Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: takermysterio619 on September 20, 2008, 03:15:53 AM

Title: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: takermysterio619 on September 20, 2008, 03:15:53 AM
Hey there, I'm new to these boards and I really need help getting rid of this problem. Everytime I plug in a flash drive or anything in a USB slot, the file autorun.inf keeps coming up. Deleting it won't get rid of it as the virus just makes a new autorun.inf file. I really need help, I've done a boot-time scan and found a few things, corrected them, but still havent been able to get rid of this problem.

Here is the details of the autorun.inf file from the virus chest.


Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: autorun.inf
FileID: 20
Virus Description: VBS:Malware-gen


Can anyone help me get rid of this? Thanks
Title: Re: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: sandeep108 on September 20, 2008, 07:40:34 AM
I also had a variant of this nasty one - I think it was called nhatquanlan - do a google search, it will help in getting rid of it. It makes all files into folders, hides folder options in explorer and is particularly difficult to get rid of. I was in limited account mode so it could not alter the registry or install itself, but my/shared documents folders' all got hit and I had to manually delete all the nonsense it created. A friend (from whose usb drive I got it) running in admin mode, simply could not get back and had to re-install the OS.

I am surprised that despite having avast! updated, you got this one. Use tweakxp to turn off auto play for all removable drives.

Maybe others will have more suggestions or point out if I am wrong about what you have.
Title: Re: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: Lisandro on September 20, 2008, 02:29:36 PM
Maybe this helps:

Title: Re: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: Maxx_original on September 20, 2008, 02:38:19 PM
it could be a new variant of Kavo/Tavo/s00l infection... have you noticed any warning from the antirootkit module?
Title: Re: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: chaz4j on July 14, 2009, 02:54:44 PM
Hey there, I'm new to these boards and I really need help getting rid of this problem. Everytime I plug in a flash drive or anything in a USB slot, the file autorun.inf keeps coming up. Deleting it won't get rid of it as the virus just makes a new autorun.inf file. I really need help, I've done a boot-time scan and found a few things, corrected them, but still havent been able to get rid of this problem.

Here is the details of the autorun.inf file from the virus chest.


Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: autorun.inf
FileID: 20
Virus Description: VBS:Malware-gen


Can anyone help me get rid of this? Thanks

the same thing keeps happening to me!
Title: Re: VBS:Malware-gen ... autorun.inf keeps creating itself in USB drives..
Post by: DavidR on July 14, 2009, 03:44:39 PM
Then take the action suggested by Tech as that is a preventative measure to preven autorun.inf files being created in the future.

Contained in the autorun.inf file are commands to run other files and this is the true payload.

Using notepad, can you post the contents of the aurorun.inf file ?

Then you could see if the files that it mentions are actually on your system.
Upload the file/s to VirusTotal, Send a sample to avast if multiple detections at VT (see below).

Check the suspect file/s at: VirusTotal - Multi engine on-line virus scanner (http://www.virustotal.com/) and report the findings here in the topic, the URL in the Address bar of the VT results page. If multiple scanners find these infected send the samples to avast for analysis and inclusion in the virus database.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a reference to this topic (give URL) and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.