A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #13825  by Quads
 Sat Jun 09, 2012 3:20 am
Working on one where it looks like the system has both the ZeroAccess KB folder variant and the CLSID + services.exe variant, and that is just for starters I think.

OTL log attached hahahaha

Quads
Attachments
(447.84 KiB) Downloaded 42 times
 #13856  by malwarian
 Sun Jun 10, 2012 10:53 am
Hi guys,

My job is malware removal.Any idea on removing C:\windows\assembly\gac_32\desktop.ini,C:\windows\assembly\gac_64\desktop.ini.

It gets hooked into every process,it returns back even after combofix deletes it,we are not allowed to use blitzbank ,OTL.Also no chance of using farbar recovery scan tool ( remote support :P )

thanks
 #13858  by rkhunter
 Sun Jun 10, 2012 11:20 am
malwarian wrote:Hi guys,

My job is malware removal.Any idea on removing C:\windows\assembly\gac_32\desktop.ini,C:\windows\assembly\gac_64\desktop.ini.

It gets hooked into every process,it returns back even after combofix deletes it,we are not allowed to use blitzbank ,OTL.Also no chance of using farbar recovery scan tool ( remote support :P )

thanks
May be you safe remove CLSID key before? After reboot it would easy for delete files...
 #13859  by erikloman
 Sun Jun 10, 2012 11:57 am
malwarian wrote:Hi guys,

My job is malware removal.Any idea on removing C:\windows\assembly\gac_32\desktop.ini,C:\windows\assembly\gac_64\desktop.ini.

It gets hooked into every process,it returns back even after combofix deletes it,we are not allowed to use blitzbank ,OTL.Also no chance of using farbar recovery scan tool ( remote support :P )

thanks
You can use HitmanPro to remove this variant.
ZA_CLSID.png
HitmanPro 3.6 Build 158
ZA_CLSID.png (45.61 KiB) Viewed 447 times
Current build 156 removes the CLSID variant. We've released a Beta build that performs both the Removal and Repair in one single pass:
http://dl.surfright.nl/HitmanPro36beta_x64.exe
Last edited by erikloman on Sun Jun 10, 2012 12:54 pm, edited 1 time in total.
 #13860  by malwarian
 Sun Jun 10, 2012 12:08 pm
May be you safe remove CLSID key before? After reboot it would easy for delete files...

I'm not sure which key you're referring to? Doesnt malwarebytes remove the infected CLSID keys? Do you mean keys that points to wbemess.dll and shdocvw.dll ? yes i did that but desktop.ini returns back.

You can use HitmanPro to remove this variant.

Are you sure if this can remove more efficiently when combofix has failed?
Let me see if hitman pro can remove this.

Thanks
  • 1
  • 5
  • 6
  • 7
  • 8
  • 9
  • 56