Showing posts with label ACL reset. Show all posts
Showing posts with label ACL reset. Show all posts

Sunday, 30 October 2011

Google redirect - Removing Zeroaccess manually and without any tools.(except to scan)

Due to popular demand to comply with official policy on the non usage of tools such as hitman pro and tdss killer, I am releasing the guide for manual removal of the sirefef Trojan. Please note that this has been tested by me only on 32 bit systems and not on 64 bit systems.
The entries created by a zeroaccess infection are given below .The zeroccess configures a service as an autostart (Highlighted)which can be used to target it like a regular virus, instead of the kernel mode rootkit it is. The next step is determining the infected driver and finding a replacement. This can be sone by using a scanning tool such as GMER and TDSSKILLER (Please do not use these tools to remove the virus as it is against policy). Once the infected driver is determined we can replace it using a clean copy from either another location within the PC or elsewhere.
1: Delete the service from the list at HKLM\SYSTEM\ControlSet001\Services\
2: Delete the process file located at the %systemroot%( its usually numbered and the process can be viewed easily.)
3: Delete the file and it autstart from HKU\SID\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
Where SID can be \S-1-5-21-2025429265-839522115-682003330-1003 or similar.
Delete the file listed in the autostart given above : its usually in the %appdata% folder and will need to be deleted forcefully.
Restart the computer and perform a full scan, you should be clean of zeroacces
Regshot 1.8.2
Comments:
Datetime:2011/10/30 17:57:17 , 2011/10/30 17:59:49
Computer:TAU-863929E6041 , TAU-863929E6041
Username:test , test
---------------------------------Keys added:5----------------------------------
HKLM\SYSTEM\ControlSet001\Services\c697803
HKLM\SYSTEM\CurrentControlSet\Services\c697803
HKU\S-1-5-21-2025429265-839522115-682003330-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\0\1\2
HKU\S-1-5-21-2025429265-839522115-682003330-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\37
HKU\S-1-5-21-2025429265-839522115-682003330-1003\Software\Microsoft\Windows\ShellNoRoam\Bags\37\Shell
----------------------------------Values added:14----------------------------------
HKLM\SYSTEM\ControlSet001\Services\c697803\Type: 0x00000001
HKLM\SYSTEM\ControlSet001\Services\c697803\Start: 0x00000003
HKLM\SYSTEM\ControlSet001\Services\c697803\ImagePath: "\systemroot\58222860:4086728700.exe"
HKLM\SYSTEM\CurrentControlSet\Services\c697803\Type: 0x00000001
HKLM\SYSTEM\CurrentControlSet\Services\c697803\Start: 0x00000003
HKLM\SYSTEM\CurrentControlSet\Services\c697803\ImagePath: "\systemroot\58222860:4086728700.exe"
HKU\S-1-5-21-2025429265-839522115-682003330-1003\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\0\1\2: 4E 00 31 00 00 00 00 00 5E 3F A2 56 13 00 52 65 63 65 6E 74 00 00 38 00 03 00 04 00 EF BE 5E 3F 0B 52 5E 3F 39 87 14 00 22 00 52 00 65 00 63 00 65 00 6E 00 74 00 00 00 40 73 68 65 6C 6C 33 32 2E 64 6C 6C 2C 2D 31 32 36 39 31 00 16 00 00 00
HKU\S-1-5-21-2025429265-839522115-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "C:\Documents and Settings\test\Local Settings\Application Data\0c697803\X"

Saturday, 15 October 2011

Google redirect-Quick and dirty guide to zeroaccess removal.

 
How to determine if the infection is by the Zeroaccess/sirefef rootkit.
1: The continuous resetting of ACLs for any most regularly used malware scanners.
clip_image002
2: The Presence of this process in the infected computer  which runs off this autostart service.
clip_image003
- Once the computer is known to be infected by zeroaccess assume that it has been compromised, and more infections are present as the Trojan opens a backdoor on the infected machine. The most common FAKE AVs found so far on computers infected with zeroaccess are open cloud and guard AVguard, Wolfram etc.
Here are the activation code for most of the associated FAKEAVs which might make disinfection
Less distracting
Code for AV Guard online, guard online, cloud protection(NEW), try any of these:
9992665263
1148762586
1171249582
1186796371
1196121858
1225242171
1354156739
1579859198
1789847197
1835437232
1837663686
1961232582
Open Cloud antivirus Code:
DB038748-B4659586-4A1071AF-32E768CD-36005B1B-F4520642-3000BF2A-04FC910B
-The presence of a FAKE AV can complicate removal, as none of the approved removal tools except combofix can defy the ACL modifications of the rootkit and therefore be protected from any regular scanners.
-Removal of zeroaccess then has to be quick and dirty, and of necessity involve a broad spectrum of scanners.
The ideal method of remediation would be as follows.
*Unless specified otherwise run all of these tools simultaneously.*
Start the computer in safe mode with networking and remove the FAKEAV autostarts manually and if possible infected files manually. We need to do this so that we can concentrate completely on removing the main infection. RESTART THE COMPUTER IN NORMAL MODE, **very important**
FYI
Using GMER to determine the infected files is possible however requires a practiced hand and can often lead to errorneous conclusions, but it is still useful to identify the driver that zaccess infects, unless the options circled in red are unchecked however the malware soon shuts down GMER and disables it.
clip_image004
As of now the only unpatched tool which is able to defend itself against the sort of techniques zeroaccess employs is TDSS Killer. However do not use TDSS Killer to try and cure the zaccess  infected driver. Use it to target the service which runs as the numbered process, and to identify the infected driver.
clip_image005
Hitman pro can resist the ACL modification only once and does not survive a reboot, therefore it has to be run simultaneously. Running hitman pro gives us the chance to identify and remove autostarts and other infections which might possibly prove dangerous, it also gives us the option to try and replace the infected driver, use this  but make sure that it is not set to delete the infected file.
clip_image006
The infected driver now needs to be replaced we can use these tools by McAfee or ESET who have made standalone removal utilities for the Zeroaccess rootkit only. Manually replacing these is possible but is not advised as it may result in loss of functionality. Both utilities are excellent however the ESET utility has been observed to have a better detection and disinfection rate. Download links for these are at end.
clip_image007
clip_image008
McAfee sirefef removal tool: http://vil.nai.com/images/562354_2.zip
Eset Sirefef removal tool: http://download.eset.com/special/encyclopaedia/ESETSirefefRemover.exe
Tausif
clip_image009

Detect autopilot session

  Ensuring that some apps only install during autopilot is not easily accomplished, you can use the below powershell script as a requiremen...