Warning about istio.exe infection - no help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by bint, Oct 16, 2011.

Thread Status:
Not open for further replies.
  1. bint

    bint Private E-2

    Not sure where to report this. But I thought it better to get this out there. I was infected by something very sneaky that was missed by many virus scanners (see blow) and was hard to get rid of.

    C:\Documents and Settings\[User]\Application Data\Utta\istio.exe
    kept reappearing and trying to register in the registry but was blocked by my resident scanner Bitdefender.
    Also after delete, wipe and reboot the file reappeared.
    'Internet' did not seem to know what this istio.exe was.

    When it appeared BitDefender Antivirus 2010 recognized it during routine scanning as a Trojan.
    But BD was unable to remove it automatically. I could remove it by hand but not the directory it was in.

    Next to my regular scanner (BD) I scanned with the latest versions of
    Malwarebytes' Anti-Malware
    SUPERAntiSpyware
    Spybot - Search & Destroy
    TDSSKiller
    HijackThis
    RootRepeal

    None found anything except the last one.
    It found 2 active drivers with random names (e.g. 5344353.sys but they change after each reboot) loaded from C:\windows\system32\drivers\. However, the file it was loaded from appeared to be missing or invisible.

    The files scan of Rootrepeal also found a directory hidden from the Windows API: C:\recycle.bin.

    I could not reach it from inside windows so I went to dos.
    C:\recycle.bin was not listed by the dir command.
    dir *.bin listed a directory with an empty name.
    rd C:\recycle.bin did not work as the directory was not empty.
    cd c:\recycle.bin worked, but not del *.* in that directory
    del c:\recycle.bin\*.* did work
    and the subsequent rd c:\recycle.bin worked

    Now my system appears to be clean.

    Does anyone know what I just removed?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I will know when you have completely followed these procedures and attached logs. ;)

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. bint

    bint Private E-2

    Thanks for the offer, but I was not so much asking for help in cleaning my system. I did run most of the listed scanners before (ex MGtools). They all seem to agree the system is clean now.

    What I was wondering about was whether someone had seen the type of hiding I described before.

    It seems likely I was infected with a version of SpyEyes that was not detected by Bitdefender, Malwarebytes' Anti-Malware, SUPERAntiSpyware, Spybot - Search & Destroy, TDSSKiller, HijackThis. Only RootRepeal found something suspicious, which enabled me to eradicate the problem.

    If it is old news we can just drop it. If not, who do I tell (keeping in mind that I should have gotten rid of the evidence)?
    I can still post logs but would not want to waste your time as I do not have a problem myself.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, seen it many times before.
    Not sure I understand what you mean there. My apologies. What evidence?
    Entirely your choice, I do not mind either way, let me know, if you do not need any assistance I can lock the thread off. :)
     
  5. bint

    bint Private E-2

    In hindsight, my statement was ambiguous. Sorry. The evidence I was referring to was infected files. I am confident they are all gone.

    I will not waste anymore of your time.
    The thread can be closed. Thanks.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds