A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15206  by EP_X0FF
 Wed Aug 15, 2012 10:42 am
360Tencent wrote:http://www.symantec.com/connect/blogs/t ... en-ntfs-ea
Throughout Zeroaccess’ life span we have seen several novel techniques that posed various challenges; however, the antivirus industry has quickly adapted and responded with new technologies.
and

http://blog.trendmicro.com/zaccesssiref ... technique/

...
Exact two months after complete investigation they finally poped up some articles with noob screenshots and noob findings. GJ.
 #15281  by thisisu
 Tue Aug 21, 2012 4:03 pm
When experimenting with this malware, has anyone else noticed that desktop icons get repositioned on their own after a reboot?

I will give you some examples:

http://forums.majorgeeks.com/showpost.p ... ostcount=6
http://forums.majorgeeks.com/showpost.p ... stcount=11
http://forums.majorgeeks.com/showpost.p ... stcount=19
http://forums.majorgeeks.com/showpost.p ... ostcount=1 (Read title of thread)

It happens on both live and VMs for me, but I do not know what needs to be reverted in order to fix it. I'm guessing it is a certain registry value :?

Thanks for any help on this.
 #15283  by Win32:Virut
 Tue Aug 21, 2012 5:44 pm
I'm not sure, but please try (I don't know much about malware removing):
Code: Select all
reg delete HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /f
thisisu wrote:When experimenting with this malware, has anyone else noticed that desktop icons get repositioned on their own after a reboot?

I will give you some examples:

http://forums.majorgeeks.com/showpost.p ... ostcount=6
http://forums.majorgeeks.com/showpost.p ... stcount=11
http://forums.majorgeeks.com/showpost.p ... stcount=19
http://forums.majorgeeks.com/showpost.p ... ostcount=1 (Read title of thread)

It happens on both live and VMs for me, but I do not know what needs to be reverted in order to fix it. I'm guessing it is a certain registry value :?

Thanks for any help on this.
 #15284  by thisisu
 Tue Aug 21, 2012 6:24 pm
Win32:Virut wrote:I'm not sure, but please try (I don't know much about malware removing):
Code: Select all
reg delete HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} /f
Thanks for helping. I think you are onto something because that CLSID key was still present on a live machine I have here (previously infected with Sirefef). I did what you suggested and deleted it. Then I rebooted, customized the arrangement of icons, rebooted once more, but unfortunately the problem still persists. All the icons shift to the TOP LEFT portion of screen upon reboot.
 #15298  by tachion
 Wed Aug 22, 2012 10:37 am
Antivirus Reviews
what the end key / f :lol:

Thisisu


The problem is using HitmanPro.
When disinfection program Malwarebytes problem occurs

It also helps to create a new administrator account :)
Last edited by tachion on Wed Aug 22, 2012 11:56 am, edited 1 time in total.
 #15299  by malwarian
 Wed Aug 22, 2012 11:08 am
thisisu

This symptom can be found on most of zero access infected machines.You're lucky because you have only few users who complained of this stuff :lol: We are facing this for long time :( .New user account will work but problem returns when we migrate user profile from old to new one.We have opted for system restore in some cases. :lol:
 #15311  by thisisu
 Wed Aug 22, 2012 8:38 pm
tachion wrote:Antivirus Reviews
what the end key / f
Forces, no prompt before deletion.

The problem is with HitmanPro or Malwarebytes?

Thanks for the suggestions / information. :)
  • 1
  • 26
  • 27
  • 28
  • 29
  • 30
  • 56