Print Page | Close Window

Removing Poison Ivy Rat

Printed From: Sysinternals
Category: Windows Discussions
Forum Name: Malware
Forum Discription: Discussions and news on identifying, cleaning, and preventing malware
URL: http://forum.sysinternals.com/forum_posts.asp?TID=13030
Printed Date: 02 September 2010 at 3:33pm


Topic: Removing Poison Ivy Rat
Posted By: Nv-LOL GFX
Subject: Removing Poison Ivy Rat
Date Posted: 12 December 2007 at 1:10pm
Some people say that the Start up Entry Exists

1. Kill explorer.exe
2. Kill all running instances of your browser (just to be sure).
3. Remove the runkey (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components), look for a key with only a stubpath item.
4. Remove the exe the runkey is pointing to.


I cannot find anything in HKLM

This rat is hard to find because i accidentally executed the server and it runs in processes

No files, No Processes, Nothing.

Now I have no option except a reformat....

Someone shed light please - As there is no file on my computer

It runs in other processes HENCE...No anti virus can detect anything suspicious And many never did.

I notice some of my desktop shortcuts have had their names changed.



-------------
I use Windows Xp Pro sp2 -
It R0xx0rs My b0xxorz?!1!one!!one



Replies:
Posted By: fcukdat
Date Posted: 12 December 2007 at 1:18pm
Can you PM me alink to a dropper for this RATTongue

-------------
___________
Ade Gill
Malwarebytes Researcher



Posted By: Elite
Date Posted: 12 December 2007 at 1:18pm
If I remember correctly, PoisionIvy has some weak rootkit capabilities. I believe it was something like firewall bypasser (SSDT unhooking), and process hiding. Dunno about files though. Forgot how the startup/file system works on this rat though...

Chances are, if there are no processes (and no hidden processes), then it's using DLL injection. You can try posting an autoruns log, and we can try yanking it. This rat is actually fairly easy to remove.

Btw, if you scanned with KAV, you'd find it. Up to you, KAV or Autoruns log. Fire up RkU as well. 


Posted By: fcukdat
Date Posted: 12 December 2007 at 1:34pm

EmbarrassedGoogle is your freindLOL

Damn this thing is well knownWink
 
File Poison_Ivy_2.3.0.exe received on 12.12.2007 22:26:35 (CET)
Result: 27/32 (84.38%)
Antivirus Version Last Update Result
AhnLab-V3 2007.12.13.10 2007.12.12 Win-Trojan/Poisonivy.2105798
AntiVir 7.6.0.40 2007.12.12 BDS/Poisonivy.Q.2
Authentium 4.93.8 2007.12.12 W32/Backdoor.AYAT
Avast 4.7.1098.0 2007.12.11 Win32:PoisonIvy-S
AVG 7.5.0.503 2007.12.12 BackDoor.Generic7.FYC
BitDefender 7.2 2007.12.12 Trojan.Hacktool.PoisonIvy.A
CAT-QuickHeal 9.00 2007.12.12 Backdoor.PoisonIvy.q
ClamAV 0.91.2 2007.12.12 Trojan.Small-2497
DrWeb 4.44.0.09170 2007.12.12 -
eSafe 7.0.15.0 2007.12.12 Win32.PoisonIvy.q
eTrust-Vet 31.3.5371 2007.12.12 -
Ewido 4.0 2007.12.12 Backdoor.PoisonIvy.q
FileAdvisor 1 2007.12.12 High threat detected
Fortinet 3.14.0.0 2007.12.12 W32/PoisonIvy.Q!tr.bdr
F-Prot 4.4.2.54 2007.12.12 W32/Backdoor.AYAT
F-Secure 6.70.13030.0 2007.12.12 Backdoor.Win32.PoisonIvy.q
Ikarus T3.1.1.12 2007.12.12 Backdoor.Win32.PoisonIvy.q
Kaspersky 7.0.0.125 2007.12.12 Backdoor.Win32.PoisonIvy.q
McAfee 5184 2007.12.12 -
Microsoft 1.3007 2007.12.12 -
NOD32v2 2719 2007.12.12 Win32/RemoteAdmin.PoisonIvy.230
Norman 5.80.02 2007.12.12 W32/PoisonIvy.ADC
Panda 9.0.0.4 2007.12.12 Bck/PoisonIvy.V
Prevx1 V2 2007.12.12 TROJAN.POISONIVY.A
Rising 20.22.22.00 2007.12.12 Backdoor.Win32.PoisonIvy.q
Sophos 4.24.0 2007.12.12 Troj/PoisonI-C
Sunbelt 2.2.907.0 2007.12.12 Trojan.Unclassified.gen
Symantec 10 2007.12.12 Trojan Horse
TheHacker 6.2.9.156 2007.12.12 Backdoor/PoisonIvy.q
VBA32 3.12.2.5 2007.12.10 Backdoor.Win32.PoisonIvy.q
VirusBuster 4.3.26:9 2007.12.12 -
Webwasher-Gateway 6.6.2 2007.12.12 Trojan.Backdoor.Poisonivy.Q.2
Additional information
File size: 2105798 bytes
MD5: fd287794107630fa3116800e617466a9
SHA1: 19862253caacadd621aaa74b78b334c01f4f346c
PEiD: -


-------------
___________
Ade Gill
Malwarebytes Researcher



Posted By: MEGA
Date Posted: 13 December 2007 at 2:29pm
hi,
The last version uses ADS to hide itself.
BTW that PI doesn't use DLL injection,  it use process injection.
-Kill all browsers instances, then kill explorer.exe, then restart explorer.exe.
-Scan with IceSword, you will find something like, C:\Windows\:server.exe
-Delete the ADS file
-And do a full scan with an up to date AV.

Hope it will help, and sorry for my english, i know that you will be able to remove it, Not that hard, good luck :)



Print Page | Close Window