donderdag 22 september 2011
Noodpatch voor Adobe Flash Player
Adobe brengt een noodpatch uit voor een door Google ontdekt Flash-lek dat reeds actief wordt misbruikt. Naast dat kritieke lek dicht het ook grote gaten, in Flash en Reader.
Adobe raadt iedereen aan om onmiddellijk te updaten naar de net verschenen nieuwste Flash-versie. Dat is versie 10.3.183.10.
dinsdag 16 augustus 2011
Anti Malware Help veranderd van URI
http://www.antimalwarehelp.be/
Nu ook in het Engels.
U can find Anti Malware Help from today of on this URL adres:
http://www.antimalwarehelp.be/
English and Dutch
dinsdag 26 juli 2011
ShellServiceObjectDelayLoad
ShellServiceObjectDelayLoad
Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
Instead of pointing to the file itself, it points to the CLSID's InProcServer, which contains the information about the particular DLL file that is being used.
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
@="C:\\Windows\\System32\\webcheck.dll"="WebCheck"
[HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32]
@="C:\\Windows\\System32\\webcheck.dll"
"ThreadingModel"="Apartment"
The trouble is that with Windows 7, the CLSID's InProcServer {E6FB5E20-DE35-11CF-9C87-00AA005127ED} doesn't exist.
If we try too look for {E6FB5E20-DE35-11CF-9C87-00AA005127ED} in
[HKEY_CLASSES_ROOT\CLSID\] we won't find it.
So, where did it go ?
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00C6D95F-329C-409a-81D7-C46C66EA7F33}"=""
"{80009818-f38f-4af1-87b5-eadab9433e58}"="MF ADTS Property Handler"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler" <<<< This is interesting !!!
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck" <<<< Here we have our "old" CLSID
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
So lets check out "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{08165EA0-E946-11CF-9C87-00AA005127ED}]
@="WebCheckWebCrawler"
[HKEY_CLASSES_ROOT\CLSID\{08165EA0-E946-11CF-9C87-00AA005127ED}\InProcServer32]
@="C:\\Windows\\System32\\webcheck.dll" <<<< There we have it !!!!
"ThreadingModel"="Apartment"
So MS changed the CLSID for webcheck.dll, thats why we couldn't find webcheck.dll on his "old" place.
Emphyrio :)
woensdag 22 juni 2011
Windows update probleem (KB2478663 en KB2518870- Juni 2011)
Meerbepaald de beveiligingsupdate voor Microsoft .NET Framework 4.
KB2478663 .
Manueel installeren is hier de boodschap.
KB2478663 en KB2518870
Let goed op want er zijn drie verschillende builds, je moet
dus enkel diegene downloaden die voor jouw systeem geschikt is.
Bijvoorbeeld:
- NDP40-KB2478663-IA64.exe Itanium processor
- NDP40-KB2478663-x64.exe 64 Bits
- NDP40-KB2478663-x86.exe 32 Bits
Downloaden naar je bureaublad.
Dubbelklikken en installeren.
OPMERKING :
Vista en W7 gebruikers: rechtsklikken en kiezen voor Uitvoeren als administrator.
Besturingssystemen:
Windows 7;Windows Server 2003;Windows Server 2008;Windows Server 2008 R2;Windows Vista;Windows XP
dinsdag 17 mei 2011
TDL4 infectie op Windows 7-32bits
bedoeld voor malware analysten.
Het is geenszins de bedoeling deze procedure te gebruiken als gewone gebruiker.
Naar aanleiding van een rogue besmetting (Anti Malware Doctor), zette ik rkill en MBAM (volledige scan) in.
MBAM log was clean.
TDSSKiller gaf echter aanduiding van een TDL besmetting.
Uit de TDSSKiller log las ik dat hij deze verwijderde.
Omdat de TS géén antivirus had geinstalleerd, advizeerde ik hem/haar dit alsnog te doen.
Avira Antivir melde een aanwezigheid van een Rootkit en een Vundoinfectie.
Starting master boot sector scan:Master boot sector HD0
[DETECTION] Contains code of the BOO/TDss.M boot sector virus
[NOTE] The boot sector was not written!Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:Boot sector 'C:\'
[DETECTION] Contains code of the BOO/TDss.M boot sector virus
[NOTE] The boot sector was not written!
Starting to scan executable files (registry).
The registry was scanned ( '1711' files ).
Starting the file scan:
Begin scan in 'C:\Windows\system32'C:\Windows\system32\dsdmol.dll
[DETECTION] Is the TR/Vundo.Gen2 Trojan
Beginning disinfection:C:\Windows\system32\dsdmol.dll
[DETECTION] Is the TR/Vundo.Gen2 Trojan
[WARNING] The file could not be copied to quarantine!
[WARNING] The file could not be deleted!
[NOTE] The file is scheduled for deleting after reboot.
The repair notes were written to the file 'C:\avrescue\rescue.avp'.
Was opzich merkwaardig omdat MBAM hier geen melding van had gemaakt.
CF ingezet en een ongeldige Netsvc gevonden.
.....
R2 cchdohew;Crcdisk Filter Helper;c:\windows\System32\svchost.exe [2009-07-14 20992]
.....
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
cchdohew
Deze verwijderdt met een CFScript gevolgd door een tweede maal TDSSKiller.
De CF log was clean, TDSSKiller vertoonde de zelfde handelingen als ervoor.
Blijkbaar was TDSSKiller niet instaat deze te verwijderen.
aswMBR.exe ingezet.
Deze toonde netjes de Rootkit (TDL4) infectie en verwijderde die na een aswMBR fix.
aswMBR version 0.9.5.256 Copyright(c)
2011 AVAST SoftwareRun date: 2011-05-10 21:40:35-----------------------------
21:40:35.762 OS Version: Windows 6.1.7600
21:40:35.762 Number of processors: 2 586 0xF0B
21:40:35.764 ComputerName: FRANCA-PC UserName: Franca
21:40:36.212 Initialize success
21:40:42.836 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
21:40:42.838 Disk 0 Vendor: WDC_WD16 04.0 Size: 152627MB BusType: 3
21:40:42.853 Disk 0 MBR read successfully
21:40:42.856 Disk 0 MBR scan
21:40:42.859 Disk 0 TDL4@MBR code has been found
21:40:42.862 Disk 0 Windows 7 default MBR code found via API
21:40:42.866 Disk 0 MBR hidden
21:40:42.869 Disk 0 MBR [TDL4] **ROOTKIT**
21:40:42.873 Disk 0 trace - called modules:
21:40:42.878 21:40:42.882 Scan finished successfully
21:41:06.713 Disk 0 MBR has been saved successfully to "C:\Users\Franca\Desktop\MBR.dat"
21:41:06.714 The log file has been saved successfully to "C:\Users\Franca\Desktop\aswMBR.txt"
TDSSKiller was na deze handeling eveneens "clean".
http://www.nucia.eu/forum/showthread.php?t=63609
woensdag 11 mei 2011
Facebook lekt jarenlang persoonlijke data
Meer dan 100.000 applicaties hebben toegang tot de persoonlijke data van Facebookgebruikers.
Daardoor hebben adverteerders en app-aanbieders die informatie mogelijk al in handen.
Facebook gebruikt sindsdien oauth2.0 voor de authenticeren van de gebruiker.
Dat protocol is veiliger.
Het is aan te raden om je wachtwoord te veranderen.
Daardoor worden de tokens ongeldig verklaard en vraagt de applicatie bij een volgend gebruikpnieuw toestemming om toegang te krijgen tot de persoonlijke pagina’s.
Maar dan wordt dus oauth2.0 gebruikt.
zaterdag 29 januari 2011
Valse AVG Antivirus 2011
Lees meer erover in de Rogues Verwijder Instructies op Anti Malware Help.
*Een rogue is een malware tool dat pretendeert een AV tool te zijn.
zondag 27 juni 2010
Whistler Bootkit (English)
Use Combofix only in collaboration with a Qualified Helper.
Please bare in mind that following instructions is for Qualified Helpers.
If You are not, take counseling at one of the Hijackthis fora.
Don't try this fix if Your system has a factory MBR or Multiboot.
Not long ago I came across the Whistler Bootkit in a Hijackthis log.
This very aggresieve malware takes over the PC.
