Author Topic: USB "DATA Administrator" Malware  (Read 4444 times)

0 Members and 1 Guest are viewing this topic.

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
USB "DATA Administrator" Malware
« on: March 14, 2015, 05:57:27 AM »
Once again I ask to those who have more knowledge than me, thanks in advance. My problem is the following:

I used my usb pendrive on a friend's computer and it got infected, I didn't pluged it into my computer yet.

Malware Demeanour:
It creates a Data Administrator.exe file on the root of the drive. And also it replicates itself inside every folder of the drive with the [folder].exe name. It uses folder icons.

I don't know what kind of malware i'm facing, my concerns are the following:
1- Avast will kill it on sight if I plug the pendrive?
2-If the answer is no, how do I deal with the infected device? Is there anything I can do to prevent the infection of my computer before I do format the device?

Thanks again

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31073
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: USB "DATA Administrator" Malware
« Reply #1 on: March 14, 2015, 11:06:36 AM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: USB "DATA Administrator" Malware
« Reply #2 on: March 14, 2015, 11:08:57 AM »
Quote
1- Avast will kill it on sight if I plug the pendrive?
MCShield will (should) kill it ....... 
then continue with Malwarebytes and FRST logs from the guide Eddy gave you


Quote
I used my usb pendrive on a friend's computer and it got infected, I didn't pluged it into my computer yet.
your friend need to come here and get his computer cleaned


Quote
Malware Demeanour:
It creates a Data Administrator.exe file on the root of the drive. And also it replicates itself inside every folder of the drive with the [folder].exe name. It uses folder icons.
how do you know this?
is this what it has done in your friends computer?


« Last Edit: March 14, 2015, 04:16:21 PM by Pondus »

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: USB "DATA Administrator" Malware
« Reply #3 on: March 14, 2015, 04:10:11 PM »
Yes, it did that to the compute and also to the pendrive. My friend's computer is not connected to the Internet, we don't know how he got the infection, but probably vía another pendrive. He is not coming here, a format should do it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: USB "DATA Administrator" Malware
« Reply #4 on: March 14, 2015, 04:25:51 PM »
Quote
My friend's computer is not connected to the Internet, we don't know how he got the infection, but probably vía another pendrive.
if using penndrives you should always have MCShield installed .....
it usually manage to do its work without signatures, if computer is not online you can download offline database here  http://www.mcshield.net/download.html



Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: USB "DATA Administrator" Malware
« Reply #5 on: March 17, 2015, 07:51:37 PM »
I plugged the drive and Mchield said it was clean. Its a posibbility because I deleted the files the Malware created before removing it from my friend's computer. The logs from the computer I uses are attached. Waiting for more instructions.
« Last Edit: March 17, 2015, 08:14:06 PM by darth_shaker »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: USB "DATA Administrator" Malware
« Reply #6 on: March 17, 2015, 08:43:24 PM »
Looks clean apart from a few orphans, are you experiencing any problems ?

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
BHO: No Name -> {AA58ED58-01DD-4d91-8333-CF10577473F7} ->  No File
BHO-x32: No Name -> {AA58ED58-01DD-4d91-8333-CF10577473F7} ->  No File
BHO-x32: No Name -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} ->  No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-3911254397-2388004393-920576364-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: USB "DATA Administrator" Malware
« Reply #7 on: March 17, 2015, 09:41:31 PM »
Here is the logs.  Everything seems fine.

By the way, One unrelated question, since the forum was updated I cant login with my laptop, is it using java now or some sort of software im missing?

Offline darth_shaker

  • Jr. Member
  • **
  • Posts: 48
Re: USB "DATA Administrator" Malware
« Reply #8 on: March 18, 2015, 01:04:34 AM »
UPDATE:
 My friend has send me an image taken with his mobile phone, it's other of the malware's effects, it shows this screen every few hours  (maybe is this its main purpose?). I attach it for malware identification if posible.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: USB "DATA Administrator" Malware
« Reply #9 on: March 18, 2015, 04:10:22 PM »
It is the brontok worm and your friend really should get it cleaned otherwise the infection will spread to anyone else who has a USB from that computer