Zbot infection on Windows 2003 terminal server.

Hello all, I'm a long time lurker but first time poster. I used to consider myself fairly competent in exorcising malware demons from people's PCs (I certainly have enough people bringing them to me for that purpose) but my old tricks don't seem to be keeping pace with the new threats. Recently we had a Zbot outbreak on our network that pointed out glaring security holes in our defenses that existed due to lack of administrative manpower and an ill-advised managerial directive to favor data accessibility and application communication over proper security practices. After three of us losing an entire weekend to isolation, cleanup, and reimaging of servers where necessary we are changing our ways and have all servers running the latest McAfee Virusscan Enterprise with maximum protection, have closed down shares of system volumes, and have a renewed focus on proper security practices.

That being said, we are still not completely rid of the Zbot infection. The terminal server upon which we conduct our day to day activities (not online banking for now for obvious reasons) is still attempting to infect the executables of other servers on the network (one in particular seems to be its primary target). The McAfee on-access scanner on that server seems to be detecting and cleaning the infections, but some evil is definitely still at work - in TCPview I can see connections being established with unknown IPs (one of them in Russia) which are definitely not legitimate traffic. Not to mention the fraudulent charge that showed up on my corporate credit card. I have tried to watch for suspicious activity in Process Explorer but don't really know what to look for.

The odd thing (not odd for a virus I guess but perplexing and annoying) is that nothing we've tried can find a problem on the terminal server in question. We have done in-depth scanning with McAfee and the command line scanner and various other tools (GetSusp, autoruns, GMER) under the direction of McAfee support and cannot find the source of the unauthorized activity. I for my own part have tried a number of tools that have been helpful with PCs (SuperAntiSpyware, MBAM, and Spybot) and while the first scan with SAS cleaned up the usual web surfing crap subsequent scans with MBAM and Spybot came back clean. I don't think it would be advisable to run ComboFix on a terminal server, as its use even on a PC is recommended only under the guidance of a trained security professional. I have looked in the most obvious places for rogue programs starting with Windows but I just cannot find it. McAfee will not escalate the case until we can provide a malicious sample which is a huge catch 22 since neither the software, the first-level tech nor we can determine which is the malicious file.

I just don't know what else to try at this point, so I am humbly submitting this request for assistance. It seems that our Zbot variant is completely evading detection on the terminal server - I have read that even with a fully patched OS and up to date antivirus the detection rate for this virus is less than 50% and likely closer to 25%. I would appreciate any input that might help us in isolating and removing the infection, whether it be another program to try, another place to look, or a procedure to follow. I will be somewhat limited in what I can do immediately by this being a production server but will attempt to perform any suggested procedures remotely after hours. Thanks in advance for your help - I know someone out there must have the knowledge, skills, and tools to find this thing and kill it. Bonus points and a beer to anyone who can ship me the head of the bastard who coded the Zbot construction kit in a box with a pretty Christmas bow on it. I want the last three weeks of my life back!

Hello,I would like to run 2 tools and see if there is improvement.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version of the tool.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller. will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

Please perform a scan with Eset Online Antiivirus Scanner.
This scan requires Internet Explorer to work. Vista/Windows 7 users need to run Internet Explorer as Administrator.
To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run As Administrator from the context menu.
  • Click the green Posted Image button.
  • Read the End User License Agreement and check the box:
  • Check Posted Image.
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Check Remove found threats and Scan potentially unwanted applications. (If given the option, choose "Quarantine" instead of delete.)
  • Click the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer.
  • If offered the option to get information or buy software at any point, just close the window.
  • The scan will take a while so be patient and do NOT use the computer while the scan is running. Keep all other programs and windows closed.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop as ESETScan.txt.
  • Push the Posted Image button, then Finish.
  • Copy and paste the contents of ESETScan.txt in your next reply.
Note: A log.txt file will also be created and automatically saved in the C:\Program Files\EsetOnlineScanner\ folder.
If you did not save the ESETScan log, click Posted Image > Run..., then type or copy and paste everything in the code box below into the Open dialogue box:

C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Click Ok and the scan results will open in Notepad.
  • Copy and paste the contents of log.txt in your next reply.
-- Some online scanners will detect existing anti-virus software and refuse to cooperate. You may have to disable the real-time protection components of your existing anti-virus and try running the scan again. If you do this, remember to turn them back on after you are finished.

NOTE: In some instances if no malware is found there will be no log produced.
Well TDSSKiller found nothing but the ESET online scanner did find some threats that were overlooked by previous scans and things seem to be looking up - there have been no on-access detections on the server where we had been receiving them before moving the files ESET found. This is kind of ironic really, because we have a VPN and domain trust with one of our clients and they too fell prey to this outbreak. The ironic part is that I had most of their PCs and servers running ESET NOD32 Antivirus v4 and had just recently renewed their license for three years. When the systems were still heavily infected and many, many critical .exe's were compromised we deemed ESET unusable for cleanup because it did not offer an option to clean the files - only delete. We removed ESET and put McAfee on everything since it seemed to be doing a better job of cleaning the .exe's. Now that the .exe's are cleaned up for the most part and McAfee can't find the dropper that keeps trying to reinfect them, ESET is back to save the day by finding the droppers. I guess it just goes to show that the modern threats require the right mix of tools, knowledge, and a little bit of luck. Thank you so much for pointing me in the right direction!

TDSSKiller log:

ESET Online Scan log:

C:\Documents and Settings\gah\Application Data\Sun\Java\Deployment\cache\6.0\10\334136ca-6e5eb13c a variant of Java/Exploit.Agent.NAL trojan
C:\Documents and Settings\gah\Application Data\Sun\Java\Deployment\cache\6.0\58\551652ba-44b514a0 multiple threats
C:\Documents and Settings\gah\Application Data\Sun\Java\Deployment\cache\6.0\59\4900bfbb-2dbafe40 multiple threats
C:\Documents and Settings\mdh\Application Data\Qoicm\epagt.exe a variant of Win32/Kryptik.IPS trojan
C:\Documents and Settings\shh\Application Data\Etyg\iwla.exe a variant of Win32/Kryptik.IPS trojan

Meant to say that you should not run Combofix with our assistance it could shut you down and I don't think we need it. How is it running now?

Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.
Sorry it took so long to respond - holidays and all that. Things still look good - neither McAfee support nor MBAM or any other tool is detecting a problem at this point. I guess I'll have to add that ESET online scan to the antimalware toolkit - it was the only thing that was detecting the trojan dropper. Here's the MBAM log:

Malwarebytes' Anti-Malware

Database version: 5468

Windows 5.2.3790 Service Pack 2
Internet Explorer 8.0.6001.18702

1/6/2011 2:28:34 AM
mbam-log-2011-01-06 (02-28-34).txt

Scan type: Quick scan
Objects scanned: 306433
Time elapsed: 7 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ok, looks good here. Yes it's good to have a few tools handy as no one tool can get it all. Good luck.

If there are no more problems or signs of infection, you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:
