News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
June 19, 2013, 09:38:23
Pages: 1 2 3 [4] 5 6 7   Go Down
  Print  
Topic: New CoolWebSearch variants  (Read 78484 times)
0 Members and 2 Guests are viewing this topic.
« Reply #45 on: January 14, 2004, 17:49:37 »
Unzy
Guest

Another variant :

O4 - HKCU\..\Run: [winrar] C:\WINDOWS\winrar.exe

Attempts to change the homepage to hxxp://my.search/sp.php and tries to launch editpad.exe, which is a known cws file.

As seen HERE

Cheers,
Logged
« Reply #46 on: January 20, 2004, 00:34:34 »
Merijn Offline
Newbie

*

Karma: 0
Posts: 44



Thanks Pieter and Unzy, I've added that last one to CWShredder as well.

I'm a little fuzzy on the variants that kill HT/CWShredder/AA/SSD, and/or use the ShellServiceObjectDelayLoad startup. I'm seeing bits and pieces all over the boards, but I can't form a clear picture out of these. Do you know anything about them?
Logged
« Reply #47 on: January 20, 2004, 01:57:19 »
Metallica Offline
Global Moderator WWW

Karma: 4
Posts: 4840



Hi Merijn, Smile

Here is a nice example:
http://www.wilderssecurity.com/index.php?board=17;action=display;threadid=19475

The thread at SWI Expert forum is here

Regards,

Pieter
Logged

« Reply #48 on: January 21, 2004, 11:12:22 »
Merijn Offline
Newbie

*

Karma: 0
Posts: 44



OK, got it. I got a sample and added the whole thing to CWShredder as CWS.Smartfinder.
Logged
« Reply #49 on: January 22, 2004, 06:41:14 »
Unzy
Guest

Good job, as always Merijn!

Cheers,
Logged
« Reply #50 on: February 01, 2004, 05:36:33 »
Unzy
Guest

A little update, once again :

This new CWS domain seems to be spreading fast :

hxxp://www.magicsearch.ws/?q=

Triggered by a variety of .exe's , (there are probably a lot more)

O4 - HKCU\..\Run: [MicrosoftWindows] C:\Program Files\Common Files\Services\winmgnt.exe
O4 - HKLM\..\Run: [MicrosoftWindows] C:\Windows\system\systeem.exe
O4 - HKCU\..\Run: [MicrosoftWindows] C:\Windows\system\exploreer.exe

-> the name ID tag always is [MicrosoftWindows] , so watch out for that entry

**Taken from TonyKlein's weekly startups update at SWI :

Quote

As for MicrosoftWindows = winmgnt.exe, this CWS variant uses various other file names as well.
Merijn just provided the following list of alternatives spotted:

autorun.exe
clrssn.exe
critical.exe
directx32.exe
directx.exe
explore.exe
explorer32.exe
iexplorer.exe
inetinf.exe
milannet.exe
sistem.exe
systeem.exe
time.exe
uninstall.exe
volume.exe
win32e.exe


Log examples :

HERE


Also look out for this new CWS variant, random name tag and random executable, but pretty easy to recognise (10 digit exe file):

O4 - HKCU\..\Run: [ww64wzwhyi] C:\WINDOWS\FUPBCYV0Z5.EXE
O4 - HKCU\..\Run: [yd036jz1oh] C:\WINDOWS\5h5budvghj.exe

Usually combined with a hijack to a cws domain

Additional info :

Seemingly a dropper for DNSErr.dll and control.exe

thnx to FAL and Merijn for analyzing

Log examples :

HERE

HERE

Have files in my possession

Cheers,
Logged
« Reply #51 on: February 06, 2004, 06:19:45 »
Metallica Offline
Global Moderator WWW

Karma: 4
Posts: 4840



O2 - BHO: ShowSearch module - {E2DDF680-9905-4dee-8C64-0A5DE7FE133C} - C:\Documents and Settings\4nvile\Application Data\winny\mssearch.dll

O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.dll,Install

Variant of Winshow. The winny folder name changes.
First spotted here: http://boards.cexx.org/viewtopic.php?t=4092
Logged

« Reply #52 on: February 13, 2004, 13:32:59 »
Metallica Offline
Global Moderator WWW

Karma: 4
Posts: 4840



Found by Mosaic1:

As seen here:
http://computercops.biz/postp83223.html#83223

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.enjoysearch.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.enjoysearch.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.enjoysearch.info/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.enjoysearch.info/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.enjoysearch.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.enjoysearch.info/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.enjoysearch.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.enjoysearch.info/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.enjoysearch.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.enjoysearch.info/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.enjoysearch.info/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.enjoysearch.info/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.enjoysearch.info/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.enjoysearch.info/search.html

O4 - HKLM\..\Run: [xxxvid] C:\WINDOWS\system32\xxxvideo.hta
O4 - HKCU\..\Run: [xxxvid] C:\My Documents\xxxvideo.hta

[Merijn, if you read this, I have the files as well, so if you can't reach Mosaic1...]
Logged

« Reply #53 on: February 15, 2004, 02:14:11 »
Anonymous
Guest

Thanks Pieter, I got the files from Mosaic at ComputerCops.
Added to CWShredder 1.49 as CWS.Xxxvideo, compiled and uploaded, but I'm not sure if anyone can even reach the download Razz

We're working on a solution.
Logged
« Reply #54 on: February 16, 2004, 19:36:37 »
Shooter
Guest

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html

O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - D:\WINDOWS\winres.dll

http://discuss.futuremark.com/forum/showflat.pl?Cat=&Board=techoperatingsystems&Number=3450803

I have saved winres.dll if you want me to submit it.
Logged
« Reply #55 on: February 17, 2004, 05:03:21 »
Unzy
Guest

Hi Shooter,

Hmm, I had a look at that dll he uploaded and the version tab says it's a Microsoft dll

I hope it's not one of those cws infections where they try to trick the shredder into removing a valid windows file.

Waiting for an opinion from Merijn or Pieter

Cheers,
Logged
« Reply #56 on: February 17, 2004, 05:35:26 »
Metallica Offline
Global Moderator WWW

Karma: 4
Posts: 4840



KAV does not like it:

Current object: winres.dll
winres.dll Packed: UPX
winres.dll Infected: Trojan.Win32.Ideach.f

Certainly no MS file.

I will have a closer look later on, but it sure looks like a hijacker at first glance.

Pieter
Logged

« Reply #57 on: February 17, 2004, 06:44:20 »
Unzy
Guest

Yep it sure does Smile

The version tab of the file displays microsoft corp. Rolling Eyes

tsss

Cheers,
Logged
« Reply #58 on: February 22, 2004, 02:59:35 »
Merijn Offline
Newbie

*

Karma: 0
Posts: 44



I'd love to take a look at winres.dll. I remember working on that one just before the DDoS started and haven't finished it yet. [edit] I got the file from futuremarks.com. Not sure if it's a new variant of a new version of Googlems.
Logged
« Reply #59 on: February 22, 2004, 05:17:54 »
Merijn Offline
Newbie

*

Karma: 0
Posts: 44



Added it as CWS.Winres to CWShredder 1.50.

I'm emailing it to phoenix22 of Computercops.biz for his mirror. If anyone else wants to mirror it, send me your email addy and I'll notify you when a new ver is out.
Logged
 
Pages: 1 2 3 [4] 5 6 7   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.467 seconds with 20 queries.