Author Topic: I'm an idiot  (Read 2693 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
I'm an idiot
« on: February 07, 2014, 02:01:12 AM »
Uhh, so yeah. Title explains it all. Except the fix for it won't work.

It's a VBS worm. I've removed the attached USB devices, and Anti-VBS/VBE x64 will not remove it all. I can't find anything like wscript.exe running in Task Manager. MCShield detects and removes just to be reinfected. I need my USB's for school tomorrow. Ideas?

Do you guys need OTL?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #1 on: February 07, 2014, 02:17:20 AM »
OTL + Extra's

MBAM Coming. Anti VBS/VBE attached.

THen 30 seconds later. Run Anti-VBS again.

Also who is this User? Taraneh

This computer has 1 user account, and that is me. Not Taraneh. User account name for me is Michael
« Last Edit: February 07, 2014, 02:20:24 AM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: I'm an idiot
« Reply #2 on: February 07, 2014, 07:11:54 AM »
Can you attach FRST report?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #3 on: February 07, 2014, 11:20:01 AM »
FRST + Addition.txt are attached.

Thanks Twin
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: I'm an idiot
« Reply #4 on: February 07, 2014, 03:22:01 PM »
1. Please download ComboFix by sUBs from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
Note: ComboFix must be downloaded to your Desktop.


--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
  • Right click on the avast! system tray icon () in the lower right corner of the screen and scroll up to avast! shield controls;
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.

--------------------------------------------------------------------
3. Run ComboFix. Click on I Agree!

- ComboFix will display DISCLAIMER of warranty on software.
By clicking I Agree ComboFix shall continue.

- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.

--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
Attach log reports ( ComboFix.txt) back to topic.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #5 on: February 07, 2014, 03:45:10 PM »
At school right now. Will do that when I get home.

Thanks for the help. Time to report that to Magna86?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: I'm an idiot
« Reply #6 on: February 07, 2014, 04:05:28 PM »
What to report?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #7 on: February 07, 2014, 05:39:03 PM »
Is Magna not one of the authors of Anti-VBS/VBE? If not, Nevermind. I was going to tell him about Anti-VBS/VBE not removing the infection fully, and the fact it just comes back w/o anything plugged in..

Ohhhh. I see my mistake already. Anti-VBSVBE is posting the previous detections.... Not redetecting it. I just need to let MCShield pick it up and remove it. Wow.
« Last Edit: February 07, 2014, 05:44:48 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: I'm an idiot
« Reply #8 on: February 07, 2014, 05:57:21 PM »
dr_Bora created this tool :)

Did you fixed issues you had?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #9 on: February 07, 2014, 07:40:40 PM »
dr_Bora created this tool :)

Did you fixed issues you had?

1) Oh, I thought Magna86 was a Author or co-author...
2) No, Still at school. However, at this point my only question remains. Who is the User Account Taraneh? This is a personal PC that no one in my household has access to.

Regarding the VBS Worm. I was worried because I thought Anti-VBS/VBE was redetecting the Malware. But I didn't see the dates of the scans. Thus I thought the malware was "Regenerating" hence my comment about not seeing wscript.exe in task Manager. At this point, all I need to do is attach my USB sticks for MCShield to clean them.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I'm an idiot
« Reply #10 on: February 07, 2014, 11:59:25 PM »
Yeah, I'm clean now. Thanks twin for the help :)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.