{"id":315,"date":"2014-12-14T11:00:36","date_gmt":"2014-12-14T16:00:36","guid":{"rendered":"http:\/\/triplescomputers.com\/blog\/?p=315"},"modified":"2014-12-14T11:00:36","modified_gmt":"2014-12-14T16:00:36","slug":"poweliks-widespread-malware-without-a-filesystem-object","status":"publish","type":"post","link":"https:\/\/www.triplescomputers.com\/blog\/casestudies\/poweliks-widespread-malware-without-a-filesystem-object\/","title":{"rendered":"Poweliks: Widespread malware without a filesystem object"},"content":{"rendered":"<p><strong><em>Preliminary note: \u00a0<\/em><\/strong><em>This process will normally remove Poweliks from a system. \u00a0However,\u00a0Poweliks is merely a\u00a0<em>tiny fraction\u00a0<\/em>of what is usually also alongside it on an infected system; after all, it is a downloader. \u00a0So if you&#8217;re trying DIY disinfection, just be advised that there is a\u00a0<em>very\u00a0<\/em>good chance that your system is still infected even after this process by multiple other malware families. \u00a0I would advise\u00a0hiring a professional in your local area to assist with the job instead of risking your personal information and data!<\/em><\/p>\n<p>I&#8217;ve long been preaching that scanners just don&#8217;t do the trick as a universal, one-size-fits-all solution to malware, and that&#8217;s precisely because they\u00a0<em>can&#8217;t\u00a0<\/em>possibly catch everything. \u00a0The latest zero-day threats will always find a way to evade even the best antimalware tools in some capacity, and because of that, a complete reliance on scanners for either\u00a0proactive blocking of threats\u00a0<em>or\u00a0<\/em>removal of existing embedded threats is misguided and will always run into trouble.<\/p>\n<p>This latest threat, which has now been circulating for a few months, is a perfect example of this. \u00a0It&#8217;s called\u00a0<strong>Poweliks<\/strong>, and it&#8217;s unique for one very specific reason: it\u00a0infects the system without the use of a filesystem component at all. \u00a0Now, it&#8217;s not like this is the first threat to accomplish such things; before it, we had such interesting specimens as the <a title=\"TDL4\" href=\"http:\/\/triplescomputers.com\/blog\/casestudies\/12\/\" target=\"_blank\">TDL4 rootkit<\/a>, which created a hidden, encrypted partition at the end of the drive containing the rootkit&#8217;s code, which was loaded at each boot\u00a0<em>before\u00a0<\/em>the Windows partition. \u00a0Eventually, however, this rootkit was identifiable (at least, somewhat) via the presence of a\u00a0conspicuous (and suspicious) 10 MB or so\u00a0empty space (RAW) at the end of a drive. \u00a0And it was easy to kill: simply delete that partition from offline and set the proper Windows partition as active.<\/p>\n<p>Poweliks uses a totally different approach: it embeds itself in the system&#8217;s registry in an encrypted key that\u00a0actually contains the body of the malware as opposed to mere settings and\u00a0program data (as is intended for the Windows registry to contain). \u00a0The identity of the key has changed across variants, but the most recent one I&#8217;ve seen is:<\/p>\n<blockquote><p>HKEY_LOCAL_MACHINE\\Software\\classes\\clsid\\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}\\LocalServer32<\/p><\/blockquote>\n<p>What about symptoms? \u00a0Well, they&#8217;re not all that clear-cut. \u00a0The machine will certainly be\u00a0<em>slower than normal<\/em>. \u00a0Apart from that, it may simply be generally infected, as that&#8217;s what Poweliks is all about: downloading other infections. \u00a0The problem is that you cannot search for a particular process in memory or even a file on the hard drive, as no file exists and the process is always a completely legitimate one.<\/p>\n<p>However, at least as of currently, it is\u00a0<em>not\u00a0<\/em>random. \u00a0The most recent process which\u00a0has been associated with Poweliks infections is <strong>dllhost.exe<\/strong>. \u00a0It&#8217;s a totally normal process, so seeing it running by no means indicates infection. \u00a0However, seeing it running persistently and for long periods of time is a bit more suspicious if you&#8217;re having other symptoms. \u00a0And if you close dllhost.exe using Task Manager and it repeatedly reappears in multiple instances, it&#8217;s a really suspicious scenario. \u00a0You&#8217;ll also likely see tons of other random (normally legitimate) processes running which should not need to be running. \u00a0These\u00a0can&#8217;t be specified here as they\u00a0<em>are\u00a0<\/em>random.<\/p>\n<p>For further diagnosis, however, you can download <a title=\"Process Explorer\" href=\"http:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb896653.aspx\" target=\"_blank\">Process Explorer<\/a>\u00a0to inspect the genealogy of the processes that are currently running. \u00a0It&#8217;s a dead giveaway: if dllhost.exe is launching dozens of other processes, you know it&#8217;s Poweliks.<\/p>\n<p><em><strong>Removal<\/strong><\/em><\/p>\n<p>This isn&#8217;t so bad at all if you know how to tackle it!<\/p>\n<p>The easiest way to handle it is to prepare with a tool that can handle removal first. \u00a0In this case, I recommend\u00a0<strong>RogueKiller<\/strong>.<\/p>\n<p><em><strong>NOTE: \u00a0<\/strong>This tool isn&#8217;t to be used lightly, especially by those who aren&#8217;t thoroughly familiar with\u00a0computer repair. \u00a0By design, it is heavy on false positives, so take care when agreeing to remove what it flags as suspicious.<\/em><\/p>\n<p>Try the following approach:<\/p>\n<ol>\n<li>Open RogueKiller; allow the prescan to finish. \u00a0Run a scan.<\/li>\n<li>Once the scan completes, look for its detection of Poweliks on the Registry tab. \u00a0Be sure it is selected for removal.<\/li>\n<li>Open <a href=\"http:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb896653.aspx\" target=\"_blank\">Process Explorer<\/a>. \u00a0Pause all dllhost.exe processes. \u00a0Kill all processes below any dllhost.exe process once the processes have been paused.<\/li>\n<li>Click Delete on the RogueKiller window and immediately reboot the system.<\/li>\n<\/ol>\n<p>With any luck, upon reboot, the malware will be gone. \u00a0By pausing the process with Process Explorer, you essentially negate\u00a0the malware&#8217;s ability to detect its neutralization via watchdog processes that relaunch the dllhost parent process after it&#8217;s killed. \u00a0That enables disinfection to take place before the malware is relaunched and the registry key\u00a0is reinfected.<\/p>\n<p>Of course, to repeat myself, keep in mind that Poweliks is merely a\u00a0<em>tiny fraction\u00a0<\/em>of what is usually also alongside it on an infected system; after all, it is a downloader. \u00a0So if you&#8217;re trying DIY disinfection, just be advised that there is a\u00a0<em>very\u00a0<\/em>good chance that your system is still infected even after this process by multiple other malware families. \u00a0I would advise\u00a0hiring a professional in your local area to assist with the job instead of risking your personal information and data!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Preliminary note: \u00a0This process will normally remove Poweliks from a system. \u00a0However,\u00a0Poweliks is merely a\u00a0tiny fraction\u00a0of what is usually also alongside it on an infected system; after all, it is a downloader. \u00a0So if you&#8217;re trying DIY disinfection, just be &hellip; <a href=\"https:\/\/www.triplescomputers.com\/blog\/casestudies\/poweliks-widespread-malware-without-a-filesystem-object\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[],"class_list":["post-315","post","type-post","status-publish","format-standard","hentry","category-casestudies","category-security"],"_links":{"self":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/315","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/comments?post=315"}],"version-history":[{"count":0,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/posts\/315\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/media?parent=315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/categories?post=315"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.triplescomputers.com\/blog\/wp-json\/wp\/v2\/tags?post=315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}