• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Hijack of epic proportions!!!

Joined
Nov 4, 2005
Messages
11,676 (1.73/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs and over 10TB spinning
Display(s) 56" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
Dear fellow TPUers.


I just spent yesterday cleaning a system at work from a java exploit that resulted in a very serious infection that AVG failed to catch, MSE, Malwarebytes, Blacklight, Sophos, Combofix, and many others failed to remove the infection as well.


The symptoms were, browser redirect, fake system issues, closing programs, hiding all files on HDD, removing all administrative tools and ending their processes when launched, BSOD from thread/memory hijacks when other rootkit tools were ran, system lockup, and full CPU utilization, also it infected the bootsector of the harddrive and rendered the system unable to boot cleanly even in safe mode to run any tools.


Infection started from the one java exploit as a installer that managed to get a rootkit in, the rootkit then downloaded a remote control trojan, system event fake hijackers, and damaging software.


Please http://www.java.com/en/download/index.jsp uninstall all instances of java and update if you need to run java. Java is evil, I know this, you know this. We need it for work.

Please download the following tools.

http://support.kaspersky.com/faq/?qid=208283363 TDSS Killer, anti-rootkit. If you do happen to get infected you must rename the extracted file on a USB stick and insert it and run it as soon as possible as the new variant it catches will check the signature of this file and prevent its launch even when launched from a system level account from the registry on boot.

http://www.bleepingcomputer.com/download/anti-virus/combofix Combo fix, it will clean up the effects of the infection plus any remaining secondary infections that make it past anti-virus or anit-malware.

Malwarebytes, as if you shouldn't have a clean copy of this somewhere on a CD or non-writeable media.

Hijackthis, see above. If you are unsure how to use it you can get a log and post that using a USB stick to transfer it.




The best practices with any infection is immediate isolation of the infected machine, as in physically unplugging the network cable, turning off the switch for wifi, or powering down any access point to limit any secondary infections, or transfer of data. Once the machine is clean a full system scan with each tool and a test of active connections to and from it with a firewall or any modern router to make sure nothing is left to phone home.


Please update all anti-virus signatures and run at least a malware/rootkit scan once a month. For those without anti-virus, get some. There are many free versions, and your belief you are immune or your would "know" is worthless.

Avast
MSE
AVG

There are at least three well known free anti-virus products that are easy to use, and little to no maintenance is required.



******************************************************


Attached is a removal tool that can be copied to a USB stick and it must be copied to the C:\ drive and extracted there.


Extract the zip file after copying by double clicking, then inside the extracted folder double click the "fixit.reg" file to add a runonce line to the registry for the next boot, that then runs a .bat file that renames the anti-rootkit tool and then runs it. Alternately you may double click the bat file and see if it runs.


This removes ZeroAccess rootkit among others, however the damage done by some of the secondary infections will still be present, please download and run the above mentioned tools to help the cleanup and include them on the USB stick to prevent recurring infection after running this tool.

******************************************************************


Neither I, or techpowerup or its members are responsible for any damages from fixing your computer, so after running this if you are still infected, have issues, decide to kill your dog or family, thats your problem.
 

Attachments

  • tdsskiller.zip
    1.5 MB · Views: 206
Last edited:

Cold Storm

Battosai
Joined
Oct 7, 2007
Messages
15,010 (2.49/day)
Location
In a library somewhere on this earth
System Name Haro
Processor AMD 1700x
Motherboard AsRork x370 Taichi
Cooling EK Custom Loop - CPU only
Memory 32gb G-Skill Trident Z
Video Card(s) EVGA 1080 Superclock 2
Storage Too Many
Display(s) Viewsonic VX2450WM-LED 24" & LG 32 IPS
Case Cooler Master Cosmos II
Power Supply Cooler Master V1000
Mouse SteelSeries Rival 500
Software Win10 Pro
Benchmark Scores i5 750 4.62ghz pi runs // Evga FTW p55
Thanks for the post Steevo

:toast:
 

trickson

OH, I have such a headache
Joined
Dec 5, 2004
Messages
7,595 (1.07/day)
Location
Planet Earth.
System Name Ryzen TUF.
Processor AMD Ryzen7 3700X
Motherboard Asus TUF X570 Gaming Plus
Cooling Noctua
Memory Gskill RipJaws 3466MHz
Video Card(s) Asus TUF 1650 Super Clocked.
Storage CB 1T M.2 Drive.
Display(s) 73" Soney 4K.
Case Antech LanAir Pro.
Audio Device(s) Denon AVR-S750H
Power Supply Corsair TX750
Mouse Optical
Keyboard K120 Logitech
Software Windows 10 64 bit Home OEM
Shouldn't JAVA be protecting us from there shit ?
 
Joined
Jun 12, 2007
Messages
4,815 (0.78/day)
Location
Wangas, New Zealand
System Name Darth Obsidious
Processor Intel i5 2500K
Motherboard ASUS P8Z68-V/Gen3
Cooling Cooler Master Hyper 212+ in Push Pull
Memory 2X4GB Corsair Vengeance DDR3 1600
Video Card(s) ASUS R9 270x TOP
Storage 128GB Samsung 830 SSD, 1TB WD Black, 2TB WD Green
Display(s) LG IPS234V-PN
Case Corsair Obsidian 650D
Audio Device(s) Infrasonic Quartet
Power Supply Corsair HX650w
Software Windows 7 64bit and Windows XP Home
Benchmark Scores 2cm mark on bench with a razor blade.
Haven't seen malware like this before and I've come across some nasty ones.

Hope this doesn't become a trend.
It was bad enough having those foreign people calling up claiming they are from Microsoft saying their computer is at risk whether they own a computer or not.
 

trickson

OH, I have such a headache
Joined
Dec 5, 2004
Messages
7,595 (1.07/day)
Location
Planet Earth.
System Name Ryzen TUF.
Processor AMD Ryzen7 3700X
Motherboard Asus TUF X570 Gaming Plus
Cooling Noctua
Memory Gskill RipJaws 3466MHz
Video Card(s) Asus TUF 1650 Super Clocked.
Storage CB 1T M.2 Drive.
Display(s) 73" Soney 4K.
Case Antech LanAir Pro.
Audio Device(s) Denon AVR-S750H
Power Supply Corsair TX750
Mouse Optical
Keyboard K120 Logitech
Software Windows 10 64 bit Home OEM
So should we all now uninstall all of java ? How do we know we are infected ? MSE is running and always updated on my computer . I see nothing going wrong at all . I do not have java running nor update java . I really have no idea why java installed on my computer in the first place but it is .
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
23,349 (3.76/day)
Location
London,UK
System Name Codename: Icarus Mk.VI
Processor Intel 8600k@Stock -- pending tuning
Motherboard Asus ROG Strixx Z370-F
Cooling CPU: BeQuiet! Dark Rock Pro 4 {1xCorsair ML120 Pro|5xML140 Pro}
Memory 32GB XPG Gammix D10 {2x16GB}
Video Card(s) ASUS Dual Radeon™ RX 6700 XT OC Edition
Storage Samsung 970 Evo 512GB SSD (Boot)|WD SN770 (Gaming)|2x 3TB Toshiba DT01ACA300|2x 2TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White)
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Corsair AX760
Mouse Logitech G900
Keyboard Duckyshine Dead LED(s) III
Software Windows 10 Pro
Benchmark Scores (ノಠ益ಠ)ノ彡┻━┻
So should we all now uninstall all of java ? How do we know we are infected ? MSE is running and always updated on my computer . I see nothing going wrong at all . I do not have java running nor update java . I really have no idea why java installed on my computer in the first place but it is .

