Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!

Tuesday, September 13, 2011

NDIS driver or malware?


Source
From HiJackThis
Unknown file in Winstock LSP: C:/windows/system32/nlaapi.dll
Unknown file in Winstock LSP: C:/windows/system32/napinsp.dll
Unknown file in Winstock LSP: C:/program files/bonjour/mdnsnsp.dll
From RegCleaner 4.3
(Unknown) RegisteredApplications
(Unknown) Set8187
(Unknown) Set8187B
----------------------------------------
DO NOT DELETE THOSE FILES. they are microsoft files.
nlaapi.dll should not be disabled, required for essential applications to work properly
napinsp.dll is a system file created by Microsoft Corporation. napinsp.dll is part of Windows Operating System
---------------------
If you remove the wrong LSP without restoring the correct system settings, you will loose all networking on your system.
---------------------
Do a scan with Spybot S&D from http://www.safer-networking.org
It should find LSP anomalies and report them. Sometimes it is unable to fix those problems, but it will pop-up a message with a link to a site that has a "fixer" tool for LSP problems. Download that tool first, then you can remove LSP entries to your hearts content, and run the fixer tool to repair your network after the fact.
 
Source
The following is a preview of SETUP.TXT in Archive ec28209e:
+============================+

| REALTEK RTL8187 USB Wireless LAN Driver Setup Utility |
| for Windows ME/2000/XP NDIS Driver | | Release Note | +=========================================+
How to use this Set8187 Utility 
 For Windows 2000/XP:
1. If the Operating System's Found New Hardware Wizard prompts you that "New Hardware Found" for the "Ethernet Controller", you should click "Next" until "Finish" is clicked and without specifying location of the driver. You will see the "Ethernet Controller" in the Device Manager. 
2. Then you can install or upgrade the NDIS driver with "setup" or "setup -s" command: 
a) setup: The InstallShield will prompt you the steps to install or upgrade the driver. 
b) setup -s:  The InstallShield will complete the installation or upgrade without prompting you any instruction.
3. You can remove Set8187 utility from Add/Remove Program Palette in Control Panel, 
The InstallShield will prompt you the steps to remove the driver. After remove the driver, please restart the system inmediately if you want your networking to be re-installed.

Temporarily disable protection aplications for malware removal

Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
During the process of removing malware from your computer, there are times you may need to use specialized fix tools. This is especially true if you are receiving help from a member of the HJT Team. Certain embedded files that are part of these specialized fix tools may at times be detected by your anti-virus or anti-malware scanner as a "RiskTool", "Hacking tool", "Potentially unwanted tool", a virus or a "Trojan" when that is not the case.
These tools have been carefully created and tested by security experts so if your anti-virus or anti-malware program flags them as malware, the detection is what's known as a "False Positive". Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them. In these cases, the removal of these files can have "unpredictable results" and unintentional results.
To avoid any problems while using a specialized tool it is very important that you temporarily disable your anti-virus and/or anti-malware programs before using them or when instructed by a member of the HJT Team. You can re-enable these programs after the malware removal process has been completed.
Many folks may not be sure how to do this so the BC Staff has created a list of common anti-virus programs and the relevant steps to disable their Real-time protection capabilities. When your system has been cleaned or when advised by your helper, it is important that you re-enable your security programs to avoid re-infection
============================
Malware: Viruses, Adware, and Spyware Removal Instructions
How to Get Rid of Malware & Viruses - Updated for 2011
You most likely arrived here because you think you may be infected with some sort of malicious malware. Symptoms of a rogue virus may include: unwanted pop-ups, hijacked search results, general computer / internet slowness, inability to connect to the internet, unknown processes running, etc...
New virus's and virus variants seem to come along almost everyday, so no matter what virus software you use, and how often you update it, your current security software may not be able to cure or even detect your problem.
Preparation for Malware/Virus Removal: Fortunately, virus problems are almost always curable. You will most likely need to download some new software and take a multi-step approach to remove a virus, but if you follow these instructions step-by-step, you will be back to a clean machine. Updates:
First, make sure your version of Windows is updated, especially the security patches and critical updates. Also check for Java Updates and Adobe Acrobat Updates.

Temp File Clean up:
Next, Download and Run TFC. This is a simple but useful tool that cleans all your temp folders. Using it makes your antivirus software scan a lot quicker, too.
More info about TFC here. After downloading follow these steps:
- Open TFC and close any other windows/programs. Click the Start button. Do not open any programs or windows after you have started the program.
- TFC requires a reboot immediately after running.
Continue to the next step...
Scan for Viruses Make sure your antivirus software is up-to-date. Now, run a full system scan and save a copy the log file for the last step. Recommended Free Anti-Virus Software: AVG and Avira and Avast all offer great free antivirus / computer security software. I used AVG for many years, but recently became a fan of Avast.
Scan with Malwarebytes Anti-Malware Download Malwarebytes Anti-Malware and follow these steps: - Open mbam-setup.exe and follow the instructions to install. At the end, be sure the Update & Launch and boxes are ticked, and click Finish.
- Once updated and loaded, select Perform Quick Scan, then click Scan. When complete, click OK, then Show Results.
- Be sure everything is checked, then click Remove Selected.
- A log file will open in notepad. Save this in the same place you saved your antivirus log file.
- Restart your computer.
Hopefully, these first 3 steps found and removed any sort of malware from your PC. If you want to be certain, or think you are still infected, continue on to the next steps:
GMER - Download and Run
Follow these steps:
Important Tips :

1. Install all of your anti-virus/ spyware/adware utilities in one folder for easy finding.

2. Allow your antivirus programs to check for updates and download them automatically, or do it manually at least once a week.

- Download GMER and save it to where you are storing your anti-malware utilities. Note: This file will have a random name.
- Disconnect from internet, close all running programs including any real-time virus scanning utility.
- Open the randomly named gamr file, allow gmer.sys driver to load if prompted.
- Select the Rootkit tab> click Scan
- If you get a WARNING about rootkit activity, and are prompted to fully scan your computer, click NO.
- After the scan completes, click Save button, then save results as gmer.log (again, keep track of where you have this log file).
- Exit GMER and re-enable your active virus protection.
DDS by sUBs - Download & Run Follow these steps - DDS is a program that is used to troubleshoot malware issues. The log files it produces will be needed for the last step of this process.
- Download DDS by sUBs here. After downloading, disable your virus protection/script blocking protection, and also disconnect from the internet.
- Double click on the DDS icon, allow it to run. If it won't run, rename the file and try again. A window will open, with info about the utility. You don't need to do anything, the scan is already running.
- The results will open in notepad. Click No for the Optional_Scan.
- Follow the instructions. When finished, DDS will open 2 log files: DDS.txt and Attach.txt (save these with your other log files).
- Close the DDS window. Delete the program from your where you saved it.
- Enable your virus protection and re-connect to the internet.

Final Step - Posting Logs to a Forum for Help Phew, you made it. Now you can post your log files to a malware removal help forum.
I suggest: TechSpot.com. These are a bunch of helpful folks, so please be sure to follow their posting rules completely -- before posting ;) If you follow their instructions, they will help you with the nitty-gritty details to remove problem malware.
Follow these instruction to request assistance:
- Register for forum membership at TechSpot.com
- After registration is complete, point your browser to this page. You've already done their 8 steps if you followed all the steps in the previous guide, but please read over it to make sure you didn't miss anything, then Skip to Step 7.
- Got all that? Now go to TechSpot.com's Virus & Malware Removal Board . Click the button for +New Topic, and post your message.
- I suggest you use a concise & descriptive message title, then a little bit about your malware symptoms, be sure to mention that you followed their 8 Step Guide and have your required log files. Then paste in the following logs:
  • Malwarebytes Anti-Malware log
  • GMER log
  • DDS logs: both DDS.txt and Attach.txt
Keep your antivirus scan log from earlier handy incase you are asked to post it as well.
Finish posting your assistance request to the forum, and you will recieve replies within a day, but generally within an hour or less.
Alternative Malware Removal Help:
http://www.geekstogo.com
Rogue Security Software:Many rogue malware applications imitate antivirus software with fake system scans, claims that your computer is infected with malware, and that you need to purchase the full version of the program to remove these bogus infections:
Check out this list on Wikipedia of Rogue Anti Virus / Security Software.
===================
Source
Please visit this webpage for instructions for running ComboFix:
http://www.bleepingc...to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.
-----------------
Please go to VirusTotal, and upload the following file for analysis:
C:\WINDOWS\system32\logon.scr
Post the results in your reply.

Monday, September 12, 2011

"Hard disk not found"

Source
System administrator rights needed to control the hard disks
No Drive Letters Show in Disk Management
Try rescan for drive information
Start/run/cmd
diskpart
rescan
When finished type "exit" to quit diskpart and "exit" again to quit command prompt window.
Recheck Disk management for missing partitions.
 --------------------
If the problem is still valid here is a solution for you:
Start Windows - press Start - run - type regedit and press ok/enter.
Then find the following key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
There you will need to select Edit - New - Multi-String Value.
Rename it to UpperFilters. Then right click on this value and select Modify. Type PartMgr.
Quit and then restart Windows.
Since then the drive letters will be in WDM. The cause of the problem is in rootkit viruses to my mind.

Win32/Vundo.H

  •  Win32/Rbot!generic (CA)
  • W32/Rbot-Fam (Sophos)
  • Backdoor.Win32.Rbot.aeu (Kaspersky)
  • W32/Sdbot.worm (McAfee)
  • :W32/Gaobot.gen.worm (Panda)
  • W32.IRCBot (Symantec)
  • WORM_RBOT.GEN-1 (Trend Micro)
 geekstogo.com/forum/   trojan-vundoh-bho-and-trojanagent
/forums.majorgeeks.com/showthread.php?t=161380
========================

http://free.antivirus.com/hijackthis/
microsoft.com/security/pc-security/malware-removal.aspx

Thursday, September 8, 2011

Windows PowerShell and GPO

Deploying with SCCM has nothing to do with UAC.  UAC only counts when you are logged into the machinelocally.
The script you are running is set of batch commands that can be executed by SCCM.  ALl of these commands can also be done using POwerShell remnotely which also does nnot require UAC elevation.
None of the scenarios you describe indicate that UAC is your problem.
If run under SCCM it will be silent. SCCM runs elevated always.
This is a process that only ever gets run once. Wy is it a problem to have to eleavter.  Just choose to right click runas.  Running silently locally would only be required if you were trying to make something happen that shouldn't happen.
Use the PowerSHell sIIS 7 shell to run all of those commands remotely or even WMI remotely assuming you ae an administrator.  Remote operations with the administrator account do  not trigger UAC.

Using PowerShell remotely:
--------------------
As you may know, Windows PowerShell 2.0 introduced a new remoting feature, allowing for remote management of computers.
While this feature can be enabled manually (or scripted) with the PowerShell 2.0 cmdlet Enable-PSRemoting, I would recommend using Group Policy whenever possible. This guide will show you how this can be accomplished for Windows Vista, Windows Server 2008 and above. For Windows XP and Windows Server 2003, running Enable-PSRemoting in a PowerShell startup script would be the best approach.
Windows PowerShell 2.0 and WinRM 2.0 shipped with Windows 7 and Windows Server 2008 R2. To take advantage of Windows PowerShell Remoting, both of these are required on the downlevel operating systems Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008. Both Windows PowerShell 2.0 and WinRM 2.0 are available for download here, as part of the Windows Management Framework (Windows PowerShell 2.0, WinRM 2.0, and BITS 4.0). To deploy this update to downlevel operating systems I would recommend to use WSUS, which are described in detail in this blog post by Kurt Roggen.
Group Policy Configuration
Open the Group Policy Management Console from a domain-joined Windows 7 or Windows Server 2008 R2 computer.
Create or use an existing Group Policy Object, open it, and navigate to Computer Configuration->Policies->Administrative templates->Windows Components
Here you will find the available Group Policy settings for Windows PowerShell, WinRM and Windows Remote Shell:
image
To enable PowerShell Remoting, the only setting we need to configure are found under “WinRM Service”, named “Allow automatic configuration of listeners”:
More at link
-----------------------
Installing Roles and Features remotely on multiple computers simultaneously

Add elevated command prompt to context menu

Source 
I would like to add to my context menu an elevated command prompt (with administrator privileges) in the same or similar coding fashion (not binary code) as in this example below. The key is that it has to be "elevated" with Administrator privileges, not just a normal command prompt to open. I am not sure how to write a working script since it "MAY" (probably is) quite different than the coding pattern in my example here after including the 'elevated' coding component part to it:
[HKEY_CLASSES_ROOT\Directory\Background\shell\Elevated Command Prompt]
[HKEY_CLASSES_ROOT\Directory\Background\shell\Elevated Command Prompt\command]
@="control appwiz.cpl"
Please correct by adding and or deleting or modifying the script above so the code that would demonstrate a working "elevated" command prompt script to open in a window.
I would also like to add the command prompt icon to my context menu too. I am very sure that it would look something like this (pretty sure if the registry key information is correct though, probably it is not since I am looking for the script to be 'elevated' as I have already stated):
[HKEY_CLASSES_ROOT\Directory\Background\shell\Elevated Command Prompt]
"Icon"="C:\\Windows\\Context Menu Icons\\Elevated Command Prompt.ico"
Where an "Elevated Command Prompt" ico icon in a "Context Menu Icons" folder would be FIRST placed in the C:\Windows folder location BEFORE running a workable elevated command prompt registry script.
So what is the proper coding I need to do (and appropriately placed in this script) in order to add an elevated command prompt with the icon to this script so it works in the context menu???
sevenforums.com/tutorials/47415-open-command-window-here-administrator
1. To Add "Open Command Window Here as Administrator"
A) Click on the download button below to download the file below.
Add_Open_Command_Window_Here_as_Administrator.reg
download
B) Go to step 3.
2. To Remove "Open Command Window Here as Administrator"
A) Click on the download button below to download the file below.
Remove_Open_Command_Window_Here_as_Administrator.reg
download
3. Click on Save, and save the .reg file to the desktop.
4. Right click on the downloaded .reg file and click on Merge.
5. When prompted, click on Run, Yes, Yes, and OK to approve merging the .reg file.
6. You can now delete the downloaded .reg file if you like.
 

Elevation of privilege per script

Source
The designers of Windows Vista's User Account Control expressly decided not to incorporate functionality like setuid/suid or sudo found in Unix and Unix-like OSes such as Mac OS X. I think they made the right decision.  
Large parts of the Windows ecosystem have a long legacy of assuming that the end user has administrative permissions, and consequently a lot of programs work correctly only when run that way. (I'm not going to delve into that history here, nor will I entertain any finger-pointing on the topic at this time. One of these days I'll post my thoughts on that subject.) As computer security has become increasingly important, breaking that cycle became absolutely imperative. It is with the release of Windows Vista that the first major move in that direction is achieved. Indeed, the primary purpose of the technologies that comprise UAC is to make the "standard user" the default for Windows, encouraging software developers to create applications that do not require admin. It's not perfect by any means, but changing the ecosystem will take a long time, and UAC is a good first step.
Pre-approving code to run with elevated permissions without going through an elevation prompt, as described in the bulleted scenarios above, seems at first glance to be both useful and convenient. However, the negatives far outweigh those benefits. In particular:
  • The "standard user by default" vision would become impossible and ultimately never happen;
  • Elevation of privilege (EoP) would be trivial – any compromise could lead to full system compromise.
If it were possible to mark an application to run with silently-elevated privileges, what would become of all those apps out there with LUA bugs? Answer: they'd all be marked to silently elevate. How would future software for Windows be written? Answer: To silently elevate. Nobody would actually fix their apps, and end-user applications will continue to require and run with full administrative permissions unnecessarily.
What if the application could not mark itself for silent elevation but instead had to be marked by the consumer or enterprise administrator installing the application? Answer: the developer of the installation program (which necessarily runs with admin/system permissions in order to install machine-wide) would figure out where the setting lived, and set it. (Several major ISVs told us directly that they would in fact do exactly that.) There would be no real way to protect that setting from anything running as admin. This would be especially true if it were settable via Group Policy (which would be expected, if not demanded).
"Well, so what? We're only talking about applications I approved!" OK, let's say that's true, but how do you ensure that a malicious user cannot use the application for purposes other than those for which it was intended? And at least as important – how do you ensure that malware that has infected the user's session cannot drive a setuid application programmatically to take over the system? Ensuring strict behavioral boundaries for complex software running with elevated privileges is (at best) incredibly difficult. And ensuring that it is free of exploitable design and implementation bugs is far beyond the capabilities of software engineering today. The complexity and risk compounds when you consider how many apps have extensibility points that load code that you or your IT admin may not be aware of, or that can load code or consume data from user-writable areas with minimal if any validation.
Privilege escalation due to setuid and sudo has plagued Unix-like systems for many years, and continues to do so. In fact, several of the bugs in the recent Month of Apple Bugs fell into this category. Follow these links for lots more references: (*)
In the past, elevation of privilege has tended not to be noticed in Windows – there is no real "elevation" if you're already running as admin. (**) With the Vista shift toward "standard user", EoP threats become much more important, and it is vital that Windows do as much as practical to mitigate them. That is also why Windows services are no longer able to interact with the user desktop. Taking on the setuid headaches that *nix has had to live with does not seem like a profitable deal.
We expect that in ordinary day-to-day usage, users should rarely, if ever, see elevation prompts, since most should rarely, if ever, have to perform administrative tasks – and never in a well-managed enterprise. Elevation prompts are to be expected when setting up a new system or installing new software. Beyond that, they should be infrequent enough that they catch your attention when they occur, and not simply trigger a reflexive approval response. This will increasingly be the case as more software conforms to least-privilege norms, and as improvements in the Windows user experience reduces prompting further.
Having said all that, there is a Local Security Policy option to change the behavior of the elevation prompt for Administrators to "elevate without prompting". With this option selected, anything that requests elevation gets elevated without prompting the user. (The default setting is "prompt for consent"; the third option is "prompt for credentials". Note that "elevate without prompting" is available only for members of the Administrators group. The options for standard users are "prompt for credentials" and "automatically deny elevation requests".) While "elevate without prompting" may be useful in well-constrained, secure environments for automated testing and possibly for initial system setup, having this option selected otherwise is very risky and strongly discouraged. (Note also that Vista's Home SKUs do not include the policy editor.)
Nitpicker's corner (***)
(*) Pointing out the obvious: local privilege escalation by definition means that the bad actor is already on your system. However, there's a huge difference between malware running as you (non-admin) and malware running with root privileges.  If there weren't, there would be no point (from a security point of view) in running with least privilege.
(**) "Elevation of privilege" in this context means "unauthorized elevation of privilege". Technically, yes, Administrator is not as powerful as System (in that there are operations that Administrator will get Access Denied where System will succeed), and System is not as powerful as kernel-mode code (in that there are operations that fail for user-mode code running as System that succeed when called from kernel code). However, two of the things that Administrator is authorized to do include: 1) configuring arbitrary code to run as System, and running it; and 2) loading arbitrary code into the kernel, and running it. Hence, if code is running as admin, there is nothing it is not authorized to do.
(***) "Nitpicker's corner" might be a trademark of The Old New Thing.
--------------------------------------
if wscript.arguments.named.exists("elevated") = false then
  createobject("Shell.Application").ShellExecute "wscript.exe", """" & wscript.scriptfullname & """ / elevated", "", "runas", 1
else
  'what you want to do with elevated rights
end if
=================
Source
The VB Script below will raise a UAC challenge, then invoke your batch file, but it won't turn off UAC.
'---------------------------------------------
'Invoke a batch file under elevated privileges
'25.2.2011 FNL
'---------------------------------------------
bElevate = False
if WScript.Arguments.Count > 0 Then If WScript.Arguments(WScript.Arguments.Count-1) <> "|" then bElevate = True
if bElevate Or WScript.Arguments.Count = 0 Then ElevateUAC
Set oWshShell = CreateObject("WScript.Shell")
oWshShell.run "d:\temp\Ariel.bat"

