{"id":222,"date":"2012-01-27T14:35:25","date_gmt":"2012-01-27T21:35:25","guid":{"rendered":"http:\/\/www.wei-tek.com\/myblog\/?p=222"},"modified":"2012-08-02T17:12:32","modified_gmt":"2012-08-03T00:12:32","slug":"new-malware-strain-infection","status":"publish","type":"post","link":"https:\/\/blog.wei-tek.com\/?p=222","title":{"rendered":"New Malware Infection"},"content":{"rendered":"<p>Had a client with a system that was infected with an new strain of malware. It was identified as Trojan.Win32.Genome.arbx and was infecting the svchost.exe.<\/p>\n<p>The system was running Windows XP Kaspesky Antivirus 2011. The client complaint was that the system had been locking up and running slow. Initial contact with the system was remotely.\u00a0 Initial check show that the Kaspersky was was running and the database were up to date.<\/p>\n<p>I checked\u00a0 the task manager and found 6 iexplorer processes running without a user interface. Attempts to kill the process would restart a new process.\u00a0 I updated Malwarebytes, Ran a scan<!--more--> and found 155 infected objects, deleted those objects and restarted the system.\u00a0 After the reboot, Kaspersky popped a message stating the svchost.exe was infected with the Trojan, and in would only allow it to be ignored.<\/p>\n<p>I checked the task manager and the iexplorer processes were still running.\u00a0 I check the setting in Kasperky and found the the setting to ignore the svchost.exe removed it from the expetion list, only to have it return.<\/p>\n<p>Ran Malwarebytes full scan and did not locate any malware. At this point I shutdown the system and told the client I wold pickit up when I got back into town. I picked up the system and took it to the office I ran my tools in safe mode and did not find the malware.\u00a0 I finally did a repair install of WinXP that got rid of the trojan.<\/p>\n<p>After patching the system. Kaspersky would not start it protective services on boot, I had to start them manually. I tried updating to 2012 and still had the same problem. I finally un-installed Kaspersky and scrubbed the registry and residual\u00a0 keys, after reinstalling everything was working properly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Had a client with a system that was infected with an new strain of malware. It was identified as Trojan.Win32.Genome.arbx and was infecting the svchost.exe. The system was running Windows XP Kaspesky Antivirus 2011. The client complaint was that the system had been locking up and running slow. Initial contact with the system was remotely.\u00a0 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[24],"tags":[51,50],"class_list":["post-222","post","type-post","status-publish","format-standard","hentry","category-windows","tag-kaspersky","tag-malware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New Malware Infection - WEI-Tek Consulting Company Blog<\/title>\n<meta name=\"description\" content=\"The trials and tribulations of Malware\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.wei-tek.com\/?p=222\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Malware Infection - WEI-Tek Consulting Company Blog\" \/>\n<meta property=\"og:description\" content=\"The trials and tribulations of Malware\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.wei-tek.com\/?p=222\" \/>\n<meta property=\"og:site_name\" content=\"WEI-Tek Consulting Blog\" \/>\n<meta property=\"article:published_time\" content=\"2012-01-27T21:35:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2012-08-03T00:12:32+00:00\" \/>\n<meta name=\"author\" content=\"rainewalker\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"rainewalker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222\"},\"author\":{\"name\":\"rainewalker\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/#\\\/schema\\\/person\\\/57843d667045c1d2e92f6709b31826cc\"},\"headline\":\"New Malware Infection\",\"datePublished\":\"2012-01-27T21:35:25+00:00\",\"dateModified\":\"2012-08-03T00:12:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222\"},\"wordCount\":297,\"commentCount\":10,\"keywords\":[\"Kaspersky\",\"Malware\"],\"articleSection\":[\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222\",\"url\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222\",\"name\":\"New Malware Infection - WEI-Tek Consulting Company Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/#website\"},\"datePublished\":\"2012-01-27T21:35:25+00:00\",\"dateModified\":\"2012-08-03T00:12:32+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/#\\\/schema\\\/person\\\/57843d667045c1d2e92f6709b31826cc\"},\"description\":\"The trials and tribulations of Malware\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/?p=222#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/blog.wei-tek.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Malware Infection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/#website\",\"url\":\"https:\\\/\\\/blog.wei-tek.com\\\/\",\"name\":\"WEI-Tek Consulting Blog\",\"description\":\"Tip, Tricks and Letting off steam\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.wei-tek.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.wei-tek.com\\\/#\\\/schema\\\/person\\\/57843d667045c1d2e92f6709b31826cc\",\"name\":\"rainewalker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g\",\"caption\":\"rainewalker\"},\"sameAs\":[\"http:\\\/\\\/www.my-businessmail.com\"],\"url\":\"https:\\\/\\\/blog.wei-tek.com\\\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New Malware Infection - WEI-Tek Consulting Company Blog","description":"The trials and tribulations of Malware","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.wei-tek.com\/?p=222","og_locale":"en_US","og_type":"article","og_title":"New Malware Infection - WEI-Tek Consulting Company Blog","og_description":"The trials and tribulations of Malware","og_url":"https:\/\/blog.wei-tek.com\/?p=222","og_site_name":"WEI-Tek Consulting Blog","article_published_time":"2012-01-27T21:35:25+00:00","article_modified_time":"2012-08-03T00:12:32+00:00","author":"rainewalker","twitter_misc":{"Written by":"rainewalker","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.wei-tek.com\/?p=222#article","isPartOf":{"@id":"https:\/\/blog.wei-tek.com\/?p=222"},"author":{"name":"rainewalker","@id":"https:\/\/blog.wei-tek.com\/#\/schema\/person\/57843d667045c1d2e92f6709b31826cc"},"headline":"New Malware Infection","datePublished":"2012-01-27T21:35:25+00:00","dateModified":"2012-08-03T00:12:32+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.wei-tek.com\/?p=222"},"wordCount":297,"commentCount":10,"keywords":["Kaspersky","Malware"],"articleSection":["Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.wei-tek.com\/?p=222#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.wei-tek.com\/?p=222","url":"https:\/\/blog.wei-tek.com\/?p=222","name":"New Malware Infection - WEI-Tek Consulting Company Blog","isPartOf":{"@id":"https:\/\/blog.wei-tek.com\/#website"},"datePublished":"2012-01-27T21:35:25+00:00","dateModified":"2012-08-03T00:12:32+00:00","author":{"@id":"https:\/\/blog.wei-tek.com\/#\/schema\/person\/57843d667045c1d2e92f6709b31826cc"},"description":"The trials and tribulations of Malware","breadcrumb":{"@id":"https:\/\/blog.wei-tek.com\/?p=222#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.wei-tek.com\/?p=222"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/blog.wei-tek.com\/?p=222#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.wei-tek.com\/"},{"@type":"ListItem","position":2,"name":"New Malware Infection"}]},{"@type":"WebSite","@id":"https:\/\/blog.wei-tek.com\/#website","url":"https:\/\/blog.wei-tek.com\/","name":"WEI-Tek Consulting Blog","description":"Tip, Tricks and Letting off steam","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.wei-tek.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.wei-tek.com\/#\/schema\/person\/57843d667045c1d2e92f6709b31826cc","name":"rainewalker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d680e5f042d634a22d17592d61565cd82ae4b89c745ba619c1d8e796fb79b89?s=96&d=identicon&r=g","caption":"rainewalker"},"sameAs":["http:\/\/www.my-businessmail.com"],"url":"https:\/\/blog.wei-tek.com\/?author=2"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p2SXof-3A","_links":{"self":[{"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=\/wp\/v2\/posts\/222","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=222"}],"version-history":[{"count":0,"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=\/wp\/v2\/posts\/222\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wei-tek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}