Author Topic: Shortcut virus CMD in C:\Windows\System32 - How to erase it???  (Read 10657 times)

0 Members and 1 Guest are viewing this topic.

Acnalb

  • Guest
Hi!

Yesterday I used my USB to print a document in an internet cafe. When I came back home I inserted the USB in my laptop and all my USB files turned into shorcuts.
Each time I erase the files and put new ones, they turn into shorcuts. I right-clicked one of the shortcuts, and looked at the target location, and it's somewhere in System32, and the file in System32 that it highlights is cmd.exe
Basically, I have the same problem solved here:

http://forum.avast.com/index.php?topic=138715.0

but I guess each PC needs a special treatment in this matter. Thank you all for your answers :)

PS: I won't insert any other USB until I'm sure it's solved.

Valinorum

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #1 on: April 25, 2014, 07:45:37 AM »
Peruse the thread here and attach the following logs --
  • OTL.txt
  • Extras.txt
  • aswMBR Log
  • MCShield



A helper will be here to assist you.

Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #2 on: April 26, 2014, 10:20:15 PM »
I don't get this :/

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #3 on: April 26, 2014, 10:21:20 PM »
Maybe its not in their database yet.

Attach OTL and aswMBR logs here please.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #4 on: April 26, 2014, 11:07:47 PM »
Maybe its not in their database yet.
because it is a filetype that Malwarebytes does not target?...

« Last Edit: April 26, 2014, 11:14:03 PM by Pondus »

Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #5 on: April 27, 2014, 02:38:00 AM »
Done :)
the following are OTL logs
« Last Edit: April 27, 2014, 03:44:29 AM by Acnalb »

Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #6 on: April 27, 2014, 02:39:38 AM »
And these are aswMBR logs

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #7 on: April 27, 2014, 02:41:54 AM »
i think all malware experts are in bed now so it will be some hours before they are online.....


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #8 on: April 27, 2014, 03:01:20 AM »
Did you tell mbam to scan the usb?
And get mcshield. ( http://www.mcshield.net/ )

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #9 on: April 27, 2014, 03:16:44 AM »
Did you tell mbam to scan the usb?
And get mcshield. ( http://www.mcshield.net/ )
the cleaning guys does this in a certain order Eddy ..... and Malwarebytes does not detect this if it is a VBS worm




Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #10 on: April 27, 2014, 03:42:19 AM »
I'm doing this before I go to sleep, that's why I post so late ;)

Valinorum

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #11 on: April 27, 2014, 06:36:14 AM »
While I analyze your log, read my reply here and attach the MCShield log. :)

Valinorum

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #12 on: April 27, 2014, 12:21:49 PM »
Hi Acnalb, :)

Did you knowingly make the following directory?
Code: [Select]
C:\Users\user\Desktop\fuck


  • Step #1 Fix with OTL
    • Re-run OTL by right clicking and choosing Run as administrator;
    • Under the Custom Scans/Fixes Box copy and paste the following contents inside the code box.
Code: [Select]
:Commands
[createrestorepoint]

:OTL
O4 - HKU\S-1-5-21-157729090-2090861767-380975361-1000..\Run: [jSugLyCC] wscript.exe //B "C:\Users\user\AppData\Local\Temp\jSugLyCC.vbs" File not found
O13 - gopher Prefix: missing

:Commands
[emptytemp]
  • Click on "Run Fix" and let the program run unhindered;
  • Your PC will reboot automatically and a log will be opened;
  • Please attach it in your next reply.



  • Step #2 Fix With Anti-VBS/VBE
    Download and run the appropriate version from here. Let the scan finish and attach the log when done.


  • Step #3 Scan with OTL
    • Re-run OTL.exe
    • Copy and Paste the following code inside the Custom Scans/Fixes box;
    Code: [Select]
    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    dir "%systemdrive%\*" /S /A:L /C
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
      • Click the Quick Scan button;
      • After the scan two logs will be produced;
      • Attach the logs in your next reply



    • Required Log(s):
      • OTL Log(s) --
        • OTL Fix Log;
        • OTL.txt
      • Anti-VBS Log
    Regards,
    Valinorum

Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #13 on: April 27, 2014, 12:22:57 PM »
MCS log

Acnalb

  • Guest
Re: Shortcut virus CMD in C:\Windows\System32 - How to erase it???
« Reply #14 on: April 27, 2014, 12:26:00 PM »
Oh yes, I'm sorry! I was so angry about losing my files (all my university classes were there) so I created that directory and I put there the files I managed to save