It’s been months since I have gone through the database to update the records to pick up new radio stations.
So I’m maybe 20 records into about 100 waiting to be updated, when my computer goes nuts…
The browser crashes (I’m using Firefox, not MSIE)… and then the Microsoft Security Essentials “alerts” me to this guy:
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Alureon
but it didn’t stop the infection. Then the typical “Your computer is turning into a pile of smoking rubble” messages start. I am able to boot the computer into safe mode, see that it has stuffed itself into the \application data file as a randomly named .exe and added itself to the system startup.
From the Safe mode startup, I tell it to invoke system Restore and keep my fingers crossed. Safe Mode boot was not seeing the system Restore as an option in the Programs menu.
System Restore seems to have worked, but the description above is totally creeping me out. I’m not an inexperienced or naive computer user. Maybe I now understand why people are leaving their computers turned off.
At this point, I really am not comfortable with “volunteers” following links to what should be trusted web sites, but increasingly the “real” web sites are infected with trojans.
Hello Art,
Visit the Kaspersky website, and get ‘TDSS Killer’ root-kit remover.
http://support.kaspersky.com/viruses/solutions?qid=208280684
This handy little tool is an effective -first- step when a root-kit is involved.
For WinXP, follow up with 2 or 3 separate apps/scans: Malwarebytes, SuperAntiSpyware, and then Spybot Search and Destroy if needed.
For Windows 7, run Malwarebytes, and then install the free (aka Personal) version of Avira as a resident anti-virus app.
When I did a complete scan using Microsoft Security Essentials, it found about a half dozen java related things that are fairly recent. I have a rootkit searcher that I’ll run eventually. I don’t think it did a whole lot before I caught it and started reacting.
One of my handy little tricks is when realizing that something has snuck in, do a File Search on things modified in the last day, then sort it by time… and look for anything that was updated just before and following the infection – it usually shows all the breadcrumbs left behind (other than the registry changes).
I view the antivirus companies as part of the problem (those that charge). It’s a symbiotic relationship – the more viruses there are, the more scared people are of them, and willing to pay “protection” money. It’s not a shock that the antivirus companies employ people who used to write viruses
Malwarebytes just found one additional “drop” file sitting in \local settings\temp
The thing that is why I’m exasperated is the frequency of this happening is going up, and I’m going to spend the best part of day making sure the system is “clean” again.
At an even higher level, all this activity is ultimately going to result in the “end game” that some government entity will have to be created to “protect us” from this… the same governments that created Stuxnet.
The other things MSE found were interestingly found in the cache for the [Google] Chrome browser, which I use only rarely. Based on what seemed to be involved, I suspect the entry point fo this was either Flash or Java, which is why the browser choice didn’t matter.
I don’t use MSE, prefer Avira (free) for Windows 7.
Java… very leery of it, and that’s what Android apps use.
Figured you had an arsenal, but thought I’d mention TDSS Killer. After that, if a root-kit is found (or still suspected) I inspect with HiJackThis, RootKitRevealer, or Combofix; and then scan with the anti-virus products mentioned previously.
BTW, don’t forget to clear (turn off) the pagefile.sys as well as the hiberfil.sys while disinfecting things… can’t be too careful.
Registry ‘Export’ is less than complete, so I use ERUNT.
The one problem with System Restore is it cannot export a full restore point to a DVD (a la LiveCD), so the next best option is to do it via third-party solution such as BartPE (PE Builder).
Don’t you wish Linux could do a recovery like System Restore?
Dittos on searching and filtering the date/time stamp of files.
I agree with your assessment of ‘paid’ anti-virus apps and the developers, but I think it has improved in recent years with the onslaught from Russia/China. I only use ‘free’ versions anyway.
In conversations with a few 4Chan and ‘Anonymous’ members I’ve pointed out that their activities might eventually result in mandatory authentication to get online in the future… i.e. The notion of ‘privacy’ will be respected, but ‘anonymity’ will be prohibited. Their response? (cue chirping crickets)
It wouldn’t surprise me if some part of ‘Anonymous’ is CIA.
