Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 3rd, 2009, 03:02 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default I got Rooted in Vista !!!

Yes in Vista and with IE8 and UAC, just the other day !

It all started so innocently. I Googled for a very well know carpet store hxxp://www.alliedcarpets.com/storelocator.aspx and clicked on the genuine link. ( Rmus kindly checked out the link and reported back that he didn't find/see anything dodgy ) Almost immediately after reaching there, Avira popped up with a Heuristic jscript warning.

As it was Heuristic i thought it might be a FP, and clicked ignore. Yes i know lol. Nothing obvious or out of the ordinary appeared to be happening, and i continued viewing the site for only about a minute. Of course by that time it would be way to late ! Anyway i carried on surfing some regular safe sites, like here, and after about an hour i shut down the PC as i had to go out.

When i came back and rebooted, i noticed the HD wasn't making the usual noises. The log on screen appeared and i logged on, in Admin as usual. As the desktop appeared i saw the taskbar looked faded compared to normal, and some of my Apps hadn't started, including ZoneAlarm. Also Avira had been disabled, and even worse was greyed out. I knew something wasn't right but what ?

As i'm also using a router, i launched a browser and attempted to go online to see if i could. Didn't work, and looking at the routers Led's i saw problems there too. Oh dear !

Went to do a System Restore, but they had ALL gone, now what ? As this PC ( Vista ) isn't mine i felt awful, especially as they would want to use it later on. I rebooted and went into SafeMode, with networking, still no sign of them, and stayed in SM. Launched IE and had no problems this time getting out through the Router to the web.

I have a USB stick with lots of portable security Apps on it. So i plugged it in and updated MBAM, SAS and a2 then scanned in turn, but didn't delete yet as i wanted to see what they all found first. They all detected various things connected with a Bagle nasty and a Trojan. In the heat of the moment i can't have taken any a2 pics, or lost them !

I located the nasties and uploaded the two .SYS to VT. Notice how the file names are different to what i Actually sent ?

uzmwmzg5.sys = uzi4ndaz.sys

utmwmzg5.sys = 11s11ro1s1a2sergio.sys

perce.gif

Deleted all the nasties.

Also ran several other Apps afterwards such as, avz4, Autoruns, HJT, ADS Scanner Version 2.00, mbr v0.3.1 and some ARK's. GMER, Kernel Detective v1.2, RootRepeal v1.2.3.0. I didn't see anything unusual.

In the end there turned out to be too much damage to try and waste time repairing. I reinstalled from the backup drive, and other places, and back now as good as new.

The only other recent change made to this PC, was to install Skype yesterday. Only added 2 video contacts to test, which went very smoothly and worked fine first time. Having said that, even though i set it reject all but in the contacts, 2 unknown messages got through. How did they get in ? They were both from sex chat/contact sites lol. I copied the obsufcated links and pasted into IE to see, very enlightening. Still got them if you wanna have a look, for research purposes of course !

Was it the furniture www Script, something received via Skpye or ? I don't know. But as the problems visibly appeared after the Avira warning and my reboot, i'm presuming it might have been the furniture www that has/had been compromised somehow. If so then my fault for ignoring the prompt from Avira.

The strange thing though, is that in the VirusTotal scan Avira is a No show for this Bagle ? So i'm still not sure exactly where it came from.

What an adventure !


Sreenies to follow
  #2  
Old July 3rd, 2009, 03:04 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

1st Screenies
Attached Images
    
  #3  
Old July 3rd, 2009, 03:09 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

2nd lot

~VirusTotal screenshots removed~
Attached Images
  

Last edited by ronjor : July 3rd, 2009 at 03:22 PM. Reason: Remove VirusTotal screenshots
  #4  
Old July 3rd, 2009, 03:51 PM
kC_'s Avatar
kC_ kC_ is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 436
Default Re: I got Rooted in Vista !!!

you sound surprised?
  #5  
Old July 3rd, 2009, 04:19 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

Re the VT screenies that have been removed !

utmwmzg5.sys = 11s11ro1s1a2sergio.sys was only detected by 18 out of 41

uzmwmzg5.sys = uzi4ndaz.sys was a no detect by any.

I should have originally added, VT stated both files had been scanned before and i clicked to show those results.

@ kC, without the Sunshine band. Nice tunes !

Yes and no ! Mostly yes.

EDIT

SAS must have been run in Safe Mode, as it's not a PA. Sorry for any confusion there.
  #6  
Old July 3rd, 2009, 04:26 PM
zopzop's Avatar
zopzop zopzop is offline
Frequent Poster
 
Join Date: Apr 2006
Posts: 594
Default Re: I got Rooted in Vista !!!

@StevieO

I can confirm that the link is clean. I went there and nothing out of the ordinary happened (a fully updated Avira was quiet). I think you got that rootkit elsewhere.
__________________
Current Security Apps -
Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand)

LUA+SRP+KAFU = WIN!!!111
  #7  
Old July 3rd, 2009, 05:10 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

It's a mystery !!!

But the main thing is, look what they did to " MS's safest OS ever " as touted pre launch by Bill Gates and baldy ? And running the " safest IE ever " with no ActiveX, iframes etc enabled, and UAC.

zopzop

You just nudged me into going there again, and this time i didn't get the Alert i got before.

So either it was a FP originally and Avira fixed it, or there was something but it got removed by the IT peeps ?

If niether then, lord knows where that crap came from. I wasn't emailing, downloading anything etc etc.
  #8  
Old July 3rd, 2009, 06:12 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: I got Rooted in Vista !!!

Can u share the samples( just PM)? Thanks
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #9  
Old July 3rd, 2009, 07:52 PM
arran's Avatar
arran arran is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 1,092
Default Re: I got Rooted in Vista !!!

can you me pm me the samples as well?
__________________
Win7 64bit Ultimate
Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt |
FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar
  #10  
Old July 3rd, 2009, 08:02 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,353
Default Re: I got Rooted in Vista !!!

This isn't a malware trading forum. Take your messages private. Thanks.
  #11  
Old July 3rd, 2009, 08:19 PM
Wildest's Avatar
Wildest Wildest is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 304
Default Re: I got Rooted in Vista !!!

Quote:
Originally Posted by StevieO
Almost immediately after reaching there, Avira popped up with a Heuristic jscript warning.
Quote:
But as the problems visibly appeared after the Avira warning and my reboot, i'm presuming it might have been the furniture www that has/had been compromised somehow. If so then my fault for ignoring the prompt from Avira.
Quote:
The strange thing though, is that in the VirusTotal scan Avira is a No show for this Bagle ?
Whoa!!

Correct me if I am wrong, but does this imply that there is some value to Avira's WebGuard?
I have read many post here that WebGuard is just marketing gimmick but this seems to be proof to the contrary?
  #12  
Old July 3rd, 2009, 09:59 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,632
Default Re: I got Rooted in Vista !!!

Hi StevieO,

The AV message with the Heuristic jscript warning for jquery.js could have been a false alert. Wepawet reports it as free from the normal stuff:

Quote:
Analysis report for jquery[1].js

Detector Result
Jsand 1.03.02 benign
No exploits were identified.
No evals.
No objects/controls.
No shellcode was identified.
No additional malware was retrieved.
The AV may have responded to the packed code, which is common in both legitimate and malicious javascript files (search for jquery for a description).

