Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Thanks ever so much Java, for that biz-wide rootkit infection
The Register ^ | 3rd September 2012 11:00 GMT | Trevor Pott

Posted on 09/03/2012 10:05:45 AM PDT by Ernest_at_the_Beach

Cup of coffee actually a carboy of toxic Kool-Aid

Sysadmin blog Right on cue, Java has responded to my hatred in kind. Shortly after I awoke to discover my previous article denouncing the language had been published, a client called to inform me his computer had contracted some malware. Java has, if you'll forgive the anthropomorphization of a bytecode virtualization engine, decided to exact its revenge.

Closer inspection of the infection revealed deep network penetration that the installed antivirus applications were completely unable to cope with. The chief financial officer of the company relies on cloudy applications that require Java-in-the-web-browser. Contrary to early reports that we should only fear Java 7, this beauty crawled in through a fully up-to-date Java 6 browser plugin and installed some friends.

I have no idea what the initial vector was beyond the swift appearance and disappearance of some malicious Java archive files; the primary delivery mechanism scrubbed itself clean (along with significant chunks of the browser history) right after it downloaded its payload onto the compromised Microsoft Windows PC.

The payload: a software nastie called Sirefef. This itself is actually irrelevant; even Microsoft Security Essentials can find and kill most variants. The purpose of Sirefef is to serve as the staging component for the coup de grace: the highly sophisticated Zeroaccess rootkit (Sirefef downloaded some other friends too, but once the rootkit is dealt with, they are easily dispatched.)

Zeroaccess is a nightmare. It creates a hidden partition to run components from, deletes the BITS and Windows Update services, infects system restore and then removes the system restore interface from Windows. It locks you out of various sections of your file system it has decided to secrete backup copies of itself into. (C:\Windows\Temp, C:\Windows\System32\Config\Systemprofile and so forth.)

Zeroaccess knows all the standard tricks; it hides itself from Trend Micro's virus scanner Housecall, kills industrial-strength bleach Combofix (attempting to run this tool will freeze the system), resists cleaning by SurfRight's Hitman Pro, Symantec's resident AV and so forth. If you delete the hidden partition after booting from a Linux Live CD, chances are you didn't get every last remnant of the thing and it will be back in due time. It also prevents remote support app Teamviewer from starting properly with Windows.

If any residue of the rootkit lingers, or if Sirefef and/or its downloaded friends remain, they will all download and reinstall one another and we get to play whack-a-malware one more time. Bonus points were awarded for exploiting known Windows 7 vulnerabilities to infect every other machine on the network; that was a nice touch that really made my Friday.

Cleaning up this one Trojan-horse town

So what's the solution? It turns out that some combination therapy kills the Zeroaccess variant in question. The solution I have settled upon is this:


  1. Disconnect every Windows system from the network; if one is infected, they are all infected. (I have absolutely no idea what they used to get through the firewalls on client PCs, but it was effective.) You need to clean all systems one at a time on a quarantine basis. If you have a way to automate the rest of this list for enterprise deployment, please let me know.

  2. Create a new local user with admin privileges, reboot and log on as that user. (You need as clean a profile as possible.)

  3. Download and run Symantec's Zeroaccess removal tool. It will ask you to reboot; do so. A widget will pop up when you next log in that says the rootkit was not found. This is a lie. The removal tool got rid of it, and you have already been reinfected. Fortunately, it can't do anything until the next reboot.

  4. Run Trend Micro's Housecall; kill all the things. Do not reboot.


  5. Repair the background intelligent transfer service (BITS).


  6. Repair the Windows automatic updates service. (If you get the popup for the "Microsoft Fixit" tool, use it. It will fix your broken Windows update service.)

  7. Install Windows updates. Do not reboot.


  8. Run Microsoft Security Essentials; kill all the things. Do not reboot. At this point, you should have killed all of Zeroaccess's little friends.


  9. Re-run the Symantec Zeroaccess removal tool. It should kill the newly reinfected (but still dormant) variant of Zeroaccess.

  10. Reboot. When the system comes back up, make sure you log in as the "new" local administrative account you created.


  11. Run Combofix. If it doesn't lock up your system, you're good!

  12. Reboot back into your regular account, and delete the local account you created for this process. You win.

If you are infected with Zeroaccess, exercise extreme caution. Someone is actively versioning this rootkit. I detected at least three different variants on one network alone. More to the point, the little friends that serve as satellite malware are also seeing some rapid evolution; what worked for me today may not work a week from now.

This incident should serve to underscore exactly how serious the Java exploits in question are. If you can, uninstall Java. If you must use Java, keep it as up-to-date as possible and see if you can disable or remove the plugins for your browsers. (In an attempt to help resolve the current crisis, Ninite is offering free access to the pro version for a limited time; it can really help with the updating.) If you absolutely must use Java-in-the-browser then it's time to start taking security very seriously; break out the tinfoil and start making some shiny hats.

Java-in-the-browser absolutely must be treated as "already compromised". There is no wiggle room here. Do not under any circumstances run Java in the browser on any production system or any client system in which any other application is used. Go buy another Windows licence and put Java inside a virtual machine.

Ring-fence the virtual machine by placing it on its own VLAN and subnet. Keep that virtual machine's traffic as separate from the rest of your network and system as you possibly can: Java-in-the-browser is a live grenade and you can't afford to have it go off inside your network. If you can, deploy the virtual machine from a managed template; the ability to destroy it at the end of the day and revert to a "known good" is a huge advantage when dealing with a threat of this magnitude.

Even if Oracle gets its act together and solves the immediate issues, this is only the latest in a long line. Java is simply is not developed with an adequate "security first" approach; Oracle is used to dealing with large corporations, not consumers. It doesn't have the experience to fight these kinds of rapidly escalating arms races, and it shows.

There isn't time to wait for Oracle to overcome its corporate inertia. It is time for systems administrators to act. It is our duty to depopulate Java with extreme prejudice. ®


TOPICS: Computers/Internet
KEYWORDS: java; javaexploits; javascript; linuxlivecd; malware; sirefef; teamviewer; whackamalware; zeroaccess; zeroaccessbotnet; zeroacess
Navigation: use the links below to view more comments.
first 1-2021-4041-53 next last

1 posted on 09/03/2012 10:05:49 AM PDT by Ernest_at_the_Beach
[ Post Reply | Private Reply | View Replies]

To: Ernest_at_the_Beach

Thanks for posting this antihelminthic procedure. Well-written too.


2 posted on 09/03/2012 10:10:58 AM PDT by thecodont
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Later read!


3 posted on 09/03/2012 10:13:05 AM PDT by RoseofTexas
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Bump for later.


4 posted on 09/03/2012 10:13:25 AM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

If you have Windows 7 or God forbid Vista, doing a system restore to an earlier date also seems to work.

I’ve ran across a few of these lately. What fun!


5 posted on 09/03/2012 10:13:38 AM PDT by unixfox (Abolish Slavery, Repeal The 16th Amendment!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Noumenon

Ping.


6 posted on 09/03/2012 10:13:53 AM PDT by DuncanWaring (The Lord uses the good ones; the bad ones use the Lord.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

fyi


7 posted on 09/03/2012 10:16:13 AM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
It is our duty to depopulate Java with extreme prejudice.

OK, what is the recommended alternative to creating java aps?
8 posted on 09/03/2012 10:18:39 AM PDT by RushingWater (Let's have a brokered convention and page Sarah Palin - especially if Condi is the VP nominee)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
Not sure all the inbedded links work....so here is a FR Thread on the :

Technical paper: The ZeroAccess rootkit under the microscope

9 posted on 09/03/2012 10:18:42 AM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 7 | View Replies]

To: Ernest_at_the_Beach

bookmark


10 posted on 09/03/2012 10:31:20 AM PDT by dadfly
[ Post Reply | Private Reply | To 1 | View Replies]

To: dadfly

read later


11 posted on 09/03/2012 10:41:48 AM PDT by knarf (I say things that are true ... I have no proof ... but they're true)
[ Post Reply | Private Reply | To 10 | View Replies]

To: RushingWater

No Idea...but doesn’t look easy.


12 posted on 09/03/2012 10:43:49 AM PDT by Ernest_at_the_Beach ((The Global Warming Hoax was a Criminal Act....where is Al Gore?))
[ Post Reply | Private Reply | To 8 | View Replies]

To: Ernest_at_the_Beach

BOOKMARK.


13 posted on 09/03/2012 10:50:07 AM PDT by The Cajun (Sarah Palin, Mark Levin......Nuff said.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox
"If you have Windows 7 or God forbid Vista, doing a system
restore to an earlier date also seems to work."

That is if the bug hasn't infected the other backups, virii
love to stick around and infect other restore points.
I have Windows Restore set to off and use "ERUNT"
"WinRescue" instead:
http://www.larshederer.homepage.t-online.de/erunt
http://regvac.com/frescuemenu.htm

14 posted on 09/03/2012 10:52:49 AM PDT by LouieFisk
[ Post Reply | Private Reply | To 5 | View Replies]

To: lysie

bookmark


15 posted on 09/03/2012 10:58:02 AM PDT by lysie
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

I was wondering when someone was going to turn the spyware root-kits into a virus. One or two you can fix, 200 at a time will be a problem and if it can cross subnets, look out.


16 posted on 09/03/2012 11:01:19 AM PDT by ClayinVA ("Those who don't remember history are doomed to repeat it")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

So, what’s the skinny? Should we not be running Java?


17 posted on 09/03/2012 11:02:04 AM PDT by bcsco (Bourbon gets better with age...I age better with Bourbon.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Hey, Ernest, I don’t have Sun java running on mine, but I did disable it off of my mom’s business pc, thanks so much for the heads up on this ^^


18 posted on 09/03/2012 11:03:27 AM PDT by chris37 (Heartless.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bcsco
"So, what’s the skinny? Should we not be running Java?"

I uninstalled it after the last infection it gave my PC.
It's rarely needed in my case. YMMV.
19 posted on 09/03/2012 11:09:32 AM PDT by LouieFisk
[ Post Reply | Private Reply | To 17 | View Replies]

To: Ernest_at_the_Beach

These people need to be put up against a wall and shot. And then the video put on YouTube for all the world to see.


20 posted on 09/03/2012 11:09:32 AM PDT by ottbmare (The OTTB Mare)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-53 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson