Author Topic: Shortcut virus - location: cmd (C:\Windows\System32) ????  (Read 8857 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Shortcut virus - location: cmd (C:\Windows\System32) ????
« on: February 17, 2015, 04:38:08 AM »
hi all!
my USB drive picked up a virus from an Internet cafe, and now every time that I've inserted an USB in the laptop my files turned into shortcuts. I right-clicked one of the shortcuts, and looked at where its target location is, and it's somewhere in System32. When I open its target location, it takes me to System32, and the file in System32 that it highlights is cmd.exe

plzz help  me:(


REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #2 on: February 17, 2015, 05:01:59 AM »
i found some old topic, and maby you can help me here? i need code for  fixlist.txt

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37621
  • Not a avast user
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #3 on: February 17, 2015, 07:57:37 AM »
see here  https://forum.avast.com/index.php?topic=53253.0
 scroll down to  SPECIFIC INFECTIONS LOGS  run MCShield as instructed, this log you copy and paste in next reply

essexboy will be online later today and help you


REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #4 on: February 17, 2015, 01:59:52 PM »
ok thanks,  im waiting him,

here log file from MCShield,  its show me program deleted virus but after some seconds its back:(
« Last Edit: February 17, 2015, 02:02:46 PM by Anzori »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31078
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #5 on: February 17, 2015, 02:01:25 PM »
Please attach the log again, this time saved as plain text (UTF-8)

REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #6 on: February 17, 2015, 02:08:07 PM »
again problem with log,



MCShield ::Anti-Malware Tool:: http://www.mcshield.net/

>>> v 3.0.5.28 / DB: 2015.2.15.1 / Windows 8.1 <<<


17.02.2015 13:56:00 > Drive F: - scan started (no label ~1912 MB, FAT flash drive )...



---> Executing generic S&D routine... Searching for files hidden by malware...


---> Items to process: 1

---> F:\Sexy.jpg > unhidden.



>>> F:\Sexy.lnk - Malware > Deleted. (15.02.17. 13.56 Sexy.lnk.650097; MD5: fde45e6ed202ee88663341bfffa68f27)

>>> F:\MerciJacquieMichel.vbe - Malware > Deleted. (15.02.17. 13.56 MerciJacquieMichel.vbe.139808; MD5: 08efa9b636991a80da1a6fd09fccce5e)

>>> F:\System Volume Information.lnk - Malware > Deleted. (15.02.17. 13.56 System Volume Information.lnk.912023; MD5: 866f6d8cd08f0d5f7d6c2aaad05421c6)

> Resetting attributes: F:\System Volume Information < Successful.


=> Malicious files   : 3/3 deleted.
=> Hidden folders    : 1/1 unhidden.
=> Hidden files      : 1/1 unhidden.

____________________________________________

::::: Scan duration: (Interactive mode) ::::
____________________________________________

« Last Edit: February 17, 2015, 02:19:06 PM by Anzori »

REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #7 on: February 17, 2015, 02:38:24 PM »
nobody cant help me? :-[

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76029
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #8 on: February 17, 2015, 02:39:34 PM »
Be patient, it might take a while...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #9 on: February 17, 2015, 02:59:32 PM »
in task manager im kill process lssass  and Microsoft ® Windows Based Script Host,
after disable thise programs in autorun,
flash usb shows me file sexy( size 50 mg) im deleted ,  after reconect usb and it was empty no virus!  im enable autorun process again  and after restarting pc  shortcut of sexy file ''virus'' again in my  flash usb:((((


p.s.  sory for my bad english  :P
« Last Edit: February 17, 2015, 03:01:04 PM by Anzori »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #10 on: February 17, 2015, 04:53:48 PM »
Run MCShield on completion of the FRST fix please

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKU\S-1-5-21-2651378886-156977901-1411103180-1001\...\Run: [MerciJacquieMichel] => wscript.exe //B "C:\Users\anzori\AppData\Local\Temp\MerciJacquieMichel.vbe" <===== ATTENTION
HKU\S-1-5-21-2651378886-156977901-1411103180-1001\...\Run: [Microsoft] => C:\Users\anzori\AppData\Roaming\lssass.exe [52428800 2012-12-10] ()
HKU\S-1-5-21-2651378886-156977901-1411103180-1001\...\Run: [HKCU] => C:\Users\anzori\AppData\Roaming\windir\svchost.exe [52428800 2012-12-10] ()
Startup: C:\Users\anzori\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MerciJacquieMichel.vbe ()
U3 pxldrpog; \??\C:\Users\anzori\AppData\Local\Temp\pxldrpog.sys [X]
2015-02-16 21:34 - 2012-12-10 15:48 - 52428800 ___SH () C:\Users\anzori\AppData\Roaming\lssass.exe
C:\Users\anzori\AppData\Local\Temp\MerciJacquieMichel.vbe
C:\Users\anzori\AppData\Roaming\lssass.exe
C:\Users\anzori\AppData\Roaming\windir
C:\Users\anzori\AppData\Local\Temp\pxldrpog.sys
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #11 on: February 17, 2015, 05:45:07 PM »
i did it,  i think its over!  thank you very very! 

how i can make thise fixlist.txt  for my other pc?
« Last Edit: February 17, 2015, 05:54:57 PM by Anzori »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37621
  • Not a avast user
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #12 on: February 17, 2015, 06:03:58 PM »
Quote
  how i can make thise fixlist.txt  for my other pc? 
by attaching logs from that computer as you did with this one.... But dont start before essexboy say so, he is not finish with this one yet


REDACTED

  • Guest
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #13 on: February 17, 2015, 06:08:46 PM »
i cant do it without ataching files here?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37621
  • Not a avast user
Re: Shortcut virus - location: cmd (C:\Windows\System32) ????
« Reply #14 on: February 17, 2015, 06:16:35 PM »
i cant do it without ataching files here?
the fix made is based on the logs that comes from that specific computer  ...... read the red txt in essexboys post