Code:
eval(function(p, a, c, k, e, r) { e = function(c) { return (c < a ? '' : e(parseInt(c / a))) + ((c = c % a) > 35 ? String.fromCharCode(c + 29) : c.toString(36)) }; if (!''.replace(/^/, String)) { while (c--) r[e(c)] = k[c]e(c); k = [function(e){ return r[e] } ]; e = function() return '\\w+' };c = 1 };while (c--) if (k[c])p.replace(new RegExp('\\b' + e(c) + '\\b', 'g'),

Usually an injected script on the main page will call out to a malicious server for a rigged javascript file. alliedcarpets.com loads jquery.js directly from its server:

Code:
script src="/Scripts/jquery.js"
This would a typical malware injection:

Code:
script src="http://www.3ttgfor.com/jquery.js"
As you say, it's possible that it has been cleaned up, but I checked yesterday when you notified me by PM. You didn't mention the alert for the jquery.js file so I didn't look at it at that time. Unless you had zipped all of the cached files immediately for later analysis, all at this point is speculation.

Quote:
i continued viewing the site for only about a minute. Of course by that time it would be way to late ! Anyway i carried on surfing some regular safe sites, like here, and after about an hour i shut down the PC as i had to go out.
In this case, how do you know it happened while viewing alliedcarpets.com? Did you check the file creation date/time for the files? That would tell you whether or not the malware installed on your watch!

Regarding rootkit.bagle:

Everything I've seen written about rootkit.bagle shows this malware to be delivered via e-mail messages, file-sharing networks, and downloader sites piggy-backing on something else. It's hard to imagine that this could have sneaked in as a drive-by download - Websense, f-secure, would be all over something like this.

Quote:
Originally Posted by StevieO
But the main thing is, look what they did to " MS's safest OS ever " as touted pre launch by Bill Gates and baldy ? And running the " safest IE ever " with no ActiveX, iframes etc enabled, and UAC.
In tests, I've seen UAC effectively block anything from writing to a system directory. I don't see that this exploit goes anywhere on VISTA with UAC unless installation privileges were granted.

Could this have happened when another user was on the computer?

regards,

rich

Last edited by Rmus : July 4th, 2009 at 12:22 AM.
  #13  
Old July 4th, 2009, 01:30 AM
innerpeace's Avatar
innerpeace innerpeace is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: Mountaineer Country
Posts: 1,942
Default Re: I got Rooted in Vista !!!

StevieO, Is there any particular reason your running as Admin on your Vista system? If not, try setting your daily use account as User. I setup my sis's Vista rig like that and she hasn't had a problem so far.
__________________
XP Home SP3, Nat router, Firefox3.5, Online Armor Premium 4.5, AntiVir 9 free, Sandboxie, and Returnil RVS
Are you running vulnerable programs? Check online now with the Secunia Online Software Inspector.
  #14  
Old July 4th, 2009, 07:31 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

Wildest

Avira's WebGuard is far from any marketing gimmick. I've lost count on the amount of times it's detected real things on infected www's. Those were no FP's either. www's with verified nasties, and also ones that were later confirmed to be.

Rmus

Yes it could have been a packed code detect. I thought i'd mentioned i got a Heuristic jscript alert from Avira ? I didn't check the file creation date/time. Looks like this " exploit " didn't go anywhere on VISTA with UAC afterall. Thanx for posting the code etc.

innerpeace

I've run as Admin since 98SE days, and just prefer it, no noise. Never had any problems doing so.

----------

Well guess what ?

On further checking utmwmzg5.sys and utmwmzg5.sys look as if if they are connected with AVZ. In which case all those detects by the Apps i scanned with were and are FP's !

So that leaves perce.gif that was detected, which i don't have now, but probably wasn't a nasty. And it was a .GIF as i have show extentions etc enabled.

What does this all mean then ? Well either i was hit with some new unknown zero day nasty from i don't know where, or the PC went wibbly wobbly. Could have been a temp hardware issue i suppose, but i doubt it.

Wish i knew what really happened. But ones things for sure, something/s did and then several Apps detected the same files as nasties. How wierd.
Attached Images
 
  #15  
Old July 4th, 2009, 08:09 PM
1boss1's Avatar
1boss1 1boss1 is offline
Frequent Poster
 
Join Date: Jun 2009
Location: Australia
Posts: 401
Default Re: I got Rooted in Vista !!!

