Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Is this a new Virus/Rootkit I have?

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Is this a new Virus/Rootkit I have?
Reply
 
Thread Tools
Old 27-05-2010, 20:18   #1
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Is this a new Virus/Rootkit I have?

Got a few laptops from where I work and they all have these files in the system32 folder:

Trapkey.dll
InfectDirectx.dll
MaskMessage.dll
Qicksnk.sys
and probably wpa.dbl (but think that's Windows Product Activation but it gets created each logon)

Can't seem to find the cuplrit as the files come back if deleted in DOS mode and can't see anything suspicious in the Registry RUN keys or Startup menu or Task Scheduler!! Task Manager doesn't seem to show anything suspicious either. We run Sophos Anti Virus that gets updated via a server and that's not found anything, so a nasty rootkit or new virus then?
Web-Junkie is offline   Reply With Quote
Advertisement
Old 27-05-2010, 20:21   #2
zing_deleted
Guest
 
Posts: n/a
Re: Is this a new Virus/Rootkit I have?

http://www.extremetech.com/article2/...1151566,00.asp wpa.dbl looks legit
  Reply With Quote
Old 27-05-2010, 20:34   #3
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Is this a new Virus/Rootkit I have?

yeah zing, I think wpa.dbl is legit.

Those other files are not packed or encrypted as you can put them in a Hex editor and scan the file, this is what the InfectDirectx.dll has inside it:

f:\RControl\InfectDDrawEx\Release\InfectDDrawEx.pd b

This is the same for the other files:

f:\RControl\MaskMessage\Release\MaskMessage.pdb
f:\RControl\TrapKey\Release\TrapKey.pdb
F:\RControl\HookDisplay\objfre\i386\HookDisplay.pd b

So they all part of the same infection. Disabled all Startup items and deleted the files in DOS but they still come back, even in safe mode!!

Bit of a bugger to pin down.
Web-Junkie is offline   Reply With Quote
Old 27-05-2010, 20:38   #4
zing_deleted
Guest
 
Posts: n/a
Re: Is this a new Virus/Rootkit I have?

any unusual network traffic? anything suss in hijackthis?. If they come back there is a run command in reg somewhere for them

---------- Post added at 19:38 ---------- Previous post was at 19:36 ----------

I had a machine here the other week with a fake AV that was to new for malwarebytes. It had fixes for older versions but even running it from safe mode with command prompt and running explorer from there it couldnt shift it
  Reply With Quote
Old 27-05-2010, 20:55   #5
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Is this a new Virus/Rootkit I have?

Just ran a Malwarebytes scan with Database version 4149 and nothing found!

We have had few laptops have their wireless connections stop working, they can see the networks but fail to connect, wired connections work fine!

Got to pop out for a few hours so i'll look at them later and run a Hijackthis scan and see if it finds anything!

Keep you posted zing!
Web-Junkie is offline   Reply With Quote
Old 27-05-2010, 23:45   #6
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Is this a new Virus/Rootkit I have?

OK zing, I think it's a false alarm!

Ran Hijackthis and couldn't see anything suspicious in the list it generated so I downloaded Unlocker 1.8.9 and used it see what was attached to InfectDirectx.dll and got these 2 files:

ImperoRemoteControlServer.exe
Marker.exe

These are two programs that run anyway on our laptops.

ImperoRemoteControlServer.exe is from Impero, a program that remotely monitors a PC/Laptop and can take full control of it or lockout anybody/thing the controller wants, it's installed as a client/server so those files are exactly like spyware/malware and do infact take remote control of a computer as it's supposed to, but in this case legit!

Marker.exe is part of SMARTBoard software for Interactive Whiteboards so you can attach a PC/Laptop to a projector and use the Interactive board like a touchscreen to control your PC/Laptop!

Impero creates these files when run:
Quiksnk.sys
MaskMessage.dll
InfectDirectx.dll

Not sure where TrapKey.dll comes into it as it's attached to Winlogon.exe which is a valid file with a digital cert attached but I'd guess it's also part of Impero so it traps ALT+CTRL+DEL!!

So I think after running Malwarebytes, Sophos and Hijackthis and not finding anything remotely (no pun intended) suspicious I think I can safely say this is NOT a rootkit/virus!!

But of a letdown in the end, hoped I'd found something new and be the first to say I'd got it
Web-Junkie is offline   Reply With Quote
Old 27-05-2010, 23:53   #7
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 77
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Is this a new Virus/Rootkit I have?

I guess it would take a very stupid virus writer to give his files such obvious names. Normally they try very hard to disguise them as legit system-related files.

Still, it would have been exciting to discover something new. (Until you got to the rebuilding all the laptops stage anyway)
Dai is offline   Reply With Quote
Old 28-05-2010, 00:23   #8
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Is this a new Virus/Rootkit I have?

That thought had crosed my mind, usually they compress/encrypt the files so the fact they were not compressed nor encrypted and no virus/spyware scan found them suspicious made me dig a bit deeper until I found what they were!

Still, the satisfaction of finding out exactly what those files are is some small reward.
Web-Junkie is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:34.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum