Author Topic: Shortcut virus - Location: cmd (C:\Windows\System32)  (Read 13204 times)

0 Members and 1 Guest are viewing this topic.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #15 on: March 17, 2014, 02:14:39 PM »
Hi Breymon,
I'll will be working on your Malware issues ...


Three steps, preform one by one:
1. Detach USB devices. Do NOT use any USB device while cleaning is in progress:

2. Re-run OTL.exe.

  • Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.

Code: [Select]
:Processes
wscript.exe

:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKU\S-1-5-21-29226177-2797569431-4076014346-1000\..\SearchScopes\{B782F22C-BB0A-4653-BF20-AFB286FEE882}: "URL" = http://www.mysearchresults.com/search?c=3523&t=01&q={searchTerms}
FF - HKCU\Software\MozillaPlugins\@tightropeinteractive.com/Plugin: C:\Users\USER\AppData\Local\TNT2\2.0.0.1663\npTNT2.dll File not found
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?ctid=CT3321897&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP4884FE15-4AFA-4B68-AC16-F10F359F4332&q={searchTerms}&SSPV=
CHR - default_search_provider: suggest_url = http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms},
O4 - HKU\S-1-5-21-29226177-2797569431-4076014346-1000..\Run: [sdfsgj] wscript.exe //B "C:\Users\USER\AppData\Local\Temp\sdfsgj.vbs" File not found
O4 - Startup: C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sdfsgj.vbs ()
F3 - HKU\S-1-5-21-29226177-2797569431-4076014346-1000 WinNT: Load - (C:\Users\USER\LOCALS~1\Temp\ccavzxccu.exe) -  File not found
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\rjatydimofu.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O33 - MountPoints2\{5682d94b-2cdb-11df-b6e8-000df07632fc}\Shell - "" = AutoRun
O33 - MountPoints2\{5682d94b-2cdb-11df-b6e8-000df07632fc}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d06cd67-14bc-11df-af15-000df07632fc}\Shell - "" = AutoRun
O33 - MountPoints2\{9d06cd67-14bc-11df-af15-000df07632fc}\Shell\AutoRun\command - "" = G:\.\ShowModem.exe

:Files
dir C:\FRST /c
C:\install.exe
C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\xdfua2ld.default\extensions\{21D93807-FE23-3647-D96B-51819DE2CD46}
C:\Users\USER\AppData\Roaming\mozilla\Firefox\Profiles\xdfua2ld.default\extensions\34f57b0c-8cdb-4914-818c-928df47c6c4f@3a243122-a6fc-40c9-a1e6-ba11e930da09.com
C:\Users\USER\AppData\Roaming\mozilla\firefox\profiles\xdfua2ld.default\extensions\{25d71abf-7776-46f5-a269-9951331f9030}.xpi
C:\Users\USER\AppData\Roaming\mozilla\firefox\profiles\xdfua2ld.default\extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi
C:\Users\USER\AppData\Roaming\mozilla\firefox\profiles\xdfua2ld.default\searchplugins\utorrentcontrolv6-customized-web-search.xml
C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaabcbmongicmdegkmmfgdickgnnob
C:\Users\USER\AppData\Local\Temp\*.vbs
C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.vbs
DEL %TEMP%\*.* /F /S /Q /c

:Commands
[Reboot]

  • Then click the Run Fix button at the top.
  • Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
If the log doesn't appear, it can be found here:

c:\_OTL\MovedFiles\mmddyyyy_hhmmss.log



3. Make sure MCShield is active, re-attach all your USB devices and allow MCShield to preform the cleaning.


« Last Edit: March 17, 2014, 02:17:30 PM by magna86 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #16 on: March 17, 2014, 02:26:27 PM »
Thanks Magna,

breymon, from now on, listen to magna. He is much more trained then I am. No doubt about that. If you have any questions please direct the to him.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

SosVirus

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #17 on: March 19, 2014, 11:04:14 AM »
Hi ,

UsbFix Is easy to use

The infection VB here is an infection of dinihou type ( FR Info Dinihou : http://www.sosvirus.net/infection-dinihou-vous-explique-son-fonctionnement-t4852.html )
UsbFix takes care of this family of infection

Tutorial : http://www.en.usbfix.net/2014/02/usbfix-tutorial-clean-option/
Infection spreading through usb peripherals – What is it ? : http://www.en.usbfix.net/2014/03/infections-spreading-usb-peripherals/

Cordialy

El Desaparecido.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #18 on: March 19, 2014, 11:17:10 AM »
I presume you are from the SOSVirus team with g3n?

Not to "put you down". But they'll be many ways to fix this. Including MCShield which also picked the infection up. To prevent further infection, Magna has provided a fixlist that will remove the VBS file and any run keys on the machine.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

gen-hackman

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #19 on: March 19, 2014, 11:20:00 AM »
With USBFix , no need to fixlist , the tool does all in the same time :)

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #20 on: March 19, 2014, 11:21:06 AM »
Has that been confirmed though? Currently on Avast! it's the perferred way to remove USB VBS Worms
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

gen-hackman

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #21 on: March 19, 2014, 11:54:36 PM »
Yes confirm !! very better than McShield which forces you to script behind because it doesn't delete all the infection

it deletes IFEOs too
it cuts all processes while operating
it reattibutes "no hidden" files/folders in removables"

and does so many things else :)

good discover of the tool :D

SosVirus

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #22 on: March 20, 2014, 06:47:10 AM »
Hello Michael ,

Quote
I presume you are from the SOSVirus team with g3n?

I'm El Desaparecido , Webmaster of SosVirus.net and developper of UsbFix.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #23 on: March 20, 2014, 10:40:20 AM »
Hmm, okay, can we take this into a Private chat that way we don't interefere with Magna?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

SosVirus

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #24 on: March 20, 2014, 11:05:38 AM »
Quote
Hmm, okay, can we take this into a Private chat that way we don't interefere with Magna?

I'm not authorized to answer private message on this forum.. :(

The IFEO 64bit will be added to the next version of usbfix ;)

To contact me : http://www.en.usbfix.net/contact/

Have fun Michael !

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #25 on: March 21, 2014, 06:48:52 AM »
Hi all,
People, you mustn't not mix tool with the software and because of favoritism to little confuse people.
Shouldn't be exaggerated and laud some software without giving any explanation. You all mising some big point here.
Btw, it isn't McShield but MCShield alias for MyCity (forum) Shield.


Like I've sad, you are mixing the two different things: USBFix and MCShield are not the same and probably never will be ! !
USBFix is a portable (executive) tool. MCShield is a installation program. If just a someone was run both tool (run USBFix and install MCShield) it would understood the difference as a fact.

Btw, do NOT get me wrong, USBFix is a valid and usefull tool, yes. I have been used this more than 'few' times for advanced diagnostics, testing...etc
USBFix is not a stranger to me. Congratulations to competition, it's nice to have this kind of software as alternative. ;)

But let's reconcile with the fact:
USBFix is mainly for trained eye only. Only someone who knows what he's doing can use USBFix.
You can not expect e.g. my sister to use USBFix. She doesn't even know that she have MCShield installed on computers (who does everything in auto mod without knowing that something is preformd), not to mention of using USBFix.


While USBFix is for trained eyes, MCShield is noob ready + has RTM (real-time monitor) module. Again, for note, do not let yourself be underestimated MCShield develop and years of experience.
Authors of MCS program are two men who were among the first people in ASAP Alliance, later emerged and UNITE alliance. MCShield is successor of former USBNoRisk, once great (and only of his kind at that time) diagnostic tool as it is today USBFix.
At that time USBNoR. was the only tool of this type, but only for trained eyes.
When there was USBNoR. tool, it did not exist USBFix nor any other similar tool. Then, the authors decided to write a better program that anyone can use (for noob and IT users),
not to stay only at advanced diagnostic tool level that would be limited only for IT sector.


Let's return to USBFix and MCShield era. As a fix tool (USBFix) have a purpose to preform system diagnostics and target known malware or to script that.
Active softwer (MCShield's RTM) have the effect of real-time provide protection and prevent infection of any USB based malware as a portable (USB) device to your PC.
In addition, MCS shall remove all malware from USB device, without exception. With MCShield all your USB devices will stay clean. MCS's official description:
" MCShield is an antimalware program designed to prevent infections transmitted via removable drives. "

We believe that cleaning malware from the computer itself should be left for AV/AM program or some other tool. MCShield as a program should not interfere in AM/AV's malware cleaning process. MCS does not seek malware on the host system. Not designed for it and that isn't MCS's job. His job is clearly stated in the description. To make shure USB devices are clean.
What MCS does on system is searching for the root partition and mointpoint2 reg keys (I think that I haven't forgotten something).

As for the VBS/VBE script worms, for these reasons, we have these standalone tool named Anti-vbs/vbe tool.
http://www.mcshield.net/download/tools/Anti-VBSVBE/
It should be stated that this type of worm is not complicated to remove from the system. It can be done with the simple batch file. All you have to do is to kill 'wscript.exe' process BC that is what it holds the worms.
When process is killed, you can delete the malware, whichever way you want, even manually. As for removing the infection from USB device, it can be done with FRST and CMD:' utility without using MCShield program or USBFix tool.

For this reason, I stated the following !
If host mashine is malware free (again, this is job for some AV/AM program), and if AV program does not interfere in the MCS's work,
I guarantee that MCShield shall clean all malware from all USB devices using the powerful combination of different heuristics engine for detections USB based malware.
MCS prevents infection from some file infector transferred via USB (like Sality) as well as other dangerous worms like Conficker, Stuxnet, Flame, Crypt  known and unknown...
With heuristics of: AntiAutorun, AntiScript, AntiLNK, pair of AntiMimics routines, three AntiReplicator routines, AntiRimecud, known bad file/folder names check, AntiEsfury (stands for folder name heur. few similar routines), AntiCryptoLocker (USB based), hashes, general/blended file heuristics (files are checked in 6 ways), CheckFileSignatures ...etc, I feel comfortable to say: I guarantee that MCShield will keep you USB drives clean.



---       ---      ---      ---      ---      ---      ---
To comment above posted posts :)

@SosVirus (El Desaparecido)
Hello and welcome to avast!. ;)
For some time I follow your work. USBFix is great tool, good job.
Quote
I'm not authorized to answer private message on this forum..
You can do that with 20 post, not before. Forum rules.


@g3n
Quote
very better than McShield which forces you to script behind because it doesn't delete all the infection

Stating this fact at least you should explain to people how this malware works, not to get far confusion. Such publicly claiming this is a serious accusation.
So @all, allow me to clarify this in the simplest possible terms:
These script worms has the job to seek any posible USB attached device and to copy his malware file on USB device in attempt for future spreading or re-infections and vice versa.
*This means:
- If USB device is infected and host system if clean, malware from USB shall load malware o host system.
- If USB device is clean and host system is infected, malware from host shall load malware setting and files on USB device.
Result: If you attempt to clean USB device while host system is infected, re-infections occur. If you attempt to clean host system while attached USB device is infected, re-infections occur.

Let's go further ... If MCShield attempt to preform his job (to clean malware from USB) he will do that. MCS shall targets this malware family using more than one routines. But if host system is infected (precisely, if AV/AM program does not do his part of job as they should) it turns out that MCShield doesn't complete disinfection, but it does. The trick is, if malware is still alive and loaded on host, re-infections on USB will occur. MCShield shall target the infection again . . re-infection . . and loop may occour.
It is not true that MCS does not do his job, it's actually the other way around. MCShield does his job as it should but some other program doesn't do the job from his side.
« Last Edit: March 21, 2014, 07:42:17 AM by magna86 »

gen-hackman

  • Guest
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #26 on: March 21, 2014, 09:08:28 AM »
We believe that cleaning malware from the computer itself should be left for AV/AM program or some other tool. MCShield as a program should not interfere in AM/AV's malware cleaning process. MCS does not seek malware on the host system. Not designed for it and that isn't MCS's job. His job is clearly stated in the description. To make shure USB devices are clean.

04 - HKCU\..\Run : [MCShield Monitor] C:\Program Files\MCShield\mcshieldrtm.exe

F3 - HKCU\..\Windows : [Load] C:\Users\USER\LOCALS~1\Temp\ccavzxccu.exe
04 - HKCU\..\Run : [sdfsgj] wscript.exe //B "C:\Users\USER\AppData\Local\Temp\sdfsgj.vbs"
Found ! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\sdfsgj.vbs
Found ! H:\sdfsgj.vbs
Found ! C:\Users\USER\AppData\Local\Temp\sdfsgj.vbs
Found ! H:\Red.lnk
Found ! H:\Voter ID ko.lnk
Found ! H:\RoboCop.lnk

Found ! C:\Users\USER\AppData\Local\Temp\userid
Found ! HKU\S-1-5-21-29226177-2797569431-4076014346-1000\Software\Microsoft\Windows\CurrentVersion\Run|sdfsgj

let me have a little doubt....

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Shortcut virus - Location: cmd (C:\Windows\System32)
« Reply #27 on: March 21, 2014, 10:16:12 AM »
That's why we have Anti-VBS/VBE. MCShield will not go to a system and start looking round for the VBS file. I've never used USBFix. I will look at it on the weekend (It's Friday morning here)...

Please let Magna do his job. We can take this into a PM and I can contact SOSVirus at the same time via email
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.