Out of curiosity i reversed the packer on the jquery.js script to check the plain source: http://pastebin.com/m7c0b3e24

It mainly just deals with forms, layout data, browser compatibility etc. Something "could" of happened at the particular time you were on the site, but it's more than likely your problems stemmed from elsewhere.
__________________
Malware Defender
  #16  
Old July 9th, 2009, 05:11 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

1boss1

Thanx for doing that, and the info.
  #17  
Old July 9th, 2009, 05:19 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

utmwmzg5.sys Malware or what ?

Latest results from a few hours ago -

At least 17 vendors are seeing this file as Malware, for eg -

RK Bagle, Trojan unknown, Trojan.Rootkit.Agent

Now either it's a Major FP from all of them, or they are missing a Real serious threat. Whichever way it's not good.

I still have this file if any vendors etc wish to test it.
  #18  
Old July 9th, 2009, 08:15 AM
Windchild's Avatar
Windchild Windchild is offline
Frequent Poster
 
Join Date: Jun 2009
Posts: 563
Default Re: I got Rooted in Vista !!!

Quote:
Originally Posted by StevieO
utmwmzg5.sys Malware or what ?

Latest results from a few hours ago -

At least 17 vendors are seeing this file as Malware, for eg -

RK Bagle, Trojan unknown, Trojan.Rootkit.Agent

Now either it's a Major FP from all of them, or they are missing a Real serious threat. Whichever way it's not good.

I still have this file if any vendors etc wish to test it.

You might want to send it in for analysis, then, to such vendors that detect it only heuristically or as "suspicious" or similar.

One thing is sure, though. Any .sys file that resides in a user profile folder is inherently extremely suspicious. Basically, it is almost certainly one of two things: either it's malware, or it's part of some anti-malware/anti-rootkit/similar thing that probably wasn't programmed all that well and may be a hazard in itself even if it isn't malware.
__________________
Save your tears, for your tears will not save you :: Shameless LUA troll
  #19  
Old July 9th, 2009, 11:14 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: I got Rooted in Vista !!!

Quote:
Originally Posted by StevieO
utmwmzg5.sys Malware or what ?

Latest results from a few hours ago -

At least 17 vendors are seeing this file as Malware, for eg -

RK Bagle, Trojan unknown, Trojan.Rootkit.Agent

Now either it's a Major FP from all of them, or they are missing a Real serious threat. Whichever way it's not good.

I still have this file if any vendors etc wish to test it.
Why u think them malware while they are shown to be part of AVZ?
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #20  
Old July 9th, 2009, 01:28 PM
zopzop's Avatar
zopzop zopzop is offline
Frequent Poster
 
Join Date: Apr 2006
Posts: 594
Default Re: I got Rooted in Vista !!!

Did anyone contact the maker(s) of AVZ and the various antivirus vendors to report this as a false positive?
__________________
Current Security Apps -
Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand)

LUA+SRP+KAFU = WIN!!!111
  #21  
Old July 9th, 2009, 05:35 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: I got Rooted in Vista !!!

Windchild

Sending that file to ALL those vendors is i'm afraid unrealistic. If we were allowed to post online scan images on here then hopefully some/all the vendors would find out it's a FP, and fix it sooner or later.

Uploading to VT/Jotti etc is a good way to reach all the vendors listed as the files get forwarded to them afterwards. But obviously they only respond to files they interpret as Malware. As it stands FP's such as this will always have to wait. Pity Jo average who gets alerted with FP's and deletes something/s critical etc !

Yes it's an anti-malware/anti-rootkit .SYS file in AVZ.

aigle

Because of the initial above alert i got from Avira, which led me to scan locally with amongst others, MBAM/SAS. I then uploaded the detected files to VirusTotal & Jotti, and nearly half those vendors then detected Rootkit Bagle etc.

zopzop

I havn't contacted AVZ as yet, but will do. See above about contacting ALL the vendors.

Thanx to everyone for your patience regarding this adventure, which i don't want to repeat any time soon !
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:39 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums