Browser Hijacking - Why Can't Norton fix these?

The above blog version used is one of the earlier versions.

 

Here is a GMER log showing the TDL3  atapi.sys suspicious modification entry of a later version

 


GMER 1.0.15.15252 - http://www.gmer.net

Rootkit scan 2009-12-03 16:21:49

Windows 5.1.2600 Service Pack 3

Running: zioycjt9.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kwwyyaob.sys

 

Shortened to fit by Quads  

 

---- Devices - GMER 1.0.15 ----

 

AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                             SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                            SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                            SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                          SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

AttachedDevice  \FileSystem\Fastfat \Fat                                                                                             fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

 

Device           -> \Driver\atapi \Device\Harddisk0\DR0                                                                              84A8D618

 

---- Files - GMER 1.0.15 ----

 

File            C:\WINDOWS\system32\drivers\atapi.sys                                                                                suspicious modification

 

---- EOF - GMER 1.0.15 ----

 



Borrowed from another thread.

 

The Version of TDL3 I played with didn't even show that. 

 

Quads 

 

 

Well, this morning I woke up and fired up the laptop.  Strange because I went to bed with superantispyware running a scan and the PC had shut itself down for some reason.

 

Anyway, I fired up IE, went to Google, did a search on "browser hijack." I clicked on a link to www.microsoft.com and it took me to www.sanuga.com and then opened a  window a degrees.classesusa.com.  So, I told Microsoft to reopen the case.

 

I do "get it" about TDL3 and atapi.sys, but I figure if Microsoft is willing to offer free tech support I am going to take them up on it.  

 

Looks like Windows Automatic updates was just able to download the December 2009 update of MRT.EXE.  Funny, because the browser based update wasn't working last night.  MRT just identified some malicious software and removed it.  Now it is running a full system scan.  


I just tried Windows Update and it is now working.  I am downloading the High Priority update for Windows XP which fixes some of the security vulnerabilities. 

What we've found is that scans will remove assorted malware as it arrives.  The main job of the rootkit is download whatever malware is required for it to do its work of transmitting your personal information.  You will continue to get redirects, keyloggers, trojans, and other nasties.  The scans will not remove the rootkit.  If some scan removes the atapi.sys, or corrupts it, you will end up in a blue screen boot-reboot loop.

 

The malware removal forums are also free. :smileywink:


UncleWillie wrote:
... I figure if Microsoft is willing to offer free tech support I am going to take them up on it.  ....
 

I don't know.

 

If my car had a bad starter and the local clinic was offering free mammograms ...

 

Anyway, we do sincerely hope for the best for you.  And if MS actually really fixes the problem, please, please let us know.

"If my car had a bad starter and the local clinic was offering free mammograms"  :smileyvery-happy:

 

With the TDL3 I placed with,  (second time around I was successful in causing a BSOD boot loop) Even some programs specially created for detecting TDL3 and repairing the driver did NOT detect my variant.

 

On uploading "atapi.sys" to virustotal, and getting it scanned by the 40 engines everyone can guess the detection results.

 

http://www.virustotal.com/analisis/b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9-1260319831

 

The 1 that did generically detect the file could be dangerous as it would probably delete "atapi.sys"    :smileysad:

 

 

Quads 

Hi

 

This goes to show you that these rootkits are continuously changing and the cure has to be customized for the individual's computer and has to constantly monitoring the computer for changes as the fixes are being worked out. From what limited knowledge I have about these things, there isn't going to be possible to actually have a program set up that can actually clean the machine and at the same time fix the machine so it can continue to be working. As soon as a fix comes out, it's already been changed and is out of date. I don't think it would be possible for a antivirus program to be able to fix a rootkit that affects such critical components of a computer because the fix doesn't just have to take out the bad files, but has to be able to replace them with the right files and clean ones. From my limited knowledge, that seems to have to be done on a 1 to 1 basis with close cooperation between the user and the fixer.

 

I hope I haven't got off topic with this comment.

floplot, so then the question becomes, is it worth it to even try and fix, or do you just punt and re-install the OS?  Will a reinstall fix the problem, or would it require wiping the hard drive completely? 

 

I would probably opt to reinstall, but I don't think the laptop came with the OS media.

 

Willie

It's just a matter of carefully swapping the driver over

 

Quads 

Hi UncleWillie:

 

Been watching this thread... and floplot's post above has merit.

 

As you can plainly see, some Rootkits can be kind of devestating. :smileysad:

 

I am not really a fan of reloading, but of backing up the whole system on a daily basis, called a bare metal backup.

 

It probably makes sense to reload, if this can't be brought to a successful conclusion in the very near future. I understand that you might not have the original System Software, which could be a real pain, but not insurmountable. What I am concerned about the most is the integrity of you existing data and if it could be moved onto another system which has NIS 2010 fully updated, or online.

 

You might wish to format the drive(s) with a real good program that a program that conforms to the US DoD/NSA or similar.

 

I could recommend some programs to nicely do all of the above, but let's wait for a final verdict.

 

Regards.

Message Edited by Plankton on 12-10-2009 04:57 PM

UncleWillie:

 

It probably would be faster to reformat.  The forums for malware removal are all quite busy at the moment.  They will be able to do the repair as Quads has said. 

 

If you reformat, which will require stripping everything off the drive, you can't just reload or the rootkit will remain, re-installing the operating system, all of your programs, and restoring all of the data that you saved prior to reformatting.  A drive image is not a good plan as it will also copy the infection.  Documents and photographs and personal files should be safe.

 

A download for XP sp3 can be found here, if you wish to go that route.

 

http://www.microsoft.com/downloads/en/confirmation.aspx?familyId=2fcde6ce-b5fb-4488-8c50-fe22559d164e&displayLang=en

 

 

 

Hi UncleWillie:

 

I just wish to clarify my above post, just in case delphinium or anyone else might misinterpret it.

 

You would want to perform a low level DoD/NSA format of your entire system, reload the OS, NIS 2010, MBAM, SAS and your Applications.

 

When complete, your computer should be fully scanned by each security program for any threats.

 

Only then would it be safe to transfer the user data back to the newly restaged system, IMO.

 

Then run all three product scans again.

 

Once the system is running perfectly and secondary scans are clean and complete, would I consider bare metal imaging the entire restaged system onto an external HDD.

 

Please let us know if you are in need of any recommendations, regarding this approach.

 

Thanks.

Message Edited by Plankton on 12-10-2009 06:06 PM

Hi All

 

I recall reading an article this time last year....that claimed million's of computers are discarded (and replaced) every year just because of an infection.   Imagine the financial gain to PC vendors, manufacturers, suppliers, recyclers, software vendors  etc. etc.   

I wonder if there is any correlation....? 

 

bjm_

Hi bjm_ :

 

Perhaps this is the the way "they could do it:" -

 

http://arstechnica.com/security/news/2009/03/researchers-demonstrate-bios-level-rootkit-attack.ars

 

Hmm...

Plankton:

 

I'm not really understanding here.  If we have a low level format, with nothing but the O/S, Norton, MBAM, and SAS, I'm not understanding why Uncle would need to scan it with three products, twice.  Presumably he would be reloading from his program discs, which should be virus clean.  It just seems like an unecessary use of possibly 6-10 hours of scan time.

 

The user data could be scanned after loading it into an external drive. It will certainly be scanned again during the reload.

Hi Plankton

 

Just what I need another threat window.... :smileymad:

 

Hopefully, Win7 will close that darn open window a little...  http://technet.microsoft.com/en-us/security/ee794675.aspx

 

and I imagine the MSRC is working overtime....  http://blogs.technet.com/msrc/archive/2009/12/08/december-2009-security-bulletin-release.aspx

 

One can only hope...you know efforts by consumer advocates to persuade governments to classify computer crimes as a national defense issue have been stifled despite all the promising rhetoric....One of these days we may all face a black screen....Imagine the worldwide financial ramifications. 

Merry X-Mas and Happy New Year  :smileywink: 

bjm_

Hi delphinium -

 

It is just a suggestion. I use these three products on all of my systems prior to doing the bare metal image.

 

I like this layered approach as NIS, MBAM and SAS all work well together. UW could omit the first scan if he has a trusted source for the program discs (OS, drivers, utilities, etc.). Guess that I am a bit cautious, considering what I have seen in my travels. I have read a few reports in the past about infected CD/DVD Application, Driver and other discs and experienced it firsthand on two occasions.

 

As for the scan time, that depends on a number of factors, including how much data that needs to be scanned, type and configuration of the computer, etc. Additional time is needed for the creation of the backup image file onto an external/internal HDD or online, as well.

 

Hope that this addresses your post. :smileyhappy:

 

Message Edited by Plankton on 12-10-2009 07:40 PM

"It's just a matter of carefully swapping the driver over"

 

Is this a solution? other than going to bleeping computer....or have I mis read it?

OK, I signed up for bleepingcomputer.  Great name, by the way.  I am following the instructions on the preparation guide page:

http://www.bleepingcomputer.com/forums/topic34773.html

 

Unfortunately Norton won't let me download RootRepeal.  It identifies it as suspicious. (spelled it right that time).  

 

So, what do I do?  Disable NIS and download it anyway?  Thanks.

 

Willie

UncleWillie:

 

It is very important to follow all instructions you are given at Bleeping.  Disable Norton in order to run the scans requested by them.  

OK, I ran the tools and posted at bleeping computer:

 

http://www.bleepingcomputer.com/forums/index.php?showtopic=277956&st=0&p=1533147&#entry1533147