Gmer, The Avenger 2, Combofix,.. didn't give any solution.
Nor did a System Recovery !
Next symptoms are visible:
Kaspersky :
HEUR: Trojan.Win32.Generic in de C:\System Volume Information folder
Dr Web :
smss.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 No recovery.Replaced
svchost.exe C:\System Volume Information\Whistler Win32.HLLC.Asdas.8 No recovery.Replaced
In Hijackthis, one can notice the following:
Running processes:
C:\System Volume Information\Whistler\svchost.exe
C:\System Volume Information\Whistler\smss.exe
or after a system recovery :
C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exe
C:\System Volume Information\_restore{d5fffa500b1b}\smss.exe
Combofix shows us :
------------------------ Other active processes------------------------
c:\system volume information\_restore{d5fffa500b1b}\svchost.exe
c:\system volume information\_restore{d5fffa500b1b}\smss.exe
(or C:\System Volume Information\Whistler\svchost.exe
C:\System Volume Information\Whistler\smss.exe )
The Startup list of Hijackthis shows the following (if systemrecovery was used)
Windows NT 'Wininit.ini' :
PendingFileRenameOperations: C:\System Volume Information\_restore{d5fffa500b1b}\svchost.exeC:\System Volume Information\_restore{d5fffa500b1b}\smss.exeC:\System Volume Information\_restore{d5fffa500b1b}\SMSS.EXEC:\System Volume Information\_restore{d5fffa500b1b}\SVCHOST.EXE
The PendingFileRenameOperations value under [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] wasn't present.
Combofix en The Avenger deletes the two files, but after a reboot they immediately came back..
Identification:
Intensive search on Google learns me that I have to deal with a Whistler Bootkit.
The solution:
Because this one hides himself in the bootsector , speed and accuracy is of the most importance.
Step 1
Downloadt bootkit_remover.rar (INFO)
Unzip the file.
Open the directory map bootkitremover en double click on remover.exe.
Post whats appears on the screen. (copy & paste)
Step 2
A infected bootsector looks like this:
Bootkit Remover version 1.0.0.1
(c) 2009 eSage Lab
http://www.esagelab.com/
\\.\C: ->
\\.\PhysicalDrive0
MD5: 274955059efe9236c07688c5ff9242b2
Size Device
Name MBR Status
--------------------------------------------
74 GB
\\.\PhysicalDrive0 Unknown boot code
Unknown boot code has been found on
some of your physical disks.
To inspect the boot code manually, dump the
master boot sector:remover.exe dump [output_file]
To disinfect
the master boot sector, use the following command:remover.exe fix
This line gets my immediately attention : \\.\PhysicalDrive0
Before moving on with the repair, doublecheck this with MBRcheck:
Download MBRCheck.exe towards your desktop.
Dblclick MBRCheck.exe.
If You get a message rapport, typ N and Enter.
Enter again.
On your desktop You will find MBRCheck_mm.dd.yy_hh.mm.ss .
If it look something like this :
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: MAXTORSTM380815AS, Rev: 3.AAD
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: F238F1FE114296B6DC7716517DC1DADB3FF3D5C6
Done!
Then we are done !
Else, follow the next instructions.
We remove this by writing a batch with a switch for remover.exe :
@ECHO OFF
START remover.exe fix \\.\PhysicalDrive0
EXIT
By executing this batch, the PC has to reboot immediately.
Its is very important that the TS does this because of the possibility of reinfection.
One can also implement the DOS command SHUTDOWN -r into the batch:
@ECHO OFF
START remover.exe fix \\.\PhysicalDrive0
SHUTDOWN -r
EXIT
After a reboot, ask the TS to run remover.exe again and let him post the remover.exe log.
If everything was going ok, the log must look like this:
Bootkit Remover version 1.0.0.1
(c) 2009 eSage Lab
http://www.esagelab.com
\\.\C: -> \\.\PhysicalDrive0
MD5: 6def5ffcbcdbdb4082f1015625e597bd
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 OK (DOS/Win32 Boot code found)
Double check it with Gmer and Hijackthis.
Its recommended to let the TS change his passwords.
Emphyrio :)
Thanks to Marckie for support me with this difficult infection .