Author Topic: ATTENTION! essexboy new TDL4 botnet on client machine need help!  (Read 13934 times)

0 Members and 1 Guest are viewing this topic.

true indian

  • Guest
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #30 on: February 16, 2012, 04:38:45 PM »
@essexboy

Thanks! good idea i will give it a try!

Do u think linux slax bootable disk is a good idea as all linux enviroments are exploited...can i give this a try?

@Don

can u give me a link to the MBRTool please?


Thanks to all who try to help me.

true indian

  • Guest
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #31 on: February 16, 2012, 04:44:26 PM »
Essexboy U are awesome!  ;D

I found the Registry value its here:

\HKEY_LOCAL_MACHINE\SYSTEM\Mounted Devices\Dos Devices\BLACKTERROR!!!!!!!!!!!!!!!

What would u recommend?

Should i boot via linux slax and then take care of it? is that a good idea?

I feel that u would be tell me what will be more secure to do?

Yes...i have full access on that key even in normal windows....Very strange type infection!  :P ::)
« Last Edit: February 16, 2012, 05:05:17 PM by true indian »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #32 on: February 16, 2012, 08:47:13 PM »
Could you export that entire key, post it here  and then we will see if I can use OTL to delete it.  Unless it has some real strong protection... In which case I know another tool that will kill the reg key stone dead

DonZ63

  • Guest
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #33 on: February 16, 2012, 10:09:34 PM »
MBRTool.exe link: http://www.diydatarecovery.nl/mbrtool.htm
Note: I have not personally used this so I can't vouch for it.
« Last Edit: February 16, 2012, 10:13:11 PM by DonZ63 »

true indian

  • Guest
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #34 on: February 17, 2012, 12:57:37 PM »
The content in reg value:

Code: [Select]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BTNT"="Kad.exe "X:/BTNR.exe"
-<<ROOT>> +$ EXTEND .HS.
$ Extend +$ RECYCLE.BIN .HS.
+$ Recycle.bin +$ SYSTEM ~ 1 .HS.
System Volume Inf + $ EXTRA.!!!
+!!! Extra Deleted $ mft 262144 .HS.
$ mftmirr 4096 .HS.
$ logfile 4194304 .HS.
$ volume 0 .HS.
$ attrdef 2560 .HS.
$ bitmap 1976752 .HS.
$ boot 8192 .HS.
$ badclus 0 .HS.
$ Secure 0 .HS.
$ upcase 131072 .HS.
« Last Edit: February 17, 2012, 01:03:09 PM by true indian »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
« Reply #35 on: February 17, 2012, 08:03:03 PM »
On completion of this can you run OTL as I need to find the location of the following two files :

BTNR.exe
Kad.exe


1. Please download The Avenger by Swandog46 to your Desktop.

  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Code: [Select]
Begin copying here:
Registry values to replace with dummy:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|BTNT
Note: the above code was created specifically for this user.  If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the avenger folder and start The Avenger program by clicking on its icon.


    • Accept the disclaimer


    • Right click on the window under Input script here:, and select Paste.



    • You can also click on this window and  press (Ctrl+V) to paste the contents of the clipboard.
    • Click on Execute

    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:

    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions.  This log file will be located at  C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please copy/paste the content of c:\avenger.txt into your reply.

    true indian

    • Guest
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #36 on: February 18, 2012, 06:12:44 AM »
    Hi essexboy yes i know about avenger from ages...


    And yes! It worked...

    I couldnt find the log but the fake floppy disk image was there after taking out the reg value and i easily removed it via Killdisk.
    And the two files were in the fake floppy disk partition that i removed via killdisk after following your fix.

    This was a nasty guy!  ;D

    It was your idea of deleting the reg value....so u own the credit.

    Thanks a lot man!

    Now i can give the client his PC back today evening.
    Thanks again.
    « Last Edit: February 18, 2012, 06:15:43 AM by true indian »

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #37 on: February 18, 2012, 12:38:40 PM »
    Do you have copies of the two files to send to Avast ?

    I replaced the  run key with a dummy just in case it was being monitorerd

    true indian

    • Guest
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #38 on: February 18, 2012, 05:06:51 PM »
    Hi essexboy,

    Currently the FBI are tracking the Bot network.....fortunately the 2 files were uploaded at Virustotal...But a good news is kaspersky and avast! have the detection.so we are protected  ;D
    « Last Edit: February 18, 2012, 05:12:25 PM by true indian »

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #39 on: February 18, 2012, 05:23:05 PM »
    Any idea on the dropper ?

    true indian

    • Guest
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #40 on: February 18, 2012, 05:27:01 PM »
    Here are the detections for 2 files:

    Kaspersky: Backdoor Tdss.dos

    Avast!:Win32.Rootkit.gen[rtk]

    Dropper file is also detected....
    Name of the file:[random numbers].exe
    Avast!:Win32.rootkit.gen

    I Hope FBI will catch the Bot master.
    « Last Edit: February 18, 2012, 05:32:41 PM by true indian »

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #41 on: February 18, 2012, 05:32:34 PM »
    The same name as a standard TDL dropper - must be using the same package

    true indian

    • Guest
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #42 on: February 18, 2012, 05:34:47 PM »
    The same name as a standard TDL dropper - must be using the same package

    I am ultra suspicious of this varient...

    This varient follows the characteristics of the new varient of TDL4 that creates its own partition...

    The only difference is This one creates a Floppy disk partition and is hidden and cannot be seen unless we remove the reg value.More stealth than ever.Hence very close to indestructible. :'(

    May be military grade malware? any idea?

    As it is the malware U and I see regularly are just consumer based malware and there are malware made by government organizations to spy...
    « Last Edit: February 18, 2012, 05:37:26 PM by true indian »

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #43 on: February 18, 2012, 05:42:50 PM »
    No I just think it is a new twist, as we kill one variant another pops up

    true indian

    • Guest
    Re: ATTENTION! essexboy new TDL4 botnet on client machine need help!
    « Reply #44 on: February 18, 2012, 05:45:33 PM »
    No I just think it is a new twist, as we kill one variant another pops up

    I hope............

    As it is this thing was annoying me for this week.Unless your suggested idea worked.

    Thanks!

    Now my tubelight didnt strike this time  ;)

    Now i will make this as a note to myself as it will be good for me in future.  :)
    « Last Edit: February 18, 2012, 05:47:38 PM by true indian »