Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
sfwarlock
Aug 11, 2007

theHUNGERian posted:

Hey guys,

I just recovered from a 'Smart HDD' attack.

I followed the instructions from a youtube video posted here, and almost everything is back to normal. However, when I click on a link to take me to legit antivirus pages, I get redirected to garbage sites. I deleted the hosts file and let spybot create a new one, but the problem persists.

What do I do?

Thanks for the help guys.

Check your proxies. Check your DNS server setting. Check for a rootkit.

Adbot
ADBOT LOVES YOU

Dilbert As FUCK
Sep 8, 2007

by Cowcaster
Pillbug

theHUNGERian posted:

Hey guys,

I just recovered from a 'Smart HDD' attack.

I followed the instructions from a youtube video posted here, and almost everything is back to normal. However, when I click on a link to take me to legit antivirus pages, I get redirected to garbage sites. I deleted the hosts file and let spybot create a new one, but the problem persists.

What do I do?

Thanks for the help guys.

hit man pro fixes this, combofix will as well

bascially hti hardcodes an IP for google in /hosts so when you go to anything google related it redirects to X

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
edit: ^ Also what he said is a good idea too

If you're getting that most likely you've been hit by the secondary infection that gets dropped by Smart HDD if you haven't already give TDSSKiller a run if that doesn't work give Yorkyt.exe (Panda Security ZAccess Removal Tool) a spin. If it isn't ZeroAccess then it is probably MaxSS/TDL in which case if TDSSKiller fails give FixTDSS (Symantec Tool) a try.

theHUNGERian
Feb 23, 2006

I ran ComboFix and the problem remains. I'm running HitmanPro right now.

I removed Smart HDD from the startup in msconfig in safe mode. Once done, I deleted all part of the sotware manuall. I then ran MalwareBytes, TDSKiller, and the unhide tool. Unfortunately, the shortcuts from the start menu were deleted during the infection, but they are just shortcuts.

Will report back.

Edit: HitmanPro for the win! Everything back to normal. I need to upgrade my spyware defenses.

theHUNGERian fucked around with this message at 18:50 on Apr 3, 2012

Puseklepp
Jan 9, 2011

like watching the most beautiful ballerina on the best stage

Hex Darkstar posted:

Just removed one of those earlier today. That site has a location for the files but the one I came across today was in a different location also *DO NOT* delete the %temp%\smtmp\ folder or any subfolders of it that is where the malware moves all of your shortcuts and there's no restoring them unless you're lucky and they go to the recycle bin instead of the twisting nether of bits.

The files the malware uses to startup will be hidden under either:
Windows XP: %allusersprofile%\application data
Windows 7 : C:\ProgramData

Either on your PC in SafeMode or on another PC and transfer with a thumb drive download unhide.exe from http://www.bleepingcomputer.com/download/anti-virus/unhide. This is a Sysdef.b variant and dropped ZeroAccess on the machine I was working with so i'm going to assume the worst that you have admin rights and it probably tried to install it as well, you'll probably want to run http://support.kaspersky.com/faq/?qid=208280684. Unhide will take care of most of the files the malware hid from you. And just to be safe maybe give http://www.microsoft.com/security/scanner/en-us/default.aspx a whirl on full system scan to make sure everything is gone.

In order to unhide your start menu items you'll need to:
1) Right click on the taskbar
2) Go to properties then under there find the "start menu" tab and click "Customize"
3) Under there locate the "Advanced Tab"
4) Go through the list of common items that display in your Start Menu most of them will be switched to "Don't Display Item" you'll want to change that to "Display as a Link"
5) When done hit Ok or Apply and that should return all your start menu items minus maybe the recently used programs list.

