions and to auto protect exclusions.

 

Unfortunately, the GMER mention of atapi.sys pretty much confirms that you do have a rootkit active on that machine.  If your wife is still using the laptop, it is extremely insecure.  There should be no banking done, or credit card purchases, or sensitive information transmitted.  You will need to change all passwords for this type of usage.

 

Oracles have long been noted as the bearers of bad news. :smileywink:

 

I will give you the names of a couple of malware removal sites, where they have the tools and know-how to assist you in the safe removal. Save all of the data that is important on the laptop, first thing.  The removal is a risky business.

 

www.bleepingcomputer.com


http://www.geekstogo.com/forum/

 

Get back to us if you can and let us know how it goes for you.

Hi Uncle Willie

 

When you go to these sites for help, please remember to ask any questions you have before you try a process or scan that they tell you to do. It is always better to ask to clarify something than to wait till after when it may be too late. Good luck.

Delphinium, My wife drove to the office with the scan still running, but I did not have "registry" checked.  Good thing I got her that new heavy duty battery! As soon as I saw the strang pop-ups I told her no bankig or credit card transactions. I will also check those removal sites.  I didn't quie understand "computer pane>settings> scroll down to Exclusions >configure
and add atapi.sys to both the scan exclusions and to auto protect
exclusions."  Is that from inside NIS?  Thanks.

 

I will ask her to rescan with "registry" checked.  FWIW, here is the output of the GMER scan with  services, system and files chosen:

 

GMER 1.0.15.15273 - http://www.gmer.net

Rootkit scan 2009-12-09 10:23:37
Windows 5.1.2600 Service Pack 3
Running: 2gb4ssq1.exe; Driver: C:\DOCUME~1\MA\LOCALS~1\Temp\fgtdypob.sys

 

---- System - GMER 1.0.15 ----

SSDT  8A035E80    ZwAlertResumeThread
SSDT  8A2E80E8    ZwAlertThread
SSDT  8A49E0C0    ZwAllocateVirtualMemory
SSDT  89E38100      ZwAssignProcessToJobObject
SSDT  89200460      ZwConnectPort
SSDT  \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)                     ZwCreateKey [0xA4283210]
SSDT  8A0B6C28   ZwCreateMutant
SSDT  89EA28C0   ZwCreateSymbolicLinkObject
SSDT  89F6DC60   ZwCreateThread
SSDT  89E380C8    ZwDebugActiveProcess
SSDT  \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)                     ZwDeleteKey [0xA4283490]
SSDT  \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)                     ZwDeleteValueKey [0xA42839F0]

SSDT  8A301948   ZwDuplicateObject
SSDT  8A0F8E58  ZwFreeVirtualMemory
SSDT  8A3C9440  ZwImpersonateAnonymousToken
SSDT  8A321100   ZwImpersonateThread
SSDT  891DB830  ZwLoadDriver
SSDT  89F3AC00  ZwMapViewOfSection
SSDT  8A304A48  ZwOpenEvent
SSDT  \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)                     ZwOpenKey [0xA42837A0]
SSDT  8A49C538  ZwOpenProcess
SSDT  8A096E60  ZwOpenProcessToken
SSDT  89E37158   ZwOpenSection
SSDT  8A30C308  ZwOpenThread
SSDT  8A0F8F78  ZwProtectVirtualMemory
SSDT  8A169A98  ZwResumeThread
SSDT  89EEDCF0 ZwSetContextThread
SSDT  8A0CAE08 ZwSetInformationProcess
SSDT  89E37660    ZwSetSystemInformation
SSDT  \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)                     ZwSetValueKey [0xA4283C40]
SSDT  8A10DD60  ZwSuspendProcess
SSDT  89E37C58                                                                                                       ZwSuspendThread
SSDT  \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com)  ZwTerminateProcess [0x9D9370B0]
SSDT  89E33A30    ZwTerminateThread
SSDT  89F05BA0    ZwUnmapViewOfSection
SSDT  89E339E0     ZwWriteVirtualMemory

---- EOF - GMER 1.0.15 ----

Hi delphinium:

 

Two questions -

 

1) How do you know that atapi.sys is actually compromised?

 

2) How did NIS 2010 let it get infected? (New generation of Rootkit not detected yet by NIS?)

 

Curious... thanks.

Message Edited by Plankton on 12-09-2009 11:56 AM

Plankton, For #2, My wife's PC was running McAfee when it got infected, not NIS.  NIS was installed after the fact to try to fix the problem.So that question would have to go to a McAfee board.  :) Although it is disappointing that Nortion can't detect it after the fact.  :(

 

Willie

Hi UncleWillie:

 

All these threats are getting so sophisticated, that it may not be possible to pin it on a particular product.

 

Thanks for the info!

Just for info.  Antivirus software is extremely sticky.  It has to be that way.  So if you just removed McAfee from the computer using Add/Remove, you would not have removed it completely.  Each antivirus has its own removal tool.  That kind of thing interferes with the correct operation of the newly installed antivirus, no matter whose it is.

 

Second, rootkits come with their own list of antivirus names and sites to block.  This prevents many products from accessing updates, their own websites, and prevents you from accessing, downloading and running products that could interfere with the rootkit.

 

Thirdly, downloading an antivirus into a severely infected machine, corrupts the installation, and prevents it from doing what it is supposed to do.  So try not to think too badly of Norton, it never had a chance.

 

 The 2010 antivirus engines have cut down the number of rootkit infections to almost nothing on this forum.  The problem is that the malware writers have had to get more creative in their bid to infect machines.  The malware always comes out first.  Once it is discovered, Symantec takes it apart and writes changes into their product to block the attacks. Then it begins again.  This is very sophisticated malware, frequently acquired by a careless click of the mouse in the wrong place.

 

Sorry, yes.  The settings are in the main screen for Norton.  The top pane is the computer, settings you will find on the right side.

 

 

Message Edited by delphinium on 12-09-2009 09:37 AM

Gen 3 and GMER, if GMER is able to show it should show up for one in the "devices" section, so no point in just scanning the "services", "registry" .......................,

 

UncleWillie stated further up

 

 


Getting ready to run GMER.  When it starts up, it lists a ble c:\WINDOWS\system32\drivers\atapi.sys      suspiscious modification
Which sounds like Gen3 (TDL3) that's why it has, in this case luck enough appeared.

 

 

Quads 

 

 

Delphinium, 

1) I did use McAfee uninstall.

2) Thankfully access to the Norton website has not been blocked and it was able to download updates.

3) True, but I also tried booting from the CD, downloading updates and running a scan.  That didn't find anything either. 

 

Microsoft released a bunch of drive-by security updates today, including a modified version of MRT.exe.  Unfortunatly they came a couple of weeks to late from my wife's laptop.

 

http://blogs.zdnet.com/security/?p=5096&tag=nl.e539

 

Will Windows 7 be any better?

 

Willie

 

Hi Delphinium:

 

How do you know that atapi.sys is actually compromised?

 

Didn't get your answer on this one just yet.

 

Thanks.

Maybe I am a cynic, but I don't believe there will ever be anything developed that some other individual can not find holes to take advantage of.  There will always be browser vulnerabilities, program vulnerabilities, and errors in judgment.

 

Security is composed of patching software vulnerabilities, such as in Java, MS Office, Windows, Adobe, and a multitude of others.  It also depends on the things we do, such as P2P, file sharing, torrents, Facebook, etc.  The more popular the site, the more likely malware will be inserted.  There is no point in placing your malware in a place where nobody goes.

 

Doubling up on real-time antivirus scanners is problematic, and many of the rootkit infections we have seen here were on machines with more than one active antivirus engine.

 

In the end, no matter how careful and prudent we are, sooner or later, we will get infected.  It is good to know what to do about it and where to go for help. Malware is now a fact of internet usage and as unavoidable as death and taxes.

Plankton:

 

Regarding your question:

 

We are forced to deal with indications with these infections.  If you read the articles provided by Voyager 10, and Quads's posts, it will help you.  It is simply one of the files that the rootkit over-writes.  It is not necessarily the only one, but if you notice, the OP did say that it showed in GMER.

Hi delphinium:

 

Understood.

 

I will take a look at this more deeply, as it is of great interest to me.

 

Thanks for the reply!


delphinium wrote:

 ... the OP did say that it showed in GMER.


What does "showed" mean here?  Doesn't GMER list a lot of things, not just infected entries and files?