Author Topic: Servieca.vbs Virus even the famouse antivirus can't detect  (Read 19777 times)

0 Members and 1 Guest are viewing this topic.

gasparmx

  • Guest
Servieca.vbs Virus even the famouse antivirus can't detect
« on: December 14, 2012, 05:11:27 AM »
Recently my PC in Mexico got infected by an annoying virus who replaces every file in usb with shortcuts. Avast can't detect this thing, bypassed my Avast Internet Security. Im kinda annoyed because i tought Avast could protect me for everything, anyway i leave this.

A tutorial how to eliminate this annoying virus called Servieca.vbs http://www.taringa.net/posts/hazlo-tu-mismo/15946707/Como-eliminar-el-Virus-Servieca_vbs-Crea-Accesos-Directos.html

I atacched the file Servieca.vbs anyway im uninstalling it manually. Even the famouse antivirys Bitdefender and avast can't detect this thing.


All files on my usb are like this.
C:\Windows\system32\cmd.exe /c start Servieca.vbs&start mumble-1.2.3a.msi & exit

Malwarebytes, Kaspersky, Bitdefender detects nothing even adwcleaner 2.0 show my pc as clean.
Im scared of put my usb on my pc because this virus can back.

Servieca
Link removed
« Last Edit: December 15, 2012, 07:22:51 AM by gasparmx »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #1 on: December 14, 2012, 08:15:08 AM »
Quote
Im kinda annoyed because i tought Avast could protect me for everything, anyway i leave this.
no security program have 100% detection....and never will

if you have a infection problem....
follow the guide here and attach the logs.   http://forum.avast.com/index.php?topic=53253.0
« Last Edit: December 14, 2012, 03:20:59 PM by Pondus »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #2 on: December 14, 2012, 12:14:21 PM »
Quote
Avast can't detect this thing, bypassed my Avast Internet Security.
https://www.virustotal.com/file/dbc0ec30e3dc431ff9c7559479901ee6fd0a7298bf16148e10004efaf12c1b68/analysis/1355484806/

Sendt avast lab   ;)

« Last Edit: December 14, 2012, 01:22:17 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #3 on: December 14, 2012, 03:01:36 PM »
Hi gasparmx,

Break that second link as hxtp pr wXw, so the unaware wont click through, please.
Quttera flagged this as potentionally suspicious file:
/js/master_85930.js
File size[byte]:   
553962
Severity:   
Potentially Suspicious
Details:   
Detected procedure that is commonly used in suspicious activity.
Reason:   
Too low entropy detected in string 'undefined|undefined|undefined|undefined|undefined|undefined|undefined|undefined|undefined|undefined|' of length 5119 which may points to obfuscation or shellcode.
MD5:   
4E6D0946F43611FAEE3F6E62D42CBB0A
Quttera scan results

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #4 on: December 14, 2012, 03:08:07 PM »
@ gasparmx
I don't believe the link should be broken, it should be completely removed.

Samples should be sent directly to avast not hosted on a file sharing site where you have no control over who can download it or what they might do with it.

It has already been sent to the avast labs, so that mediafire link can now be removed completely.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #5 on: December 14, 2012, 03:15:01 PM »
Agree with DavidR,

Better to remove that link alltogether, as these should be send directly to virus AT avast dot com. Always remember that malcreants look over our shoulder here as well,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
« Last Edit: December 14, 2012, 08:59:36 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

true indian

  • Guest

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #8 on: December 16, 2012, 02:38:27 PM »
@ gasparmx

This is a new type of infection. MCShield is a program that will prevent and disinfect any infection that comes with a USB device.
Although he has able to see, disinfect and remove this malware (due to MCShield detecting heur. routines) these days MCShield has been fully optimized for this type of malware.

---------------------------------




Download MCShield from one of the following links:

MyCity -  Official download link
Softpedija - Mirror download link

  • Double click MCShield-Setup to install the application.
  • Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
  • Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.
When all scanning is done, you need to attach a logreport that has made MCShield.

Start -> All Programs -> MCShield -> Logs

Attach here -> AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.



--------------------------




It would be good to check OS for malware. Read these instructions for running AdwCleaner, OTL and aswMBR tool and attach here their reports for review.
http://forum.avast.com/index.php?topic=53253.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #9 on: December 16, 2012, 02:53:45 PM »
Hi Magna86 where do I go to report a false positive ? 

It is detecting Reatogo.exe as infected, this is part of the programme I use with OTLPE to work outside of windows
http://www.reatogo.de/REATOGO.htm

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Servieca.vbs Virus even the famouse antivirus can't detect
« Reply #10 on: December 16, 2012, 03:04:48 PM »
Hi essexboy,

You may report FP to MCShield author's.

This is MCShield support mail.
Quote
MCShield.Support|AT|gmail.com (replace |AT| with @).

(dr_Bora is mostly behind the mail)
Thanks for reporting. :)