Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  find hooked process

Topic created on: February 20, 2012 08:14 CST by charlie .

hi all,
I've a malware which hooks into the Windows shutdown procedure by deleting its own copy, is there a way to find the process which had hooked to this procedure ?

I know its hooked because its resident in memory my antivirus scan doesn't get rid of it. It deletes the on disk files and is resident in memory.

related to this http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor:Win32/Caphaw.A.

I want to find the culprit process and kill it manually.

thanks in advance.

charlie

  tresp4sser   February 24, 2012 17:55.18 CST
Have you read the technical analysis on the link you provided? Everything is written there: The backdoor injects itself to firefox/iexplore/explorer/reader_sl and also writes itself to the registry (HKCU\Software\Microsoft\Windows\CurrentVersion\Run).

If you tried to disable the techniques described in the link you provided and you haven't been able to get rid of the malware, I would suggest you to run Sysinternal's procmon and configure it to write its output into a file. Also make it run on startup automatically. Then, with Procmon running, shutdown your computer. After reviewing the procmon's output, you should be able to quickly determine which process injected the malware again.

Good luck.

  charlie     February 26, 2012 14:58.59 CST
Thanks for the tip Tresp4sser. The link just only explains part of the behaviour, the stealthiness of this malware is it creates a hidden run key and injects into explorer, deletes itself using a batch file and stays active in memory. I was able to find the hook using rootkit tools like kernel detective and able to clean it.

  raxen     March 27, 2012 20:47.16 CDT
Null modem + Windows Kernel Debugger + Another PC + a few dozen breakpoints = Answer but the procmon route is the more time conservative approach!

  zaltekk     July 27, 2012 13:47.13 CDT
Check out a tool called HookShark that DeepBlueSea over at GameDeception made.

Note: Registration is required to post to the forums.

There are 29,950 total registered users.


Recently Created Topics
Disassembling Motoro...
Jun/13
ida plugin writing f...
Jun/02
New version of RE-Go...
May/29
Decompiling raw bina...
May/22
Incorrect bitness wh...
May/20
PaiMei stalker modul...
May/19
Attach to program us...
May/13
IDA PRO how to make ...
May/12
FACT: OpenRCE is dead.
May/08
Int 3 anti debug?
May/05


Recent Forum Posts
Good Binary Code Pro...
alton
Int 3 anti debug?
SteveIRQL
Attach to program us...
SteveIRQL
Ollydbg 2.0 - Plugin...
openrce...
IDA PRO how to make ...
codeinject
FACT: OpenRCE is dead.
codeinject
IDA Resource Viewer ...
r2x64
FACT: OpenRCE is dead.
djnemo
FACT: OpenRCE is dead.
codeinject
FACT: OpenRCE is dead.
pedram


Recent Blog Entries
lowpriority
Apr/13
OllyMigrate Plugin for Olly...

everdox
Mar/08
2 anti-trace mechanisms spe...

everdox
Mar/07
Advanced debugging techniques

everdox
Mar/06
Branch tracing and LBR acce...

everdox
Mar/05
Using pre-paged in virtual ...

More ...


Recent Blog Comments
newlulu on:
Jun/10
Branch tracing and LBR acce...

newlulu on:
Jun/10
Advanced debugging techniques

newlulu on:
Jun/10
2 anti-trace mechanisms spe...

newlulu on:
Jun/10
OllyMigrate Plugin for Olly...

clarisonic on:
Apr/03
New version of Ollydbg!

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit