OS : Windows XP sp1.
Apps affected: IE6sp1 or sp2 and IE7. Firefox.
Symtoms: google, yahoo and windows live search redirects to bogus sites such as monstermarketplace. Example: you type in google "quantum physics"; the search returns: wikipedia at the top, but at the bottom it says monstermarketplace. Using netmon you see the infection goes to 78.157.142.58 before the results are returned in google. This ip has been flagged on SBL as part of a block of IPs belonging to a Russian Cybercrime hosting company. The virus even runs in safe mode with networking. This is not the common google redirect that involves tds*.dlls. This is something new and very dangerous. I am currently working with kaspersky and eset, but they have no clue at the moment.
Things I have tried:
Kaskerpsky purchased edition with infected drive slaved - nothing.
Eset purchased edition with infected drive slaved - nothing.
Panda antirootkit - nothing
F-backlight - nothing
Sophos antirootkit - nothing.
IceSword - nothing
Avenger - nothing.
Logs analyzed by me:
combofix - clean
hijackthis - clean
findawf - clean
After making an Acronis image I updated to IE7 and windows xp sp2 - no change.
Gmer - log is clean from hidden processess or services but it does find hooks.
Gmer - stack modifications found.
When windows is first started GMER shows the following:
.text ntoskrnl.exe!KeInitializeInterrupt + B67 804DA23C 1 Byte [ 06 ]
Whenever IE is opened these additional stack mods are found:
.text C:\Program Files\internet explorer\iexplore.exe[280] kernel32.dll!ExitProcess 77E798FD 6 Bytes PUSH 10002970; RET
.text C:\Program Files\internet explorer\iexplore.exe[280] WS2_32.dll!WSARecv 71AB19A0 6 Bytes PUSH 10002504; RET
.text C:\Program Files\internet explorer\iexplore.exe[280] WS2_32.dll!send 71AB1AF4 6 Bytes PUSH 1000269C; RET
.text C:\Program Files\internet explorer\iexplore.exe[280] WS2_32.dll!recv 71AB5690 6 Bytes PUSH 100024C4; RET
.text C:\Program Files\internet explorer\iexplore.exe[280] WS2_32.dll!WSASend 71AB5722 6 Bytes PUSH 10002924; RET
After restoring the code (ie unhooking) then IE and google function properly until IE is opened again and GMER shows these hooks are now back!
I have been working on this for 3 weeks and have even replaced windows xp low level files such as kernel32,ws2_32.dll and others but to know avail.
I can make the infection stop with IE explorer if I remove the Browsenewprocess keys from the registry which means that mshtml will be running as a process in place of IE. But Firefox still has symptoms.
Then I tried blocking 78.157.142.58 at the firewall. IT IS BLOCKED. When I open IE, netmon shows that this ip is connected!!!
When I add 78.157.142.58 to the host file and point it to 127.0.0.6 it stills says connected in the network monitor programs I use.
This is when I started considering suicide as a viable option.
I need your help in finding this one. I may have to use ollydbug which I am not very good at.
I have not posted anywhere else, but of course I have searched.
If you need more info on this just type 78.157.142.58 virus in google and you will see there are only about 4 topics on this all without answers. So it is very new and very deep. According to these threads it may also affect Vista.
Please help.

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Back to top