'-----------------------------------------
'Run this script under elevated privileges
'-----------------------------------------
Sub ElevateUAC
    sParms = " |"
    If WScript.Arguments.Count > 0 Then
        For i = WScript.Arguments.Count-1 To 0 Step -1
            sParms = " " & WScript.Arguments(i) & sParms
        Next
    End If
    Set oShell = CreateObject("Shell.Application")
    oShell.ShellExecute "wscript.exe", WScript.ScriptFullName & sParms, , "runas", 1
    WScript.Quit
End Sub
===============================

It seems that you want to run the copy action as an administrator using the script itself.
You can refer the following URLs, hope it would be helpful.
Utility Spotlight - Script Elevation PowerToys for Windows Vista
http://technet.microsoft.com/en-us/magazine/2007.06.utilityspotlight.aspx?pr=blog
How Can I Run a Script Under Alternate Credentials?
http://blogs.technet.com/heyscriptingguy/archive/2004/12/13/how-can-i-run-a-script-under-alternate-credentials.aspx

Since this issue is more related to scripting, I recommend you open a thread to Official Scripting Guys Forum in Technet so those coders can help you fix the issue in a timely manner.
Official Scripting Guys Forum http://social.technet.microsoft.com/Forums/en/ITCG/threads
Script Center:  http://technet.microsoft.com/en-us/scriptcenter/default.aspx
===============================================

You should be able to get around this by using the runas command:
runas /user:administrator /savecred c:\batchfile.bat
you can also use the run as to place the admin's username and password in plain text, but that less desirable. In the above example, the batchfile.bat would contain all of your copy and install commands for the citrix client.