Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 06:15:54 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212227
Posts
24530
Topics
57713
Members
Latest Member:
desertrat2143
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
NewHeur_PE virus Removal?
« previous
next »
Pages:
[
1
]
2
Author
Topic: NewHeur_PE virus Removal? (Read 10817 times)
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
NewHeur_PE virus Removal?
«
on:
November 06, 2007, 06:13:21 AM »
Need some help here please. I am trying to clean a friends notebook (seems he likes collecting malware!!!!) and I've run into a brick wall. I removed nearly all nasties on his system bar one, that is the NewHeur_PE virus.
From what I can make out, this little sod is of Chinese origin and in the case of this notebook, manifests it's self as a file called sxs2.exe, which apparently is in the root directory, even though it can't be seen!
He has Symantec AV (eeek) installed and it doesn't see it. I've tried AVG, Avast, and Antivir, likewise they don't see it. I've also tried SuperAntiSpyware, Spyware Terminator, and AVG AS. No joy.
Apparently NOD32 kind of recognises it but is a bit dubious.
As my Chinese is limited to only 20 or so words, reading the Chinese sites on how to remove this is beyond me. If anyone can help, it would be much appreaiated.
Toggie
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: NewHeur_PE virus Removal?
«
Reply #1 on:
November 06, 2007, 07:36:23 AM »
You have probably already seen these but they may help so here goes:
http://forums.spybot.info/archive/index.php/t-12192.html
http://translate.google.com/translate?hl=en&sl=zh-CN&u=http://www.wangyx.com/%3Fp%3D14&sa=X&oi=translate&resnum=9&ct=result&prev=/search%3Fq%3Dsxs2.exe%26hl%3Den%26sa%3DG
The second link seems to have a batch file to aid removal - I have no idea if this is safe or not as the link is for a page translated by google.
Logged
Post proelia praemia.
Die dulci fruere.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: NewHeur_PE virus Removal?
«
Reply #2 on:
November 06, 2007, 08:16:43 AM »
Quote
The second link seems to have a batch file to aid removal - I have no idea if this is safe or not as the link is for a page translated by google.
Thanks for the reply N.T.T.W, I've seen the first link, SBSD doesn't detect it either
The second link might be interesting, but the batch file has many entries in Chinese, which probably won't work on an non Chinese system.
It seems strange to me that all the so called 'best' AV programs can't detect a Chinese AV...
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: NewHeur_PE virus Removal?
«
Reply #3 on:
November 06, 2007, 08:31:34 AM »
Quote from: Toggie on November 06, 2007, 08:16:43 AM
It seems strange to me that all the so called 'best' AV programs can't detect a Chinese AV...
I know what you mean, you would think these well known products would be up to date for viruses wordlwide.
Perhaps if you use Autoruns to find any iffy startup entries it may give you ideas how to remove various components of the nasty or at least disable them.
I will keep looking for an answer.
Logged
Post proelia praemia.
Die dulci fruere.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: NewHeur_PE virus Removal?
«
Reply #4 on:
November 06, 2007, 08:38:22 AM »
Quote
Perhaps if you use Autoruns to find any iffy startup entries it may give you ideas how to remove various components of the nasty or at least disable them.
I tried that, both autoruns and process explorer show the same information, C:\sxs2.exe but nothing can find it in that location. It's supposed to be associated with autorun.exe or autorun.inf, but again these files don't appear to exist. The sxs2.exe process still shows in process explorer, twice!!
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: NewHeur_PE virus Removal?
«
Reply #5 on:
November 06, 2007, 08:40:52 AM »
http://www.f-secure.com/blacklight/
Always worth a try...
Logged
Post proelia praemia.
Die dulci fruere.
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: NewHeur_PE virus Removal?
«
Reply #6 on:
November 06, 2007, 10:39:48 AM »
"NewHeur" indicates heuristic (behavioral) detection which means it could be a little bit of anything to everything.
Can or did you already send samples to
bocleansubmissions@comodo.com
&
malwaresubmit@avlab.comodo.com
?
Honestly, once you're backdoored the best practice is to nuke and reinstall. There's no telling what doors have been opened within the OS.
As we all know, prevention is the only real cure.
Logged
Parched dry and thirsty, knee deep in the river of life.
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: NewHeur_PE virus Removal?
«
Reply #7 on:
November 06, 2007, 01:12:21 PM »
Hey
I've checked some post in the NOD32 forum and as far as they know it's a false positive but the're still analyzing it.
If you want to be sure you can upload the file to Virustotal
http://www.virustotal.com/
and see if any other antivirus finds it. (if you know were it is of course)
Hope I could help ya a bit
Xan
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: NewHeur_PE virus Removal?
«
Reply #8 on:
November 06, 2007, 05:50:29 PM »
Quote from: N.T.T.W. on November 06, 2007, 08:40:52 AM
http://www.f-secure.com/blacklight/
Always worth a try...
I haven't tried Blacklight, but I have been through the system with gmer and Icesword, neither of which were able to detect it
Quote from: ~cat~ on November 06, 2007, 10:39:48 AM
"NewHeur" indicates heuristic (behavioral) detection which means it could be a little bit of anything to everything.
Can or did you already send samples to bocleansubmissions [ at ] comodo.com & malwaresubmit [ at ] avlab.comodo.com ?
Hi ~cat~ If I could actually find the files that are loading the proceess I would submit them, but that's half the problem
Quote
Honestly, once you're backdoored the best practice is to nuke and reinstall. There's no telling what doors have been opened within the OS.
As we all know, prevention is the only real cure.
Agreed, and if it was my system I would. It may well come to that in the end, but I said I'd try to clean first, if only to preserve his game data!
Quote from: alaertsxan on November 06, 2007, 01:12:21 PM
Hey
I've checked some post in the NOD32 forum and as far as they know it's a false positive but the're still analyzing it.
Hi alaertsxan, I saw that info, and it seems a bit vague to me. Something is definately loading sxs2.exe in to memory, what it's doing once loaded, however, is another matter
Quote
If you want to be sure you can upload the file to Virustotal
http://www.virustotal.com/
and see if any other antivirus finds it. (if you know were it is of course)
Hope I could help ya a bit
Xan
As I said to ~cat~, I can't actually find how the file is being loaded. Everything points to sxs2.exe existing in C:\ (root) but it doesn't. I've got show hidden files turned on as well as show system files. I've also searched the entire disk, but I can't find it. I even tried searching ADS!
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
~cat~
Global Moderator
Comodo's Hero
Offline
Posts: 964
CBO "...there is nothing better."
Re: NewHeur_PE virus Removal?
«
Reply #9 on:
November 06, 2007, 06:45:07 PM »
Have you tried using the command prompt to browse to and list the file directory?
Logged
Parched dry and thirsty, knee deep in the river of life.
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: NewHeur_PE virus Removal?
«
Reply #10 on:
November 06, 2007, 06:49:26 PM »
Quote from: ~cat~ on November 06, 2007, 06:45:07 PM
Have you tried using the command prompt to browse to and list the file directory?
I did, both Normal and safe mode. I even added the recovery console and tried that way too.
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 2773
Why not ? The choice is yours !
Re: NewHeur_PE virus Removal?
«
Reply #11 on:
November 07, 2007, 03:36:40 AM »
Perhaps we should try it otherwise, please send a hijackthis! log so we can see if indeed something is wrong
Xan
Logged
OK, we'll see each other outside
. But err... different countries ?
Vista Ultimate 64bit SP1
l
Comodo Internet Security
l
Comodo BoClean
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: NewHeur_PE virus Removal?
«
Reply #12 on:
November 07, 2007, 04:27:10 AM »
Hi Toggie,
download
a-squared Free 3.0
.
I would also advise you to use a bartPe cd. It will help you see what is going on outside the os.
Logged
Toggie
Global Moderator
Comodo's Hero
Offline
Posts: 1256
"Oh, let me have just a little bit of peril"
Re: NewHeur_PE virus Removal?
«
Reply #13 on:
November 11, 2007, 07:05:15 PM »
Thanks for the replies everyone, I believe I finally managed to eliminate this particular nasty.
Thanks pandlouk for reminding me about a-squared, I'd forgotten about that program. It was with this I made some progress. After downloading the command line version and running a scan, a variant of the Trojan-Downloader.win32.Agent was detected in sxs2.exe. A-squared also allowed me to quarantine the file. Interestingly, it wasn't able to remove a number of associated files and registry entries.
From what I have discovered, in addition to the sxs2.exe there are a number of 'autorun.*' files located in the root and %winroot%\system32. These files perform a number os tasks including, creating an autorun enrty in userinit.exe, changing the attributes on all the related files to hidden, system, and read only and also changing the value in:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" so that it's impossible to choose the show hidden and system files in explorer.
The 'autorun.*' files, by the way, are:
autorun.inf
autorun.bat
autorun.reg
autorun.bin
autorun.exe
autorun.vbs
autorun.wsh
autorun.fcb
autorun.srm
autorun.txt
autorun.ini
autorun.ico
Thanks again all
Toggie
Logged
One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: NewHeur_PE virus Removal?
«
Reply #14 on:
November 12, 2007, 01:59:10 PM »
Glad to see that you nailed that little $%^#.
ps. tell you friend to instal CFP3. At least he will get an alert when he add another "bad guy" in his personal collection.
Panagiotis
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.446 seconds with 19 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com