-
January 26th, 2008, 06:20 AM
#1
injecting browser helper objects remotely =?
Some system monitoring program gave me this message
A new startup program has been detected
D:\windows\system32\jkhfd.dll,c
which means that it is executing the function whose name is c which is exported by jkhfd.dll
I dissassembled the file(jkhfd.dll) and found the following list of exported functions-
c
DllCanUnloadNow
DllGetClassObject
f
InitSecurityInterfaceWLsaApCallPackage
LsaApCallPackagePassthrough
LsaApCallPackageUntrusted
LsaApInitializePackage
LsaApLogonTerminated
LsaApLogonUser
LsaApLogonUserEx
o
s
SpInitialize
(the function c, as I suspected, is exported)
Some sysinternals tools told me that the above dll is there(injected?) as the browser helper objects
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
{B2CEFDCD-4318-4FD1-B87F-3E28D54ECF8D} d:\windows\system32\jkhfd.dll
From the above list of exported functions, most are implemented by the dll creator herself. But the win32 function(s) like LogonUser(which attempts to logon,probably remotely) has aroused my suspicion.
My questions-
What's the prefix LsaAp means ?
Since the dissassembler can't locate the functions in the dissassembly, please suggest some other way of reversing the dll ?
Any further info on this method of attack, that is, how can someone remotely inject BHOs(browser helper objects) ?
-
January 26th, 2008, 07:04 AM
#2
LSA =Local Security Authority but i dont know what the ap means..
-
January 29th, 2008, 07:23 AM
#3
If I remember correctly to the machine I was cleaning 2 days ago.... That is the latest incarnation of the virtumonde trojan. If so, your gonna have fun cleaning it out as safe mode isnt enough. It makes copies of itself to programs. ie ccapp.exe would be infected and running but ccapp .exe is the original and not running. Notice the space.
Sysinternals helps to root these out with process mon and autoruns
Before i forget, there should be an exe file with the same name as that dll hiding somewhere probably another dll and its exe too.
Run a virus/spyware scan.
<chsh> I've read more interesting technical discussion on the wall of a public bathroom than I have at AO at times
-
February 4th, 2008, 03:26 PM
#4
Junior Member
its trying to get your login passwords to root your system.
-
February 4th, 2008, 04:04 PM
#5
From what I have seen "Ap" generally means "application"
Here is some more information about your malware:
http://www.prevx.com/filenames/10879...JKHFD.DLL.html
I looks as if Darksnake is right and this is a new variant that has just surfaced.
I believe that it actually tries to protect itself against dissassembly, which would explain the results you got?
-
February 4th, 2008, 09:26 PM
#6
A co-worker of mine cleaned his portable by connecting to it with another PC, because as previously mentioned, it doesn't help by doing it in safe mode. Normally this co-worker wouldn't bother, but he was intrigued on how this happened to him.
Back when I was a boy, we carved our own IC's out of wood.
-
February 4th, 2008, 10:33 PM
#7
Hi Cemetric,
From what I saw it was looking for network drives?
I would not really want to connect that to another machine............ I guess I would try something like the UBCD as a first shot?..............unless I was using a linux distro on the cleaning device?
Similar Threads
-
By karavay in forum Microsoft Security Discussions
Replies: 3
Last Post: August 13th, 2006, 12:53 AM
-
By mikem0327 in forum AntiOnline's General Chit Chat
Replies: 0
Last Post: March 24th, 2004, 04:36 AM
-
By Szafran in forum Miscellaneous Security Discussions
Replies: 1
Last Post: September 7th, 2003, 09:41 PM
-
By E5C4P3 in forum Product / Book / Training / Conference Reviews
Replies: 2
Last Post: March 3rd, 2002, 03:24 PM
-
By ac1dsp3ctrum in forum The Security Tutorials Forum
Replies: 8
Last Post: February 13th, 2002, 12:36 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|