After doing my normal list, I went and used that. It found no rookits either in normal or safe mode. MSE appears to have a process now that runs all the time specifically looking for things trying to install rootkits.
I don’t go to dodgy web sites and engage in risky things like P2P file sharing, so I mostly avoid the really nasty things. This one as merely a “Google hit” that looked plausible like it might be related to the radio station I was looking for.
Yep, been there done that a few times. 😉
I haven’t resume testing stations yet, is there a way to flag ‘infected’ links or is that a non-issue for the most part?
Not directly. Any time you add a note to a web site, it is immediately emailed to me – so if I’m awake, I’ll see it.
The most likely time visitors are exposed is when a domain expires…. suddenly sunny1093.com is pointing to some rogue site in China. I have a process that tries to catch that kind of issues, but it may not catch it for months.
In a prior case of this several years ago, I added a large note that “This web site is infected with a trojan”, only to have someone see the message and then go to the web site to see if it was true. With his computer infected, he reported that it was true.
[This was not the incident involving you :)]
WMCA’s web site was infected several times, so just being a large station is not a guarantee of safety.
After the last bout of this, I started using linux to do the testing, hoping it would be less likely to have a problem. I may have to go back to doing that…… or do web browsing under VMWare to “sandbox” things.
While Microsoft RootkitDetector was running, MSE Alerted to
Exploit:Java/CVE-2010-0840.NI
which was just added today to MSE’s definitions….. which matches my general impression that the entry point for the attack was using Java.
Wasn’t it impossible for a computer to be harmed because Java was sandboxed? [rhetorical question]
Runescape uses Java. They’ve basically declared war on the people who were writing bots, doing phishing attacks and selling gold. So it is probably worth avoiding them entirely for now so as to not be hit in the crossfire. I don’t think this was runescape related, but it might have been.
Actually, it was my brief foray into RuneScape two years ago that gave me very cold feet with Java. Soon we’ll see how well Android stands up to the malware.
FWIW, after my previous reply I began searching for PE/LiveCD solutions for Windows 7. It appears there are a few (e.g. Make_PE3) along with MS WAIK.
I remember the ZLOB infections years ago, back when I was still convinced that Microsoft was supreme. I had to remove a ZLOB infection, manually. But root-kit infections are more than viruses or trojans, and they are extremely hard to remove, from what I’ve read and heard. Kim Komando a year or two back spoke about root-kits, and she recommended a complete OS reinstallation, and wiping out all data and programs stored on or copied from infected machines, as the only sure way to be free of them once they set in. This sort of thing is the reason why I believe that cyber crimes should be classified and prosecuted as felonies with very severe penalties. These are not pranksters; they are hardcore criminals. So sorry to hear about this, Art.
Sandboxie is my next experiment.
I wasted a day (again) trying to get VMWare under Windows XP to do something helpful, only to realize that Fedora is not a supported guest OS. It got stuck trying to install VMWare tools…. recompling the linux kernel to slip in “hooks” for VMware is way beyond my pain threshhold level, unless it worked the first time, which it didn’t.
Sandboxie purports to isolate your browser (or anything else you choose to sandbox) and totally block it from updating your file system or the registry unless you give it explicit permission. We’ll see how well that works out.
Okay, I’m flummoxed…
Why not just run a virtual instance of XP for browsing, testing, etc?
FWIW, my installation of VMware Workstation 7.1 (host is Win7) shows both ‘Fedora’ and ‘Fedora 64’ on the Guest OS setup wizard, plus dozens of others.
Take note, when you install VM Tools on a Linux guest, it can take a LONG time to complete… it took 15+ minutes for my distro to build the VM Tools.
VMware Tools are not needed unless you want to use the VMware ‘Unity’ feature (guest apps appear on host’s desktop) or universal clipboard, etc.
In fact, my distro (PCLinuxOS) is not in the drop-down list; however, selecting ‘Other Linux 2.6.x’ and installing via CD worked flawlessly.
Let us know how Sandboxie works… always looking for new tools.
So far, it looks great.