a lot of websites and programs require that Java be installed to run. You cant really avoid it
 

trickson

OH, I have such a headache
Joined
Dec 5, 2004
Messages
7,595 (1.07/day)
Location
Planet Earth.
System Name Ryzen TUF.
Processor AMD Ryzen7 3700X
Motherboard Asus TUF X570 Gaming Plus
Cooling Noctua
Memory Gskill RipJaws 3466MHz
Video Card(s) Asus TUF 1650 Super Clocked.
Storage CB 1T M.2 Drive.
Display(s) 73" Soney 4K.
Case Antech LanAir Pro.
Audio Device(s) Denon AVR-S750H
Power Supply Corsair TX750
Mouse Optical
Keyboard K120 Logitech
Software Windows 10 64 bit Home OEM
a lot of websites and programs require that Java be installed to run. You cant really avoid it

Ok so then what ? I mean if it is this bad then what can you do ? Is Sun Java going to fix there shit or is it up to us to do all this work ? I am not all that good at doing stuff like this and can not afford some one else to do it . How do I know I am not infected ? :banghead:
 
Joined
Nov 4, 2005
Messages
11,676 (1.73/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs and over 10TB spinning
Display(s) 56" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
Uninstall old versions and install only the new version, and run in sandbox mode.


It really sucks as I now have 50ish more machines that are running old versions as Java is such a fucking piece of shit it never uninstalls the old version when updating. So the computer that we had infected had almost 500MB of 6 versions installed.


DL and run the TDSS and keep your MSE up to date with a full scan scheduled to run at least once a week and you should be OK.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
I saw an article a few weeks back, where some security expert said that it's nuts to install JAVA, especially on corporate PC's, because of the vulnerabilities, so I'm not that surprised this happened.

If I can across an infected system, I wouldn't waste time trying to reimage. I would simply rescue any data on it and reinstall/reimage the thing. The problem is you can never be sure to have got rid of every last infection, plus the OS might be damaged such that it'll never be the same, no matter what you do to it.
 

trickson

OH, I have such a headache
Joined
Dec 5, 2004
Messages
7,595 (1.07/day)
Location
Planet Earth.
System Name Ryzen TUF.
Processor AMD Ryzen7 3700X
Motherboard Asus TUF X570 Gaming Plus
Cooling Noctua
Memory Gskill RipJaws 3466MHz
Video Card(s) Asus TUF 1650 Super Clocked.
Storage CB 1T M.2 Drive.
Display(s) 73" Soney 4K.
Case Antech LanAir Pro.
Audio Device(s) Denon AVR-S750H
Power Supply Corsair TX750
Mouse Optical
Keyboard K120 Logitech
Software Windows 10 64 bit Home OEM
I can not find were there is a problem at all with java ! Nothing at all is wrong on my system .
 
Joined
Nov 4, 2005
Messages
11,676 (1.73/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs and over 10TB spinning
Display(s) 56" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
I saw an article a few weeks back, where some security expert said that it's nuts to install JAVA, especially on corporate PC's, because of the vulnerabilities, so I'm not that surprised this happened.

If I can across an infected system, I wouldn't waste time trying to reimage. I would simply rescue any data on it and reinstall/reimage the thing. The problem is you can never be sure to have got rid of every last infection, plus the OS might be damaged such that it'll never be the same, no matter what you do to it.

If I weren't leaving all next week for training, have my own new laptop to stage, and lots of other things to do I probably would have reinstalled and copied last weeks image over, but it is a critical machine, so 8 hours of cleaning and fixing is better than the 14-20 hours of a reinstall and restage and testing. Plus with our nice firewalls here at work I just put a trace on its IP and can see all active connections and resolved names, ports, etc.... so I put the block on all the bad IP's out there it was trying to connect to.

get-answers-fast dot com was the biggest hijacker redirect and about 12 others, and most were hosted on the same subnet, so it all got blocked.

So I'm sure its clean after 24 hours of monitored connections and all scans came up clean and a rewrite of the bootsector and using a hex editor to peek directly at the disk from a live linux distro. int13 was clean.
 
Joined
Nov 4, 2005
Messages
11,676 (1.73/day)
System Name Compy 386
Processor 7800X3D
Motherboard Asus
Cooling Air for now.....
Memory 64 GB DDR5 6400Mhz
Video Card(s) 7900XTX 310 Merc
Storage Samsung 990 2TB, 2 SP 2TB SSDs and over 10TB spinning
Display(s) 56" Samsung 4K HDR
Audio Device(s) ATI HDMI
Mouse Logitech MX518
Keyboard Razer
Software A lot.
Benchmark Scores Its fast. Enough.
Bump for removal tool.
 
Joined
Apr 16, 2010
Messages
3,456 (0.68/day)
Location
Portugal
System Name LenovoⓇ ThinkPad™ T430
Processor IntelⓇ Core™ i5-3210M processor (2 cores, 2.50GHz, 3MB cache), Intel Turbo Boost™ 2.0 (3.10GHz), HT™
Motherboard Lenovo 2344 (Mobile Intel QM77 Express Chipset)
Cooling Single-pipe heatsink + Delta fan
Memory 2x 8GB KingstonⓇ HyperX™ Impact 2133MHz DDR3L SO-DIMM
Video Card(s) Intel HD Graphics™ 4000 (GPU clk: 1100MHz, vRAM clk: 1066MHz)
Storage SamsungⓇ 860 EVO mSATA (250GB) + 850 EVO (500GB) SATA
Display(s) 14.0" (355mm) HD (1366x768) color, anti-glare, LED backlight, 200 nits, 16:9 aspect ratio, 300:1 co
Case ThinkPad Roll Cage (one-piece magnesium frame)
Audio Device(s) HD Audio, RealtekⓇ ALC3202 codec, DolbyⓇ Advanced Audio™ v2 / stereo speakers, 1W x 2
Power Supply ThinkPad 65W AC Adapter + ThinkPad Battery 70++ (9-cell)
Mouse TrackPointⓇ pointing device + UltraNav™, wide touchpad below keyboard + ThinkLight™
Keyboard 6-row, 84-key, ThinkVantage button, spill-resistant, multimedia Fn keys, LED backlight (PT Layout)
Software MicrosoftⓇ WindowsⓇ 10 x86-64 (22H2)
Thank you very much for this, Steevo. Really valuable information.
I have Java on my computer, though I think I never used/needed it. Maybe I'll consider uninstalling it.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.99/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
If I weren't leaving all next week for training, have my own new laptop to stage, and lots of other things to do I probably would have reinstalled and copied last weeks image over, but it is a critical machine, so 8 hours of cleaning and fixing is better than the 14-20 hours of a reinstall and restage and testing. Plus with our nice firewalls here at work I just put a trace on its IP and can see all active connections and resolved names, ports, etc.... so I put the block on all the bad IP's out there it was trying to connect to.

get-answers-fast dot com was the biggest hijacker redirect and about 12 others, and most were hosted on the same subnet, so it all got blocked.

So I'm sure its clean after 24 hours of monitored connections and all scans came up clean and a rewrite of the bootsector and using a hex editor to peek directly at the disk from a live linux distro. int13 was clean.
Dang, sounds like you know what you're doing. :respect: Yes, I can see how this "compromise" is a good solution for your situation, especally as you can put the damned thing on probation afterwards with the firewall. :p
 
Joined
Nov 29, 2007
Messages
979 (0.16/day)
Location
Netherlands
I have encountered one of the Java exploit rootkits on a pc that a customer turned in for repairs, me being an intern and a total idiot I hooked it up on the network without checking it out first.

1 minute later our ISP blocked our internet connection saying we had a botnet.
4 Other Windows XP machines were infected within a couple of minutes as well because they were also connected to the same network, Luckily windows 7 wasn't vulnerable for that type of rootkit or we would have had a huge problem.

That is why my boss always tells us to run TDSS and Combofix first on every computer before we hook it on the network.

Still havent seen the virus steevo was talking about, but I can say that the tools he recommends are awesome I now use them everytime and Combofix pretty much catches all the bad stuff(It is updated EVERY day so dont use old versions)
 
Top