A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #13861  by rkhunter
 Sun Jun 10, 2012 12:16 pm
malwarian wrote:yes i did that but desktop.ini returns back.
Yep, key with {CLSID} that respond to it autorun.
For remove key you can use Xuetr tool with block access to all parent keys after {CLSID} key deletion, coz it rewrite key before reboot.
Also look http://www.kernelmode.info/forum/viewto ... 310#p13380
 #13864  by erikloman
 Sun Jun 10, 2012 6:10 pm
malwarian wrote:rkhunter

Thanks for the tool but i used another way.Services.exe was infected on the customer PC.Replaced it and now system is clean.

Appreciate your help
To date I haven't found a sample that infects the services.exe. Anyone has a working sample that is infecting services.exe?
 #13873  by spandexednaps
 Mon Jun 11, 2012 2:11 am
malwarian wrote:rkhunter

Thanks for the tool but i used another way.Services.exe was infected on the customer PC.Replaced it and now system is clean.

Appreciate your help
From what I have seen, Services.exe is not infected but has the Sirefef file system from C:\Windows\Installer\{GUID} loaded into it. After correcting the CLSIDs and rebooting, sometimes Services.exe is still loading the Sirefef filesystem. Killing Services.exe, safe mode seems to be most effective, and then deleting the C:\Windows\Installer\{GUID} should solve your issue. Process explorer can kill Services.exe but be aware that the computer will reboot shortly there after.

Although if there is a variant which does truly infect the Services.exe and someone has a sample they can post, it would be most appreciated.
 #13875  by Quads
 Mon Jun 11, 2012 2:46 am
That didn't work for my user even after restarts and the removal of the CLSID, I had to copy over a legit copy of services.exe (correct MD5) then zeroaccess in the memory stopped.

Combofix after removing the CLSID so combofix will run now detects and disinfects services.exe even if the cat at it :)

Symantec / Norton detects it as Trojan.Patchep!sys

Quads
 #13880  by Quads
 Mon Jun 11, 2012 5:13 am
Another MD5 is

[-] 2009-07-14 . 014A9CB92514E27C0107614DF764BC06 . 328704 . . [6.1.7600.16385] .. c:\windows\system32\services.exe

Quads
  • 1
  • 6
  • 7
  • 8
  • 9
  • 10
  • 56