Installation is very simple. Once installed, “Run sandboxed” is added on the menu choices to make it simple to run anything sandboxed. It creates a mini registry hive, and mini file system. Any changes made by anything inside the sandbox doesn’t leave the sandbox (I hope). You are given the option to copy things in/out of the sandbox if you choose (like saving bookmarks to the real favorites folder.
It sticks a [#] on each end of the window title bar, and makes the window border yellow when you mouse over it, so it is clear if the window you’re looking at is or isn’t in the sandbox.
When you’re done, you just delete the instance of the sandbox.
http://www.sandboxie.com/
Of course, the real test won’t happen until something does sneak by. It’s probably not such widely used thing that a virus/trojan writer would target it specifically to detect if it was inside the sandbox and try to evade it.
The “sandbox” itself is maintained on the C: Drive – I suspect if a trojan sneaks in, existing anti-virus things will still “alert” and block it – what the sandbox does is catches the stuff that sneaks by the existing antivirus/spyware stuff.
I have wireshark installed, which I can use to look at sneaky stuff on the internet traffic, but it’s a very complex program intended for advanced TCP/IP gurus (I’m close).
What Windows needs (maybe Win7 has it) is a simple utility to monitor and control outbound TCP/IP connections. Firewalls work on the principle that anything in the “safe” area can be trusted and if it connects outbound to some remote server, that is not a problem and things don’t need to be monitored. ZoneAlarm used to do that (maybe still does), but for the casual user who doesn’t undestand their computer, after a few times, they just automatically click “Is it okay if ‘x’ does ‘y’?”
Really basic things like not allowing executables to run from data directories or temporary folders is pretty obvious. I don’t want Unix security, but a little basic security would go a long way. They completely botched the notion of a “limited user” by not doing it from win 3.1 onward.
Why again did Microsoft go away from the idea of application programs doing configuration in .ini files in the installation directory and steer applications to store everything inside the Registry? I suspect that was to make remote management of corporate desktops simpler – but if registry updates were rare (like only when you installed a new program), then things couldn’t sneak into the abyss of the hive to hide.
Art, visit SysInternals at MS and try TCPView (or the entire SI suite)… you might find some useful Win tools.
It appears Mark Russinovich is ‘back in the saddle’ and has been busy updating his Windows system utilities.
http://technet.microsoft.com/en-us/sysinternals
Regarding .ini configuration vs the Registry; I think the move was two-fold: to complicate things for the hacks, and to prevent people from copying the app directory & ini files to other machines (i.e. licen$ing in$tallation$).
I have process explorer sitting on my desktop…. I already used netstat to look at network connections – I wonder the degree to which the TCP/IP stack can be compromised – by Microsoft as well as others – to hide certain transmissions of data.
Monitoring is nice, but control is the issue. It takes but a millisecond for some process on your PC to open a UDP port and blast out information to somewhere in China or Eastern Europe. You’ll never see it happen.
A person I talk to recently bought a wireless printer, and noticed how it was able to get right onto his secured wireless network without any messy key exchanges, and immediately connected him to his account at a web site where pictures are stored.
I’ve heard stories (I accept that it is probably true) that most currency is encoded with a watermark so that if you attempt to scan money in a color scanner, the firmware shoots off a message to the authorities without your knowledge. I’m not advocating counterfeiting, but if it can be done for that reason, there really isn’t anything your computer couldn’t be told to do against your will or consent. We’ve talked in the past about remote activation of cameras and microphones.
My old linksys router used to have a View Log facility that would show all inbound and outbound TCP connections, but later versions stripped post of that out and now I’m on an AT&T provided uVerse router. All of this “security” is based on the premise that the job of security is to keep the bad guy from breaching the perimeter.
The key to Houdini’s bank vault “escapes” is that everything is outbound facing – it protect the inside of the vault from someone getting in. It is not designed to keep a person inside the vault from getting out.
Art, to block outbound tcp/udp, try NetLimiter 3 Pro.
http://www.netlimiter.com/featurelistnl3.php
That is what I’m using…
My cat uses Litterboxie. (Sorry, it’s late and I felt compelled.)