Malicious Software Removal Tool 5.43 released

Brink

Administrator
Staff member
Local time
6:39 AM
Messages
74,803
Location
Oklahoma
In this month’s Microsoft Malicious Software Removal Tool (MSRT) release, we continue taking down unwanted software, the pesky threats that force onto our computers things that we neither want nor need.

BrowserModifier:Win32/Clodaconas, for instance, displays ads when you’re browsing the internet. It modifies search results pages so that you see unsolicited ads related to your searches.

For example, if you were looking for a gift to give a loved one this holiday season and are searching for “fitness tracker”, your search results page might contain an ad like this:

Clo1.png


Figure 1. Ads injected by Clodaconas to search results for “fitness tracker”

It can also add pop-up ads when you’re visiting online retailer websites. For example, if you previously searched for “TV”, and then visited an online shop, the threat may display the following ad:

Clo2.png


Figure 2. Pop-up ad injected by Clodaconas to online retailer pages

BrowserModifier:Win32/Clodaconas does this by hijacking your domain name server (DNS) settings.

Injecting ads through DNS hijacking

When you browse the Internet, your PC contacts a DNS server to resolve the domain of the website you’d like to access. The DNS server returns the IP address of the website, which your PC then accesses to get the content to display.

Clo3.png


Figure 3. Normal domain name resolution by legitimate DNS servers

BrowserModifier:Win32/Clodaconas compromises this process to inject ads. It modifies DNS settings in your registry so that they point to a rogue DNS server. All DNS queries are therefore redirected to this DNS server, which resolves specific domains to the IP address of another attacker-controlled server.

This results in a man-in-the-middle (MITM) attack. Instead of getting content directly from the server of the website you’re accessing, your PC gets content from the MITM server. It contacts legitimate websites to get the actual content you’re looking for, but modifies it before it is displayed on your browser. This is how the unwanted ads are displayed on your search results pages or on online retail websites.

Clo4.png


Figure 4. In DNS hijacking, DNS requests are redirected to a rogue DNS server

This method of injecting ads meets the evaluation criteria that Microsoft Malware Protection Center (MMPC) uses for identifying unwanted software. This threat modifies webpage content without your consent. It also does this without using the browser’s supported extensibility models, hence our classification of this program as unwanted software.

Using rogue root certificate

Many websites use SSL encryption to protect transactions. This mechanism also prevents the modification of content served by websites. Browsers check the validity of a website’s SSL certificate against trusted root certification authorities’ certificates stored on your PC. Browsers show a warning page or icon if a website’s certificate is not trusted.

To avoid triggering this alert, BrowserModifier:Win32/Clodaconas installs a root certificate as a trusted root certification authority. With the rogue root certificate installed, ads can be injected into encrypted content and still appear valid to the browser.

MSRT removes Clodaconas

This month, we’re adding detections for BrowserModifier:Win32/Clodaconas to Microsoft Malicious Software Removal Tool (MSRT). If your PC is infected with this threat, run MSRT to remove all related files and restore all system modifications on your PC.

You may need to clear your browser cache after the threat is removed. The browser might still hold cache of a website you recently visited, so you might still see the ads.

Prevention, detection, and recovery

Stay protected from BrowserModifier:Win32/Clodaconas and other threats:

  • Keep your Windows operating system and antivirus up-to-date; if you haven’t already, upgrade to Windows 10.
  • Use Microsoft Edge. It can:
    • Help warn you about sites that are known to be hosting exploits and other threats
    • Help protect you from social engineering attacks such as phishing and malware downloads
    • Automatically detect bad changes and protect settings
  • Use the Settings app to reset to Microsoft recommended defaults if your default apps were changed.
    • Launch the Settings app.
    • Navigate to the Default apps page.
    • From Home go to System > Default apps.
    • Click Reset.
  • Ensure your antimalware protection (such as Windows Defender and Microsoft Malicious Software Removal Tool) is up-to-date.
    • If you are using Windows Defender, you can check your exclusion settings to see whether the malware added some entries in an attempt to exclude folders from being scanned.
      • To check and remove excluded items in Windows Defender:
        1. Navigate to Settings > Update & security > Windows Defender > Add an exclusion.
        2. Go through the lists under Files and File locations, select the excluded item that you want to remove, and click Remove.
        3. Click OK to confirm.
  • Use cloud protection to help guard against the latest malware threats. It’s turned on by default for Microsoft Security Essentials and Windows Defender for Windows 10. Go to All settings > Update & security > Windows Defender and make sure that your Cloud-based Protection settings is turned On.

Jody Koo
MMPC


Source: MSRT December 2016 addresses Clodaconas, which serves unsolicited ads through DNS hijacking Microsoft Malware Protection Center


See also:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Thanks Brink, great info.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Build
OS
Windows 7 Professional X64 Service Pack 1
CPU
AMD Phenom II X4 955 3.20GHz
Motherboard
Gigabyte GA-MA790X-UD4P
Memory
8G
Graphics Card(s)
GX550 Ti
Sound Card
On board
Monitor(s) Displays
Asus VW246H & Syncmaster 2243swx
Screen Resolution
1920x1080 & 1920x1080
Hard Drives
M4-CT128 SSD2, Samsung 840 256GB, 1 WDC 1TB
PSU
Corsair TX750W-V2
Case
Antec
Cooling
2 120mm fan
Keyboard
Microsoft Wireless 3050
Mouse
Microsoft Wireless 5000
Internet Speed
72/6Mbs (Cable)
Other Info
Asus AC1900 router, 8 port Trendnet Switch - Logitech Webcam Pro 9000
Is this included in the December Security Only Update? Or do I need to install it separately?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway GT5656
OS
Windows 7 x64 SP1
CPU
AMD Athlon 64 X2 6000+ / 3.0 GHz
Motherboard
NVIDIA GeForce 6150 SE
Memory
6 GB
Monitor(s) Displays
Lenovo LED
Screen Resolution
1920 X 1080
Hard Drives
Windows on 500 GB spinner; Ubuntu 16 on Sandisk 250GB SSD; Bodhi5 on Samsung 250GB SSD; another old spinner for fooling around.
PSU
Original that came with computer
Keyboard
Logitech wireless
Mouse
Logitech wireless
Antivirus
Microsoft Sec Essentials
Browser
Vivaldi
Is this included in the December Security Only Update? Or do I need to install it separately?

The Windows Malicious Software Removal Tool is shown as a separate item in this months Updates & is listed as KB890830 for the 64 bit computers.

If you download the December Updates you will see it listed.

If you install it, it is not shown in Installed Updates, so keep that in mind.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
Back
Top