Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 28th, 2009, 11:12 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Malicious link with Opera

When I go to this page with Opera via a google search, suddenly Opera tries to acees a lot reg enteries, maily related to disbling an AV running on the sytem I think. I came to know this from geswall.

hxxp://www.bleepingcomputer.com/files/adsspy.php

Can anyone check this page? Alos click on download ADS Spy link.

May be this link is causing trouble or my recent play with a lot of malware left some nasty remnants. It,s more of a test XP SP2 installation.

I have good image backup on an external but just curious to know what is this infact.

Thanks
Attached Images
 
Attached Files
File Type: txt log.txt (52.4 KB, 11 views)
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by aigle : August 28th, 2009 at 11:45 PM.
  #2  
Old August 28th, 2009, 11:48 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,620
Default Re: Malicious link with Opera

Just went there with Opera 9.64 and encountered no problems or warnings. running XP sp2
Attached Images
  
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #3  
Old August 28th, 2009, 11:49 PM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Malicious link with Opera

Just tried the link with Opera 10 RC and I get an error.
The address type is unknown or unsupported

Tried again and it connects.
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #4  
Old August 28th, 2009, 11:55 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,632
Default Re: Malicious link with Opera

I tried with Opera 9.64 and IE6 and nothing happens out of the ordinary. I don't see anything about redirects in the source code.

----
rich
  #5  
Old August 29th, 2009, 12:17 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

thanks. So some thing wrong on my system. By the way, can you try to download and save it to desktop until it it's complete. Then wait a few min.
Thanks
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #6  
Old August 29th, 2009, 12:52 AM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,632
Default Re: Malicious link with Opera

Download what?

----
rich
  #7  
Old August 29th, 2009, 01:13 AM
The_1337's Avatar
The_1337 The_1337 is offline
Regular Poster
 
Join Date: Aug 2007
Posts: 108
Default Re: Malicious link with Opera

I'm using Opera 10 RC2 and I downloaded the file and nothing happened.
  #9  
Old August 29th, 2009, 02:34 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

Thanks all. As i said, i was going to restore am image. It's sure on my system only.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #10  
Old August 29th, 2009, 02:43 AM
thathagat
 
Posts: n/a
Default Re: Malicious link with Opera

Quote:
Originally Posted by aigle
Thanks all. As i said, i was going to restore am image. It's sure on my system only.
hey....agile did you run some scans: prevx/hitman/mbam etc so as to find what it is....?
  #12  
Old August 29th, 2009, 01:41 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

Seems i figured it out. I tried many things.

1- Antivir free- can,t update due to some rerason. Nothing found
2- MBAN- can,t update, nothing found except hijacked reg enteries
3- Hostman- nothing found
4- Prevx- nothing found
5- SAS- can,t update, nothing found
6- gmer seems clear
7- IceSword will not run
8- RootRpeal showed a hidden driver
9- An autostart reg entery in Autoruns with no associated file

Seems a rootkit( however I am not an expert and not sure about my findings) that uses different processes n browsers to download tons of malware from internet. It,s at this point that Antivir, Prevx, MAM, SAS etc start catching the stuff.

I tried a lot of malware recently in last week, seems something got loose from me. Anyway going to restore a fresh image.

Name:  v (1).png
Views: 378
Size:  21.3 KB
Name:  v.png
Views: 382
Size:  23.2 KB
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?

Last edited by aigle : August 29th, 2009 at 01:51 PM.
  #13  
Old August 29th, 2009, 11:57 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: Malicious link with Opera

Both your atapi.sys show 95,360 bytes and they are in the same space.

What are you trying to show us in Autoruns ?

Have/can you copy/save atapi.sys with an ARK so others can take a look at it ?

-

" Description: atapi.sys is located in the folder C:\Windows\System32\drivers. Known file sizes on Windows XP are 95,360 bytes (95% of all occurrence), 96,512 bytes.

The driver can be started or stopped from Services in the Control Panel or by other programs. It is a Windows system file. The program is not visible. The service has no detailed description. File atapi.sys is a trustworthy file from Microsoft. Therefore the technical security rating is 18% dangerous, however also read the users reviews.

Some malware camouflage themselves as atapi.sys, particularly if they are located in c:\windows or c:\windows\system32 folder. "

http://www.file.net/process/atapi.sys.html
  #14  
Old August 30th, 2009, 12:04 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

In the autoruns there is any entery with no file. It,s about:Home. About atapi.sys, may be it,s just a false positive from rootrepeal though malware sure looked like a rootkit from the OS and different applications behaviour. I was not able to copy it via rootrepeal.

Anyway sorry to bother u all and thanks for ur kind replies. I was just fed up and have restored a clean image already.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #15  
Old August 30th, 2009, 12:12 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Thumbs up Re: Malicious link with Opera

The autorun entery with no file about:Home was nothing to worry about, i've had it and deleted it, doesn't hurt anything to get rid of it.. It happens when you customise/change your start page.

No bother, only wish i'd posted earlier !

Glad you got it sorted anyway.
  #16  
Old August 30th, 2009, 07:35 AM
Mapson Mapson is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 54
Post Re: Malicious link with Opera

aigle, see if the live cd from Dr Web identifies anything:

http://www.freedrweb.com/livecd

As it boots from CD with it's own OS it can 'see' all files that may be hidden by a rootkit.
  #17  
Old August 30th, 2009, 09:39 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

before an image restore i tried dr.web cureit and found nothing.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #18  
Old August 30th, 2009, 09:47 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

Interestingly i have solved the mystery how i got it. As a matter of fact i got it again.
It's a malware that i am playing with recently under shadow mode of shadow surfer. It's bypassing the shadow mode and is still there after a reboot.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #20  
Old August 30th, 2009, 11:11 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Malicious link with Opera

I have no VM but I have image backups on an external, so it,s OK anyway.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:44 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums