Puzzling attack on my System
Page 1 of 1
Sedolf




Posts: 996

PostPosted: Sun, 29th Jun 2008 14:04    Post subject: Puzzling attack on my System
Something quite disturbing happened today with my system and I'd like to post that here, hoping to find some answers. Gladly, I'm pretty sure I got rid of it now.
I think whatever hit me is something thats new, it went undetected through Outpost Firewall, NOD32 and a totally up-to-date WinXP. I searched google, but with no results.
It started today, when I was booting up my computer. The first thing I noticed was that the quickstart taskbar was absent. I reactivated it and went online to do my daily news browsing.
But something was wrong with the Internet. It was extremely slow, some sites didn't even load, but others did. Firing up Tune-Up Utilities process manager unveiled the evildoer:

 Spoiler:
 


Checking out system32 then revealed to me a total of 7 dll's with what seemed to be randomly generated names:

cuikyvrm.dll
dwolhm.dll
nhxbcwet.dll
opnmJAQJ.dll
tuvUnKCt.dll
aaywqjaf.dll
bqujjkkp.dll

The timestamp said that they were created yesterday and today. (28th and 29th of June)
They were initialized through rundll32.exe and hooked to every single process that was active at the moment. I got angry and used the Unlocker tool to eradicate all of those things which resulted in a lot of errors and program crashes but I managed to delete 4 of the dll's via cmd after killing off explorer.exe. Trying to unlock one of the remaining dll's - aaywqjaf.dll - which was still bound to winlogon.exe and lsass.exe made the computer crash completely. After the forced reboot, I changed to Vista and got rid of the final 3 dll's which was not problem since they weren't in use now. Now back to WinXP. On booting I get some error messages, that rundll32 cannot initiate aaywqjaf.dll and cuikyvrm.dll and the quickstart bar was gone again. This was because the entries were still in MSCONFIG:

 Spoiler:
 


I deactivated the 2 entries and rebooted. And now - bam! - everything seems to be working fine again. Internet is good, quickstart is there, suspicious processes are gone.

But what was it that nefariously attacked me there? I barely remember Outpost Host Protection giving out a warning about rundll32.exe but not doing anything about it, that was yesterday at night and I think it was the time I got attacked. Now I'm looking for answers and/or people that have experienced something similar. If anyone is interested, I made back-ups of the 7 dll files and uploaded them here:

http://rapidshare.com/files/125828796/dlls.rar.html

Thanks
Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Sun, 29th Jun 2008 20:38    Post subject:
Use something like http://www.virustotal.com/ to see what it was. There are some spam/botnets out there that get detected by only a few virusscanners.
Back to top
Sedolf




Posts: 996

PostPosted: Mon, 30th Jun 2008 01:06    Post subject:
Ok thanks for the link its getting some positives on the dll's. Stupid malware.

http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.Win32.Monder.gen&threatid=245957


4GB i7 860 @3.0 GTX275 AMP
Back to top
Cohen




Posts: 7155
Location: Rapture
PostPosted: Mon, 30th Jun 2008 02:17    Post subject:
been surfing some dodgy porn mate? Laughing


troll detected by SiN
Back to top
Sedolf




Posts: 996

PostPosted: Mon, 30th Jun 2008 12:51    Post subject:
Wink


4GB i7 860 @3.0 GTX275 AMP
Back to top
Photish




Posts: 1244

PostPosted: Mon, 30th Jun 2008 13:45    Post subject:
Do the limbodance Very Happy


Btw there are some cool free tools on www.sysinternals.com that has much better explaining than tuneup etc.

My advice is try this one http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Back to top
Trolldeg




Posts: 508
Location: Sweden
PostPosted: Mon, 30th Jun 2008 13:48    Post subject:
Scary thing is that you are actually listening to David Hasselhoff. Surprised
Back to top
FusionDexterity




Posts: 1834

PostPosted: Mon, 30th Jun 2008 18:22    Post subject:
Trolldeg wrote:
Scary thing is that you are actually listening to David Hasselhoff. Surprised


Agreed Laughing
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Operating Systems
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group