Thanks. I followed the video linked to in the thread I posted and that seemed to remove it. Didn't touch the registry much though. A bit hesitant there. I've run a Hitman Pro scan, a Malwarebytes scan, a Kaspersky TDSSKiller scan and now running that microsoft security scanner you linked. Anything else I need to do now? Planning to do a full system scan with Trend Micro Internet Security at the end.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
For now that should do it if none of the other removal tools came back with any detections you might want to try and google something and see if you're being redirected or anything like that but otherwise you're more than likely back to normal although after an infection there's always that question of what else did it change :(

As for today:


drat near poo poo my pants when I saw that then I checked and ONE machine is generating 3218 events out of the 4000 something total. The person who is using that machine has to be blatantly ignoring virus scan pop ups on their machine I seriously want to talk to them and ask them what the gently caress. Problem is they won't answer their phone :sotw:

e: Mind you all those detections came in and are still coming in within the last 3 1/2 hours. About to tell networking to shut their port off

Hex Darkstar fucked around with this message at 19:21 on Apr 5, 2012

RadicalR
Jan 20, 2008

"Businessmen are the symbol of a free society
---
the symbol of America."
Yeah, my agency is getting hit with that SMART HDD poo poo. Thankfully, we got the poo poo locked down so all it can do is just flash that annoying window. (No admin rights! HA!)

I just wrote up some instructions on how to clean it up and created a batch file that'll unhide the files and folder the users needs. (We can't use "unhide.exe". Government agency.)

El Goatherd
Jun 25, 2005

hate is art
A machine came in today with a note saying Avira had stopped working for some reason. A quick peek at the logs revealed this :

code:
26/10/2011,10:17:44 [DETECTION]  Is the TR/Spy.463227 Trojan!
  C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll
      [USER] NT AUTHORITY\SYSTEM
      [INFO] The file access was denied!
(12 identical entries removed for brevity..)

code:
26/10/2011,11:59:40 [DETECTION]  Is the TR/Spy.463227 Trojan!
  C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll
      [USER] NT AUTHORITY\SYSTEM
      [INFO] The file access was denied!
26/10/2011,12:00:21 Avira AntiVir Personal - Free Antivirus service has been stopped!
26/10/2011,12:01:31 ---------------------------------------------------------
26/10/2011,12:01:32       [WARNING] The engine and VDF could not be loaded from the installation directory. The engine and VDF will be loaded from the back-up copy instead.
So Avira wasn't working because it had mistakenly detected itself as a virus. :stare:

http://www.theregister.co.uk/2011/10/26/avira_auto_immune_false_positive/

Scaramouche
Mar 26, 2001

SPACE FACE! SPACE FACE!

I've seen these before, but apparently it's back, in POG form:
http://www.theregister.co.uk/2012/04/05/police_themed_ransomware/

Scareware that implies its found illegal material on your computer and you have to pay it off to not get arrested.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
It's weird I never see those tailored to the US. Only time I ever encountered one was a user visiting Germany got hit by that ransom crapware that was the one and only time i've had to do a removal for it ah well not going to complain the less of those around here the better.

Scaramouche
Mar 26, 2001

SPACE FACE! SPACE FACE!

It must be because none of your users ever has illegal material on their computers!!

Hex Darkstar
May 28, 2004

I think I need another liver transplant.

Scaramouche posted:

It must be because none of your users ever has illegal material on their computers!!

The amount of .torrent files I see begs to differ :( Although not porn mostly TV shows goddamn them, had to add all the popular bit torrent clients to the list of unwanted programs so our virus scan suite nukes them before users can use them. You can get around it with renaming the exe file since we're not using a signature just based off exe name but most of them don't realize that so it works out in the end :v:

At least they're not doing it on our network our IDS systems monitor for that and it never seems to happen but they're still using a work resource to do it outside of work.

Knobjockey
Jul 21, 2003

Crush your enemies.
Bang! and the alien is gone.
Hear the lamentation of Dr. Vahlen.

Scaramouche posted:

I've seen these before, but apparently it's back, in POG form:
http://www.theregister.co.uk/2012/04/05/police_themed_ransomware/

Scareware that implies its found illegal material on your computer and you have to pay it off to not get arrested.

Yes, there was one purporting to be Strathclyde (Glasgow) Police.

Initially McPolice issued a statement saying "it's not us, don't pay, get a computer bloke in" or similar.

After some thought (and presumably a few confessions) they later changed their position to "it's not us, it's malware but if you'd like to talk to us about it the number is..."

example

El Goatherd
Jun 25, 2005

hate is art
Here's an easier to read screenshot from one of the most recent machines we had in infected with it (click for big) :



Because everyone knows that the standard punishment for being a pedophile with 'secret terroristic plans' is a hundred quid fine paid with a money order.

FronzelNeekburm
Jun 1, 2001

STOP, MORTTIME

Hex Darkstar posted:

It's weird I never see those tailored to the US. Only time I ever encountered one was a user visiting Germany got hit by that ransom crapware that was the one and only time i've had to do a removal for it ah well not going to complain the less of those around here the better.
That old admin@cia.gov virus from about ten years ago springs to mind. I miss viruses that made you open a passworded ZIP file and run the contents to get infected.

Oddhair
Mar 21, 2004

Has anyone seen that Smart HDD malware remove entire swaths of registry entries? I've got a coworker who had Smart HDD, and I removed it with MS' standalone system sweeper. Now this key is entirely missing:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\*

I've tried exporting the key from a VM I keep around, regedit doesn't import it correctly, says it's an invalid file type. Since this covers file types and their handlers, it's hampering my repairs.

Double Punctuation
Dec 30, 2009

Ships were made for sinking;
Whiskey made for drinking;
If we were made of cellophane
We'd all get stinking drunk much faster!

Oddhair posted:

Has anyone seen that Smart HDD malware remove entire swaths of registry entries? I've got a coworker who had Smart HDD, and I removed it with MS' standalone system sweeper. Now this key is entirely missing:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\*

I've tried exporting the key from a VM I keep around, regedit doesn't import it correctly, says it's an invalid file type. Since this covers file types and their handlers, it's hampering my repairs.

Did you try using "REG IMPORT whatever.reg" from the command line?

KomradeVirtunov
Sep 14, 2007

Oddhair posted:

Has anyone seen that Smart HDD malware remove entire swaths of registry entries? I've got a coworker who had Smart HDD, and I removed it with MS' standalone system sweeper. Now this key is entirely missing:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\*

I've tried exporting the key from a VM I keep around, regedit doesn't import it correctly, says it's an invalid file type. Since this covers file types and their handlers, it's hampering my repairs.

If I recall, this little piece of malware likes to put in an entry for regedit in Image File Execution Options to redirect to its wonderful little executables. I'm not sure if the "reg import" would work, but I've had luck with using autoruns to remove these sorts of entries.

Oddhair
Mar 21, 2004

I'm going to try autoruns now, and I hadn't tried the command line merge, only from within regedit.

repeating
Nov 14, 2005
Smart HDD/SystemCheck is destroying me right now. Many of them are dropping/resulting from TDSS/Alureon/Tidserv or something similar and they're breaking our custom MBR. Half of my calls lately are "When I turn my computer on it just has a blinking cursor on the top right and it won't do anything."

Hex Darkstar
May 28, 2004

I think I need another liver transplant.

repeating posted:

Many of them are dropping/resulting from TDSS/Alureon/Tidserv or something similar and they're breaking our custom MBR. Half of my calls lately are "When I turn my computer on it just has a blinking cursor on the top right and it won't do anything."

Ooooh they're spreading TDL again? If it is anything like in the past the FakeAV part of SmartHDD phones home after installing then downloads and runs a rootkit either TDL or ZAccess if the user has admin rights. All of the ones i've come across have been ZeroAccess infections so far that dropped along side Smart HDD. Luckily they leave the MBR unharmed but removal is still an annoyance if the self defense mechanisms in it are actually working. That stupid ADS executable it uses as a trip wire always causes problems unless you're using a tool specialized to removing ZeroAccess.

precedence
Jun 28, 2010
So I'm a computer science major in college(so i'm not totally ignorant) and my laptop hard drive space appears to fluctuate a large amount. from day to day. today i appear to have 10 extra gigs of freespace out of nowhere which is a really large jump from what it normally does. until now i just assumed it was temporary files of programs or something (VM maybe?). I've scanned several times with MSE and MalwareBytes.

is there a rootkit/virus that does this? or is my harddrive just being weird?

I'm running windows 7 home premium.

tjl
Aug 6, 2005

precedence posted:

So I'm a computer science major in college(so i'm not totally ignorant) and my laptop hard drive space appears to fluctuate a large amount. from day to day. today i appear to have 10 extra gigs of freespace out of nowhere which is a really large jump from what it normally does. until now i just assumed it was temporary files of programs or something (VM maybe?). I've scanned several times with MSE and MalwareBytes.

is there a rootkit/virus that does this? or is my harddrive just being weird?

I'm running windows 7 home premium.
It might just be old system restore snapshots being deleted if that feature is enabled. By default I think it enabled for the C: drive, and uses a certain percentage of the space.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.
Well thats a first, came across a detection on a users machine that was a heuristic detection by Artemis for a .scr file named "Recycled". I sent it off to ThreatExpert and the results were kind of disturbing. It creates a sys file and service based off that sys file that is set to start at 0x1 so it is set to start as a system service :stonk: Oh yea did I forget to mention that it also tries to contact a remote location that was in China according to the report?

Curious about this one, it was in a backup the user made so I have a feeling if it ever ran on one of their systems it was already reimaged since then but still what was it doing while it was active.

Scaramouche
Mar 26, 2001

SPACE FACE! SPACE FACE!

Hex Darkstar posted:

Well thats a first, came across a detection on a users machine that was a heuristic detection by Artemis for a .scr file named "Recycled". I sent it off to ThreatExpert and the results were kind of disturbing. It creates a sys file and service based off that sys file that is set to start at 0x1 so it is set to start as a system service :stonk: Oh yea did I forget to mention that it also tries to contact a remote location that was in China according to the report?

Curious about this one, it was in a backup the user made so I have a feeling if it ever ran on one of their systems it was already reimaged since then but still what was it doing while it was active.

I had a buddy get something similar off of a USB stick our boss brought back from a trip to China. I don't remember the specifics (>2 years ago) but I do remember a *.scr file in the recycle bin and the 0x1 service entry. It was super chatty with China. He wouldn't let me troubleshoot it so he just reformatted.

Hex Darkstar
May 28, 2004

I think I need another liver transplant.

Scaramouche posted:

I had a buddy get something similar off of a USB stick our boss brought back from a trip to China. I don't remember the specifics (>2 years ago) but I do remember a *.scr file in the recycle bin and the 0x1 service entry. It was super chatty with China. He wouldn't let me troubleshoot it so he just reformatted.

I have a sample of the dropper/backdoor install still I am going to try and run it via a VM that i've locked down and do a wireshark dump on what it is sending in hopes that it isn't a bunch of encrypted traffic. The family it comes from apparently consists of a Rootkit and possibly a PWS Component. At this point there's no real reason for me to do this besides curiosity the Virus Total results on it was a crap storm of detections on the 43 scans they use so now i'm just wondering if it was actually sending anything home still or if the C&C for it has been shut down.

The backup the employee made was of his Blackberry's storage so I am thinking that it might have copied itself to his phone to try and spread by an auto-runs whenever his MicroSD card got mounted like a USB drive.

Zogo
Jul 29, 2003

precedence posted:

...my laptop hard drive space appears to fluctuate a large amount. from day to day. today i appear to have 10 extra gigs of freespace out of nowhere which is a really large jump from what it normally does.

You could try the spacemonger program to see if there's files or folders that stick out or fluctuate from day to day.

http://www.sixty-five.cc/sm/v1x.php

Tapedump
Aug 31, 2007
College Slice
The gently caress is up with iGoogle right now? My wife just called me in to show me how trying to close an iGoogle Chrome tab brings up a "Are you sure you want to leave this page? Find love or sex here!" which links to cafebar.ro

(Search Google for "iGoogle cafebar.ro" and watch how many strange hits come up.)

My Chrome profile will not produce the same results. Her Firefox does the above, too, while mine does not.

This is the same situation on three known-safe computers (the second has literally not been used today until now for the sake of testing, the third I just finished up a clean Win7 install). The behavior stopped for about two minutes before starting again, but this time when trying to close Chrome (on an iGoogle tab) itself.

For now she is just avoiding iGoogle, and I'm scanning the hell out of her system tonight, but in the case its not a local infection what could cause this?

Shalhavet
Dec 10, 2010

This post is terrible
Doctor Rope
To clarify, if you log into your iGoogle on her machine, this behavior does not occur. If she logs into her iGoogle on your machine, it does.

If that's the case it sounds like she's got some nasty little widget added to her homepage.

Technogeek
Sep 9, 2002

by FactsAreUseless

Tapedump posted:

The gently caress is up with iGoogle right now? My wife just called me in to show me how trying to close an iGoogle Chrome tab brings up a "Are you sure you want to leave this page? Find love or sex here!" which links to cafebar.ro

(Search Google for "iGoogle cafebar.ro" and watch how many strange hits come up.)

My Chrome profile will not produce the same results. Her Firefox does the above, too, while mine does not.

This is the same situation on three known-safe computers (the second has literally not been used today until now for the sake of testing, the third I just finished up a clean Win7 install). The behavior stopped for about two minutes before starting again, but this time when trying to close Chrome (on an iGoogle tab) itself.

For now she is just avoiding iGoogle, and I'm scanning the hell out of her system tonight, but in the case its not a local infection what could cause this?

I found a report over here that claims this is caused by problematic iGoogle gadgets -- one person claimed that Match Up (a synonym quiz thing) was the culprit for them, but it may be different for your wife.

Tapedump
Aug 31, 2007
College Slice

Shalhavet posted:

To clarify, if you log into your iGoogle on her machine, this behavior does not occur. If she logs into her iGoogle on your machine, it does.
Exactly.

Technogeek posted:

I found a report over here that claims this is caused by problematic iGoogle gadgets
Thank you both. I thought that might be the case as the gadgets are the only real variable left.

BillWh0re
Aug 6, 2001


Hex Darkstar posted:

Well thats a first, came across a detection on a users machine that was a heuristic detection by Artemis for a .scr file named "Recycled". I sent it off to ThreatExpert and the results were kind of disturbing. It creates a sys file and service based off that sys file that is set to start at 0x1 so it is set to start as a system service :stonk: Oh yea did I forget to mention that it also tries to contact a remote location that was in China according to the report?

Curious about this one, it was in a backup the user made so I have a feeling if it ever ran on one of their systems it was already reimaged since then but still what was it doing while it was active.

That sys file isn't part of the virus. It's the system component of the Themida copy protection system: http://www.oreans.com/themida.php

The malware author has just packed his lovely bot with Themida, which is what's dropped the sys file. So you don't have that to worry about at least -- and leaving the sys file around probably won't do any harm. The connections to China are definitely not from that though.

Sab669
Sep 24, 2009

Just a heads up for you guys, I got in to work yesterday and boot up my computer (which a few other users also use) to find it infected with some "Security Fortress 2012" bullshit, I think it was. Got past MSE, apparently.

Bokito
Jul 25, 2007
Going Ape
MSE has been updated to version 4 (skipping version 3 entirely):

- Enhanced protection through automatic malware remediation: The program will clean highly impacting malware infections automatically, with no required user interaction.
- Enhanced performance: Version 4.0 includes many performance improvements to make sure your PC performance isn’t compromised.
- Simplified UI – Simplified UI makes Microsoft Security Essentials easier to use.
- New and improved protection engine: The updated engine offers enhanced detection with cleanup capabilities and better performance.


http://windows.microsoft.com/en-US/windows/products/security-essentials/

Maniaman
Mar 3, 2006

Bokito posted:

MSE has been updated to version 4 (skipping version 3 entirely):


- Simplified UI – Simplified UI makes Microsoft Security Essentials easier to use.


Just updated, the UI looks very much the same as the previous version except they went back to a blue background that gradually fades to gray and got rid of the weird texture thing.

Kind of excited to see the speed improvements though, I always hated doing full scans because they would sometimes take over 6 hours.

Also as a person that installs MSE for people who bring in computers for viruses, I wish/hope its fixed in this version, that MSE scans would prevent the computer from going to sleep if a scan is running and it's not on battery.

Maniaman
Mar 3, 2006
Got a new one in yesterday. One of the fake HDD antiviruses. It would BSOD the computer when running any virus scan. Pulled the drive and ran MSE on it, and it got rid of a variant of Alureon and a bunch of other stuff.

Now I'm left with cleaning up after it (unhiding files, fixing the start menu), and there's one issue I can't for the life of me figure out.

The virus has screwed with font rendering where only on certain programs and dialog boxes, no text is rendered (or if its rendered you can't read it).

I've tried resetting font settings, resetting the theme, messing around with DPI and accessibility options, to no avail. SFC found no integrity violations with any system files. I tried creating a new user profile and it does the same thing.

The biggest issue is probably the Internet Options dialog. It shows all the GUI controls and all the icons, but not a single bit of text.

It's a customers computer and they have a bunch of junk on it, so I'm trying to avoid a flatten & reinstall if at all possible.

I should also mention that things such as the ClearType tuner will open and then lock up or crash explorer.

probably drunk
Dec 25, 2009

by Lowtax
Does anyone know what to do with a Windows 7 box that constantly goes into repair mode, no cause identified, and an SFC /scannow doesn't find any problems?

pixaal
Jan 8, 2004

All ice cream is now for all beings, no matter how many legs.


Maniaman posted:

Got a new one in yesterday. One of the fake HDD antiviruses. It would BSOD the computer when running any virus scan. Pulled the drive and ran MSE on it, and it got rid of a variant of Alureon and a bunch of other stuff.

Now I'm left with cleaning up after it (unhiding files, fixing the start menu), and there's one issue I can't for the life of me figure out.

The virus has screwed with font rendering where only on certain programs and dialog boxes, no text is rendered (or if its rendered you can't read it).

I've tried resetting font settings, resetting the theme, messing around with DPI and accessibility options, to no avail. SFC found no integrity violations with any system files. I tried creating a new user profile and it does the same thing.

The biggest issue is probably the Internet Options dialog. It shows all the GUI controls and all the icons, but not a single bit of text.

It's a customers computer and they have a bunch of junk on it, so I'm trying to avoid a flatten & reinstall if at all possible.

I should also mention that things such as the ClearType tuner will open and then lock up or crash explorer.

Have you replaced all the files in the font folder? It's possible the were hosed up somehow. Any custom fonts they have installed they'll have to do again, just copy the font folder from a clean install over it so you don't run into any legal issues if you have purchased fonts. The font files might also be on the windows disc easy enough to just drag out if you don't have a clean install.

repeating
Nov 14, 2005

Maniaman posted:

Got a new one in yesterday. One of the fake HDD antiviruses. It would BSOD the computer when running any virus scan. Pulled the drive and ran MSE on it, and it got rid of a variant of Alureon and a bunch of other stuff.

Now I'm left with cleaning up after it (unhiding files, fixing the start menu), and there's one issue I can't for the life of me figure out.

The virus has screwed with font rendering where only on certain programs and dialog boxes, no text is rendered (or if its rendered you can't read it).

I've tried resetting font settings, resetting the theme, messing around with DPI and accessibility options, to no avail. SFC found no integrity violations with any system files. I tried creating a new user profile and it does the same thing.

The biggest issue is probably the Internet Options dialog. It shows all the GUI controls and all the icons, but not a single bit of text.

It's a customers computer and they have a bunch of junk on it, so I'm trying to avoid a flatten & reinstall if at all possible.

I should also mention that things such as the ClearType tuner will open and then lock up or crash explorer.

sfc?

Adbot
ADBOT LOVES YOU

mindphlux
Jan 8, 2004

by R. Guyovich

repeating posted:

sfc?

http://www.com????

  • Locked thread