Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 15th, 2007, 04:53 PM
Liquidslam Liquidslam is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 15
Default Trojan Horse BackDoor. Hupigon3.xkf

AVG anti-virus hit me with this one after a routine scan yesterday. The exact infection details it gave were:

File: Partition table (MBR) Change
File: Boot sector of Disk Change
File: Hosts Change
File: Dc16.exe
Path: C:\RECYCLER\S-1-5-21-1085031214-1614895754-725345543-1003\Dc16.exe

It promptly deleted the .exe from the RECYCLE folder at the end of the scan. After a system reboot and another scan ithe trojan itself did not reappear but the information regarding the Partiton Table, Boot Sector and Hosts file change remained.

I've since installed KIS v7, ran all the scans but they showed nothing? I've Googled this RAT by name and came up with all kinds of horror stories leading up to the only cure being a complete OS reinstallation. I'm not ready to go down that path yet just yet but do need some advice as to how to proceed.

One other thing. My anti rootkit software picked up a hidden driver:
C: WINDOWS System32\drivers\a5m5eobq.SYS
for which Google finds absolutely nothing and I'm wondering if this could be related. The program offers me the choice of deleting it at the same time that it warns me of the possible consequences.
Thanks
  #2  
Old December 16th, 2007, 05:49 AM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: Trojan Horse BackDoor. Hupigon3.xkf

Quote:
C: WINDOWS System32\drivers\a5m5eobq.SYS

Do you have Alcohol/Daemon tools installed ?

If so there is a very high probability it is related to the legitimate RK in that software.

As for the rest i am not fammiliar with AVG reporting so cannot comment with any degree of certainty.I do know that RATS as with all malware need a loading point/entry point and withthat using a tool such as Autoruns and verifying the data returned you would be able locate a load point for a RAT if it is present(AVG AV would not delete that value).
http://www.microsoft.com/technet/sys.../AutoRuns.mspx

If there is no load value present then you are most likely looking at a False/Positive by AVG on the file in RB.

HTH
__________________
Ade Gill
Malwarebytes Researcher
  #3  
Old December 16th, 2007, 05:15 PM
Liquidslam Liquidslam is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 15
Default Re: Trojan Horse BackDoor. Hupigon3.xkf

Thanks for your reply. Yes, I am using Daemon Tools so that clears that up.
I have now downloaded autoruns a program which I can see is definitely not for the uninitiated. Frankly I wouldn't know how to find a loading point/entry point if it was staring me in the face so it looks like I'm going to have to find a tutorial for this program.
  #4  
Old December 17th, 2007, 02:44 AM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: Trojan Horse BackDoor. Hupigon3.xkf

Here's a small routine that both simplifies the Autoruns output(in quantity of data) and actually utilizes it to its full potential>>>

Run a scan but press ESC to stop it .

Click options .

Check both "verify code signatures" and "hide signed microsoft entries" . This will make the list a lot shorter .

Now press F5 to rerun the scan with the new settings .

Click file , save as and save the log to your desktop .

* if your firewall requests outbound connection for Autoruns(grant it permission) as it is phoning home to the central databse to verify signatures of files

If you post back your log generated i can advise what to do next with the data returned
__________________
Ade Gill
Malwarebytes Researcher
  #5  
Old December 17th, 2007, 07:59 AM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Trojan Horse BackDoor. Hupigon3.xkf

Hello Liquidslam,

Since Wilders no longer offers one on one cleaning services, I'm afraid we're going to have to refer you to one of the security forums that has active Spyware Cleaning services available.

Read the following thread and choose one of the forums listed in it, join there and they should be able to assist you:

http://www.wilderssecurity.com/showthread.php?t=42148
----------------------------

Quote:
post back your log generated
As noted in our long standing Announcement concerning HJT and\or similar logs....
Quote:
Please note that from time to time a HijackThis log may still be requested by a moderator (or specially titled forum expert) for use in other types of problem diagnosis. Only those logs requested by a Wilders Team Member will be worked on in forum
Quote:
* The restriction on posting unsolicited HijackThis logs also applies to unsolicited ASviewer (Autostart Viewer), Spybot S&D, Ad-aware, plus the new generation of Anti-Rootkit detection logs (gmer, rkunhooker, etc.) and other similar product logs.
Regards,
Bubba
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:37 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums